|
Splunk RCE Through Arbitrary File Write to Windows System Root
|
Splunk
|
T1210
|
Hunting
|
Splunk Vulnerabilities
|
2026-05-14
|
|
Windows AD add Self to Group
|
Windows Event Log Security 4728
|
T1098
|
TTP
|
Medusa Ransomware, Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows PowerShell Add Module to Global Assembly Cache
|
Powershell Script Block Logging 4104
|
T1505.004
|
TTP
|
IIS Components
|
2026-05-13
|
|
Windows Group Discovery Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
T1069.002
|
Hunting
|
Active Directory Discovery, IcedID, Cleo File Transfer Software, Graceful Wipe Out Attack, Windows Discovery Techniques, Rhysida Ransomware, Windows Post-Exploitation, SolarWinds WHD RCE Post Exploitation, Volt Typhoon, Prestige Ransomware, Microsoft WSUS CVE-2025-59287, Azorult, Medusa Ransomware
|
2026-05-13
|
|
CMLUA Or CMSTPLUA UAC Bypass
|
Sysmon EventID 7
|
T1218.003
|
TTP
|
LockBit Ransomware, DarkSide Ransomware, Ransomware, ValleyRAT
|
2026-05-13
|
|
Windows PowerShell Invoke-Sqlcmd Execution
|
Powershell Script Block Logging 4104
|
T1059.001
T1059.003
|
Hunting
|
SQL Server Abuse, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Potato Privilege Escalation Tool Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1068
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Windows InstallUtil URL in Command Line
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.004
|
TTP
|
Living Off The Land, Compromised Windows Host, Cisco Network Visibility Module Analytics, Signed Binary Proxy Execution InstallUtil
|
2026-05-13
|
|
Windows New Service Security Descriptor Set Via Sc.EXE
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1564
|
Anomaly
|
Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Windows Excel Spawning Microsoft Project Application
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
|
Anomaly
|
PathWiper
|
2026-05-13
|
|
Deleting Shadow Copies
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
CISA AA22-264A, Black Basta Ransomware, Compromised Windows Host, Ransomware, VanHelsing Ransomware, Rhysida Ransomware, Chaos Ransomware, Medusa Ransomware, SamSam Ransomware, Storm-2460 CLFS Zero Day Exploitation, Windows Log Manipulation, Cactus Ransomware, Clop Ransomware, Void Manticore, LockBit Ransomware, Prestige Ransomware, Termite Ransomware, DarkGate Malware
|
2026-05-13
|
|
Windows Rasautou DLL Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055.001
T1218
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host, Hellcat Ransomware
|
2026-05-13
|
|
Windows Credentials from Password Stores Deletion
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1555
|
TTP
|
DarkGate Malware, NetSupport RMM Tool Abuse, Compromised Windows Host
|
2026-05-13
|
|
Windows Impair Defense Set Win Defender Smart Screen Level To Warn
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
USN Journal Deletion
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070
|
TTP
|
Ransomware, Windows Log Manipulation
|
2026-05-13
|
|
Mshta spawning Rundll32 OR Regsvr32 Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
TTP
|
Living Off The Land, Trickbot, APT37 Rustonotto and FadeStealer, IcedID
|
2026-05-13
|
|
Logon Script Event Trigger Execution
|
Sysmon EventID 13
|
T1037.001
|
TTP
|
VIP Keylogger, Windows Persistence Techniques, Data Destruction, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Execution of File with Multiple Extensions
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
|
TTP
|
DarkGate Malware, Masquerading - Rename System Utilities, Windows File Extension and Association Abuse, AsyncRAT
|
2026-05-13
|
|
MSBuild Suspicious Spawned By Script Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1127.001
|
TTP
|
Storm-2460 CLFS Zero Day Exploitation, Trusted Developer Utilities Proxy Execution MSBuild
|
2026-05-13
|
|
Windows Anomalous Registry Value Length in Environment Key
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
VIP Keylogger
|
2026-05-13
|
|
PowerShell 4104 Hunting
|
Powershell Script Block Logging 4104
|
T1059.001
|
Hunting
|
SystemBC, Braodo Stealer, Data Destruction, Lumma Stealer, PHP-CGI RCE Attack on Japanese Organizations, GhostRedirector IIS Module and Rungan Backdoor, Water Gamayun, Cleo File Transfer Software, Axios Supply Chain Post Compromise, APT37 Rustonotto and FadeStealer, Hermetic Wiper, Medusa Ransomware, Flax Typhoon, Scattered Spider, CISA AA24-241A, Rhysida Ransomware, MuddyWater, Salt Typhoon, Cactus Ransomware, Malicious PowerShell, DarkGate Malware, XWorm, China-Nexus Threat Activity, 0bj3ctivity Stealer, Microsoft WSUS CVE-2025-59287, CISA AA23-347A, Hellcat Ransomware, Interlock Ransomware
|
2026-05-13
|
|
Windows Password Policy Discovery with Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1201
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Potential Cloudflared Network Connection
|
Sysmon EventID 3
|
T1572
|
Hunting
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows WMI Process And Service List
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Reg exe Manipulating Windows Services Registry Keys
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.011
|
TTP
|
Windows Persistence Techniques, Windows Service Abuse, Living Off The Land
|
2026-05-13
|
|
Windows Gather Victim Identity SAM Info
|
Sysmon EventID 7
|
T1589.001
|
Hunting
|
Brute Ratel C4
|
2026-05-13
|
|
Windows Local Administrator Credential Stuffing
|
Windows Event Log Security 4624, Windows Event Log Security 4625
|
T1110.004
|
TTP
|
Active Directory Privilege Escalation, Scattered Lapsus$ Hunters, Active Directory Lateral Movement
|
2026-05-13
|
|
Suspicious Copy on System32
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
|
Anomaly
|
Qakbot, Water Gamayun, Sandworm Tools, Compromised Windows Host, AsyncRAT, Volt Typhoon, IcedID, Unusual Processes
|
2026-05-13
|
|
Spike in File Writes
|
Sysmon EventID 11
|
N/A
|
Anomaly
|
Rhysida Ransomware, SamSam Ransomware, Ransomware, Ryuk Ransomware
|
2026-05-13
|
|
Windows PowerShell WMI Win32 ScheduledJob
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Detect RTLO In Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.002
|
TTP
|
Spearphishing Attachments
|
2026-05-13
|
|
Detect RTLO In File Name
|
Sysmon EventID 11
|
T1036.002
|
TTP
|
Spearphishing Attachments
|
2026-05-13
|
|
Windows Administrative Shares Accessed On Multiple Hosts
|
Windows Event Log Security 5140, Windows Event Log Security 5145
|
T1135
|
TTP
|
Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Impair Defense Disable Controlled Folder Access
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, BlankGrabber Stealer
|
2026-05-13
|
|
Windows MSIExec DLLRegisterServer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
TTP
|
Water Gamayun, Windows System Binary Proxy Execution MSIExec
|
2026-05-13
|
|
Windows ESX Admins Group Creation Security Event
|
Windows Event Log Security 4737, Windows Event Log Security 4727, Windows Event Log Security 4730
|
T1136.001
T1136.002
|
TTP
|
VMware ESXi AD Integration Authentication Bypass CVE-2024-37085
|
2026-05-13
|
|
Windows TeamCity Payload Execution from Temp Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
T1190
T1505.003
|
TTP
|
JetBrains TeamCity Vulnerabilities, JetBrains TeamCity Unauthenticated RCE
|
2026-05-13
|
|
Windows Screen Capture in TEMP folder
|
Sysmon EventID 11
|
T1113
|
TTP
|
Braodo Stealer, APT37 Rustonotto and FadeStealer, VIP Keylogger, Crypto Stealer, StealC Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Windows Rundll32 with Non-Standard File Extension
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
Anomaly
|
Gh0st RAT, Living Off The Land, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows AD Privileged Object Access Activity
|
Windows Event Log Security 4662
|
T1087.002
|
TTP
|
Active Directory Discovery, BlackSuit Ransomware
|
2026-05-13
|
|
Windows Defender ASR or Threat Configuration Tamper
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
PowerShell Invoke WmiExec Usage
|
Powershell Script Block Logging 4104
|
T1047
|
TTP
|
Scattered Lapsus$ Hunters, Suspicious WMI Use
|
2026-05-13
|
|
Windows Level RMM PowerShell Script Installer
|
Powershell Script Block Logging 4104
|
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Detect Empire with PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Data Destruction, Malicious PowerShell, Hellcat Ransomware, Hermetic Wiper
|
2026-05-13
|
|
ICACLS Grant Command
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222
|
Anomaly
|
Ransomware, Crypto Stealer, Defense Evasion or Unauthorized Access Via SDDL Tampering, XMRig, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Crowdstrike RTR Script Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Anomaly
|
Living Off The Land, Malicious PowerShell, Cobalt Strike, Suspicious MSHTA Activity
|
2026-05-13
|
|
Powershell Load Module in Meterpreter
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
MetaSploit
|
2026-05-13
|
|
Windows Chromium Process Launched with Logging Disabled
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Disable Windows App Hotkeys
|
Sysmon EventID 13
|
T1112
T1685
|
TTP
|
Windows Registry Abuse, XMRig
|
2026-05-13
|
|
GetWmiObject Ds Group with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Explorer.exe Spawning PowerShell or Cmd
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1204.002
|
Hunting
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Suspicious Rundll32 StartW
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Graceful Wipe Out Attack, Cobalt Strike, Hellcat Ransomware, Trickbot, BlackByte Ransomware, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows Binary Execution from an Archive
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Windows PowerView Kerberos Service Ticket Request
|
Powershell Script Block Logging 4104
|
T1558.003
|
TTP
|
Active Directory Kerberos Attacks, Rhysida Ransomware
|
2026-05-13
|
|
Clop Ransomware Known Service Name
|
Windows Event Log System 7045
|
T1543
|
TTP
|
Clop Ransomware, Compromised Windows Host
|
2026-05-13
|
|
System User Discovery With Whoami
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Qakbot, Active Directory Discovery, Winter Vivern, Lotus Blossom Chrysalis Backdoor, Rhysida Ransomware, LAMEHUG, CISA AA23-347A, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Windows Odbcconf Load Response File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.008
|
TTP
|
Living Off The Land
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender Signature Retirement
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Audit Policy Auditing Option Disabled via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
TTP
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows AD Suspicious Attribute Modification
|
Windows Event Log Security 5136
|
T1222.001
T1550
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Spoolsv Writing a DLL - Sysmon
|
Sysmon EventID 11
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Execute Javascript With Jscript COM CLSID
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.005
|
TTP
|
Ransomware
|
2026-05-13
|
|
Windows Impair Defense Define Win Defender Threat Action
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows IOBit Unlocker Extension DLL Registration via Regsvr32
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.010
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Modify Registry Do Not Connect To Win Update
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
RedLine Stealer
|
2026-05-13
|
|
Windows DnsAdmins New Member Added
|
Windows Event Log Security 4732
|
T1098
|
TTP
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Drivers Loaded by Signature
|
Sysmon EventID 6
|
T1014
T1068
|
Hunting
|
CISA AA22-320A, Windows Drivers, AgentTesla, BlackByte Ransomware
|
2026-05-13
|
|
Disabling SystemRestore In Registry
|
Sysmon EventID 13
|
T1490
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, NjRAT
|
2026-05-13
|
|
Windows Proxy Execution of .NET Utilities via Scripts
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218
|
Anomaly
|
VIP Keylogger
|
2026-05-13
|
|
Windows Remote Access Software RMS Registry
|
Sysmon EventID 13
|
T1219
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Large Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
T1135
|
Anomaly
|
Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
Suspicious msbuild path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1127.001
|
TTP
|
Graceful Wipe Out Attack, Storm-2460 CLFS Zero Day Exploitation, Trusted Developer Utilities Proxy Execution MSBuild, Cobalt Strike, BlackByte Ransomware, Living Off The Land, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Windows ConsoleHost History File Deletion
|
Sysmon EventID 26, Sysmon EventID 23
|
T1070.003
|
Anomaly
|
Medusa Ransomware
|
2026-05-13
|
|
Remote Process Instantiation via WMI and PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Kerberos Coercion via DNS
|
Windows Event Log Security 5137, Windows Event Log Security 4662, Windows Event Log Security 5136
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS
|
2026-05-13
|
|
Detect Regsvr32 Application Control Bypass
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.010
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Suspicious Regsvr32 Activity, Cobalt Strike, BlackByte Ransomware, Living Off The Land, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Windows Entra User Management Via Azure CLI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1078.004
T1098
T1136
|
Anomaly
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Windows DNS Query Request To TinyUrl
|
Sysmon EventID 22
|
T1105
|
Anomaly
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Wscript Or Cscript Suspicious Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
T1134.004
T1543
|
Anomaly
|
WhisperGate, Axios Supply Chain Post Compromise, XWorm, VIP Keylogger, NjRAT, MuddyWater, FIN7, Data Destruction, 0bj3ctivity Stealer, Remcos, Unusual Processes, ShrinkLocker
|
2026-05-13
|
|
Windows Outlook Dialogs Disabled from Unusual Process
|
Sysmon EventID 13
|
T1112
T1685
|
TTP
|
Windows Registry Abuse, NotDoor Malware
|
2026-05-13
|
|
Common Ransomware Notes
|
Sysmon EventID 11
|
T1485
|
Hunting
|
Black Basta Ransomware, Ransomware, Rhysida Ransomware, Chaos Ransomware, SamSam Ransomware, Clop Ransomware, LockBit Ransomware, Storm-0501 Ransomware, Termite Ransomware, Ryuk Ransomware, Medusa Ransomware, NailaoLocker Ransomware, Hellcat Ransomware, Interlock Ransomware
|
2026-05-13
|
|
Windows Hosts File Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Gh0st RAT, BlankGrabber Stealer
|
2026-05-13
|
|
Powershell Processing Stream Of Data
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Braodo Stealer, IcedID, XWorm, AsyncRAT, MuddyWater, PXA Stealer, Data Destruction, MoonPeak, Malicious PowerShell, Hermetic Wiper, Medusa Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Exfiltration Over C2 Via Invoke RestMethod
|
Powershell Script Block Logging 4104
|
T1041
|
TTP
|
Water Gamayun, Winter Vivern, APT37 Rustonotto and FadeStealer, Microsoft WSUS CVE-2025-59287, Hellcat Ransomware
|
2026-05-13
|
|
Print Spooler Adding A Printer Driver
|
Windows Event Log Printservice 316
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Security Solution Tampering
|
2026-05-13
|
|
Rundll32 Control RunDLL Hunt
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
Hunting
|
Microsoft MSHTML Remote Code Execution CVE-2021-40444, Living Off The Land, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows Process Injection into Commonly Abused Processes
|
Sysmon EventID 10
|
T1055.002
|
Anomaly
|
SAP NetWeaver Exploitation, BishopFox Sliver Adversary Emulation Framework, Earth Alux, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Recon Using WMI Class
|
Powershell Script Block Logging 4104
|
T1059.001
T1592
|
Anomaly
|
Qakbot, Axios Supply Chain Post Compromise, AsyncRAT, VIP Keylogger, Malicious Inno Setup Loader, Data Destruction, MoonPeak, Malicious PowerShell, Quasar RAT, LockBit Ransomware, Hermetic Wiper, Industroyer2, Scattered Spider, BlankGrabber Stealer
|
2026-05-13
|
|
Domain Controller Discovery with Wmic
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Domain Account Discovery Via Get-NetComputer
|
Powershell Script Block Logging 4104
|
T1087.002
|
Anomaly
|
CISA AA23-347A
|
2026-05-13
|
|
Windows Remote Assistance Spawning Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
Unusual Processes, Compromised Windows Host
|
2026-05-13
|
|
Windows AD SID History Attribute Modified
|
Windows Event Log Security 5136
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Wmic Group Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
|
Anomaly
|
Active Directory Discovery, LAMEHUG
|
2026-05-13
|
|
Windows Steal or Forge Kerberos Tickets Klist
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1558
|
Hunting
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows SIP WinVerifyTrust Failed Trust Validation
|
Windows Event Log CAPI2 81
|
T1553.003
|
Anomaly
|
Subvert Trust Controls SIP and Trust Provider Hijacking
|
2026-05-13
|
|
Windows Modify Registry WuServer
|
Sysmon EventID 13
|
T1112
|
Hunting
|
RedLine Stealer
|
2026-05-13
|
|
Powershell Using memory As Backing Store
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Data Destruction, MoonPeak, Malicious PowerShell, Hermetic Wiper, IcedID, Medusa Ransomware
|
2026-05-13
|
|
Windows RDP Bitmap Cache File Creation
|
Sysmon EventID 11
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows Chromium process Launched with Disable Popup Blocking
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Windows WSUS Spawning Shell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1190
T1505.003
|
TTP
|
Microsoft WSUS CVE-2025-59287
|
2026-05-13
|
|
Windows Service Created with Suspicious Service Name
|
Windows Event Log System 7045
|
T1569.002
|
Anomaly
|
Qakbot, Brute Ratel C4, Snake Malware, Clop Ransomware, Tuoni, Active Directory Lateral Movement, Gh0st RAT, Flax Typhoon, PlugX, CISA AA23-347A
|
2026-05-13
|
|
Windows Credentials from Web Browsers Saved in TEMP Folder
|
Sysmon EventID 11
|
T1555.003
|
TTP
|
Braodo Stealer, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Process With NamedPipe CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
Anomaly
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Malicious Powershell Executed As A Service
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Rhysida Ransomware, Malicious PowerShell, Compromised Windows Host
|
2026-05-13
|
|
CMD Echo Pipe - Escalation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
T1543.003
|
TTP
|
Compromised Windows Host, Cobalt Strike, Graceful Wipe Out Attack, BlackByte Ransomware
|
2026-05-13
|
|
User Discovery With Env Vars PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows BitLockerToGo with Network Activity
|
Sysmon EventID 22
|
T1218
|
Hunting
|
Lumma Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Disable Defender BlockAtFirstSeen Feature
|
Sysmon EventID 13
|
T1685
|
TTP
|
IcedID, SolarWinds WHD RCE Post Exploitation, Windows Registry Abuse, Azorult, CISA AA23-347A
|
2026-05-13
|
|
Windows Proxy Via Netsh
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Windows SqlWriter SQLDumper DLL Sideload
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
APT29 Diplomatic Deceptions with WINELOADER
|
2026-05-13
|
|
Windows GrimResource - MMC Process Accessing APDS DLL
|
Windows Event Log Security 4663
|
T1059.007
T1218.014
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
MacOS - Re-opened Applications
|
Sysmon EventID 1
|
N/A
|
TTP
|
ColdRoot MacOS RAT
|
2026-05-13
|
|
Suspicious Scheduled Task from Public Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
Anomaly
|
Azorult, APT37 Rustonotto and FadeStealer, Medusa Ransomware, Living Off The Land, Scattered Spider, CISA AA24-241A, Crypto Stealer, Salt Typhoon, SolarWinds WHD RCE Post Exploitation, Malicious Inno Setup Loader, Quasar RAT, Ryuk Ransomware, XWorm, Ransomware, China-Nexus Threat Activity, Windows Persistence Techniques, Scheduled Tasks, MoonPeak, NetSupport RMM Tool Abuse, DarkCrystal RAT, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Powershell Execute COM Object
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Data Destruction, Malicious PowerShell, Ransomware, Hermetic Wiper
|
2026-05-13
|
|
Unload Sysmon Filter Driver
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
Disabling Security Tools, CISA AA23-347A
|
2026-05-13
|
|
WSReset UAC Bypass
|
Sysmon EventID 13, Sysmon EventID 12
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, MoonPeak, Living Off The Land
|
2026-05-13
|
|
Windows RMM Tool Execution
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
NetSupport RMM Tool Abuse, Remote Monitoring and Management Software, Suspicious User Agents
|
2026-05-13
|
|
Elevated Group Discovery with PowerView
|
Powershell Script Block Logging 4104
|
T1069.002
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Auto Admin Logon Registry Entry
|
Sysmon EventID 13
|
T1552.002
|
TTP
|
BlackMatter Ransomware, Windows Registry Abuse
|
2026-05-13
|
|
DSQuery Domain Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1482
|
TTP
|
Domain Trust Discovery, Active Directory Discovery, Compromised Windows Host
|
2026-05-13
|
|
Windows Remote Management Execute Shell
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.006
|
Anomaly
|
Crypto Stealer
|
2026-05-13
|
|
Windows Service Stop Attempt
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1489
|
Hunting
|
Gh0st RAT, Scattered Lapsus$ Hunters, Prestige Ransomware, Graceful Wipe Out Attack
|
2026-05-13
|
|
System User Discovery With Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Medusa Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Spoolsv Suspicious Process Access
|
Sysmon EventID 10
|
T1068
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
MS Exchange Mailbox Replication service writing Active Server Pages
|
Sysmon EventID 11, Sysmon EventID 1
|
T1133
T1190
T1505.003
|
TTP
|
Ransomware, ProxyShell, BlackByte Ransomware
|
2026-05-13
|
|
Windows Command and Scripting Interpreter Path Traversal Exec
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Windows Defense Evasion Tactics, Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Compromised Windows Host
|
2026-05-13
|
|
Detect Rundll32 Inline HTA Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
TTP
|
Living Off The Land, NOBELIUM Group, Suspicious MSHTA Activity, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Mailsniper Invoke functions
|
Powershell Script Block Logging 4104
|
T1114.001
|
TTP
|
Data Exfiltration
|
2026-05-13
|
|
Windows Modify Registry DisAllow Windows App
|
Sysmon EventID 13
|
T1112
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Net System Service Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1007
|
Hunting
|
Gh0st RAT, LAMEHUG
|
2026-05-13
|
|
SecretDumps Offline NTDS Dumping Tool
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.003
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Rhysida Ransomware, Storm-0501 Ransomware, Credential Dumping
|
2026-05-13
|
|
Impacket Lateral Movement Commandline Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
WhisperGate, Compromised Windows Host, Graceful Wipe Out Attack, Volt Typhoon, Data Destruction, CISA AA22-277A, Storm-0501 Ransomware, Prestige Ransomware, Active Directory Lateral Movement, Industroyer2, Gozi Malware
|
2026-05-13
|
|
Windows Azure PowerShell Module Installation Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1021.007
T1069.003
T1078
T1098
T1136.003
|
Anomaly
|
Azure Active Directory Persistence, Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
