open-menu
closeme
File and Directory Discovery
calendar
Jan 9, 2023
·
Elastic
Host
Windows
Threat Detection
Discovery
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process from Conhost
calendar
Jan 9, 2023
·
Elastic
Host
Windows
Threat Detection
Defense Evasion
·
Share on:
twitter
facebook
linkedin
copy
Threat Intel Filebeat Module (v7.x) Indicator Match
calendar
Jan 9, 2023
·
Elastic
Windows
Elastic Endgame
Network
Continuous Monitoring
SecOps
Monitoring
·
Share on:
twitter
facebook
linkedin
copy
Whitespace Padding in Process Command Line
calendar
Jan 9, 2023
·
Elastic
Host
Windows
Threat Detection
Defense Evasion
·
Share on:
twitter
facebook
linkedin
copy
Potential Privilege Escalation via Local Kerberos Relay over LDAP
calendar
Aug 1, 2022
·
Elastic
Host
Windows
Threat Detection
Privilege Escalation
Credential Access
·
Share on:
twitter
facebook
linkedin
copy
Potential PrintNightmare Exploit Registry Modification
calendar
Mar 17, 2022
·
Elastic
Host
Windows
Threat Detection
Privilege Escalation
·
Share on:
twitter
facebook
linkedin
copy
Potential PrintNightmare File Modification
calendar
Mar 17, 2022
·
Elastic
Host
Windows
Threat Detection
Privilege Escalation
·
Share on:
twitter
facebook
linkedin
copy
Network Connection via Mshta
calendar
Oct 20, 2021
·
Elastic
Host
Windows
Threat Detection
Defense Evasion
·
Share on:
twitter
facebook
linkedin
copy
PowerShell spawning Cmd
calendar
Apr 21, 2021
·
Elastic
Host
Windows
Threat Detection
Execution
·
Share on:
twitter
facebook
linkedin
copy
Query Registry via reg.exe
calendar
Apr 21, 2021
·
Elastic
Host
Windows
Threat Detection
Discovery
·
Share on:
twitter
facebook
linkedin
copy
Process Discovery via Tasklist
calendar
Apr 15, 2021
·
Elastic
Host
Windows
Threat Detection
Discovery
·
Share on:
twitter
facebook
linkedin
copy
Trusted Developer Application Usage
calendar
Apr 15, 2021
·
Elastic
Host
Windows
Threat Detection
Defense Evasion
·
Share on:
twitter
facebook
linkedin
copy
Execution via Regsvcs/Regasm
calendar
Mar 19, 2021
·
Elastic
Host
Windows
Threat Detection
Execution
·
Share on:
twitter
facebook
linkedin
copy
to-top