open-menu
closeme
Operator Bloopers Cobalt Strike Commands
calendar
Mar 18, 2025
·
attack.execution
attack.t1059.003
stp.1u
·
Share on:
twitter
facebook
linkedin
copy
Bumblebee WmiPrvSE execution pattern
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1036
·
Share on:
twitter
facebook
linkedin
copy
Conhost Suspicious Command Execution
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1564.003
dist.public
·
Share on:
twitter
facebook
linkedin
copy
Custom Cobalt Strike Command Execution
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1562.001
attack.execution
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Deleting Windows Defender scheduled tasks
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Enable WDigest using PowerShell
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enabling RDP service via reg.exe command execution
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.lateral-movement
attack.t1021.001
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Enabling restricted admin mode
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Exchange WebShell Creation
calendar
Mar 18, 2025
·
attack.t1505.003
attack.persistence
attack.t1190
attack.initial-access
·
Share on:
twitter
facebook
linkedin
copy
Execution of ZeroLogon PoC executable
calendar
Mar 18, 2025
·
attack.execution
attack.lateral-movement
attack.t1210
·
Share on:
twitter
facebook
linkedin
copy
FlawedGrace spawning threat injection target
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1055
dist.public
·
Share on:
twitter
facebook
linkedin
copy
Hiding local user accounts
calendar
Mar 18, 2025
·
attack.t1564.002
attack.defense-evasion
·
Share on:
twitter
facebook
linkedin
copy
JavaScript Execution Using MSDOS 8.3 File Notation
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1059
dist.public
·
Share on:
twitter
facebook
linkedin
copy
Lazagne dumping credentials
calendar
Mar 18, 2025
·
attack.credential-access
attack.t1555
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz Command Line With Ticket Export
calendar
Mar 18, 2025
·
attack.credential-access
attack.t1003
attack.t1003.001
attack.t1003.002
attack.t1003.004
attack.t1003.005
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
Mshta Executing from Registry
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1218.005
·
Share on:
twitter
facebook
linkedin
copy
Operator Bring Your Own Tools
calendar
Mar 18, 2025
·
attack.command-and-control
attack.t1105
·
Share on:
twitter
facebook
linkedin
copy
QBot process creation from scheduled task REGSVR32 (regsvr32.exe), -s flag and SYSTEM in the command line
calendar
Mar 18, 2025
·
attack.persistence
attack.privilege-escalation
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
Renamed Autohotkey Binary
calendar
Mar 18, 2025
·
attack.defense-evasion
attack.t1036.003
·
Share on:
twitter
facebook
linkedin
copy
SplashTop Process
calendar
Mar 18, 2025
·
attack.lateral-movement
attack.t1133
attack.command-and-control
attack.t1219
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Commands by SQL Server
calendar
Mar 18, 2025
·
attack.initial-access
attack.persistence
attack.privilege-escalation
·
Share on:
twitter
facebook
linkedin
copy
Viewing remote directories
calendar
Mar 18, 2025
·
attack.discovery
attack.t1083
dist.public
·
Share on:
twitter
facebook
linkedin
copy
AdFind Discovery
calendar
Aug 2, 2024
·
attack.discovery
attack.t1018
attack.t1482
attack.t1069.002
attack.t1087.002
attack.s0552
·
Share on:
twitter
facebook
linkedin
copy
AteraAgent malicious installations
calendar
Aug 2, 2024
·
attack.execution
attack.t1059.006
·
Share on:
twitter
facebook
linkedin
copy
CHCP CodePage Locale Lookup
calendar
Aug 2, 2024
·
attack.discovery
attack.t1614.001
·
Share on:
twitter
facebook
linkedin
copy
Default Account Usage
calendar
Aug 2, 2024
·
attack.t1136
attack.t1136.001
·
Share on:
twitter
facebook
linkedin
copy
Driverquery Lookup
calendar
Aug 2, 2024
·
attack.discovery
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Emotet Child Process Spawn Pattern
calendar
Aug 2, 2024
·
attack.discovery
attack.t1087
·
Share on:
twitter
facebook
linkedin
copy
List remote processes using tasklist
calendar
Aug 2, 2024
·
attack.discovery
attack.t1057
dist.public
·
Share on:
twitter
facebook
linkedin
copy
MOFComp Execution
calendar
Aug 2, 2024
·
attack.execution
attack.t1546.003
·
Share on:
twitter
facebook
linkedin
copy
NIM Pass The Hash Tooling Detection
calendar
Aug 2, 2024
·
attack.t1136
·
Share on:
twitter
facebook
linkedin
copy
Nslookup Local
calendar
Aug 2, 2024
·
attack.discovery
attack.t1016
·
Share on:
twitter
facebook
linkedin
copy
Operator Bloopers Cobalt Strike Modules
calendar
Aug 2, 2024
·
attack.execution
attack.t1059.003
·
Share on:
twitter
facebook
linkedin
copy
PSEXEC Custom Named Service Binary
calendar
Aug 2, 2024
·
Share on:
twitter
facebook
linkedin
copy
Registry Query for WDigest
calendar
Aug 2, 2024
·
attack.discovery
attack.t1012
·
Share on:
twitter
facebook
linkedin
copy
Scheduled task executing powershell encoded payload from registry
calendar
Aug 2, 2024
·
attack.execution
attack.persistence
attack.t1053.005
attack.t1059.001
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Scheduled Task Creation to execute LOLbins
calendar
Aug 2, 2024
·
attack.persistence
attack.t1053.005
·
Share on:
twitter
facebook
linkedin
copy
System Time Lookup
calendar
Aug 2, 2024
·
attack.discovery
attack.t1124
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Windows Feature - Defender
calendar
Aug 2, 2024
·
attack.t1562.001
·
Share on:
twitter
facebook
linkedin
copy
Ursnif Loader
calendar
Aug 2, 2024
·
Share on:
twitter
facebook
linkedin
copy
WinEvent Security Query
calendar
Aug 2, 2024
·
attack.t1033
·
Share on:
twitter
facebook
linkedin
copy
to-top