GetWmiObject DS User with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Unusual Intelliform Storage Registry Access
|
Windows Event Log Security 4663
|
T1552.001
|
Anomaly
|
Quasar RAT, Lokibot
|
2026-05-13
|
|
Windows Excessive Service Stop Attempt
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1489
|
TTP
|
XMRig, Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows Sensitive Group Discovery With Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
Anomaly
|
Active Directory Discovery, Rhysida Ransomware, Volt Typhoon, IcedID, Microsoft WSUS CVE-2025-59287, BlackSuit Ransomware
|
2026-05-13
|
|
Windows Office Product Spawned Child Process For Download
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
TTP
|
APT37 Rustonotto and FadeStealer, NjRAT, Spearphishing Attachments, PlugX, CVE-2023-36884 Office and Windows HTML RCE Vulnerability
|
2026-05-13
|
|
Powershell Enable SMB1Protocol Feature
|
Powershell Script Block Logging 4104
|
T1027.005
|
TTP
|
Data Destruction, Malicious PowerShell, Ransomware, Hermetic Wiper
|
2026-05-13
|
|
GetLocalUser with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Suspicious microsoft workflow compiler usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1127
|
TTP
|
Living Off The Land, Trusted Developer Utilities Proxy Execution
|
2026-05-13
|
|
Windows DLL Module Loaded in Temp Dir
|
Sysmon EventID 7
|
T1105
|
Hunting
|
Interlock Rat, Lokibot, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows Modify Registry EnableLinkedConnections
|
Sysmon EventID 13
|
T1112
|
TTP
|
BlackByte Ransomware
|
2026-05-13
|
|
Windows MSIX Package Interaction
|
Windows Event Log AppXPackaging 171
|
T1204.002
|
Hunting
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows Unsigned MS DLL Side-Loading
|
Sysmon EventID 7
|
T1547
T1574.001
|
Anomaly
|
XWorm, China-Nexus Threat Activity, Salt Typhoon, Earth Alux, APT29 Diplomatic Deceptions with WINELOADER, Derusbi
|
2026-05-13
|
|
Kerberos Pre-Authentication Flag Disabled with PowerShell
|
Powershell Script Block Logging 4104
|
T1558.004
|
TTP
|
Active Directory Kerberos Attacks
|
2026-05-13
|
|
Windows Impair Defense Override SmartScreen Prompt
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Impair Defense Overide Win Defender Phishing Filter
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Child Processes of Spoolsv exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1068
|
TTP
|
Data Destruction, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Windows System Script Proxy Execution Syncappvpublishingserver
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1216
T1218
|
TTP
|
Living Off The Land
|
2026-05-13
|
|
Disabled Kerberos Pre-Authentication Discovery With PowerView
|
Powershell Script Block Logging 4104
|
T1558.004
|
TTP
|
Active Directory Kerberos Attacks, Interlock Ransomware
|
2026-05-13
|
|
Windows Obfuscated Files or Information via RAR SFX
|
Sysmon EventID 11
|
T1027.013
|
Anomaly
|
Crypto Stealer, APT37 Rustonotto and FadeStealer, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Remote Process Instantiation via WinRM and Winrs
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.006
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Trickbot Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1055
|
TTP
|
Trickbot, Hellcat Ransomware
|
2026-05-13
|
|
Windows New Custom Security Descriptor Set On EventLog Channel
|
Sysmon EventID 13
|
T1685.001
|
Anomaly
|
Defense Evasion or Unauthorized Access Via SDDL Tampering, LockBit Ransomware
|
2026-05-13
|
|
Windows System Network Config Discovery Display DNS
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1016
|
Anomaly
|
Medusa Ransomware, Water Gamayun, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows File and Directory Permissions Enable Inheritance
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1222.001
|
Hunting
|
Crypto Stealer, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Process Execution From ProgramData
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.005
|
Hunting
|
Axios Supply Chain Post Compromise, XWorm, SnappyBee, China-Nexus Threat Activity, APT37 Rustonotto and FadeStealer, Salt Typhoon, StealC Stealer, SolarWinds WHD RCE Post Exploitation, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Impair Defense Delete Win Defender Context Menu
|
Sysmon EventID 13
|
T1685
|
Hunting
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Default RDP File Creation By Non MSTSC Process
|
Sysmon EventID 11, Sysmon EventID 1
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows AD Short Lived Domain Account ServicePrincipalName
|
Windows Event Log Security 5136
|
T1098
|
TTP
|
Sneaky Active Directory Persistence Tricks, Interlock Ransomware
|
2026-05-13
|
|
Detect New Local Admin account
|
Windows Event Log Security 4720, Windows Event Log Security 4732
|
T1136.001
|
TTP
|
CISA AA24-241A, DHS Report TA18-074A, Scattered Lapsus$ Hunters, HAFNIUM Group, CISA AA22-257A
|
2026-05-13
|
|
Get ADDefaultDomainPasswordPolicy with Powershell Script Block
|
Powershell Script Block Logging 4104
|
T1201
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Odbcconf Load DLL
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.008
|
TTP
|
Living Off The Land
|
2026-05-13
|
|
Advanced IP or Port Scanner Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1046
T1135
|
Anomaly
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Security Account Manager Stopped
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1489
|
TTP
|
Scattered Lapsus$ Hunters, Compromised Windows Host, Ryuk Ransomware
|
2026-05-13
|
|
Windows Impair Defenses Disable HVCI
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, BlackLotus Campaign
|
2026-05-13
|
|
Windows Scheduled Task with Highest Privileges
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Compromised Windows Host, XWorm, Castle RAT, AsyncRAT, Scheduled Tasks, SolarWinds WHD RCE Post Exploitation, Quasar RAT, NetSupport RMM Tool Abuse, CISA AA23-347A, RedLine Stealer
|
2026-05-13
|
|
Windows InProcServer32 New Outlook Form
|
Sysmon EventID 13
|
T1112
T1566
|
Anomaly
|
Outlook RCE CVE-2024-21378
|
2026-05-13
|
|
Detect Regasm Spawning a Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.009
|
TTP
|
Suspicious Regsvcs Regasm Activity, Compromised Windows Host, Snake Keylogger, Handala Wiper, Void Manticore, DarkGate Malware, Living Off The Land
|
2026-05-13
|
|
Short Lived Scheduled Task
|
Windows Event Log Security 4698, Windows Event Log Security 4699
|
T1053.005
|
TTP
|
Compromised Windows Host, Scheduled Tasks, CISA AA22-257A, Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Windows AD Cross Domain SID History Addition
|
Windows Event Log Security 4738, Windows Event Log Security 4742
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Disabling Firewall with Netsh
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Windows Defense Evasion Tactics, BlackByte Ransomware
|
2026-05-13
|
|
Windows TOR Client Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090.003
|
Anomaly
|
Compromised Windows Host, Windows Post-Exploitation, Command And Control, Data Protection, Data Exfiltration
|
2026-05-13
|
|
GetNetTcpconnection with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1049
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Audit Policy Cleared via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
TTP
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows Compatibility Telemetry Suspicious Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Enable RDP In Other Port Number
|
Sysmon EventID 13
|
T1021
|
TTP
|
Prohibited Traffic Allowed or Protocol Mismatch, Windows RDP Artifacts and Defense Evasion, Windows Registry Abuse, Interlock Ransomware
|
2026-05-13
|
|
Windows AutoIt3 Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Crypto Stealer, DarkGate Malware, Void Manticore, Handala Wiper
|
2026-05-13
|
|
Windows Diskshadow Proxy Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218
|
TTP
|
Living Off The Land
|
2026-05-13
|
|
Windows PowerShell FakeCAPTCHA Clipboard Execution
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1059.003
T1204.001
|
TTP
|
Cisco Network Visibility Module Analytics, Scattered Lapsus$ Hunters, Fake CAPTCHA Campaigns, NetSupport RMM Tool Abuse, Interlock Ransomware
|
2026-05-13
|
|
Windows Office Product Spawned Rundll32 With No DLL
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Crypto Stealer, Prestige Ransomware, Spearphishing Attachments, CVE-2023-36884 Office and Windows HTML RCE Vulnerability
|
2026-05-13
|
|
Domain Group Discovery With Wmic
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Admon Default Group Policy Object Modified
|
Windows Active Directory Admon
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Schtasks scheduling job on remote system
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Compromised Windows Host, Scheduled Tasks, Active Directory Lateral Movement, Quasar RAT, Prestige Ransomware, Living Off The Land, Phemedrone Stealer, NOBELIUM Group, RedLine Stealer
|
2026-05-13
|
|
Windows PowerShell Export Certificate
|
Powershell Script Block Logging 4104
|
T1552.004
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows MSIExec Spawn WinDBG
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
TTP
|
DarkGate Malware, Compromised Windows Host
|
2026-05-13
|
|
Windows Modify Registry Disable WinDefender Notifications
|
Sysmon EventID 13
|
T1112
|
TTP
|
CISA AA23-347A, RedLine Stealer, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows Suspicious VMWare Tools Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
ESXi Post Compromise, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows AppX Deployment Full Trust Package Installation
|
Windows Event Log AppXDeployment-Server 400
|
T1204.002
T1553.005
|
Hunting
|
MSIX Package Abuse
|
2026-05-13
|
|
Outbound Network Connection from Java Using Default Ports
|
Sysmon EventID 1, Sysmon EventID 3
|
T1133
T1190
|
TTP
|
Log4Shell CVE-2021-44228
|
2026-05-13
|
|
Windows Powershell RemoteSigned File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Anomaly
|
Amadey
|
2026-05-13
|
|
Detect Rare Executables
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
Anomaly
|
SnappyBee, China-Nexus Threat Activity, Rhysida Ransomware, Crypto Stealer, Salt Typhoon, Unusual Processes
|
2026-05-13
|
|
SLUI Spawning a Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, DarkSide Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Windows Impair Defense Delete Win Defender Profile Registry
|
Sysmon EventID 13
|
T1685
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows AD Object Owner Updated
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Services Escalate Exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1548
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Cobalt Strike, BlackByte Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Creation of Shadow Copy
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.003
|
TTP
|
Credential Dumping, Compromised Windows Host, Volt Typhoon
|
2026-05-13
|
|
Windows Office Product Spawned Control
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
TTP
|
Microsoft MSHTML Remote Code Execution CVE-2021-40444, Spearphishing Attachments, Compromised Windows Host
|
2026-05-13
|
|
Windows Wmic CPU Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Windows OneDrive Share Mounted via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1567.002
|
Anomaly
|
Data Exfiltration
|
2026-05-13
|
|
Windows Registry Entries Exported Via Reg
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1012
|
Hunting
|
CISA AA23-347A, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Detect Remote Access Software Usage Registry
|
Sysmon EventID 13
|
T1219
|
Anomaly
|
CISA AA24-241A, Ransomware, Seashell Blizzard, Insider Threat, Scattered Lapsus$ Hunters, Cactus Ransomware, Remote Monitoring and Management Software, Command And Control, Gozi Malware, Scattered Spider
|
2026-05-13
|
|
Windows Non Discord App Access Discord LevelDB
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Snake Keylogger, BlankGrabber Stealer, PXA Stealer, StealC Stealer
|
2026-05-13
|
|
Windows AppCertDLL Modification Via Command Line
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1546.009
|
Anomaly
|
Windows Persistence Techniques, Windows Privilege Escalation
|
2026-05-13
|
|
Kerberos Service Ticket Request Using RC4 Encryption
|
Windows Event Log Security 4769
|
T1558.001
|
TTP
|
Active Directory Kerberos Attacks, Scattered Lapsus$ Hunters, Active Directory Privilege Escalation
|
2026-05-13
|
|
Print Spooler Failed to Load a Plug-in
|
Windows Event Log Printservice 808, Windows Event Log Printservice 4909
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows Chrome Auto-Update Disabled via Registry
|
Sysmon EventID 13
|
T1185
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Disable Defender Enhanced Notification
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, IcedID, CISA AA23-347A, Azorult
|
2026-05-13
|
|
GetWmiObject User Account with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.001
|
Hunting
|
Water Gamayun, Active Directory Discovery, Winter Vivern
|
2026-05-13
|
|
PowerShell Get LocalGroup Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Multiple NTLM Null Domain Authentications
|
NTLM Operational 8006, NTLM Operational 8005, NTLM Operational 8004
|
T1110.003
|
TTP
|
Active Directory Password Spraying
|
2026-05-13
|
|
GetCurrent User with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Modify ACL permission To Files Or Folder
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222
|
Anomaly
|
Crypto Stealer, XMRig, Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Windows PowerShell ScheduleTask
|
Powershell Script Block Logging 4104
|
T1053.005
T1059.001
|
Anomaly
|
Scattered Spider, Scheduled Tasks
|
2026-05-13
|
|
Windows Global Object Access Audit List Cleared Via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
TTP
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Dump LSASS via procdump
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.001
|
TTP
|
Compromised Windows Host, Seashell Blizzard, Storm-2460 CLFS Zero Day Exploitation, HAFNIUM Group, CISA AA22-257A, Credential Dumping
|
2026-05-13
|
|
Windows Modify Registry to Add or Modify Firewall Rule
|
Sysmon EventID 13, Sysmon EventID 14
|
T1112
|
Anomaly
|
CISA AA24-241A, NetSupport RMM Tool Abuse, ShrinkLocker
|
2026-05-13
|
|
BITSAdmin Download File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
T1197
|
TTP
|
DarkSide Ransomware, APT37 Rustonotto and FadeStealer, Ingress Tool Transfer, Flax Typhoon, BITS Jobs, Gozi Malware, Living Off The Land, Scattered Spider, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Account Discovery With NetUser PreauthNotRequire
|
Powershell Script Block Logging 4104
|
T1087
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Windows SSH Proxy Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
T1572
|
Anomaly
|
Living Off The Land, ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Hellcat Ransomware
|
2026-05-13
|
|
Windows Modify Registry DisableSecuritySettings
|
Sysmon EventID 13
|
T1112
|
TTP
|
DarkGate Malware, CISA AA23-347A
|
2026-05-13
|
|
Windows System File on Disk
|
Sysmon EventID 11
|
T1068
|
Hunting
|
CISA AA22-264A, Windows Drivers, Crypto Stealer
|
2026-05-13
|
|
Detect SharpHound File Modifications
|
Sysmon EventID 11
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
BlackSuit Ransomware, Ransomware, Windows Discovery Techniques
|
2026-05-13
|
|
Disable Show Hidden Files
|
Sysmon EventID 13
|
T1112
T1564.001
T1685
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Azorult
|
2026-05-13
|
|
Windows Rundll32 Apply User Settings Changes
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
Anomaly
|
Rhysida Ransomware
|
2026-05-13
|
|
Possible Browser Pass View Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1555.003
|
Hunting
|
Remcos
|
2026-05-13
|
|
Network Traffic to Active Directory Web Services Protocol
|
Sysmon EventID 3
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
Hunting
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows AD Domain Root ACL Deletion
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Vulnerable Driver Loaded
|
Sysmon EventID 6
|
T1543.003
|
Hunting
|
Windows Drivers, Void Manticore, BlackByte Ransomware
|
2026-05-13
|
|
Modification Of Wallpaper
|
Sysmon EventID 13
|
T1491
|
TTP
|
BlackMatter Ransomware, Black Basta Ransomware, Brute Ratel C4, Ransomware, Rhysida Ransomware, ZOVWiper, Windows Registry Abuse, LockBit Ransomware, Revil Ransomware
|
2026-05-13
|
|
Windows SpeechRuntime COM Hijacking DLL Load
|
Sysmon EventID 7
|
T1021.003
|
TTP
|
Scattered Lapsus$ Hunters, Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows System Time Discovery W32tm Delay
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1124
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
Domain Controller Discovery with Nltest
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
TTP
|
Active Directory Discovery, Rhysida Ransomware, Medusa Ransomware, NetSupport RMM Tool Abuse, BlackSuit Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Windows HTTP Network Communication From MSIExec
|
Cisco Network Visibility Module Flow Data, Sysmon EventID 1, Sysmon EventID 3
|
T1218.007
|
Anomaly
|
Water Gamayun, Cisco Network Visibility Module Analytics, APT37 Rustonotto and FadeStealer, Windows System Binary Proxy Execution MSIExec, SolarWinds WHD RCE Post Exploitation, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Filtering Platform Policy Added to Block EDR Process
|
Sysmon EventID 13
|
T1685
|
TTP
|
Security Solution Tampering, Disabling Security Tools
|
2026-05-13
|
|
Windows Office Product Loading VBE7 DLL
|
Sysmon EventID 7
|
T1566.001
|
Anomaly
|
Qakbot, Spearphishing Attachments, NjRAT, AgentTesla, MuddyWater, Azorult, Trickbot, Remcos, IcedID, DarkCrystal RAT, PlugX
|
2026-05-13
|
|
Windows PsTools Recon Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
T1046
T1082
|
Anomaly
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Data Destruction Recursive Exec Files Deletion
|
Sysmon EventID 26, Sysmon EventID 23
|
T1485
|
TTP
|
Handala Wiper, Void Manticore, Swift Slicer, Data Destruction, Disk Wiper
|
2026-05-13
|
|
Windows Service Creation on Remote Endpoint
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.003
|
TTP
|
SnappyBee, China-Nexus Threat Activity, Salt Typhoon, Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Windows PowerView SPN Discovery
|
Powershell Script Block Logging 4104
|
T1558.003
|
TTP
|
Rhysida Ransomware, Active Directory Kerberos Attacks, CISA AA23-347A, Interlock Ransomware
|
2026-05-13
|
|
Windows AD Domain Controller Promotion
|
Windows Event Log Security 4742
|
T1207
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Sdclt UAC Bypass
|
Sysmon EventID 13, Sysmon EventID 12
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Devtunnels Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows RunMRU Command Execution
|
Sysmon EventID 13
|
T1202
|
Anomaly
|
Fake CAPTCHA Campaigns, Lumma Stealer
|
2026-05-13
|
|
Windows Office Product Loading Taskschd DLL
|
Sysmon EventID 7
|
T1566.001
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
GetCurrent User with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Powershell Get LocalGroup Discovery with Script Block Logging
|
Powershell Script Block Logging 4104
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Svchost LOLBAS Execution Process Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Living Off The Land, Scheduled Tasks, Hellcat Ransomware, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Terminating Lsass Process
|
Sysmon EventID 10
|
T1685
|
Anomaly
|
Data Destruction, Scattered Lapsus$ Hunters, Double Zero Destructor
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender App Guard
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows COM Hijacking InprocServer32 Modification
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1546.015
|
TTP
|
Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender Report Infection
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows SQL Server Startup Procedure
|
Windows Event Log Application 17135
|
T1505.001
|
Anomaly
|
SQL Server Abuse, Hellcat Ransomware
|
2026-05-13
|
|
Windows Chrome Enable Extension Loading via Command-Line
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1185
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
LOLBAS With Network Traffic
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
TTP
|
Water Gamayun, NetSupport RMM Tool Abuse, APT37 Rustonotto and FadeStealer, Malicious Inno Setup Loader, Fake CAPTCHA Campaigns, Living Off The Land, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Account Discovery for Sam Account Name
|
Powershell Script Block Logging 4104
|
T1087
|
Anomaly
|
CISA AA23-347A
|
2026-05-13
|
|
Windows Impair Defense Disable Realtime Signature Delivery
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Hiding Files And Directories With Attrib exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222.001
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host, VIP Keylogger, Crypto Stealer, Windows Persistence Techniques, Malicious Inno Setup Loader, Azorult
|
2026-05-13
|
|
Windows Command and Scripting Interpreter Hunting Path Traversal
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Hunting
|
Windows Defense Evasion Tactics, Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190
|
2026-05-13
|
|
Hide User Account From Sign-In Screen
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Warzone RAT, XMRig, Azorult
|
2026-05-13
|
|
Windows Modify Registry Disable Restricted Admin
|
Sysmon EventID 13
|
T1112
|
TTP
|
Medusa Ransomware, CISA AA23-347A, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Audit Policy Restored via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows Information Discovery Fsutil
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows User Disabled Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1531
|
Anomaly
|
XMRig
|
2026-05-13
|
|
Windows Modify Registry ValleyRat PWN Reg Entry
|
Sysmon EventID 13
|
T1112
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
Detect mshta inline hta execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
TTP
|
Compromised Windows Host, Suspicious MSHTA Activity, XWorm, APT37 Rustonotto and FadeStealer, Living Off The Land, Gozi Malware, BlankGrabber Stealer
|
2026-05-13
|
|
Windows Unusual Count Of Users Remotely Failed To Auth From Host
|
Windows Event Log Security 4625
|
T1110.003
|
Anomaly
|
Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows Suspicious React or Next.js Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1059.003
T1190
|
TTP
|
React2Shell
|
2026-05-13
|
|
Windows Query Registry Browser List Application
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Salt Typhoon, SnappyBee, RedLine Stealer, China-Nexus Threat Activity
|
2026-05-13
|
|
Excessive number of service control start as disabled
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Detect Exchange Web Shell
|
Sysmon EventID 11
|
T1133
T1190
T1505.003
|
TTP
|
Compromised Windows Host, Seashell Blizzard, ProxyNotShell, HAFNIUM Group, CISA AA22-257A, BlackByte Ransomware, ProxyShell, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Mimikatz Binary Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003
|
TTP
|
Sandworm Tools, Compromised Windows Host, Credential Dumping, Volt Typhoon, CISA AA22-320A, Flax Typhoon, Scattered Spider, CISA AA23-347A
|
2026-05-13
|
|
Enumerate Users Local Group Using Telegram
|
Windows Event Log Security 4798
|
T1087
|
TTP
|
Water Gamayun, XMRig, Compromised Windows Host
|
2026-05-13
|
|
Windows Audit Policy Excluded Category via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows Driver Inventory
|
|
T1068
|
Hunting
|
Windows Drivers
|
2026-05-13
|
|
Suspicious Process Executed From Container File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.008
T1204.002
|
TTP
|
Water Gamayun, APT37 Rustonotto and FadeStealer, Amadey, Remcos, Snake Keylogger, Unusual Processes, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Clop Common Exec Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
TTP
|
Clop Ransomware, Compromised Windows Host
|
2026-05-13
|
|
WinEvent Scheduled Task Created to Spawn Shell
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
SystemBC, Windows Error Reporting Service Elevation of Privilege Vulnerability, Compromised Windows Host, Ransomware, Winter Vivern, China-Nexus Threat Activity, Castle RAT, Windows Persistence Techniques, Scheduled Tasks, Salt Typhoon, 0bj3ctivity Stealer, CISA AA22-257A, Ryuk Ransomware, Medusa Ransomware
|
2026-05-13
|
|
PowerShell Start-BitsTransfer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1197
|
TTP
|
Gozi Malware, BITS Jobs
|
2026-05-13
|
|
AdsiSearcher Account Discovery
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery, Scattered Lapsus$ Hunters, Data Destruction, Industroyer2, CISA AA23-347A
|
2026-05-13
|
|
Excessive Usage of NSLOOKUP App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1048
|
Anomaly
|
Dynamic DNS, Command And Control, Suspicious DNS Traffic, Data Exfiltration
|
2026-05-13
|
|
Windows Scheduled Task Created Via XML
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
Anomaly
|
Winter Vivern, Scheduled Tasks, Malicious Inno Setup Loader, MoonPeak, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Windows Cabinet File Extraction Via Expand
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
NetSupport RMM Tool Abuse, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Suspicious Child Process Spawned From WebServer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1505.003
|
Anomaly
|
CISA AA22-264A, Compromised Windows Host, ProxyNotShell, SysAid On-Prem Software CVE-2023-47246 Vulnerability, Citrix ShareFile RCE CVE-2023-24489, Microsoft SharePoint Vulnerabilities, HAFNIUM Group, Microsoft WSUS CVE-2025-59287, CISA AA22-257A, BlackByte Ransomware, Medusa Ransomware, Flax Typhoon, WS FTP Server Critical Vulnerabilities, ProxyShell, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows NirSoft Tool Bundle File Created
|
Sysmon EventID 11
|
T1588.002
|
Anomaly
|
Data Destruction, WhisperGate, Unusual Processes
|
2026-05-13
|
|
Non Firefox Process Access Firefox Profile Dir
|
Windows Event Log Security 4663
|
T1555.003
|
Anomaly
|
AgentTesla, Azorult, Phemedrone Stealer, SnappyBee, StealC Stealer, Remcos, NjRAT, FIN7, Salt Typhoon, Malicious Inno Setup Loader, Quasar RAT, DarkGate Malware, Snake Keylogger, 3CX Supply Chain Attack, RedLine Stealer, China-Nexus Threat Activity, VIP Keylogger, Warzone RAT, 0bj3ctivity Stealer, BlankGrabber Stealer, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Windows Potential Cloudflared Tunnel Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Network Share Discovery Via Dir Command
|
Windows Event Log Security 5140
|
T1135
|
Hunting
|
IcedID
|
2026-05-13
|
|
Set Default PowerShell Execution Policy To Unrestricted or Bypass
|
Sysmon EventID 13
|
T1059.001
|
TTP
|
SystemBC, SolarWinds WHD RCE Post Exploitation, Data Destruction, Malicious PowerShell, HAFNIUM Group, Hermetic Wiper, DarkGate Malware, Credential Dumping
|
2026-05-13
|
|
Notepad with no Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
BishopFox Sliver Adversary Emulation Framework
|
2026-05-13
|
|
Detect Password Spray Attack Behavior On User
|
Windows Event Log Security 4624, Windows Event Log Security 4625
|
T1110.003
|
TTP
|
Crypto Stealer, Compromised User Account
|
2026-05-13
|
|
Single Letter Process On Endpoint
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
|
TTP
|
Compromised Windows Host, DHS Report TA18-074A
|
2026-05-13
|
|
Windows Steal Authentication Certificates Export Certificate
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows Increase in User Modification Activity
|
Windows Event Log Security 4720
|
T1098
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Sdelete Application Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070.004
T1485
|
TTP
|
Scattered Spider, Masquerading - Rename System Utilities, Void Manticore
|
2026-05-13
|
|
Windows Downdate Registry Activity
|
Sysmon EventID 13, Sysmon EventID 12, Sysmon EventID 14
|
T1112
T1689
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Disabled Kerberos Pre-Authentication Discovery With Get-ADUser
|
Powershell Script Block Logging 4104
|
T1558.004
|
TTP
|
Active Directory Kerberos Attacks, BlackSuit Ransomware, CISA AA23-347A, Interlock Ransomware
|
2026-05-13
|
|
Windows Disable Change Password Through Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Defense Evasion Tactics, Ransomware
|
2026-05-13
|
|
Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM
|
Windows Event Log Security 4776
|
T1110.003
|
Anomaly
|
Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows AD Self DACL Assignment
|
Windows Event Log Security 5136
|
T1098
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Powershell Disable Security Monitoring
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
CISA AA24-241A, Revil Ransomware, BlankGrabber Stealer, Ransomware
|
2026-05-13
|
|
Add or Set Windows Defender Exclusion
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
WhisperGate, Windows Defense Evasion Tactics, Compromised Windows Host, XWorm, Crypto Stealer, AgentTesla, ValleyRAT, Data Destruction, CISA AA22-320A, Remcos, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
NLTest Domain Trust Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1482
|
TTP
|
Qakbot, Active Directory Discovery, Cleo File Transfer Software, Domain Trust Discovery, Rhysida Ransomware, Ryuk Ransomware, Storm-0501 Ransomware, IcedID, Medusa Ransomware
|
2026-05-13
|
|
Windows Executable in Loaded Modules
|
Sysmon EventID 7
|
T1129
|
TTP
|
NjRAT, Lokibot
|
2026-05-13
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Excessive Usage Of Net App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1531
|
Anomaly
|
Graceful Wipe Out Attack, Ransomware, Rhysida Ransomware, XMRig, Windows Post-Exploitation, Prestige Ransomware, Azorult
|
2026-05-13
|
|
ConnectWise ScreenConnect Path Traversal Windows SACL
|
Windows Event Log Security 4663
|
T1190
|
TTP
|
Seashell Blizzard, Compromised Windows Host, ConnectWise ScreenConnect Vulnerabilities
|
2026-05-13
|
|
Windows Odbcconf Hunting
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.008
|
Hunting
|
Living Off The Land
|
2026-05-13
|
|
Windows Mail Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
AgentTesla
|
2026-05-13
|
|
Network Connection Discovery With Arp
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1049
|
Hunting
|
Qakbot, Active Directory Discovery, Windows Post-Exploitation, Volt Typhoon, Prestige Ransomware, IcedID, Interlock Ransomware
|
2026-05-13
|
|
Windows Computer Account Created by Computer Account
|
Windows Event Log Security 4741
|
T1558
|
TTP
|
Active Directory Kerberos Attacks, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Firewall Allowed Program Enable
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1686
|
Anomaly
|
Windows Defense Evasion Tactics, NjRAT, Azorult, BlackByte Ransomware, Medusa Ransomware, PlugX
|
2026-05-13
|
|
Elevated Group Discovery With Wmic
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Cobalt Strike PowerShell Loader
|
Powershell Script Block Logging 4104
|
T1059.001
T1608
|
TTP
|
Cobalt Strike
|
2026-05-13
|
|
Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
|
Windows Event Log Security 4768
|
T1110.003
|
TTP
|
Active Directory Kerberos Attacks, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows System User Discovery Via Quser
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Crypto Stealer, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows File Without Extension In Critical Folder
|
Sysmon EventID 11
|
T1485
|
TTP
|
Data Destruction, Hermetic Wiper
|
2026-05-13
|
|
Windows Command Shell DCRat ForkBomb Payload
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
TTP
|
DarkCrystal RAT, Compromised Windows Host
|
2026-05-13
|
|
Creation of lsass Dump with Taskmgr
|
Sysmon EventID 11
|
T1003.001
|
TTP
|
Seashell Blizzard, Scattered Lapsus$ Hunters, Cactus Ransomware, CISA AA22-257A, Credential Dumping
|
2026-05-13
|
|
NET Profiler UAC bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Excessive Attempt To Disable Services
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1489
|
Anomaly
|
XMRig, Azorult
|
2026-05-13
|
|
Disable UAC Remote Restriction
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Windows Shell Process from CrushFTP
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1059.003
T1190
T1505
|
TTP
|
CrushFTP Vulnerabilities
|
2026-05-13
|
|
Windows Scheduled Task DLL Module Loaded
|
Sysmon EventID 7
|
T1053
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
Windows Default Group Policy Object Modified with GPME
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Detect Renamed WinRAR
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1560.001
|
Hunting
|
Collection and Staging, Salt Typhoon, CISA AA22-277A, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows AD Dangerous User ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Get ADUserResultantPasswordPolicy with Powershell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1201
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender Scan On Update
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Excessive File Deletion In WinDefender Folder
|
Sysmon EventID 26, Sysmon EventID 23
|
T1485
|
TTP
|
Data Destruction, WhisperGate, BlackByte Ransomware
|
2026-05-13
|
|
WMIC XSL Execution via URL
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1220
|
TTP
|
Compromised Windows Host, Cisco Network Visibility Module Analytics, Suspicious WMI Use
|
2026-05-13
|
|
Windows AD DSRM Account Changes
|
Sysmon EventID 13
|
T1098
|
TTP
|
Windows Registry Abuse, Sneaky Active Directory Persistence Tricks, Scattered Lapsus$ Hunters, Windows Persistence Techniques
|
2026-05-13
|
|
Access LSASS Memory for Dump Creation
|
Sysmon EventID 10
|
T1003.001
|
TTP
|
Scattered Lapsus$ Hunters, Cactus Ransomware, Credential Dumping, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Detect Outlook exe writing a zip file
|
Sysmon EventID 11, Sysmon EventID 1
|
T1566.001
|
Anomaly
|
Meduza Stealer, APT37 Rustonotto and FadeStealer, PXA Stealer, Amadey, Remcos, Spearphishing Attachments
|
2026-05-13
|
|
Windows Disable Windows Event Logging Disable HTTP Logging
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1505.004
T1685.001
|
Anomaly
|
Windows Defense Evasion Tactics, IIS Components, CISA AA23-347A, Compromised Windows Host
|
2026-05-13
|
|
Windows RDPClient Connection Sequence Events
|
Windows Event Log Microsoft Windows TerminalServices RDPClient 1024
|
T1133
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion, Spearphishing Attachments
|
2026-05-13
|
|
Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Water Gamayun, ValleyRAT
|
2026-05-13
|
|
Windows Multiple Invalid Users Failed To Authenticate Using NTLM
|
Windows Event Log Security 4776
|
T1110.003
|
TTP
|
Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows Modify Registry Regedit Silent Reg Import
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1112
|
Anomaly
|
Azorult
|
2026-05-13
|
|
Windows Credentials from Password Stores Chrome Extension Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Braodo Stealer, Meduza Stealer, Malicious Inno Setup Loader, StealC Stealer, Amadey, MoonPeak, 0bj3ctivity Stealer, DarkGate Malware, Phemedrone Stealer, BlankGrabber Stealer, CISA AA23-347A, RedLine Stealer
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Persistence, Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Modify Registry With MD5 Reg Key Name
|
Sysmon EventID 13
|
T1112
|
TTP
|
NjRAT
|
2026-05-13
|
|
7zip CommandLine To SMB Share Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1560.001
|
Hunting
|
Ransomware
|
2026-05-13
|
|
Windows Process Execution From RDP Share
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
Ping Sleep Batch Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497.003
|
Anomaly
|
WhisperGate, Meduza Stealer, Warzone RAT, Void Manticore, Data Destruction, Quasar RAT, BlackByte Ransomware, Gh0st RAT
|
2026-05-13
|
|
Windows Known Abused DLL Created
|
Sysmon EventID 11
|
T1574.001
|
Anomaly
|
Windows Defense Evasion Tactics, Living Off The Land
|
2026-05-13
|
|
Malicious PowerShell Process - Encoded Command
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1027
|
Hunting
|
Qakbot, WhisperGate, Sandworm Tools, Scattered Spider, Crypto Stealer, Volt Typhoon, SolarWinds WHD RCE Post Exploitation, CISA AA22-320A, Data Destruction, Lumma Stealer, Malicious PowerShell, Microsoft SharePoint Vulnerabilities, Hermetic Wiper, Microsoft WSUS CVE-2025-59287, DarkCrystal RAT, NOBELIUM Group, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Recursive Delete of Directory In Batch CMD
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070.004
|
TTP
|
Ransomware, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Event Triggered Image File Execution Options Injection
|
Windows Event Log Application 3000
|
T1546.012
|
Hunting
|
Windows Persistence Techniques
|
2026-05-13
|
|
Excessive Usage Of Taskkill
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
CISA AA22-264A, Crypto Stealer, NjRAT, AgentTesla, XMRig, CISA AA22-277A, Azorult, BlankGrabber Stealer
|
2026-05-13
|
|
Windows Credentials in Registry Reg Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1552.002
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows AD Domain Replication ACL Addition
|
Windows Event Log Security 5136
|
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Command
|
Windows Event Log Security 4700, Windows Event Log Security 4702, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Ransomware, Seashell Blizzard, APT37 Rustonotto and FadeStealer, Windows Persistence Techniques, Scheduled Tasks, SolarWinds WHD RCE Post Exploitation, Quasar RAT, Ryuk Ransomware
|
2026-05-13
|
|
UAC Bypass MMC Load Unsigned Dll
|
Sysmon EventID 7
|
T1218.014
T1548.002
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Increase in Group or Object Modification Activity
|
Windows Event Log Security 4663
|
T1098
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Firewall Rule Deletion
|
Windows Event Log Security 4948
|
T1686
|
Anomaly
|
Medusa Ransomware, NetSupport RMM Tool Abuse, ShrinkLocker
|
2026-05-13
|
|
Windows Kerberos Local Successful Logon
|
Windows Event Log Security 4624
|
T1558
|
TTP
|
Active Directory Kerberos Attacks, Scattered Lapsus$ Hunters, Local Privilege Escalation With KrbRelayUp, Compromised Windows Host
|
2026-05-13
|
|
Windows Replication Through Removable Media
|
Sysmon EventID 11
|
T1091
|
TTP
|
APT37 Rustonotto and FadeStealer, China-Nexus Threat Activity, NjRAT, Chaos Ransomware, Salt Typhoon, Derusbi, PlugX
|
2026-05-13
|
|
Process Creating LNK file in Suspicious Location
|
Sysmon EventID 11
|
T1566.002
|
Anomaly
|
Qakbot, APT37 Rustonotto and FadeStealer, Amadey, IcedID, Gozi Malware, Spearphishing Attachments, BlankGrabber Stealer
|
2026-05-13
|
|
Windows Cisco Secure Endpoint Unblock File Via Sfc
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Security Solution Tampering
|
2026-05-13
|
|
Windows Vulnerable 3CX Software
|
Sysmon EventID 1
|
T1195.002
|
TTP
|
3CX Supply Chain Attack
|
2026-05-13
|
|
Disable Defender Submit Samples Consent Feature
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Azorult, IcedID, BlankGrabber Stealer, CISA AA23-347A
|
2026-05-13
|
|
Rubeus Kerberos Ticket Exports Through Winlogon Access
|
Sysmon EventID 10
|
T1550.003
|
TTP
|
Scattered Lapsus$ Hunters, ZOVWiper, Active Directory Kerberos Attacks, BlackSuit Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Web Servers Executing Suspicious Processes
|
Sysmon EventID 1
|
T1082
|
TTP
|
Apache Struts Vulnerability
|
2026-05-13
|
|
Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Security Solution Tampering
|
2026-05-13
|
|
Windows Defender ASR Audit Events
|
Windows Event Log Defender 1134, Windows Event Log Defender 1132, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1122
|
T1059
T1566.001
T1566.002
|
Anomaly
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Windows Advanced Installer MSIX with AI_STUBS Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
T1218
T1553.005
|
TTP
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows Service Create SliverC2
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
BishopFox Sliver Adversary Emulation Framework, Compromised Windows Host, Hellcat Ransomware
|
2026-05-13
|
|
Windows Event For Service Disabled
|
Windows Event Log System 7040
|
T1685
|
Hunting
|
Windows Defense Evasion Tactics, RedLine Stealer
|
2026-05-13
|
|
System Info Gathering Using Dxdiag Application
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1592
|
Hunting
|
Remcos
|
2026-05-13
|
|
Drop IcedID License dat
|
Sysmon EventID 11
|
T1204.002
|
Hunting
|
IcedID
|
2026-05-13
|
|
Eventvwr UAC Bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, ValleyRAT, Windows Registry Abuse, IcedID, Living Off The Land
|
2026-05-13
|
|
Windows Suspicious File in EFI Volume
|
Sysmon EventID 11
|
T1490
T1542.001
|
TTP
|
Windows BootKits, BlackLotus Campaign, Sandworm Tools
|
2026-05-13
|
|
Windows SIP Provider Inventory
|
|
T1553.003
|
Hunting
|
Subvert Trust Controls SIP and Trust Provider Hijacking
|
2026-05-13
|
|
Windows Registry Payload Injection
|
Sysmon EventID 13
|
T1027.011
|
TTP
|
Unusual Processes
|
2026-05-13
|
|
Windows NetSupport RMM DLL Loaded By Uncommon Process
|
Sysmon EventID 7
|
T1036
|
Anomaly
|
NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Process Writing File to World Writable Path
|
Sysmon EventID 11
|
T1218.005
|
Hunting
|
PathWiper, APT29 Diplomatic Deceptions with WINELOADER, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Windows Impair Defense Disable PUA Protection
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows DLL Side-Loading In Calc
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
Qakbot, Earth Alux
|
2026-05-13
|
|
Windows AD GPO Deleted
|
Windows Event Log Security 5136
|
T1484.001
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Default Rdp File Unhidden
|
Sysmon EventID 1
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Wermgr Process Spawned CMD Or Powershell Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Qakbot, Trickbot
|
2026-05-13
|
|
Windows Suspicious Process File Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.005
T1543
|
TTP
|
SystemBC, Qakbot, AsyncRAT, AgentTesla, SesameOp, Volt Typhoon, Lokibot, Data Destruction, Interlock Rat, Trickbot, Industroyer2, Azorult, Phemedrone Stealer, GhostRedirector IIS Module and Rungan Backdoor, Water Gamayun, Brute Ratel C4, Axios Supply Chain Post Compromise, SnappyBee, Meduza Stealer, Void Manticore, StealC Stealer, LockBit Ransomware, Remcos, Hermetic Wiper, BlackByte Ransomware, PlugX, NailaoLocker Ransomware, WhisperGate, Rhysida Ransomware, Chaos Ransomware, Salt Typhoon, ValleyRAT, Malicious Inno Setup Loader, Amadey, Quasar RAT, DarkGate Malware, RedLine Stealer, XWorm, Graceful Wipe Out Attack, China-Nexus Threat Activity, Handala Wiper, Warzone RAT, XMRig, PromptLock, Castle RAT, Earth Alux, Swift Slicer, VIP Keylogger, MoonPeak, Double Zero Destructor, Prestige Ransomware, IcedID, DarkCrystal RAT, CISA AA23-347A, Interlock Ransomware
|
2026-05-13
|
|
Windows Curl Upload to Remote Destination
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Compromised Windows Host, Cisco Network Visibility Module Analytics, Axios Supply Chain Post Compromise, Ingress Tool Transfer, PromptLock, NPM Supply Chain Compromise, Microsoft WSUS CVE-2025-59287
|
2026-05-13
|
|
Windows Shell or Script Execution From IIS Directory
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1190
T1505.004
|
Anomaly
|
ProxyNotShell, ProxyShell
|
2026-05-13
|
|
Print Processor Registry Autostart
|
Sysmon EventID 13
|
T1547.012
|
TTP
|
Data Destruction, Windows Persistence Techniques, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Windows Disable Internet Explorer Addons
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1176.001
|
Anomaly
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Disable ETW Through Registry
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, CISA AA23-347A, Ransomware
|
2026-05-13
|
|
Windows Modify Registry No Auto Update
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
CISA AA23-347A, RedLine Stealer
|
2026-05-13
|
|
Windows XLL File Creation Outside of Typical Location
|
Sysmon EventID 11
|
T1059
T1129
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Network Connection Discovery With Netstat
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1049
|
Hunting
|
Qakbot, Active Directory Discovery, Windows Post-Exploitation, Volt Typhoon, CISA AA22-277A, Prestige Ransomware, Medusa Ransomware, PlugX, CISA AA23-347A
|
2026-05-13
|
|
Windows Office Product Dropped Cab or Inf File
|
Sysmon EventID 11, Windows Event Log Security 4688, Sysmon EventID 1
|
T1566.001
|
TTP
|
Microsoft MSHTML Remote Code Execution CVE-2021-40444, Spearphishing Attachments, Compromised Windows Host, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Detect Password Spray Attack Behavior From Source
|
Windows Event Log Security 4624, Windows Event Log Security 4625
|
T1110.003
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
Detect Regsvcs Spawning a Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.009
|
TTP
|
Living Off The Land, Suspicious Regsvcs Regasm Activity, Compromised Windows Host
|
2026-05-13
|
|
Winhlp32 Spawning a Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
Remcos, Compromised Windows Host
|
2026-05-13
|
|
Get DomainPolicy with Powershell Script Block
|
Powershell Script Block Logging 4104
|
T1201
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
SearchProtocolHost with no Command Line with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Cobalt Strike, Cactus Ransomware, BlackByte Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Local LLM Framework Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-05-13
|
|
Windows Set Custom DNS ServerLevelPlugin Via Dnscmd
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Defender ASR Registry Modification
|
Windows Event Log Defender 5007
|
T1112
|
Hunting
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Windows Chrome Extension Allowed Registry Modification
|
Sysmon EventID 13
|
T1185
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Windows Developer-Signed MSIX Package Installation
|
Windows Event Log AppXDeployment-Server 855
|
T1204.002
T1553.005
|
Anomaly
|
MSIX Package Abuse
|
2026-05-13
|
|
Get-DomainTrust with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Get-AdComputer Unconstrained Delegation Discovery
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Medusa Ransomware, Active Directory Kerberos Attacks
|
2026-05-13
|
|
Windows SnappyBee Create Test Registry
|
Sysmon EventID 13
|
T1112
|
TTP
|
Salt Typhoon, SnappyBee, China-Nexus Threat Activity
|
2026-05-13
|
|
Kerberos Pre-Authentication Flag Disabled in UserAccountControl
|
Windows Event Log Security 4738
|
T1558.004
|
TTP
|
Active Directory Kerberos Attacks, BlackSuit Ransomware
|
2026-05-13
|
|
Windows LSA Secrets NoLMhash Registry
|
Sysmon EventID 13
|
T1003.004
|
TTP
|
Scattered Lapsus$ Hunters, CISA AA23-347A
|
2026-05-13
|
|
Suspicious Kerberos Service Ticket Request
|
Windows Event Log Security 4769
|
T1078.002
|
TTP
|
Active Directory Kerberos Attacks, Active Directory Privilege Escalation, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Get ADUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1087.002
|
Hunting
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Suspicious Regsvr32 Register Suspicious Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.010
|
TTP
|
Qakbot, IcedID, China-Nexus Threat Activity, Salt Typhoon, Suspicious Regsvr32 Activity, Derusbi, Living Off The Land
|
2026-05-13
|
|
Windows New InProcServer32 Added
|
Sysmon EventID 13
|
T1112
|
Hunting
|
Hellcat Ransomware, Outlook RCE CVE-2024-21378
|
2026-05-13
|
|
Windows Credentials from Password Stores Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1555
|
Anomaly
|
DarkGate Malware, NetSupport RMM Tool Abuse, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows AD Dangerous Group ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows UAC Bypass Suspicious Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, Castle RAT, Living Off The Land
|
2026-05-13
|
|
Detect Path Interception By Creation Of program exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.009
|
TTP
|
Windows Persistence Techniques, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Get ADDefaultDomainPasswordPolicy with Powershell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1201
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Execute Arbitrary Commands with MSDT
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218
|
TTP
|
Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Compromised Windows Host
|
2026-05-13
|
|
Windows Process Execution in Temp Dir
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.005
T1543
|
Anomaly
|
Qakbot, Axios Supply Chain Post Compromise, XWorm, Ransomware, NjRAT, AgentTesla, PathWiper, PromptLock, SesameOp, Remcos, Trickbot, Ryuk Ransomware, Gh0st RAT, Lokibot
|
2026-05-13
|
|
Detect Credential Dumping through LSASS access
|
Sysmon EventID 10
|
T1003.001
|
TTP
|
Detect Zerologon Attack, Scattered Lapsus$ Hunters, Credential Dumping, BlackSuit Ransomware, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Windows RDP Server Registry Entry Created
|
Sysmon EventID 13
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows Remote Create Service
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.003
|
Anomaly
|
BlackSuit Ransomware, CISA AA23-347A, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Guest Account Enabled Via Net.EXE
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1078.001
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Known Abused DLL Loaded Suspiciously
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos
|
Windows Event Log Security 4768
|
T1110.003
|
Anomaly
|
Active Directory Kerberos Attacks, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows LAPS Password Gathering Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1003
T1552
|
Anomaly
|
Active Directory Privilege Escalation, Credential Dumping
|
2026-05-13
|
|
Windows Access Token Winlogon Duplicate Handle In Uncommon Path
|
Sysmon EventID 10
|
T1134.001
|
Anomaly
|
PathWiper, Brute Ratel C4
|
2026-05-13
|
|
Windows Defender Exclusion Registry Entry
|
Sysmon EventID 13
|
T1685
|
TTP
|
Qakbot, Windows Defense Evasion Tactics, XWorm, Warzone RAT, ValleyRAT, Remcos, Azorult, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows PowerView AD Access Control List Enumeration
|
Powershell Script Block Logging 4104
|
T1069
T1078.002
|
TTP
|
Active Directory Privilege Escalation, Active Directory Discovery, Rhysida Ransomware
|
2026-05-13
|
|
Windows RDP Client Launched with Admin Session
|
Sysmon EventID 1
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Impacket Lateral Movement smbexec CommandLine Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
WhisperGate, Compromised Windows Host, Graceful Wipe Out Attack, Active Directory Lateral Movement, Volt Typhoon, Data Destruction, CISA AA22-277A, Prestige Ransomware, Industroyer2
|
2026-05-13
|
|
Windows Findstr GPP Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1552.006
|
TTP
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows AD Same Domain SID History Addition
|
Windows Event Log Security 4738, Windows Event Log Security 4742
|
T1134.005
|
TTP
|
Windows Persistence Techniques, Compromised Windows Host, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Recon AVProduct Through Pwh or WMI
|
Powershell Script Block Logging 4104
|
T1592
|
TTP
|
Qakbot, Ransomware, XWorm, Windows Post-Exploitation, Data Destruction, MoonPeak, Malicious PowerShell, Quasar RAT, Prestige Ransomware, Hermetic Wiper
|
2026-05-13
|
|
Windows Privileged Group Modification
|
Windows Event Log Security 4727, Windows Event Log Security 4759, Windows Event Log Security 4756, Windows Event Log Security 4744, Windows Event Log Security 4731, Windows Event Log Security 4749, Windows Event Log Security 4790, Windows Event Log Security 4754, Windows Event Log Security 4783
|
T1136.001
T1136.002
|
TTP
|
VMware ESXi AD Integration Authentication Bypass CVE-2024-37085, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Process Execution via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Windows System User Privilege Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Windows SubInAcl Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222.001
|
Anomaly
|
Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Windows File Share Discovery With Powerview
|
Powershell Script Block Logging 4104
|
T1135
|
TTP
|
Active Directory Privilege Escalation, Active Directory Discovery
|
2026-05-13
|
|
Windows Change File Association Command To Notepad
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1546.001
|
TTP
|
Prestige Ransomware, Compromised Windows Host
|
2026-05-13
|
|
PetitPotam Suspicious Kerberos TGT Request
|
Windows Event Log Security 4768
|
T1003
|
TTP
|
Active Directory Kerberos Attacks, PetitPotam NTLM Relay on Active Directory Certificate Services
|
2026-05-13
|
|
Windows MSExchange Management Mailbox Cmdlet Usage
|
|
T1059.001
|
Anomaly
|
ProxyNotShell, Scattered Spider, ProxyShell, BlackByte Ransomware
|
2026-05-13
|
|
Windows Linked Policies In ADSI Discovery
|
Powershell Script Block Logging 4104
|
T1087.002
|
Anomaly
|
Data Destruction, Active Directory Discovery, Industroyer2
|
2026-05-13
|
|
Windows Event Log Cleared
|
Windows Event Log System 104, Windows Event Log Security 1102
|
T1685.005
|
TTP
|
CISA AA22-264A, Compromised Windows Host, Ransomware, Windows Log Manipulation, Clop Ransomware, ShrinkLocker
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender Compute File Hashes
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Impair Defense Change Win Defender Quick Scan Interval
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Multiple Accounts Deleted
|
Windows Event Log Security 4726
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Rubeus Command Line Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1550.003
T1558.003
T1558.004
|
TTP
|
Active Directory Privilege Escalation, Scattered Lapsus$ Hunters, ZOVWiper, Active Directory Kerberos Attacks, BlackSuit Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Disabling Defender Services
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, RedLine Stealer, IcedID
|
2026-05-13
|
|
Windows Time Based Evasion
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497.003
|
TTP
|
NjRAT, BlankGrabber Stealer
|
2026-05-13
|
|
Windows System Binary Proxy Execution Compiled HTML File Decompile
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.001
|
TTP
|
Living Off The Land, Suspicious Compiled HTML Activity, Compromised Windows Host, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows PowerSploit GPP Discovery
|
Powershell Script Block Logging 4104
|
T1552.006
|
TTP
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Service Deletion In Registry
|
Sysmon EventID 13
|
T1489
|
Anomaly
|
Crypto Stealer, Brute Ratel C4, PlugX
|
2026-05-13
|
|
Windows Input Capture Using Credential UI Dll
|
Sysmon EventID 7
|
T1056.002
|
Hunting
|
Brute Ratel C4, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Get-ForestTrust with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Wmic Systeminfo Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
Anomaly
|
BlankGrabber Stealer, Lotus Blossom Chrysalis Backdoor, LAMEHUG
|
2026-05-13
|
|
Windows Chromium Process with Disabled Extensions
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Windows System Discovery Using ldap Nslookup
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows Modify Registry ProxyServer
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
DarkGate Malware
|
2026-05-13
|
|
Windows IIS Components Add New Module
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1505.004
|
Anomaly
|
IIS Components, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Unusually Long Command Line
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
N/A
|
Anomaly
|
Unusual Processes, Ransomware, Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns, Suspicious Command-Line Executions
|
2026-05-13
|
|
Windows .Key File Creation in Root Directory
|
Sysmon EventID 11
|
T1486
|
Anomaly
|
Ransomware
|
2026-05-13
|
|
Create or delete windows shares using net exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070.005
|
TTP
|
Windows Post-Exploitation, CISA AA22-277A, Prestige Ransomware, DarkGate Malware, Hidden Cobra Malware
|
2026-05-13
|
|
Windows Registry Delete Task SD
|
Sysmon EventID 12
|
T1053.005
T1685
|
Anomaly
|
Windows Registry Abuse, Windows Persistence Techniques, Scheduled Tasks
|
2026-05-13
|
|
Excessive number of taskhost processes
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
Meterpreter
|
2026-05-13
|
|
Conti Common Exec parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
TTP
|
Compromised Windows Host, Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Bluetooth Service Installed From Uncommon Location
|
Windows Event Log System 7045
|
T1036
T1543.003
|
Anomaly
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Get-DomainTrust with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Disable Registry Tool
|
Sysmon EventID 13
|
T1112
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, NjRAT
|
2026-05-13
|
|
Impacket Lateral Movement WMIExec Commandline Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
WhisperGate, Compromised Windows Host, Graceful Wipe Out Attack, Volt Typhoon, Data Destruction, CISA AA22-277A, Storm-0501 Ransomware, Prestige Ransomware, Active Directory Lateral Movement, Industroyer2, Gozi Malware
|
2026-05-13
|
|
Windows Outlook LoadMacroProviderOnBoot Persistence
|
Sysmon EventID 13
|
T1112
T1137
|
TTP
|
Windows Registry Abuse, NotDoor Malware
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender Network Protection
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Scattered Lapsus$ Hunters, BlankGrabber Stealer
|
2026-05-13
|
|
Detect Copy of ShadowCopy with Script Block Logging
|
Powershell Script Block Logging 4104
|
T1003.002
|
TTP
|
Credential Dumping, VanHelsing Ransomware
|
2026-05-13
|
|
Process Deleting Its Process File Path
|
Sysmon EventID 1
|
T1070
|
TTP
|
Clop Ransomware, WhisperGate, Remcos, Data Destruction
|
2026-05-13
|
|
Schtasks used for forcing a reboot
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Windows Persistence Techniques, Scheduled Tasks, Ransomware
|
2026-05-13
|
|
Windows Exfiltration Over C2 Via Powershell UploadString
|
Powershell Script Block Logging 4104
|
T1041
|
TTP
|
Winter Vivern, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows PowerShell Script Block With Malicious String
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Outlook Macro Security Modified
|
Sysmon EventID 13
|
T1008
T1137
|
TTP
|
Windows Registry Abuse, NotDoor Malware
|
2026-05-13
|
|
Windows Routing and Remote Access Service Registry Key Change
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Gh0st RAT
|
2026-05-13
|
|
Windows Compatibility Telemetry Tampering Through Registry
|
Sysmon EventID 13
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Steal Authentication Certificates Export PfxCertificate
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows Remote Services Allow Rdp In Firewall
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion, Azorult
|
2026-05-13
|
|
Rundll32 Create Remote Thread To A Process
|
Sysmon EventID 8
|
T1055
|
TTP
|
Living Off The Land, IcedID
|
2026-05-13
|
|
Windows Find Domain Organizational Units with GetDomainOU
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Steal Authentication Certificates - ESC1 Authentication
|
Windows Event Log Security 4887, Windows Event Log Security 4768
|
T1550
T1649
|
TTP
|
Windows Certificate Services, Compromised Windows Host
|
2026-05-13
|
|
Windows Anonymous Pipe Activity
|
Sysmon EventID 18, Sysmon EventID 17
|
T1559
|
Hunting
|
SnappyBee, Castle RAT, China-Nexus Threat Activity, Salt Typhoon, Interlock Rat
|
2026-05-13
|
|
Windows Unusual NTLM Authentication Users By Destination
|
NTLM Operational 8006, NTLM Operational 8005, NTLM Operational 8004
|
T1110.003
|
Anomaly
|
Active Directory Password Spraying
|
2026-05-13
|
|
Windows Find Interesting ACL with FindInterestingDomainAcl
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Cached Domain Credentials Reg Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.005
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Exchange PowerShell Abuse via SSRF
|
|
T1133
T1190
|
TTP
|
ProxyNotShell, Seashell Blizzard, ProxyShell, BlackByte Ransomware
|
2026-05-13
|
|
Windows Unusual Count Of Users Failed To Authenticate From Process
|
Windows Event Log Security 4625
|
T1110.003
|
Anomaly
|
Insider Threat, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Detect Prohibited Applications Spawning cmd exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Hunting
|
Suspicious Zoom Child Processes, NOBELIUM Group, Suspicious MSHTA Activity, Suspicious Command-Line Executions
|
2026-05-13
|
|
Windows Ldifde Directory Object Behavior
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
T1105
|
TTP
|
Volt Typhoon
|
2026-05-13
|
|
Remote Process Instantiation via DCOM and PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
|
TTP
|
Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Process Executed From Removable Media
|
Sysmon EventID 13, Sysmon EventID 1
|
T1025
T1091
T1200
|
Anomaly
|
APT37 Rustonotto and FadeStealer, Data Protection
|
2026-05-13
|
|
Windows Phishing Recent ISO Exec Registry
|
Sysmon EventID 13
|
T1566.001
|
Hunting
|
Qakbot, Brute Ratel C4, IcedID, Warzone RAT, AgentTesla, Remcos, Azorult, Gozi Malware
|
2026-05-13
|
|
Disabling FolderOptions Windows Feature
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A
|
2026-05-13
|
|
Windows Rundll32 Load DLL in Temp Dir
|
Sysmon EventID 1
|
T1218.011
|
Anomaly
|
Interlock Rat
|
2026-05-13
|
|
Remote System Discovery with Adsisearcher
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Network Connection From Program In Suspect Location
|
Sysmon EventID 3
|
T1011
|
Anomaly
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Powershell Import Applocker Policy
|
Powershell Script Block Logging 4104
|
T1059.001
T1685
|
TTP
|
Azorult
|
2026-05-13
|
|
Detect mshta renamed
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
Hunting
|
Living Off The Land, Suspicious MSHTA Activity, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Service Create Kernel Mode Driver
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1068
T1543.003
|
TTP
|
CISA AA22-320A, Windows Drivers
|
2026-05-13
|
|
Windows Remote Image Load
|
Sysmon EventID 7
|
T1059
T1068
T1129
T1203
|
Anomaly
|
LockBit Ransomware, Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows SQL Server Configuration Option Hunt
|
Windows Event Log Application 15457
|
T1505.001
|
Hunting
|
SQL Server Abuse
|
2026-05-13
|
|
Remote System Discovery with Wmic
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Suspicious Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
TTP
|
Brute Ratel C4, DarkSide Ransomware, Graceful Wipe Out Attack, APT37 Rustonotto and FadeStealer, Cobalt Strike, LockBit Ransomware, Remote Monitoring and Management Software, Trickbot, Tuoni, Meterpreter, BlackByte Ransomware, Gozi Malware, Hellcat Ransomware
|
2026-05-13
|
|
Remote System Discovery with Dsquery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
Anomaly
|
Active Directory Discovery, LAMEHUG
|
2026-05-13
|
|
Mmc LOLBAS Execution Process Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
T1218.014
|
TTP
|
Living Off The Land, Water Gamayun, XML Runner Loader, Active Directory Lateral Movement
|
2026-05-13
|
|
Potential Telegram API Request Via CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1041
T1102.002
|
Anomaly
|
Water Gamayun, XMRig, 0bj3ctivity Stealer, BlankGrabber Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Regsvr32 with Known Silent Switch Cmdline
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.010
|
Anomaly
|
Qakbot, AsyncRAT, Suspicious Regsvr32 Activity, Remcos, IcedID, Living Off The Land
|
2026-05-13
|
|
Wbemprox COM Object Execution
|
Sysmon EventID 7
|
T1218.003
|
TTP
|
LockBit Ransomware, Revil Ransomware, Ransomware
|
2026-05-13
|
|
Windows Indirect Command Execution Via pcalua
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1202
|
TTP
|
Living Off The Land
|
2026-05-13
|
|
Detect Computer Changed with Anonymous Account
|
Windows Event Log Security 4742
|
T1210
|
Hunting
|
Detect Zerologon Attack
|
2026-05-13
|
|
Windows SharePoint Spinstall0 Webshell File Creation
|
Sysmon EventID 11
|
T1190
T1505.003
|
TTP
|
Microsoft SharePoint Vulnerabilities
|
2026-05-13
|
|
Disable Schedule Task
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Living Off The Land, IcedID
|
2026-05-13
|
|
GetWmiObject Ds Group with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
RunDLL Loading DLL By Ordinal
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Living Off The Land, Unusual Processes, Suspicious Rundll32 Activity, IcedID
|
2026-05-13
|
|
Windows Credential Dumping LSASS Memory Createdump
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.001
|
TTP
|
Credential Dumping, Scattered Lapsus$ Hunters, Compromised Windows Host
|
2026-05-13
|
|
Windows Powershell Cryptography Namespace
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
VIP Keylogger, XWorm, AsyncRAT
|
2026-05-13
|
|
Suspicious WAV file in Appdata Folder
|
Sysmon EventID 11, Windows Event Log Security 4688, Sysmon EventID 1
|
T1113
|
TTP
|
Remcos
|
2026-05-13
|
|
Randomly Generated Scheduled Task Name
|
Windows Event Log Security 4698
|
T1053.005
|
Hunting
|
0bj3ctivity Stealer, Scheduled Tasks, CISA AA22-257A, Active Directory Lateral Movement
|
2026-05-13
|
|
WinRAR Spawning Shell Application
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
WinRAR Spoofing Attack CVE-2023-38831, Compromised Windows Host
|
2026-05-13
|
|
Windows Query Registry UnInstall Program List
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Meduza Stealer, RedLine Stealer, StealC Stealer
|
2026-05-13
|
|
Suspicious writes to windows Recycle Bin
|
Sysmon EventID 11, Sysmon EventID 1
|
T1036
|
TTP
|
PlugX, Collection and Staging
|
2026-05-13
|
|
Delete ShadowCopy With PowerShell
|
Powershell Script Block Logging 4104
|
T1490
|
TTP
|
DarkSide Ransomware, Ransomware, VanHelsing Ransomware, Cactus Ransomware, DarkGate Malware, Revil Ransomware
|
2026-05-13
|
|
Windows Modify Registry Qakbot Binary Data Registry
|
Sysmon EventID 13, Sysmon EventID 1
|
T1112
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows Get-Variable.EXE Execution from WindowsApps Folder
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.008
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
Medusa Ransomware, MoonPeak, Malicious PowerShell, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Windows Scheduled Task Created in a Group Policy Object
|
Windows Event Log Security 5145
|
T1053.005
T1484.001
|
TTP
|
Windows Persistence Techniques, Scheduled Tasks, Living Off The Land
|
2026-05-13
|
|
Windows Mshta Execution In Registry
|
Sysmon EventID 13
|
T1218.005
|
TTP
|
Windows Persistence Techniques, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Windows Apache Benchmark Binary
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
MetaSploit
|
2026-05-13
|
|
Windows Registry Entries Restored Via Reg
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1012
|
Hunting
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows WinRAR Launched Outside Default Installation Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Windows AdFind Exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
TTP
|
Graceful Wipe Out Attack, Domain Trust Discovery, IcedID, BlackSuit Ransomware, NOBELIUM Group
|
2026-05-13
|
|
Ntdsutil Export NTDS
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.003
|
TTP
|
NetSupport RMM Tool Abuse, Rhysida Ransomware, Volt Typhoon, HAFNIUM Group, Prestige Ransomware, Living Off The Land, Credential Dumping
|
2026-05-13
|
|
Download Files Using Telegram
|
Sysmon EventID 15
|
T1105
|
TTP
|
Water Gamayun, Snake Keylogger, Crypto Stealer, XMRig, 0bj3ctivity Stealer, Phemedrone Stealer
|
2026-05-13
|
|
LLM Model File Creation
|
Sysmon EventID 11
|
T1543
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-05-13
|
|
Windows Get Local Admin with FindLocalAdminAccess
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Process Injection into Notepad
|
Sysmon EventID 10
|
T1055.002
|
Anomaly
|
BishopFox Sliver Adversary Emulation Framework, Earth Alux, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Disabling ControlPanel
|
Sysmon EventID 13
|
T1112
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Modify Registry AuthenticationLevelOverride
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
DarkGate Malware
|
2026-05-13
|
|
Windows Network Connection Discovery Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1049
|
Hunting
|
Active Directory Discovery, Prestige Ransomware, Windows Post-Exploitation, Azorult
|
2026-05-13
|
|
Windows Files and Dirs Access Rights Modification Via Icacls
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222.001
|
Anomaly
|
Defense Evasion or Unauthorized Access Via SDDL Tampering, Amadey
|
2026-05-13
|
|
Powershell Fileless Process Injection via GetProcAddress
|
Powershell Script Block Logging 4104
|
T1055
T1059.001
|
TTP
|
Data Destruction, Malicious PowerShell, Hellcat Ransomware, Hermetic Wiper
|
2026-05-13
|
|
Schtasks Run Task On Demand
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053
|
Anomaly
|
Qakbot, XMRig, Scheduled Tasks, Data Destruction, CISA AA22-257A, Industroyer2, Medusa Ransomware
|
2026-05-13
|
|
Windows Unsigned DLL Side-Loading In Same Process Path
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
XWorm, SnappyBee, China-Nexus Threat Activity, Salt Typhoon, Malicious Inno Setup Loader, Lokibot, SolarWinds WHD RCE Post Exploitation, Derusbi, DarkGate Malware, PlugX, NailaoLocker Ransomware
|
2026-05-13
|
|
Shim Database File Creation
|
Sysmon EventID 11
|
T1546.011
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Security And Backup Services Stop
|
Windows Event Log System 7036
|
T1490
|
TTP
|
BlackMatter Ransomware, Compromised Windows Host, Ransomware, Scattered Lapsus$ Hunters, LockBit Ransomware, Termite Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Mark Of The Web Bypass
|
Sysmon EventID 23
|
T1553.005
|
TTP
|
Warzone RAT, Quasar RAT
|
2026-05-13
|
|
Windows Potential AppDomainManager Hijack Artifacts Creation
|
Sysmon EventID 11
|
T1574.014
|
Anomaly
|
SesameOp
|
2026-05-13
|
|
Domain Group Discovery With Dsquery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
Anomaly
|
Active Directory Discovery, LAMEHUG
|
2026-05-13
|
|
Windows Alternate DataStream - Process Execution
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1564.004
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host
|
2026-05-13
|
|
GetDomainController with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Service Initiation on Remote Endpoint
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.003
|
TTP
|
CISA AA23-347A, Active Directory Lateral Movement
|
2026-05-13
|
|
Domain Account Discovery with Wmic
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.002
|
TTP
|
Active Directory Discovery, Interlock Ransomware
|
2026-05-13
|
|
Windows Unsecured Outlook Credentials Access In Registry
|
Windows Event Log Security 4663
|
T1552
|
Anomaly
|
Meduza Stealer, VIP Keylogger, StealC Stealer, 0bj3ctivity Stealer, Snake Keylogger, Lokibot
|
2026-05-13
|
|
Suspicious Rundll32 no Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Graceful Wipe Out Attack, Cobalt Strike, Hellcat Ransomware, PrintNightmare CVE-2021-34527, BlackByte Ransomware, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows RDP Login Session Was Established
|
Windows Event Log Security 4624
|
T1021.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Detect Regsvcs with Network Connection
|
Sysmon EventID 3
|
T1218.009
|
TTP
|
Living Off The Land, Suspicious Regsvcs Regasm Activity, Hellcat Ransomware
|
2026-05-13
|
|
Allow Inbound Traffic By Firewall Rule Registry
|
Sysmon EventID 13
|
T1021.001
|
TTP
|
NjRAT, Windows Registry Abuse, Azorult, Medusa Ransomware, Prohibited Traffic Allowed or Protocol Mismatch, PlugX
|
2026-05-13
|
|
Windows Disable Memory Crash Dump
|
Sysmon EventID 13
|
T1485
|
TTP
|
Data Destruction, Hermetic Wiper, Ransomware, Windows Registry Abuse
|
2026-05-13
|
|
Time Provider Persistence Registry
|
Sysmon EventID 13
|
T1547.003
|
TTP
|
Windows Persistence Techniques, Windows Registry Abuse, Data Destruction, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Domain Group Discovery with Adsisearcher
|
Powershell Script Block Logging 4104
|
T1069.002
|
TTP
|
Active Directory Discovery, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Svchost.exe Parent Process Anomaly
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.009
|
Anomaly
|
SnappyBee, China-Nexus Threat Activity
|
2026-05-13
|
|
User Discovery With Env Vars PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows DLL Side-Loading Process Child Of Calc
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.001
|
Anomaly
|
Qakbot, Earth Alux
|
2026-05-13
|
|
Windows Regsvr32 Renamed Binary
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.010
|
TTP
|
Qakbot, Compromised Windows Host
|
2026-05-13
|
|
PowerShell Enable PowerShell Remoting
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
Enable WDigest UseLogonCredential Registry
|
Sysmon EventID 13
|
T1003
T1112
|
TTP
|
Windows Registry Abuse, Credential Dumping, CISA AA22-320A
|
2026-05-13
|
|
Detect Renamed 7-Zip
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1560.001
|
Hunting
|
Malicious Inno Setup Loader, Collection and Staging
|
2026-05-13
|
|
Jscript Execution Using Cscript App
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.007
|
TTP
|
FIN7, Remcos
|
2026-05-13
|
|
Windows Gdrive Binary Activity
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1567
|
TTP
|
China-Nexus Threat Activity
|
2026-05-13
|
|
GetDomainComputer with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows System Reboot CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1529
|
Hunting
|
XWorm, NjRAT, MuddyWater, Scattered Lapsus$ Hunters, MoonPeak, Quasar RAT, DarkGate Malware, DarkCrystal RAT
|
2026-05-13
|
|
Spoolsv Writing a DLL
|
Sysmon EventID 11, Windows Event Log Security 4688, Sysmon EventID 1
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Compromised Windows Host, Black Basta Ransomware
|
2026-05-13
|
|
Windows Enable PowerShell Web Access
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Malicious PowerShell, CISA AA24-241A
|
2026-05-13
|
|
WMI Recon Running Process Or Services
|
Powershell Script Block Logging 4104
|
T1592
|
Anomaly
|
Data Destruction, Malicious PowerShell, Hermetic Wiper
|
2026-05-13
|
|
Suspicious Rundll32 PluginInit
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
IcedID
|
2026-05-13
|
|
Windows Registry Dotnet ETW Disabled Via ENV Variable
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Impair Defense Deny Security Software With Applocker
|
Sysmon EventID 13
|
T1685
|
TTP
|
Scattered Lapsus$ Hunters, Azorult
|
2026-05-13
|
|
Windows Sensitive Registry Hive Dump Via CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.002
|
TTP
|
Compromised Windows Host, DarkSide Ransomware, Seashell Blizzard, Volt Typhoon, Data Destruction, Windows Registry Abuse, CISA AA22-257A, Industroyer2, Credential Dumping, CISA AA23-347A
|
2026-05-13
|
|
Windows Enable Win32 ScheduledJob via Registry
|
Sysmon EventID 13
|
T1053.005
|
Anomaly
|
Scheduled Tasks, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows List ENV Variables Via SET Command From Uncommon Parent
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows Disable LogOff Button Through Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Registry Abuse, Ransomware
|
2026-05-13
|
|
Windows WinLogon with Public Network Connection
|
Sysmon EventID 1, Sysmon EventID 3
|
T1542.003
|
Hunting
|
BlackLotus Campaign
|
2026-05-13
|
|
Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
|
Windows Event Log Security 4768
|
T1110.003
|
TTP
|
Active Directory Kerberos Attacks, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows Special Privileged Logon On Multiple Hosts
|
Windows Event Log Security 4672
|
T1021.002
T1087
T1135
|
TTP
|
Active Directory Privilege Escalation, Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows File Download Via CertUtil
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
DarkSide Ransomware, Compromised Windows Host, Cisco Network Visibility Module Analytics, Ingress Tool Transfer, Forest Blizzard, ProxyNotShell, Flax Typhoon, CISA AA22-277A, Living Off The Land
|
2026-05-13
|
|
Windows SQLCMD Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Hunting
|
SQL Server Abuse, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Time Based Evasion via Choice Exec
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497.003
|
Anomaly
|
Snake Keylogger, 0bj3ctivity Stealer, VIP Keylogger
|
2026-05-13
|
|
WBAdmin Delete System Backups
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
Ransomware, Chaos Ransomware, Storm-2460 CLFS Zero Day Exploitation, Storm-0501 Ransomware, Prestige Ransomware, Ryuk Ransomware
|
2026-05-13
|
|
CertUtil With Decode Argument
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1140
|
TTP
|
Forest Blizzard, Storm-2460 CLFS Zero Day Exploitation, APT29 Diplomatic Deceptions with WINELOADER, Living Off The Land, Deobfuscate-Decode Files or Information, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows AD Hidden OU Creation
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Disable Lock Workstation Feature Through Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Ransomware
|
2026-05-13
|
|
Registry Keys Used For Persistence
|
Sysmon EventID 13
|
T1547.001
|
TTP
|
SystemBC, Qakbot, Braodo Stealer, AsyncRAT, Lokibot, Windows Registry Abuse, Azorult, BlackSuit Ransomware, Axios Supply Chain Post Compromise, SnappyBee, APT37 Rustonotto and FadeStealer, Remcos, BlackByte Ransomware, Derusbi, Sneaky Active Directory Persistence Tricks, NjRAT, Chaos Ransomware, MuddyWater, Salt Typhoon, Emotet Malware DHS Report TA18-201A, ValleyRAT, Cactus Ransomware, Amadey, Quasar RAT, Suspicious Windows Registry Activities, DarkGate Malware, Snake Keylogger, WinDealer RAT, RedLine Stealer, Ransomware, Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns, China-Nexus Threat Activity, XWorm, Warzone RAT, DHS Report TA18-074A, Suspicious MSHTA Activity, Windows Persistence Techniques, Castle RAT, MoonPeak, 0bj3ctivity Stealer, IcedID, Gh0st RAT, NetSupport RMM Tool Abuse, DarkCrystal RAT, CISA AA23-347A, Interlock Ransomware
|
2026-05-13
|
|
Windows New Default File Association Value Set
|
Sysmon EventID 13
|
T1546.001
|
Hunting
|
Windows Persistence Techniques, Windows Registry Abuse, Data Destruction, Windows Privilege Escalation, Prestige Ransomware, Hermetic Wiper
|
2026-05-13
|
|
Windows PowerShell Export PfxCertificate
|
Powershell Script Block Logging 4104
|
T1552.004
T1649
|
Anomaly
|
Windows Certificate Services, Water Gamayun, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Detect HTML Help URL in Command Line
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.001
|
TTP
|
Compromised Windows Host, Cisco Network Visibility Module Analytics, APT37 Rustonotto and FadeStealer, Living Off The Land, Suspicious Compiled HTML Activity
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Name
|
Windows Event Log Security 4700, Windows Event Log Security 4702, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Ransomware, APT37 Rustonotto and FadeStealer, Castle RAT, Windows Persistence Techniques, Scheduled Tasks, 0bj3ctivity Stealer, Ryuk Ransomware
|
2026-05-13
|
|
Suspicious GPUpdate no Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
Cobalt Strike, Graceful Wipe Out Attack, Hellcat Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows AD Privileged Account SID History Addition
|
Windows Event Log Security 4738, Windows Event Log Security 4742
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows SpeechRuntime Suspicious Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
|
TTP
|
Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
Uninstall App Using MsiExec
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
TTP
|
Ransomware
|
2026-05-13
|
|
Windows Curl Download to Suspicious Path
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Black Basta Ransomware, Compromised Windows Host, Cisco Network Visibility Module Analytics, APT37 Rustonotto and FadeStealer, China-Nexus Threat Activity, Ingress Tool Transfer, Forest Blizzard, NPM Supply Chain Compromise, Salt Typhoon, IcedID, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Impair Defense Change Win Defender Throttle Rate
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
ServicePrincipalNames Discovery with SetSPN
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1558.003
|
TTP
|
Active Directory Privilege Escalation, Active Directory Kerberos Attacks, Active Directory Discovery, Compromised Windows Host
|
2026-05-13
|
|
Windows Impair Defense Disable Defender Protocol Recognition
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
XMRIG Driver Loaded
|
Sysmon EventID 6
|
T1543.003
|
TTP
|
CISA AA22-320A, XMRig, Crypto Stealer
|
2026-05-13
|
|
Windows Wmic DiskDrive Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Windows AD Replication Request Initiated by User Account
|
Windows Event Log Security 4624, Windows Event Log Security 4662
|
T1003.006
|
TTP
|
Sneaky Active Directory Persistence Tricks, Credential Dumping, Compromised Windows Host
|
2026-05-13
|
|
Windows Outlook WebView Registry Modification
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Suspicious Windows Registry Activities
|
2026-05-13
|
|
Windows AD ServicePrincipalName Added To Domain Account
|
Windows Event Log Security 5136
|
T1098
|
TTP
|
Sneaky Active Directory Persistence Tricks, Interlock Ransomware
|
2026-05-13
|
|
Windows Impair Defense Disable Defender Firewall And Network
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Privilege Escalation Attempt Via MSI Rollback
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1068
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Windows Archive Collected Data via Powershell
|
Powershell Script Block Logging 4104
|
T1560
|
Anomaly
|
CISA AA23-347A, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows PowerView Constrained Delegation Discovery
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Rhysida Ransomware, Active Directory Kerberos Attacks, CISA AA23-347A
|
2026-05-13
|
|
Unusual Number of Kerberos Service Tickets Requested
|
Windows Event Log Security 4769
|
T1558.003
|
Anomaly
|
Active Directory Kerberos Attacks
|
2026-05-13
|
|
Windows Cmdline Tool Execution From Non-Shell Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.007
|
Anomaly
|
Qakbot, Water Gamayun, Rhysida Ransomware, FIN7, Volt Typhoon, SolarWinds WHD RCE Post Exploitation, CISA AA22-277A, Tuoni, Gh0st RAT, BlankGrabber Stealer, Medusa Ransomware, Gozi Malware, DarkGate Malware, CISA AA23-347A
|
2026-05-13
|
|
Windows Office Product Spawned Uncommon Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
TTP
|
Qakbot, IcedID, Compromised Windows Host, Spearphishing Attachments, APT37 Rustonotto and FadeStealer, NjRAT, AgentTesla, FIN7, Warzone RAT, MuddyWater, DarkCrystal RAT, Remcos, CVE-2023-21716 Word RTF Heap Corruption, Trickbot, Azorult, CVE-2023-36884 Office and Windows HTML RCE Vulnerability, PlugX
|
2026-05-13
|
|
Windows Domain Admin Impersonation Indicator
|
Windows Event Log Security 4627
|
T1558
|
TTP
|
Active Directory Kerberos Attacks, Gozi Malware, Active Directory Privilege Escalation, Compromised Windows Host
|
2026-05-13
|
|
Disabling Remote User Account Control
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, AgentTesla, Windows Registry Abuse, Remcos, Azorult, Suspicious Windows Registry Activities
|
2026-05-13
|
|
System Information Discovery Detection
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
TTP
|
Cleo File Transfer Software, NetSupport RMM Tool Abuse, Windows Discovery Techniques, Lotus Blossom Chrysalis Backdoor, SolarWinds WHD RCE Post Exploitation, LAMEHUG, BlankGrabber Stealer, Medusa Ransomware, Gozi Malware, BlackSuit Ransomware, Interlock Ransomware
|
2026-05-13
|
|
GetDomainGroup with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows PowerShell Invoke-RestMethod IP Information Collection
|
Powershell Script Block Logging 4104
|
T1016
T1059.001
T1082
|
Anomaly
|
Water Gamayun
|
2026-05-13
|
|
Windows EFI Bootloader File Modification
|
Sysmon EventID 11
|
T1542.003
|
TTP
|
Windows BootKits
|
2026-05-13
|
|
Windows Identify PowerShell Web Access IIS Pool
|
Windows Event Log Security 4648
|
T1190
|
Hunting
|
CISA AA24-241A
|
2026-05-13
|
|
Mimikatz PassTheTicket CommandLine Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1550.003
|
TTP
|
Sandworm Tools, Scattered Lapsus$ Hunters, CISA AA22-320A, Active Directory Kerberos Attacks, CISA AA23-347A
|
2026-05-13
|
|
Unloading AMSI via Reflection
|
Powershell Script Block Logging 4104
|
T1059.001
T1685
|
TTP
|
Data Destruction, Malicious PowerShell, Hermetic Wiper
|
2026-05-13
|
|
ConnectWise ScreenConnect Path Traversal
|
Sysmon EventID 11
|
T1190
|
TTP
|
Seashell Blizzard, ConnectWise ScreenConnect Vulnerabilities
|
2026-05-13
|
|
Windows Chromium Browser Launched with Small Window Size
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
|
TTP
|
Browser Hijacking
|
2026-05-13
|
|
Windows Steal Authentication Certificates CryptoAPI
|
Windows Event Log CAPI2 70
|
T1649
|
Anomaly
|
Windows Certificate Services, Hellcat Ransomware
|
2026-05-13
|
|
Windows DISM Install PowerShell Web Access
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1548.002
|
TTP
|
CISA AA24-241A
|
2026-05-13
|
|
Rundll32 Shimcache Flush
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1112
|
TTP
|
Living Off The Land, Unusual Processes, Compromised Windows Host
|
2026-05-13
|
|
First Time Seen Running Windows Service
|
Windows Event Log System 7036
|
T1569.002
|
Anomaly
|
Orangeworm Attack Group, NOBELIUM Group, Windows Service Abuse
|
2026-05-13
|
|
Kerberos User Enumeration
|
Windows Event Log Security 4768
|
T1589.002
|
Anomaly
|
Active Directory Kerberos Attacks
|
2026-05-13
|
|
Windows BootLoader Inventory
|
|
T1542.001
|
Hunting
|
Windows BootKits, BlackLotus Campaign
|
2026-05-13
|
|
Excessive Usage Of SC Service Utility
|
Sysmon EventID 1
|
T1569.002
|
Anomaly
|
Crypto Stealer, Ransomware, Azorult
|
2026-05-13
|
|
Rundll32 with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1218.011
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Cobalt Strike, Cactus Ransomware, PrintNightmare CVE-2021-34527, BlackByte Ransomware, BlackSuit Ransomware, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows Cisco Secure Endpoint Related Service Stopped
|
Windows Event Log System 7036
|
T1490
|
Anomaly
|
Security Solution Tampering, Scattered Lapsus$ Hunters, Hellcat Ransomware
|
2026-05-13
|
|
Windows AppX Deployment Package Installation Success
|
Windows Event Log AppXDeployment-Server 854
|
T1204.002
|
Anomaly
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows New EventLog ChannelAccess Registry Value Set
|
Sysmon EventID 13
|
T1685.001
|
Anomaly
|
Defense Evasion or Unauthorized Access Via SDDL Tampering, LockBit Ransomware
|
2026-05-13
|
|
Windows LOLBAS Executed As Renamed File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1218.011
|
TTP
|
Water Gamayun, Living Off The Land, Windows Defense Evasion Tactics, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Windows Export Certificate
|
Windows Event Log CertificateServicesClient 1007
|
T1552.004
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows Snake Malware File Modification Crmlog
|
Sysmon EventID 11
|
T1027
|
TTP
|
Snake Malware
|
2026-05-13
|
|
Windows Modify Registry UpdateServiceUrlAlternate
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
RedLine Stealer
|
2026-05-13
|
|
Windows WPDBusEnum Registry Key Modification
|
Sysmon EventID 13, Sysmon EventID 12
|
T1025
T1091
T1200
|
Anomaly
|
APT37 Rustonotto and FadeStealer, Data Protection
|
2026-05-13
|
|
Windows Unusual Process Load Mozilla NSS-Mozglue Module
|
Sysmon EventID 7
|
T1218.003
|
Anomaly
|
VIP Keylogger, StealC Stealer, 0bj3ctivity Stealer, Quasar RAT, Lokibot
|
2026-05-13
|
|
DNS Exfiltration Using Nslookup App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1048
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Dynamic DNS, Command And Control, Data Exfiltration
|
2026-05-13
|
|
Windows System Shutdown CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1529
|
Anomaly
|
Sandworm Tools, XWorm, NjRAT, MuddyWater, Scattered Lapsus$ Hunters, ZOVWiper, MoonPeak, Quasar RAT, DarkGate Malware, DarkCrystal RAT
|
2026-05-13
|
|
Windows Attempt To Stop Security Service
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
WhisperGate, Disabling Security Tools, Graceful Wipe Out Attack, Data Destruction, Trickbot, Azorult
|
2026-05-13
|
|
Detect HTML Help Using InfoTech Storage Handlers
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.001
|
TTP
|
Living Off The Land, Suspicious Compiled HTML Activity, Compromised Windows Host, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Excessive distinct processes from Windows Temp
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
Meterpreter
|
2026-05-13
|
|
Ransomware Notes bulk creation
|
Sysmon EventID 11
|
T1486
|
Anomaly
|
BlackMatter Ransomware, Black Basta Ransomware, DarkSide Ransomware, Rhysida Ransomware, Chaos Ransomware, Cactus Ransomware, Clop Ransomware, LockBit Ransomware, Termite Ransomware, Medusa Ransomware, NailaoLocker Ransomware, Hellcat Ransomware, Interlock Ransomware
|
2026-05-13
|
|
Windows AD DCShadow Privileges ACL Addition
|
Windows Event Log Security 5136
|
T1207
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD GPO Disabled
|
Windows Event Log Security 5136
|
T1484.001
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
|
Windows Event Log Security 4648
|
T1110.003
|
TTP
|
Insider Threat, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Services LOLBAS Execution Process Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.003
|
TTP
|
Qakbot, Active Directory Lateral Movement, Living Off The Land, CISA AA23-347A, Hellcat Ransomware
|
2026-05-13
|
|
Windows AD Replication Request Initiated from Unsanctioned Location
|
Windows Event Log Security 4624, Windows Event Log Security 4662
|
T1003.006
|
TTP
|
Sneaky Active Directory Persistence Tricks, Credential Dumping, Compromised Windows Host
|
2026-05-13
|
|
Windows AD Short Lived Domain Controller SPN Attribute
|
Windows Event Log Security 4624, Windows Event Log Security 5136
|
T1207
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows Defacement Modify Transcodedwallpaper File
|
Sysmon EventID 11, Sysmon EventID 1
|
T1491
|
Anomaly
|
Brute Ratel C4
|
2026-05-13
|
|
Windows Njrat Fileless Storage via Registry
|
Sysmon EventID 13
|
T1027.011
|
TTP
|
NjRAT
|
2026-05-13
|
|
Windows Modify Registry Risk Behavior
|
|
T1112
|
Correlation
|
Windows Registry Abuse
|
2026-05-13
|
|
Get DomainUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Windows Hidden Schedule Task Settings
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Active Directory Discovery, Compromised Windows Host, Scheduled Tasks, Malicious Inno Setup Loader, Data Destruction, Cactus Ransomware, CISA AA22-257A, Industroyer2, Hellcat Ransomware
|
2026-05-13
|
|
Windows Binary Proxy Execution Mavinject DLL Injection
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.013
|
TTP
|
Living Off The Land
|
2026-05-13
|
|
Windows System LogOff Commandline
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1529
|
Anomaly
|
NjRAT, DarkCrystal RAT, Scattered Lapsus$ Hunters, XWorm
|
2026-05-13
|
|
Windows InstallUtil Uninstall Option
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.004
|
TTP
|
Living Off The Land, Compromised Windows Host, Signed Binary Proxy Execution InstallUtil
|
2026-05-13
|
|
Windows EFI Volume Mount Attempt Via Mountvol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
T1542
T1688
|
Anomaly
|
Compromised Windows Host
|
2026-05-13
|
|
Detect Certify With PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1059.001
T1649
|
TTP
|
Windows Certificate Services, Malicious PowerShell
|
2026-05-13
|
|
Windows Non-System Account Targeting Lsass
|
Sysmon EventID 10
|
T1003.001
|
TTP
|
Credential Dumping, Scattered Lapsus$ Hunters, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Detect PsExec With accepteula Flag
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
|
TTP
|
IcedID, DarkSide Ransomware, DHS Report TA18-074A, Sandworm Tools, Seashell Blizzard, Rhysida Ransomware, VanHelsing Ransomware, SamSam Ransomware, Volt Typhoon, Cactus Ransomware, CISA AA22-320A, BlackByte Ransomware, Storm-0501 Ransomware, HAFNIUM Group, Active Directory Lateral Movement, Medusa Ransomware, DarkGate Malware
|
2026-05-13
|
|
Windows TeamCity Plugin Installed
|
Sysmon EventID 11
|
T1059
T1190
T1505.003
|
Anomaly
|
JetBrains TeamCity Vulnerabilities, JetBrains TeamCity Unauthenticated RCE
|
2026-05-13
|
|
Windows Indirect Command Execution Via forfiles
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1202
|
TTP
|
Living Off The Land, Windows Post-Exploitation
|
2026-05-13
|
|
Windows MSIExec Unregister DLLRegisterServer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
TTP
|
Windows System Binary Proxy Execution MSIExec
|
2026-05-13
|
|
Windows Hunting System Account Targeting Lsass
|
Sysmon EventID 10
|
T1003.001
|
Hunting
|
Credential Dumping, Scattered Lapsus$ Hunters, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Revil Registry Entry
|
Sysmon EventID 13, Sysmon EventID 12
|
T1112
|
TTP
|
Windows Registry Abuse, Revil Ransomware, Ransomware
|
2026-05-13
|
|
Suspicious DLLHost no Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
Cobalt Strike, Graceful Wipe Out Attack, Cactus Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
GetAdGroup with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Detect Remote Access Software Usage File
|
Sysmon EventID 11
|
T1219
|
Anomaly
|
CISA AA24-241A, Ransomware, Seashell Blizzard, Insider Threat, Interlock Ransomware, Scattered Lapsus$ Hunters, Cactus Ransomware, Remote Monitoring and Management Software, Command And Control, Gozi Malware, Scattered Spider, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Eventlog Cleared Via Wevtutil
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.005
|
Anomaly
|
Ransomware, Rhysida Ransomware, Windows Log Manipulation, Clop Ransomware, CISA AA23-347A, ShrinkLocker
|
2026-05-13
|
|
Windows User Execution Malicious URL Shortcut File
|
Sysmon EventID 11
|
T1204.002
|
Anomaly
|
XWorm, APT37 Rustonotto and FadeStealer, NjRAT, Chaos Ransomware, Quasar RAT, Snake Keylogger
|
2026-05-13
|
|
Powershell Windows Defender Exclusion Commands
|
Powershell Script Block Logging 4104
|
T1685
|
TTP
|
Windows Defense Evasion Tactics, WhisperGate, Warzone RAT, AgentTesla, CISA AA22-320A, Data Destruction, Remcos, NetSupport RMM Tool Abuse, BlankGrabber Stealer
|
2026-05-13
|
|
Windows Modify Registry Utilize ProgIDs
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
ValleyRAT
|
2026-05-13
|
|
Windows Sqlservr Spawning Shell
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1505.001
|
Hunting
|
SQL Server Abuse
|
2026-05-13
|
|
Windows Mustang Panda USB Tool Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1020
T1204.002
T1574.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Event Logging Service Has Shutdown
|
Windows Event Log Security 1100
|
T1685.005
|
Hunting
|
Clop Ransomware, Scattered Lapsus$ Hunters, Ransomware, Windows Log Manipulation
|
2026-05-13
|
|
Windows File Transfer Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
Snake Keylogger, AgentTesla, Hellcat Ransomware
|
2026-05-13
|
|
GetNetTcpconnection with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1049
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Suspicious microsoft workflow compiler rename
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1127
|
Hunting
|
Graceful Wipe Out Attack, Cobalt Strike, BlackByte Ransomware, Living Off The Land, Masquerading - Rename System Utilities, Trusted Developer Utilities Proxy Execution
|
2026-05-13
|
|
Windows Credentials from Password Stores Creation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1555
|
TTP
|
DarkGate Malware, NetSupport RMM Tool Abuse, Compromised Windows Host
|
2026-05-13
|
|
Create Remote Thread In Shell Application
|
Sysmon EventID 8
|
T1055
|
TTP
|
Qakbot, Warzone RAT, IcedID
|
2026-05-13
|
|
Allow Network Discovery In Firewall
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1686.001
|
TTP
|
Ransomware, NjRAT, BlackByte Ransomware, Medusa Ransomware, Revil Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Remote Services Allow Remote Assistance
|
Sysmon EventID 13
|
T1021.001
|
Anomaly
|
Azorult
|
2026-05-13
|
|
Windows Unusual NTLM Authentication Destinations By Source
|
NTLM Operational 8006, NTLM Operational 8005, NTLM Operational 8004
|
T1110.003
|
Anomaly
|
Active Directory Password Spraying
|
2026-05-13
|
|
Disabling Task Manager
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, NjRAT
|
2026-05-13
|
|
Windows NorthStar C2 Agent Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
T1547.001
T1608
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Potential System Network Configuration Discovery Activity
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1016
|
Anomaly
|
Unusual Processes
|
2026-05-13
|
|
Windows DLL Search Order Hijacking with iscsicpl
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.001
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, Compromised Windows Host
|
2026-05-13
|
|
Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos
|
Windows Event Log Security 4768
|
T1110.003
|
Anomaly
|
Active Directory Kerberos Attacks, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows MSIExec Remote Download
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
Anomaly
|
Water Gamayun, Cisco Network Visibility Module Analytics, Windows System Binary Proxy Execution MSIExec, SolarWinds WHD RCE Post Exploitation, StealC Stealer
|
2026-05-13
|
|
Windows ComputerDefaults Spawning a Process
|
Sysmon EventID 1
|
T1548.002
|
TTP
|
BlankGrabber Stealer, Castle RAT
|
2026-05-13
|
|
Screensaver Event Trigger Execution
|
Sysmon EventID 13
|
T1546.002
|
TTP
|
Windows Persistence Techniques, Windows Registry Abuse, Data Destruction, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Windows Remote Host Computer Management Access
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.006
|
Anomaly
|
Medusa Ransomware
|
2026-05-13
|
|
Check Elevated CMD using whoami
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
TTP
|
FIN7
|
2026-05-13
|
|
Windows Remote Services Rdp Enable
|
Sysmon EventID 13
|
T1021.001
|
TTP
|
Medusa Ransomware, Windows RDP Artifacts and Defense Evasion, BlackSuit Ransomware, Azorult
|
2026-05-13
|
|
Windows Security Support Provider Reg Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1547.005
|
Anomaly
|
Sneaky Active Directory Persistence Tricks, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows Registry BootExecute Modification
|
Sysmon EventID 13
|
T1542
T1547.001
|
TTP
|
Windows BootKits
|
2026-05-13
|
|
Detect Regasm with Network Connection
|
Sysmon EventID 3
|
T1218.009
|
TTP
|
Suspicious Regsvcs Regasm Activity, Handala Wiper, Void Manticore, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
System Processes Run From Unexpected Locations
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
|
Anomaly
|
Qakbot, Windows Error Reporting Service Elevation of Privilege Vulnerability, Ransomware, Suspicious Command-Line Executions, DarkGate Malware, Unusual Processes, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Vbscript Execution Using Wscript App
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.005
|
TTP
|
FIN7, Remcos, AsyncRAT
|
2026-05-13
|
|
Windows Firewall Rule Modification
|
Windows Event Log Security 4947
|
T1686
|
Anomaly
|
Medusa Ransomware, NetSupport RMM Tool Abuse, ShrinkLocker
|
2026-05-13
|
|
Windows Registry SIP Provider Modification
|
Sysmon EventID 13
|
T1553.003
|
TTP
|
Subvert Trust Controls SIP and Trust Provider Hijacking
|
2026-05-13
|
|
Windows Application Layer Protocol RMS Radmin Tool Namedpipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1071
|
TTP
|
Azorult
|
2026-05-13
|
|
Get DomainUser with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.002
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Windows Modify Registry MaxConnectionPerServer
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Warzone RAT
|
2026-05-13
|
|
Powershell Remote Thread To Known Windows Process
|
Sysmon EventID 8
|
T1055
|
TTP
|
Trickbot
|
2026-05-13
|
|
Windows Registry Certificate Added
|
Sysmon EventID 13
|
T1553.004
|
Anomaly
|
Windows Registry Abuse, Windows Drivers
|
2026-05-13
|
|
Get ADUserResultantPasswordPolicy with Powershell Script Block
|
Powershell Script Block Logging 4104
|
T1201
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Malicious InProcServer32 Modification
|
Sysmon EventID 13, Sysmon EventID 12
|
T1112
T1218.010
|
TTP
|
Suspicious Regsvr32 Activity, Remcos
|
2026-05-13
|
|
Windows Indicator Removal Via Rmdir
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070
|
Anomaly
|
DarkGate Malware, ZOVWiper, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Disable Logs Using WevtUtil
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.005
|
TTP
|
Rhysida Ransomware, CISA AA23-347A, Ransomware
|
2026-05-13
|
|
Windows Credentials Access via VaultCli Module
|
Sysmon EventID 7
|
T1555.004
|
Anomaly
|
Meduza Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Windows Rundll32 Execution With Log.DLL
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574
|
Anomaly
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Windows AD Domain Root ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Executables Or Script Creation In Temp Path
|
Sysmon EventID 11
|
T1036
|
Anomaly
|
Qakbot, AsyncRAT, AgentTesla, SesameOp, Volt Typhoon, Data Destruction, Interlock Rat, Trickbot, Azorult, Industroyer2, Brute Ratel C4, Axios Supply Chain Post Compromise, Meduza Stealer, SnappyBee, APT37 Rustonotto and FadeStealer, PromptFlux, Void Manticore, LockBit Ransomware, Remcos, Hermetic Wiper, Derusbi, BlackByte Ransomware, PlugX, WhisperGate, Crypto Stealer, NjRAT, Rhysida Ransomware, Chaos Ransomware, Salt Typhoon, ValleyRAT, Amadey, XML Runner Loader, DarkGate Malware, WinDealer RAT, Snake Keylogger, RedLine Stealer, AcidPour, Graceful Wipe Out Attack, China-Nexus Threat Activity, Handala Wiper, Warzone RAT, XMRig, PromptLock, VIP Keylogger, Swift Slicer, MoonPeak, Double Zero Destructor, IcedID, DarkCrystal RAT, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Windows Devtunnels Image Loaded
|
Sysmon EventID 7
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows Modify Registry USeWuServer
|
Sysmon EventID 13
|
T1112
|
Hunting
|
RedLine Stealer
|
2026-05-13
|
|
Windows Delete or Modify System Firewall
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1686
|
Hunting
|
NjRAT, ShrinkLocker
|
2026-05-13
|
|
Detect Remote Access Software Usage Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1219
|
Anomaly
|
GhostRedirector IIS Module and Rungan Backdoor, CISA AA24-241A, Ransomware, Seashell Blizzard, Insider Threat, Scattered Lapsus$ Hunters, Cactus Ransomware, Storm-0501 Ransomware, Remote Monitoring and Management Software, Command And Control, Gozi Malware, Scattered Spider, Interlock Ransomware
|
2026-05-13
|
|
Windows Ngrok Reverse Proxy Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090
T1102
T1572
|
Anomaly
|
CISA AA22-320A, CISA AA24-241A, Reverse Network Proxy
|
2026-05-13
|
|
Windows Unusual NTLM Authentication Destinations By User
|
NTLM Operational 8006, NTLM Operational 8005, NTLM Operational 8004
|
T1110.003
|
Anomaly
|
Active Directory Password Spraying
|
2026-05-13
|
|
Windows Process Injection Wermgr Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
Anomaly
|
Qakbot, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-05-13
|
|
Possible Lateral Movement PowerShell Spawn
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
T1021.006
T1047
T1053.005
T1059.001
T1218.014
T1543.003
|
Anomaly
|
CISA AA24-241A, Scheduled Tasks, Active Directory Lateral Movement, Data Destruction, Malicious PowerShell, Hermetic Wiper, Microsoft WSUS CVE-2025-59287
|
2026-05-13
|
|
Windows Possible Credential Dumping
|
Sysmon EventID 10
|
T1003.001
|
TTP
|
CISA AA22-264A, Detect Zerologon Attack, DarkSide Ransomware, Scattered Lapsus$ Hunters, CISA AA22-257A, Credential Dumping, CISA AA23-347A
|
2026-05-13
|
|
Suspicious SearchProtocolHost no Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Cobalt Strike, Cactus Ransomware, BlackByte Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Active Setup Registry Autostart
|
Sysmon EventID 13
|
T1547.014
|
TTP
|
Data Destruction, Windows Persistence Techniques, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
BCDEdit Failure Recovery Modification
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
Compromised Windows Host, Ransomware, Storm-2460 CLFS Zero Day Exploitation, Void Manticore, Ryuk Ransomware
|
2026-05-13
|
|
Windows Registry Modification for Safe Mode Persistence
|
Sysmon EventID 13
|
T1547.001
|
TTP
|
Windows Registry Abuse, Windows Drivers, Ransomware
|
2026-05-13
|
|
Runas Execution in CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1134.001
|
Hunting
|
Data Destruction, Windows Privilege Escalation, Quasar RAT, Hermetic Wiper
|
2026-05-13
|
|
Allow File And Printing Sharing In Firewall
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1686.001
|
TTP
|
Ransomware, Hellcat Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Suspicious MSBuild Rename
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1127.001
|
Hunting
|
Graceful Wipe Out Attack, Storm-2460 CLFS Zero Day Exploitation, Trusted Developer Utilities Proxy Execution MSBuild, Cobalt Strike, BlackByte Ransomware, Living Off The Land, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Windows PowerShell Process Implementing Manual Base64 Decoder
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1027.010
T1059.001
|
Anomaly
|
Deobfuscate-Decode Files or Information, Compromised Windows Host
|
2026-05-13
|
|
Detect Mimikatz With PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1003
T1059.001
|
TTP
|
CISA AA22-264A, Sandworm Tools, CISA AA22-320A, Data Destruction, Malicious PowerShell, Hermetic Wiper, Scattered Spider, CISA AA23-347A, Hellcat Ransomware
|
2026-05-13
|
|
Windows UAC Bypass Suspicious Escalation Behavior
|
Sysmon EventID 1
|
T1548.002
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, Compromised Windows Host
|
2026-05-13
|
|
Suspicious mshta child process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
TTP
|
MuddyWater, Living Off The Land, Lumma Stealer, Suspicious MSHTA Activity
|
2026-05-13
|
|
BITS Job Persistence
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1197
|
TTP
|
Living Off The Land, BITS Jobs
|
2026-05-13
|
|
Disable Defender Spynet Reporting
|
Sysmon EventID 13
|
T1685
|
TTP
|
Qakbot, Windows Registry Abuse, Azorult, IcedID, CISA AA23-347A
|
2026-05-13
|
|
Disable Defender AntiVirus Registry
|
Sysmon EventID 13
|
T1685
|
TTP
|
Black Basta Ransomware, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Windows Registry Abuse, Cactus Ransomware, IcedID
|
2026-05-13
|
|
Detect HTML Help Renamed
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.001
|
Hunting
|
Living Off The Land, Suspicious Compiled HTML Activity, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Modify Registry Tamper Protection
|
Sysmon EventID 13
|
T1112
|
TTP
|
Scattered Lapsus$ Hunters, RedLine Stealer
|
2026-05-13
|
|
Certutil exe certificate extraction
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1649
|
TTP
|
Compromised Windows Host, Windows Certificate Services, Windows Persistence Techniques, Storm-2460 CLFS Zero Day Exploitation, Living Off The Land, Cloud Federated Credential Abuse
|
2026-05-13
|
|
Malicious PowerShell Process - Execution Policy Bypass
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Anomaly
|
DHS Report TA18-074A, XWorm, AsyncRAT, China-Nexus Threat Activity, APT37 Rustonotto and FadeStealer, MuddyWater, Salt Typhoon, Volt Typhoon, 0bj3ctivity Stealer, HAFNIUM Group, DarkCrystal RAT, BlankGrabber Stealer
|
2026-05-13
|
|
WMI Permanent Event Subscription - Sysmon
|
Sysmon EventID 21
|
T1546.003
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Windows Gather Victim Host Information Camera
|
Powershell Script Block Logging 4104
|
T1592.001
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
GetAdGroup with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1069.002
|
Hunting
|
Active Directory Discovery, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Control Loading from World Writable Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.002
|
TTP
|
Microsoft MSHTML Remote Code Execution CVE-2021-40444, Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
GetDomainController with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Rundll32 WebDAV Request
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1048.003
|
Hunting
|
CVE-2023-23397 Outlook Elevation of Privilege
|
2026-05-13
|
|
Suspicious Rundll32 dllregisterserver
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Living Off The Land, Suspicious Rundll32 Activity, IcedID
|
2026-05-13
|
|
Windows RunMRU Registry Key or Value Deleted
|
Sysmon EventID 12
|
T1112
|
Anomaly
|
NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Disable Shutdown Button Through Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Registry Abuse, Ransomware
|
2026-05-13
|
|
Windows Rundll32 WebDav With Network Connection
|
Sysmon EventID 1, Sysmon EventID 3
|
T1048.003
|
TTP
|
CVE-2023-23397 Outlook Elevation of Privilege
|
2026-05-13
|
|
Detect Renamed RClone
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1020
|
Hunting
|
Black Basta Ransomware, DarkSide Ransomware, Ransomware, Cactus Ransomware
|
2026-05-13
|
|
Windows Steal Authentication Certificates CS Backup
|
Windows Event Log Security 4876
|
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows Executable Masquerading as Benign File Types
|
Sysmon EventID 29
|
T1036.008
|
Anomaly
|
NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Suspicious Driver Loaded Path
|
Sysmon EventID 6
|
T1543.003
|
TTP
|
APT37 Rustonotto and FadeStealer, XMRig, AgentTesla, CISA AA22-320A, BlackByte Ransomware, Snake Keylogger, Interlock Ransomware
|
2026-05-13
|
|
Windows Schtasks Create Run As System
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Qakbot, Castle RAT, Windows Persistence Techniques, Scheduled Tasks, SolarWinds WHD RCE Post Exploitation, Medusa Ransomware
|
2026-05-13
|
|
Disabling Windows Local Security Authority Defences via Registry
|
Sysmon EventID 13
|
T1556
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Renamed Powershell Execution
|
Sysmon EventID 1
|
T1036.003
|
TTP
|
Axios Supply Chain Post Compromise, XWorm, Hellcat Ransomware
|
2026-05-13
|
|
PowerShell Invoke CIMMethod CIMSession
|
Powershell Script Block Logging 4104
|
T1047
|
Anomaly
|
Malicious PowerShell, Scattered Lapsus$ Hunters, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Modify Registry Suppress Win Defender Notif
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
CISA AA23-347A, Azorult
|
2026-05-13
|
|
Suspicious Reg exe Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1112
|
Anomaly
|
Windows Defense Evasion Tactics, Disabling Security Tools, DHS Report TA18-074A
|
2026-05-13
|
|
Wermgr Process Create Executable File
|
Sysmon EventID 11
|
T1027
|
TTP
|
Trickbot
|
2026-05-13
|
|
Windows Wmic Memory Chip Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Windows Process With NetExec Command Line Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1550.003
T1558.003
T1558.004
|
TTP
|
Active Directory Kerberos Attacks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Screen Capture Via Powershell
|
Powershell Script Block Logging 4104
|
T1113
|
TTP
|
Winter Vivern, Water Gamayun, BlankGrabber Stealer, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Remote WMI Command Attempt
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Suspicious WMI Use, Graceful Wipe Out Attack, Volt Typhoon, IcedID, Living Off The Land, CISA AA23-347A
|
2026-05-13
|
|
Windows Group Policy Object Created
|
Windows Event Log Security 5137, Windows Event Log Security 5136
|
T1078.002
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows PowerShell IIS Components WebGlobalModule Usage
|
Powershell Script Block Logging 4104
|
T1505.004
|
Anomaly
|
IIS Components, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows AD Short Lived Server Object
|
Windows Event Log Security 5137, Windows Event Log Security 5141
|
T1207
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows Admon Group Policy Object Created
|
Windows Active Directory Admon
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Detection of tools built by NirSoft
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1072
|
Anomaly
|
Emotet Malware DHS Report TA18-201A
|
2026-05-13
|
|
Sunburst Correlation DLL and Network Event
|
Sysmon EventID 22, Sysmon EventID 7
|
T1203
|
TTP
|
NOBELIUM Group
|
2026-05-13
|
|
Windows Modify Registry ProxyEnable
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
DarkGate Malware
|
2026-05-13
|
|
Windows Multiple Account Passwords Changed
|
Windows Event Log Security 4724
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Windows File and Directory Enable ReadOnly Permissions
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1222.001
|
TTP
|
Crypto Stealer, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Excessive Usage Of Cacls App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222
|
Anomaly
|
Crypto Stealer, Defense Evasion or Unauthorized Access Via SDDL Tampering, XMRig, Windows Post-Exploitation, Prestige Ransomware, Azorult
|
2026-05-13
|
|
Credential Dumping via Copy Command from Shadow Copy
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.003
|
TTP
|
Credential Dumping, Compromised Windows Host
|
2026-05-13
|
|
Interactive Session on Remote Endpoint with PowerShell
|
Powershell Script Block Logging 4104
|
T1021.006
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Windows MSHTA Writing to World Writable Path
|
Sysmon EventID 11
|
T1218.005
|
TTP
|
APT29 Diplomatic Deceptions with WINELOADER, Suspicious MSHTA Activity, XWorm
|
2026-05-13
|
|
Windows Defender ASR Rule Disabled
|
Windows Event Log Defender 5007
|
T1112
|
TTP
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Rundll32 Control RunDLL World Writable Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Microsoft MSHTML Remote Code Execution CVE-2021-40444, Living Off The Land, Compromised Windows Host, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows AD Privileged Group Modification
|
Windows Event Log Security 4728
|
T1098
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Privilege Escalation System Process Without System Parent
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, BlackSuit Ransomware
|
2026-05-13
|
|
Windows EventLog Recon Activity Using Log Query Utilities
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1654
|
Anomaly
|
BlankGrabber Stealer, Windows Discovery Techniques
|
2026-05-13
|
|
Detect Renamed PSExec
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1569.002
|
Hunting
|
DarkSide Ransomware, DHS Report TA18-074A, Sandworm Tools, China-Nexus Threat Activity, Rhysida Ransomware, VanHelsing Ransomware, Medusa Ransomware, Salt Typhoon, Active Directory Lateral Movement, SamSam Ransomware, Cactus Ransomware, CISA AA22-320A, HAFNIUM Group, BlackByte Ransomware, DarkGate Malware
|
2026-05-13
|
|
WinRM Spawning a Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1190
|
TTP
|
Rhysida Ransomware, Unusual Processes, CISA AA23-347A, Microsoft WSUS CVE-2025-59287
|
2026-05-13
|
|
Windows Archive Collected Data via Rar
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1560.001
|
Anomaly
|
DarkGate Malware, Salt Typhoon, APT37 Rustonotto and FadeStealer, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Rapid Authentication On Multiple Hosts
|
Windows Event Log Security 4624
|
T1003.002
|
TTP
|
Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
SAM Database File Access Attempt
|
Windows Event Log Security 4663
|
T1003.002
|
Hunting
|
Rhysida Ransomware, Credential Dumping, Graceful Wipe Out Attack
|
2026-05-13
|
|
Windows Service Create RemComSvc
|
Windows Event Log System 7045
|
T1543.003
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows KrbRelayUp Service Creation
|
Windows Event Log System 7045
|
T1543.003
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Compromised Windows Host
|
2026-05-13
|
|
Windows Process Injection In Non-Service SearchIndexer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1055
|
TTP
|
Qakbot
|
2026-05-13
|
|
Windows SQL Server xp_cmdshell Config Change
|
Windows Event Log Application 15457
|
T1505.001
|
TTP
|
SQL Server Abuse, Seashell Blizzard, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
GetAdComputer with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
Hunting
|
Medusa Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Windows MSIExec Spawn Discovery Command
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
Anomaly
|
Medusa Ransomware, Water Gamayun, Windows System Binary Proxy Execution MSIExec, StealC Stealer
|
2026-05-13
|
|
Windows Impair Defense Configure App Install Control
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Modify Registry DisableRemoteDesktopAntiAlias
|
Sysmon EventID 13
|
T1112
|
TTP
|
DarkGate Malware
|
2026-05-13
|
|
Remcos client registry install entry
|
Sysmon EventID 13, Sysmon EventID 12
|
T1112
|
TTP
|
Windows Registry Abuse, Remcos
|
2026-05-13
|
|
Resize ShadowStorage volume
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
Compromised Windows Host, VanHelsing Ransomware, Clop Ransomware, BlackByte Ransomware, Medusa Ransomware
|
2026-05-13
|
|
Windows File and Directory Permissions Remove Inheritance
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1222.001
|
Anomaly
|
Crypto Stealer
|
2026-05-13
|
|
Windows Wmic Network Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Windows DNS Gather Network Info
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1590.002
|
Anomaly
|
Sandworm Tools, Volt Typhoon
|
2026-05-13
|
|
Windows App Layer Protocol Wermgr Connect To NamedPipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Permission Modification using Takeown App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222
|
Anomaly
|
Crypto Stealer, Scattered Lapsus$ Hunters, Sandworm Tools, Ransomware
|
2026-05-13
|
|
Get WMIObject Group Discovery with Script Block Logging
|
Powershell Script Block Logging 4104
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Boot or Logon Autostart Execution In Startup Folder
|
Sysmon EventID 11
|
T1547.001
|
Anomaly
|
XWorm, APT37 Rustonotto and FadeStealer, PromptFlux, Crypto Stealer, NjRAT, Chaos Ransomware, Quasar RAT, Gozi Malware, BlankGrabber Stealer, RedLine Stealer, Interlock Ransomware
|
2026-05-13
|
|
Windows Office Product Spawned MSDT
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
TTP
|
Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Spearphishing Attachments, Compromised Windows Host
|
2026-05-13
|
|
Windows BitLockerToGo Process Execution
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1218
|
Hunting
|
Lumma Stealer
|
2026-05-13
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Malicious PowerShell, Hellcat Ransomware
|
2026-05-13
|
|
Non Chrome Process Accessing Chrome Default Dir
|
Windows Event Log Security 4663
|
T1555.003
|
Anomaly
|
AgentTesla, Phemedrone Stealer, SnappyBee, StealC Stealer, Remcos, NjRAT, FIN7, Salt Typhoon, Malicious Inno Setup Loader, Quasar RAT, DarkGate Malware, Snake Keylogger, 3CX Supply Chain Attack, RedLine Stealer, China-Nexus Threat Activity, VIP Keylogger, Warzone RAT, BlankGrabber Stealer, CISA AA23-347A, Lokibot
|
2026-05-13
|
|
Windows Office Product Loaded MSHTML Module
|
Sysmon EventID 7
|
T1566.001
|
Anomaly
|
Microsoft MSHTML Remote Code Execution CVE-2021-40444, MuddyWater, Spearphishing Attachments, CVE-2023-36884 Office and Windows HTML RCE Vulnerability
|
2026-05-13
|
|
Windows Impair Defense Change Win Defender Health Check Intervals
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows IIS Components Get-WebGlobalModule Module Query
|
Powershell Installed IIS Modules
|
T1505.004
|
Hunting
|
IIS Components, WS FTP Server Critical Vulnerabilities, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Suspicious wevtutil Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.005
|
TTP
|
Ransomware, Rhysida Ransomware, Storm-2460 CLFS Zero Day Exploitation, Windows Log Manipulation, Clop Ransomware, Storm-0501 Ransomware, VoidLink Cloud-Native Linux Malware, Scattered Spider, CISA AA23-347A, ShrinkLocker
|
2026-05-13
|
|
Windows Default Cobalt Strike PowerShell Beacon
|
Powershell Script Block Logging 4104
|
T1059.001
T1204.002
|
TTP
|
Cobalt Strike
|
2026-05-13
|
|
Windows Impair Defense Disable Win Defender Gen reports
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Modify Registry Configure BitLocker
|
Sysmon EventID 13
|
T1112
|
TTP
|
ShrinkLocker
|
2026-05-13
|
|
Suspicious PlistBuddy Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.001
|
TTP
|
Silver Sparrow
|
2026-05-13
|
|
Windows Admin Permission Discovery
|
Sysmon EventID 11
|
T1069.001
|
Anomaly
|
NjRAT
|
2026-05-13
|
|
Windows Important Audit Policy Disabled
|
Windows Event Log Security 4719
|
T1685
|
TTP
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows PowerShell Get CIMInstance Remote Computer
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Modify Registry on Smart Card Group Policy
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
ShrinkLocker
|
2026-05-13
|
|
Windows Modify Registry Disable Toast Notifications
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Azorult
|
2026-05-13
|
|
Detect WMI Event Subscription Persistence
|
Sysmon EventID 20
|
T1546.003
|
TTP
|
Suspicious WMI Use, Hellcat Ransomware
|
2026-05-13
|
|
Windows Computer Account With SPN
|
Windows Event Log Security 4741
|
T1558
|
TTP
|
Active Directory Kerberos Attacks, Local Privilege Escalation With KrbRelayUp, Compromised Windows Host
|
2026-05-13
|
|
Windows Browser Process Launched with Unusual Flags
|
Sysmon EventID 1
|
T1185
|
Anomaly
|
Castle RAT
|
2026-05-13
|
|
Suspicious mshta spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
TTP
|
Living Off The Land, Suspicious MSHTA Activity, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows AI Platform DNS Query
|
Sysmon EventID 22
|
T1071.004
|
Anomaly
|
SesameOp, PromptFlux, LAMEHUG
|
2026-05-13
|
|
Windows Process Injection Remote Thread
|
Sysmon EventID 8
|
T1055.002
|
TTP
|
Qakbot, Water Gamayun, Graceful Wipe Out Attack, Warzone RAT, Earth Alux
|
2026-05-13
|
|
Windows Unusual Count Of Users Failed To Authenticate Using NTLM
|
Windows Event Log Security 4776
|
T1110.003
|
Anomaly
|
Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Disable Security Logs Using MiniNt Registry
|
Sysmon EventID 13
|
T1112
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A
|
2026-05-13
|
|
Windows Identify Protocol Handlers
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Hunting
|
Living Off The Land
|
2026-05-13
|
|
Windows SQL Server Extended Procedure DLL Loading Hunt
|
Windows Event Log Application 8128
|
T1059.009
T1505.001
|
Hunting
|
SQL Server Abuse
|
2026-05-13
|
|
Windows New Deny Permission Set On Service SD Via Sc.EXE
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1564
|
Anomaly
|
Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Windows MSC EvilTwin Directory Path Manipulation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.005
T1203
T1218
|
TTP
|
Windows Defense Evasion Tactics, Water Gamayun, Living Off The Land
|
2026-05-13
|
|
Windows Azure Storage Utility Execution Via CLI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1567.002
|
Anomaly
|
Data Exfiltration
|
2026-05-13
|
|
Windows InstallUtil in Non Standard Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1218.004
|
TTP
|
WhisperGate, Ransomware, Data Destruction, Living Off The Land, Signed Binary Proxy Execution InstallUtil, Unusual Processes, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Windows Steal Authentication Certificates - ESC1 Abuse
|
Windows Event Log Security 4887, Windows Event Log Security 4886
|
T1649
|
TTP
|
Windows Certificate Services
|
2026-05-13
|
|
Windows Process Injection Of Wermgr to Known Browser
|
Sysmon EventID 8
|
T1055.001
|
TTP
|
Qakbot
|
2026-05-13
|
|
Windows Detect Network Scanner Behavior
|
Sysmon EventID 3
|
T1595.001
T1595.002
|
Anomaly
|
Windows Discovery Techniques, Network Discovery
|
2026-05-13
|
|
Windows Execution of Microsoft MSC File In Suspicious Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.014
|
Anomaly
|
XML Runner Loader
|
2026-05-13
|
|
Windows RDP Server Registry Deletion
|
Sysmon EventID 13, Sysmon EventID 12
|
T1070.004
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows Modify Registry Disable RDP
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion, ShrinkLocker
|
2026-05-13
|
|
Windows Post Exploitation Risk Behavior
|
|
T1003
T1012
T1016
T1049
T1069
T1082
T1115
T1552
|
Correlation
|
Windows Post-Exploitation
|
2026-05-13
|
|
Windows Unusual SysWOW64 Process Run System32 Executable
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.009
|
Anomaly
|
DarkGate Malware, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Modify Registry Auto Update Notif
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
RedLine Stealer
|
2026-05-13
|
|
Revil Common Exec Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
TTP
|
Revil Ransomware, Ransomware
|
2026-05-13
|
|
Windows RDP Cache File Deletion
|
Sysmon EventID 26, Sysmon EventID 23
|
T1070.004
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows Network Share Interaction Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1039
T1135
|
Hunting
|
Active Directory Privilege Escalation, Active Directory Discovery, Network Discovery
|
2026-05-13
|
|
Detect Regsvcs with No Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.009
|
TTP
|
Living Off The Land, Suspicious Regsvcs Regasm Activity
|
2026-05-13
|
|
XSL Script Execution With WMIC
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1220
|
TTP
|
FIN7, Suspicious WMI Use
|
2026-05-13
|
|
Windows Symlink Evaluation Change via Fsutil
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222.001
|
Anomaly
|
Windows Post-Exploitation
|
2026-05-13
|
|
GetLocalUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Malicious PowerShell, Active Directory Discovery
|
2026-05-13
|
|
Windows Audit Policy Disabled via Legacy Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows Ingress Tool Transfer Using Explorer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
Powershell Remove Windows Defender Directory
|
Powershell Script Block Logging 4104
|
T1685
|
TTP
|
Data Destruction, WhisperGate
|
2026-05-13
|
|
ServicePrincipalNames Discovery with PowerShell
|
Powershell Script Block Logging 4104
|
T1558.003
|
TTP
|
Active Directory Privilege Escalation, Active Directory Discovery, Malicious PowerShell, Active Directory Kerberos Attacks, Hellcat Ransomware
|
2026-05-13
|
|
Windows Multiple Accounts Disabled
|
Windows Event Log Security 4725
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Windows Proxy Via Registry
|
Sysmon EventID 13
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Windows BitLocker Suspicious Command Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1486
T1490
|
TTP
|
ShrinkLocker
|
2026-05-13
|
|
Windows RDP Connection Successful
|
Windows Event Log RemoteConnectionManager 1149
|
T1563.002
|
Hunting
|
Windows RDP Artifacts and Defense Evasion, Active Directory Lateral Movement, BlackByte Ransomware, NetSupport RMM Tool Abuse, Interlock Ransomware
|
2026-05-13
|
|
Windows SymbolicLink-Testing-Tools Utility Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222
T1564.004
|
TTP
|
Windows Persistence Techniques, Windows Privilege Escalation, Windows Post-Exploitation
|
2026-05-13
|
|
Windows Impair Defenses Disable Win Defender Auto Logging
|
Sysmon EventID 13
|
T1685
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A
|
2026-05-13
|
|
Windows Root Domain linked policies Discovery
|
Powershell Script Block Logging 4104
|
T1087.002
|
Anomaly
|
Data Destruction, Active Directory Discovery, Industroyer2
|
2026-05-13
|
|
Windows Impair Defense Disable Web Evaluation
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Detect Remote Access Software Usage FileInfo
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Ransomware, Seashell Blizzard, Insider Threat, Scattered Lapsus$ Hunters, Cactus Ransomware, Remote Monitoring and Management Software, Command And Control, Gozi Malware, Scattered Spider, Interlock Ransomware
|
2026-05-13
|
|
PowerShell - Connect To Internet With Hidden Window
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Hunting
|
Log4Shell CVE-2021-44228, Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns, AgentTesla, Data Destruction, Malicious PowerShell, HAFNIUM Group, Hermetic Wiper
|
2026-05-13
|
|
Windows Universal Data Link File Creation
|
Sysmon EventID 11
|
T1204.002
T1566.001
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Windows Indirect Command Execution Via Series Of Forfiles
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1202
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows Defender ASR Block Events
|
Windows Event Log Defender 1121, Windows Event Log Defender 1133, Windows Event Log Defender 1126, Windows Event Log Defender 1131, Windows Event Log Defender 1129
|
T1059
T1566.001
T1566.002
|
Anomaly
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Allow Inbound Traffic In Firewall Rule
|
Powershell Script Block Logging 4104
|
T1021.001
|
TTP
|
Prohibited Traffic Allowed or Protocol Mismatch, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Kerberos TGT Request Using RC4 Encryption
|
Windows Event Log Security 4768
|
T1550
|
TTP
|
Active Directory Kerberos Attacks, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Privilege Escalation Suspicious Process Elevation
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, BlackSuit Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Command Obfuscation with Environment Variable Substrings
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1027.010
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
Kerberoasting spn request with RC4 encryption
|
Windows Event Log Security 4769
|
T1558.003
|
TTP
|
Compromised Windows Host, Data Destruction, Windows Privilege Escalation, Hermetic Wiper, Active Directory Kerberos Attacks
|
2026-05-13
|
|
Windows Alternate DataStream - Base64 Content
|
Sysmon EventID 15
|
T1564.004
|
TTP
|
Windows Defense Evasion Tactics, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Service Stop Win Updates
|
Windows Event Log System 7040
|
T1489
|
Anomaly
|
CISA AA23-347A, RedLine Stealer
|
2026-05-13
|
|
Windows Create Local Account
|
Windows Event Log Security 4720
|
T1136.001
|
Anomaly
|
Scattered Lapsus$ Hunters, GhostRedirector IIS Module and Rungan Backdoor, CISA AA24-241A, Active Directory Password Spraying
|
2026-05-13
|
|
Create Remote Thread into LSASS
|
Sysmon EventID 8
|
T1003.001
|
TTP
|
Credential Dumping, BlackSuit Ransomware, Lokibot
|
2026-05-13
|
|
Windows WBAdmin File Recovery From Backup
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
T1565.001
|
Anomaly
|
Credential Dumping
|
2026-05-13
|
|
FodHelper UAC Bypass
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1112
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host, ValleyRAT, IcedID, BlankGrabber Stealer
|
2026-05-13
|
|
Windows PowerShell Disable HTTP Logging
|
Powershell Script Block Logging 4104
|
T1505.004
T1685.001
|
TTP
|
Windows Defense Evasion Tactics, IIS Components
|
2026-05-13
|
|
Windows ClipBoard Data via Get-ClipBoard
|
Powershell Script Block Logging 4104
|
T1115
|
Anomaly
|
BlankGrabber Stealer, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows Spearphishing Attachment Onenote Spawn Mshta
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
TTP
|
Spearphishing Attachments, Compromised Windows Host, APT37 Rustonotto and FadeStealer, AsyncRAT
|
2026-05-13
|
|
WinEvent Scheduled Task Created Within Public Path
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
SystemBC, Compromised Windows Host, AsyncRAT, Data Destruction, CISA AA22-257A, Industroyer2, Winter Vivern, APT37 Rustonotto and FadeStealer, Remcos, Active Directory Lateral Movement, Medusa Ransomware, PlugX, Salt Typhoon, ValleyRAT, Malicious Inno Setup Loader, Quasar RAT, Ryuk Ransomware, XWorm, Ransomware, China-Nexus Threat Activity, Castle RAT, Windows Persistence Techniques, Scheduled Tasks, 0bj3ctivity Stealer, Prestige Ransomware, IcedID, CISA AA23-347A
|
2026-05-13
|
|
Remote Desktop Process Running On System
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
|
Hunting
|
Windows RDP Artifacts and Defense Evasion, Active Directory Lateral Movement, Hidden Cobra Malware
|
2026-05-13
|
|
Windows MpCmdRun RemoveDefinitions Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Windows Scheduled Task Service Spawned Shell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
T1059
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Modify Registry Disable Windows Security Center Notif
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
CISA AA23-347A, Azorult
|
2026-05-13
|
|
Windows Computer Account Requesting Kerberos Ticket
|
Windows Event Log Security 4768
|
T1558
|
TTP
|
Active Directory Kerberos Attacks, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Rundll32 LockWorkStation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
Anomaly
|
Ransomware
|
2026-05-13
|
|
Anomalous usage of 7zip
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1560.001
|
Anomaly
|
Graceful Wipe Out Attack, Cobalt Strike, BlackByte Ransomware, BlackSuit Ransomware, NOBELIUM Group
|
2026-05-13
|
|
Get-ForestTrust with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Processes Killed By Industroyer2 Malware
|
Sysmon EventID 5
|
T1489
|
Anomaly
|
Data Destruction, Industroyer2
|
2026-05-13
|
|
Unusual Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
|
Hunting
|
Active Directory Kerberos Attacks, Scattered Lapsus$ Hunters, Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Suspicious C2 Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
TTP
|
Brute Ratel C4, DarkSide Ransomware, Graceful Wipe Out Attack, APT37 Rustonotto and FadeStealer, Cobalt Strike, Storm-0501 Ransomware, LockBit Ransomware, Remote Monitoring and Management Software, Trickbot, Meterpreter, BlackByte Ransomware, Tuoni, Gozi Malware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Process Injection With Public Source Path
|
Sysmon EventID 8
|
T1055.002
|
Hunting
|
Brute Ratel C4, Earth Alux
|
2026-05-13
|
|
GetAdComputer with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
Hunting
|
CISA AA22-320A, Medusa Ransomware, Active Directory Discovery, Gozi Malware
|
2026-05-13
|
|
Hunting 3CXDesktopApp Software
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1195.002
|
Hunting
|
3CX Supply Chain Attack
|
2026-05-13
|
|
Windows Disable or Stop Browser Process
|
Sysmon EventID 1
|
T1685
|
TTP
|
Braodo Stealer, Castle RAT, Scattered Lapsus$ Hunters, BlankGrabber Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Linux Post-Exploitation, Compromised Linux Host, Linux Rootkit, Linux Privilege Escalation, Linux Living Off The Land, VoidLink Cloud-Native Linux Malware
|
2026-05-13
|
|
Process Writing DynamicWrapperX
|
Sysmon EventID 11
|
T1059
T1559.001
|
Hunting
|
Remcos
|
2026-05-13
|
|
Windows Certutil Root Certificate Addition
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1587.003
|
TTP
|
Secret Blizzard
|
2026-05-13
|
|
Short Lived Windows Accounts
|
Windows Event Log System 4720, Windows Event Log System 4726
|
T1078.003
T1136.001
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows MSI Rollback Script Deleted By Non-Msiexec Process
|
Sysmon EventID 23
|
T1068
T1218.007
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Remote Process Instantiation via DCOM and PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1021.003
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Add DefaultUser And Password In Registry
|
Sysmon EventID 13, Sysmon EventID 12
|
T1552.002
|
Anomaly
|
BlackMatter Ransomware
|
2026-05-13
|
|
Scheduled Task Initiation on Remote Endpoint
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Seashell Blizzard, Scheduled Tasks, Active Directory Lateral Movement, Medusa Ransomware, Living Off The Land
|
2026-05-13
|
|
Windows NirSoft AdvancedRun
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1588.002
|
TTP
|
Data Destruction, WhisperGate, Unusual Processes, Ransomware
|
2026-05-13
|
|
Exchange PowerShell Module Usage
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
CISA AA22-264A, ProxyNotShell, CISA AA22-277A, BlackByte Ransomware, Scattered Spider, ProxyShell
|
2026-05-13
|
|
Windows CAB File on Disk
|
Sysmon EventID 11
|
T1566.001
|
Anomaly
|
DarkGate Malware, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows PaperCut NG Spawn Shell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
T1133
T1190
|
TTP
|
PaperCut MF NG Vulnerability, Compromised Windows Host
|
2026-05-13
|
|
Windows Private Keys Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1552.004
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows Phishing PDF File Executes URL Link
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1566.001
|
Anomaly
|
MuddyWater, Snake Keylogger, Spearphishing Attachments
|
2026-05-13
|
|
Windows Hijack Execution Flow Version Dll Side Load
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
Brute Ratel C4, XWorm, Malicious Inno Setup Loader, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
PowerShell PInvoke Process Injection API Chain
|
Powershell Script Block Logging 4104
|
T1055.001
T1055.003
T1055.004
T1055.012
T1055.013
T1059.001
T1620
|
TTP
|
VIP Keylogger
|
2026-05-13
|
|
Loading Of Dynwrapx Module
|
Sysmon EventID 7
|
T1055.001
|
TTP
|
Remcos, AsyncRAT
|
2026-05-13
|
|
Windows WMI Process Call Create
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Hunting
|
Qakbot, Suspicious WMI Use, Volt Typhoon, Cactus Ransomware, IcedID, CISA AA23-347A
|
2026-05-13
|
|
Windows ConHost with Headless Argument
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1564.003
T1564.006
|
TTP
|
Spearphishing Attachments, Compromised Windows Host
|
2026-05-13
|
|
Shim Database Installation With Suspicious Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1546.011
|
TTP
|
Windows Persistence Techniques, Compromised Windows Host
|
2026-05-13
|
|
Windows Alternate DataStream - Executable Content
|
Sysmon EventID 15
|
T1564.004
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
PowerShell Environment Variable Execution
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
VIP Keylogger
|
2026-05-13
|
|
Windows Modify Registry No Auto Reboot With Logon User
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
RedLine Stealer
|
2026-05-13
|
|
Windows Unusual FileZilla XML Config Access
|
Windows Event Log Security 4663
|
T1552.001
|
Anomaly
|
Quasar RAT
|
2026-05-13
|
|
Rundll32 Process Creating Exe Dll Files
|
Sysmon EventID 11
|
T1218.011
|
TTP
|
Gh0st RAT, Living Off The Land, IcedID
|
2026-05-13
|
|
Overwriting Accessibility Binaries
|
Sysmon EventID 11
|
T1546.008
|
TTP
|
Data Destruction, Flax Typhoon, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Windows Create Local Administrator Account Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1136.001
|
Anomaly
|
DHS Report TA18-074A, CISA AA24-241A, Scattered Lapsus$ Hunters, CISA AA22-257A, Azorult, Medusa Ransomware, DarkGate Malware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Schedule Task with HTTP Command Arguments
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Compromised Windows Host, Winter Vivern, Windows Persistence Techniques, Scheduled Tasks, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows Raw Access To Master Boot Record Drive
|
Sysmon EventID 9
|
T1561.002
|
TTP
|
CISA AA22-264A, WhisperGate, Graceful Wipe Out Attack, NjRAT, PathWiper, Void Manticore, Data Destruction, BlackByte Ransomware, Disk Wiper, Hermetic Wiper, Caddy Wiper
|
2026-05-13
|
|
Ryuk Wake on LAN Command
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
TTP
|
Compromised Windows Host, Hellcat Ransomware, Ryuk Ransomware
|
2026-05-13
|
|
Windows IIS Components New Module Added
|
Windows IIS 29
|
T1505.004
|
TTP
|
IIS Components, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Masquerading Msdtc Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036
|
TTP
|
PlugX, Compromised Windows Host
|
2026-05-13
|
|
Windows Access Token Manipulation Winlogon Duplicate Token Handle
|
Sysmon EventID 10
|
T1134.001
|
Hunting
|
Brute Ratel C4
|
2026-05-13
|
|
Windows Modify Registry Auto Minor Updates
|
Sysmon EventID 13
|
T1112
|
Hunting
|
RedLine Stealer
|
2026-05-13
|
|
Windows MOF Event Triggered Execution via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1546.003
|
TTP
|
Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Windows RMM Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
Anomaly
|
CISA AA24-241A, Ransomware, Seashell Blizzard, Insider Threat, Interlock Ransomware, Scattered Lapsus$ Hunters, Cactus Ransomware, Remote Monitoring and Management Software, Command And Control, Gozi Malware, Scattered Spider, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
High Frequency Copy Of Files In Network Share
|
Windows Event Log Security 5145
|
T1537
|
Anomaly
|
Insider Threat, Information Sabotage, Hellcat Ransomware
|
2026-05-13
|
|
Windows SoftEther VPN Masquerading as Legitimate Binary
|
Sysmon EventID 1
|
T1036
T1572
|
TTP
|
Flax Typhoon, Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Detect AzureHound File Modifications
|
Sysmon EventID 11
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows Process Commandline Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1057
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Bcdedit Command Back To Normal Mode Boot
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
BlackMatter Ransomware, Black Basta Ransomware
|
2026-05-13
|
|
GetWmiObject Ds Computer with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Modify Registry Default Icon Setting
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
LockBit Ransomware
|
2026-05-13
|
|
Windows Snake Malware Registry Modification wav OpenWithProgIds
|
Sysmon EventID 13
|
T1112
|
TTP
|
Snake Malware
|
2026-05-13
|
|
Disabling CMD Application
|
Sysmon EventID 13
|
T1112
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, NjRAT
|
2026-05-13
|
|
Windows TinyCC Shellcode Execution
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1027
T1036
T1059.003
|
TTP
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Suspicious Computer Account Name Change
|
Windows Event Log Security 4781
|
T1078.002
|
TTP
|
Active Directory Privilege Escalation, Scattered Lapsus$ Hunters, Compromised Windows Host, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Windows InstallUtil Credential Theft
|
Sysmon EventID 7
|
T1218.004
|
TTP
|
Signed Binary Proxy Execution InstallUtil
|
2026-05-13
|
|
Windows AD Abnormal Object Access Activity
|
Windows Event Log Security 4662
|
T1087.002
|
Anomaly
|
Active Directory Discovery, BlackSuit Ransomware
|
2026-05-13
|
|
Executables Or Script Creation In Suspicious Path
|
Sysmon EventID 11
|
T1036
|
Anomaly
|
SystemBC, Qakbot, AsyncRAT, AgentTesla, SesameOp, Volt Typhoon, Lokibot, Data Destruction, Interlock Rat, Trickbot, Industroyer2, Azorult, GhostRedirector IIS Module and Rungan Backdoor, Brute Ratel C4, Axios Supply Chain Post Compromise, SnappyBee, Meduza Stealer, Void Manticore, LockBit Ransomware, Remcos, Hermetic Wiper, BlackByte Ransomware, Derusbi, PlugX, NailaoLocker Ransomware, WhisperGate, Rhysida Ransomware, Crypto Stealer, Chaos Ransomware, NjRAT, Salt Typhoon, ValleyRAT, Cactus Ransomware, Amadey, Quasar RAT, XML Runner Loader, DarkGate Malware, Snake Keylogger, WinDealer RAT, DynoWiper, RedLine Stealer, AcidPour, Graceful Wipe Out Attack, Castle RAT, China-Nexus Threat Activity, Handala Wiper, Warzone RAT, XMRig, PromptLock, VIP Keylogger, Earth Alux, Swift Slicer, MoonPeak, Double Zero Destructor, IcedID, DarkCrystal RAT, CISA AA23-347A, Interlock Ransomware
|
2026-05-13
|
|
Schedule Task with Rundll32 Command Trigger
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Compromised Windows Host, Castle RAT, Windows Persistence Techniques, Scheduled Tasks, Trickbot, IcedID, Living Off The Land
|
2026-05-13
|
|
Windows AD Dangerous Deny ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows USBSTOR Registry Key Modification
|
Sysmon EventID 13, Sysmon EventID 12
|
T1025
T1091
T1200
|
Anomaly
|
APT37 Rustonotto and FadeStealer, Data Protection
|
2026-05-13
|
|
Powershell COM Hijacking InprocServer32 Modification
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Modify Show Compress Color And Info Tip Registry
|
Sysmon EventID 13
|
T1112
|
TTP
|
Data Destruction, Windows Defense Evasion Tactics, Windows Registry Abuse, Hermetic Wiper
|
2026-05-13
|
|
Suspicious Ticket Granting Ticket Request
|
Windows Event Log Security 4781, Windows Event Log Security 4768
|
T1078.002
|
Hunting
|
Active Directory Kerberos Attacks, Active Directory Privilege Escalation, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
MS Scripting Process Loading WMI Module
|
Sysmon EventID 7
|
T1059.007
|
Anomaly
|
FIN7
|
2026-05-13
|
|
Monitor Registry Keys for Print Monitors
|
Sysmon EventID 13
|
T1547.010
|
TTP
|
Windows Registry Abuse, Windows Persistence Techniques, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Windows System Network Connections Discovery Netsh
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1049
|
Anomaly
|
VIP Keylogger, Windows Post-Exploitation, Prestige Ransomware, Snake Keylogger, BlankGrabber Stealer
|
2026-05-13
|
|
Detect RClone Command-Line Usage
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1020
|
TTP
|
Black Basta Ransomware, DarkSide Ransomware, Ransomware, Cisco Network Visibility Module Analytics, Cactus Ransomware, Storm-0501 Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Get DomainPolicy with Powershell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1201
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Disable Notification Center
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A
|
2026-05-13
|
|
Windows Phishing Outlook Drop Dll In FORM Dir
|
Sysmon EventID 11, Sysmon EventID 1
|
T1566
|
TTP
|
Outlook RCE CVE-2024-21378
|
2026-05-13
|
|
Windows Impair Defenses Disable Auto Logger Session
|
Sysmon EventID 13
|
T1685
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Batch File Write to System32
|
Sysmon EventID 11
|
T1204.002
|
TTP
|
SamSam Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Detect Use of cmd exe to Launch Script Interpreters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Anomaly
|
Azorult, Emotet Malware DHS Report TA18-201A, Suspicious Command-Line Executions
|
2026-05-13
|
|
Windows Deleted Registry By A Non Critical Process File Path
|
Sysmon EventID 12, Sysmon EventID 1
|
T1112
|
Anomaly
|
Data Destruction, Double Zero Destructor
|
2026-05-13
|
|
CSC Net On The Fly Compilation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1027.004
|
Hunting
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Process Kill Base On File Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
XMRig
|
2026-05-13
|
|
Windows AD Domain Controller Audit Policy Disabled
|
Windows Event Log Security 4719
|
T1685
|
TTP
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Get WMIObject Group Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows DotNet Binary in Non Standard Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1218.004
|
TTP
|
WhisperGate, Ransomware, Data Destruction, Signed Binary Proxy Execution InstallUtil, Unusual Processes, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Windows BitDefender Submission Wizard DLL Sideloading
|
Sysmon EventID 7
|
T1574
|
TTP
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Windows Credentials from Password Stores Chrome LocalState Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Braodo Stealer, Scattered Lapsus$ Hunters, PXA Stealer, Phemedrone Stealer, SnappyBee, Meduza Stealer, StealC Stealer, NjRAT, Salt Typhoon, Malicious Inno Setup Loader, Amadey, Quasar RAT, DarkGate Malware, Snake Keylogger, RedLine Stealer, China-Nexus Threat Activity, VIP Keylogger, Warzone RAT, Earth Alux, MoonPeak, 0bj3ctivity Stealer, BlankGrabber Stealer, Lokibot
|
2026-05-13
|
|
Detect Certify Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
T1649
|
TTP
|
Windows Certificate Services, Compromised Windows Host, Ingress Tool Transfer
|
2026-05-13
|
|
Windows ESX Admins Group Creation via PowerShell
|
Powershell Script Block Logging 4104
|
T1136.001
T1136.002
|
TTP
|
VMware ESXi AD Integration Authentication Bypass CVE-2024-37085
|
2026-05-13
|
|
Disable Windows Behavior Monitoring
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Defense Evasion Tactics, Black Basta Ransomware, Ransomware, Scattered Lapsus$ Hunters, SolarWinds WHD RCE Post Exploitation, Windows Registry Abuse, Cactus Ransomware, Storm-0501 Ransomware, Azorult, NetSupport RMM Tool Abuse, Revil Ransomware, BlankGrabber Stealer, CISA AA23-347A, RedLine Stealer
|
2026-05-13
|
|
Windows Hide Notification Features Through Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics, Ransomware
|
2026-05-13
|
|
Windows Credentials from Password Stores Chrome Login Data Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Braodo Stealer, Scattered Lapsus$ Hunters, PXA Stealer, Phemedrone Stealer, SnappyBee, Meduza Stealer, StealC Stealer, NjRAT, Salt Typhoon, Malicious Inno Setup Loader, Amadey, Quasar RAT, DarkGate Malware, Snake Keylogger, RedLine Stealer, China-Nexus Threat Activity, VIP Keylogger, Warzone RAT, Earth Alux, MoonPeak, 0bj3ctivity Stealer, BlankGrabber Stealer, Lokibot
|
2026-05-13
|
|
Windows Metasploit Confluence Plugin Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1190
T1505.003
T1608
|
TTP
|
Confluence Data Center and Confluence Server Vulnerabilities
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
|
Anomaly
|
Data Destruction, Phemedrone Stealer, PHP-CGI RCE Attack on Japanese Organizations, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, Winter Vivern, StealC Stealer, HAFNIUM Group, Hermetic Wiper, SolarWinds WHD RCE Post Exploitation, Malicious PowerShell, Cisco Network Visibility Module Analytics, XWorm, Ingress Tool Transfer, NPM Supply Chain Compromise, SysAid On-Prem Software CVE-2023-47246 Vulnerability, Tuoni, IcedID, Microsoft WSUS CVE-2025-59287, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows PuTTY Suite Utility Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.004
|
Anomaly
|
Command And Control, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows User Deletion Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1531
|
Anomaly
|
DarkGate Malware, XMRig, Graceful Wipe Out Attack
|
2026-05-13
|
|
Windows Service Execution RemCom
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1569.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Application Whitelisting Bypass Attempt via Rundll32
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Living Off The Land, Compromised Windows Host, Suspicious Rundll32 Activity
|
2026-05-13
|
|
Windows Excessive Disabled Services Event
|
Windows Event Log System 7040
|
T1685
|
TTP
|
Windows Defense Evasion Tactics, CISA AA23-347A, Compromised Windows Host
|
2026-05-13
|
|
Windows LOLBAS Executed Outside Expected Path
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.005
T1218.011
|
Anomaly
|
Living Off The Land, Windows Defense Evasion Tactics, Masquerading - Rename System Utilities
|
2026-05-13
|
|
Windows Powershell Logoff User via Quser
|
Powershell Script Block Logging 4104
|
T1059.001
T1531
|
Anomaly
|
Crypto Stealer
|
2026-05-13
|
|
CMD Carry Out String Command Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Hunting
|
Qakbot, AsyncRAT, ProxyNotShell, Data Destruction, Interlock Rat, Azorult, Winter Vivern, StealC Stealer, Hermetic Wiper, Living Off The Land, PlugX, WhisperGate, Rhysida Ransomware, Crypto Stealer, Chaos Ransomware, NjRAT, Malicious Inno Setup Loader, Quasar RAT, DarkGate Malware, RedLine Stealer, Log4Shell CVE-2021-44228, Warzone RAT, 0bj3ctivity Stealer, IcedID, Gh0st RAT, DarkCrystal RAT, CISA AA23-347A
|
2026-05-13
|
|
Windows Powershell History File Deletion
|
Powershell Script Block Logging 4104
|
T1059.003
T1070.003
|
Anomaly
|
Medusa Ransomware
|
2026-05-13
|
|
Remote Process Instantiation via WinRM and PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1021.006
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Attacker Tools On Endpoint
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003
T1036.005
T1595
|
TTP
|
CISA AA22-264A, Compromised Windows Host, Cisco Network Visibility Module Analytics, XMRig, SamSam Ransomware, Scattered Spider, Unusual Processes, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Domain Account Discovery with Dsquery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.002
|
Anomaly
|
Active Directory Discovery, LAMEHUG
|
2026-05-13
|
|
Windows Software Discovery Via PowerShell
|
Powershell Script Block Logging 4104
|
T1012
T1059.001
T1518
|
Anomaly
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows Office Product Dropped Uncommon File
|
Sysmon EventID 11, Sysmon EventID 1
|
T1566.001
|
Anomaly
|
Compromised Windows Host, Warzone RAT, AgentTesla, FIN7, CVE-2023-21716 Word RTF Heap Corruption, PlugX
|
2026-05-13
|
|
Windows Account Discovery for None Disable User Account
|
Powershell Script Block Logging 4104
|
T1087.001
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Icacls Deny Command
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1222
|
Anomaly
|
Sandworm Tools, Compromised Windows Host, Crypto Stealer, Defense Evasion or Unauthorized Access Via SDDL Tampering, XMRig, Azorult
|
2026-05-13
|
|
Msmpeng Application DLL Side Loading
|
Sysmon EventID 11
|
T1574.001
|
TTP
|
Revil Ransomware, Ransomware
|
2026-05-13
|
|
Windows Privilege Escalation User Process Spawn System Process
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, Compromised Windows Host, BlackSuit Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows MsiExec HideWindow Rundll32 Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.007
|
TTP
|
Qakbot, Water Gamayun
|
2026-05-13
|
|
Windows Raw Access To Disk Volume Partition
|
Sysmon EventID 9
|
T1561.002
|
Anomaly
|
CISA AA22-264A, Graceful Wipe Out Attack, NjRAT, PathWiper, Void Manticore, Data Destruction, BlackByte Ransomware, Disk Wiper, Hermetic Wiper, Caddy Wiper
|
2026-05-13
|
|
Windows Credentials from Password Stores Chrome Copied in TEMP Dir
|
Sysmon EventID 11
|
T1555.003
|
TTP
|
Braodo Stealer, Scattered Lapsus$ Hunters, BlankGrabber Stealer
|
2026-05-13
|
|
Windows AD DSRM Password Reset
|
Windows Event Log Security 4794
|
T1098
|
TTP
|
Sneaky Active Directory Persistence Tricks, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows AppX Deployment Unsigned Package Installation
|
Windows Event Log AppXDeployment-Server 855
|
T1204.002
T1553.005
|
TTP
|
MSIX Package Abuse
|
2026-05-13
|
|
GetDomainComputer with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows AD GPO New CSE Addition
|
Windows Event Log Security 5136
|
T1222.001
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
IcedID Exfiltrated Archived File Creation
|
Sysmon EventID 11
|
T1560.001
|
Hunting
|
APT37 Rustonotto and FadeStealer, IcedID
|
2026-05-13
|
|
Remote Process Instantiation via WMI and PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1047
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Windows WMI Reconnaissance Class Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
MS Scripting Process Loading Ldap Module
|
Sysmon EventID 7
|
T1059.007
|
Anomaly
|
FIN7
|
2026-05-13
|
|
Windows PowGoop Beacon Decoding
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Audit Policy Security Descriptor Tampering via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Suspicious IcedID Rundll32 Cmdline
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.011
|
TTP
|
Living Off The Land, IcedID
|
2026-05-13
|
|
Windows Parent PID Spoofing with Explorer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1134.004
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host
|
2026-05-13
|
|
Windows PowerShell MSIX Package Installation
|
Powershell Script Block Logging 4104
|
T1059.001
T1547.001
|
TTP
|
Malicious PowerShell, MSIX Package Abuse
|
2026-05-13
|
|
Windows Debugger Tool Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036
|
Hunting
|
DarkGate Malware, PlugX
|
2026-05-13
|
|
First Time Seen Child Process of Zoom
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1068
|
Anomaly
|
Suspicious Zoom Child Processes
|
2026-05-13
|
|
Scheduled Task Deleted Or Created via CMD
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
Anomaly
|
Qakbot, AsyncRAT, AgentTesla, Trickbot, CISA AA22-257A, Azorult, Phemedrone Stealer, Winter Vivern, APT37 Rustonotto and FadeStealer, Remcos, Medusa Ransomware, Living Off The Land, Scattered Spider, PlugX, Sandworm Tools, CISA AA24-241A, Rhysida Ransomware, NjRAT, Salt Typhoon, ValleyRAT, SolarWinds WHD RCE Post Exploitation, Amadey, Quasar RAT, NOBELIUM Group, RedLine Stealer, XWorm, DHS Report TA18-074A, China-Nexus Threat Activity, Windows Persistence Techniques, Scheduled Tasks, MoonPeak, 0bj3ctivity Stealer, Prestige Ransomware, NetSupport RMM Tool Abuse, DarkCrystal RAT, CISA AA23-347A, ShrinkLocker, Lokibot
|
2026-05-13
|
|
Windows AppLocker Block Events
|
|
T1218
|
Anomaly
|
Windows AppLocker
|
2026-05-13
|
|
Windows Raccine Scheduled Task Deletion
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
Compromised Windows Host, Ransomware
|
2026-05-13
|
|
Windows App Layer Protocol Qakbot NamedPipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows File Collection Via Copy Utilities
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1119
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Windows Access Token Manipulation SeDebugPrivilege
|
Windows Event Log Security 4703
|
T1134.002
|
Anomaly
|
Brute Ratel C4, Meduza Stealer, SnappyBee, AsyncRAT, China-Nexus Threat Activity, PathWiper, Scattered Lapsus$ Hunters, Salt Typhoon, ValleyRAT, Lokibot, Tuoni, Gh0st RAT, Derusbi, DarkGate Malware, WinDealer RAT, PlugX, CISA AA23-347A, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Registry Keys for Creating SHIM Databases
|
Sysmon EventID 13
|
T1546.011
|
TTP
|
Windows Registry Abuse, Windows Persistence Techniques, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Unusual Number of Remote Endpoint Authentication Events
|
Windows Event Log Security 4624
|
T1078
|
Hunting
|
Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
Prevent Automatic Repair Mode using Bcdedit
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
Chaos Ransomware, Ransomware, Void Manticore
|
2026-05-13
|
|
Windows Unsigned DLL Side-Loading
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
China-Nexus Threat Activity, NjRAT, Warzone RAT, Salt Typhoon, Earth Alux, SolarWinds WHD RCE Post Exploitation, Derusbi
|
2026-05-13
|
|
Windows SQL Spawning CertUtil
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
SQL Server Abuse, Flax Typhoon, Storm-2460 CLFS Zero Day Exploitation
|
2026-05-13
|
|
Windows Short Lived DNS Record
|
Windows Event Log Security 5137, Windows Event Log Security 5136
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS
|
2026-05-13
|
|
Windows Disable Windows Group Policy Features Through Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A, Ransomware
|
2026-05-13
|
|
Windows Server Software Component GACUtil Install to GAC
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1505.004
|
TTP
|
IIS Components
|
2026-05-13
|
|
Script Execution via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Scattered Spider, Suspicious WMI Use
|
2026-05-13
|
|
Windows Suspect Process With Authentication Traffic
|
Sysmon EventID 3
|
T1087.002
T1204.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Disable Defender MpEngine Registry
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, IcedID
|
2026-05-13
|
|
DLLHost with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Storm-2460 CLFS Zero Day Exploitation, Cobalt Strike, Earth Alux, Cactus Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows WMI Impersonate Token
|
Sysmon EventID 10
|
T1047
|
Anomaly
|
Qakbot, Water Gamayun
|
2026-05-13
|
|
Windows Set Account Password Policy To Unlimited Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1489
|
Anomaly
|
Crypto Stealer, XMRig, Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Randomly Generated Windows Service Name
|
Windows Event Log System 7045
|
T1543.003
|
Hunting
|
BlackSuit Ransomware, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Firewall Rule Added
|
Windows Event Log Security 4946
|
T1686
|
Anomaly
|
Medusa Ransomware, NetSupport RMM Tool Abuse, ShrinkLocker
|
2026-05-13
|
|
Disabling NoRun Windows App
|
Sysmon EventID 13
|
T1112
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Default Group Policy Object Modified
|
Windows Event Log Security 5136
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
WinEvent Windows Task Scheduler Event Action Started
|
Windows Event Log TaskScheduler 200, Windows Event Log TaskScheduler 201
|
T1053.005
|
Hunting
|
SystemBC, Qakbot, AsyncRAT, Data Destruction, CISA AA22-257A, Industroyer2, BlackSuit Ransomware, Winter Vivern, Remcos, PlugX, Sandworm Tools, CISA AA24-241A, ValleyRAT, SolarWinds WHD RCE Post Exploitation, Malicious Inno Setup Loader, Amadey, Windows Persistence Techniques, Scheduled Tasks, Prestige Ransomware, IcedID, DarkCrystal RAT
|
2026-05-13
|
|
Malicious PowerShell Process With Obfuscation Techniques
|
Sysmon EventID 1
|
T1059.001
|
TTP
|
Data Destruction, Malicious PowerShell, Hermetic Wiper, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Masquerading Explorer As Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.001
|
TTP
|
Qakbot, Water Gamayun, Compromised Windows Host
|
2026-05-13
|
|
Windows System Discovery Using Qwinsta
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Qakbot
|
2026-05-13
|
|
UAC Bypass With Colorui COM Object
|
Sysmon EventID 7
|
T1218.003
|
TTP
|
LockBit Ransomware, Ransomware
|
2026-05-13
|
|
Wmic NonInteractive App Uninstallation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Hunting
|
Azorult, IcedID
|
2026-05-13
|
|
MSI Module Loaded by Non-System Binary
|
Sysmon EventID 7
|
T1574.001
|
Hunting
|
Data Destruction, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Windows WinDBG Spawning AutoIt3
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
DarkGate Malware, Compromised Windows Host
|
2026-05-13
|
|
GPUpdate with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Compromised Windows Host, Graceful Wipe Out Attack, Cobalt Strike, BlackByte Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Get ADUser with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.002
|
Hunting
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Headless Browser Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
T1564.003
|
Anomaly
|
Forest Blizzard, Browser Hijacking
|
2026-05-13
|
|
Detect Regasm with no Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.009
|
TTP
|
Living Off The Land, Suspicious Regsvcs Regasm Activity, Void Manticore, Handala Wiper
|
2026-05-13
|
|
Windows Modify Registry Disabling WER Settings
|
Sysmon EventID 13
|
T1112
|
TTP
|
CISA AA23-347A, Azorult
|
2026-05-13
|
|
Windows Protocol Tunneling with Plink
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.004
T1572
|
TTP
|
CISA AA22-257A
|
2026-05-13
|
|
Spoolsv Suspicious Loaded Modules
|
Sysmon EventID 7
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows Snake Malware Service Create
|
Windows Event Log System 7045
|
T1547.006
T1569.002
|
TTP
|
Compromised Windows Host, Snake Malware
|
2026-05-13
|
|
Windows Visual Basic Commandline Compiler DNSQuery
|
Sysmon EventID 22
|
T1071.004
|
TTP
|
Lokibot
|
2026-05-13
|
|
Windows MOVEit Transfer Writing ASPX
|
Sysmon EventID 11
|
T1133
T1190
|
TTP
|
MOVEit Transfer Critical Vulnerability, Hellcat Ransomware
|
2026-05-13
|
|
Network Discovery Using Route Windows App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1016.001
|
Hunting
|
Qakbot, Active Directory Discovery, Windows Post-Exploitation, CISA AA22-277A, Prestige Ransomware
|
2026-05-13
|
|
PowerShell Start or Stop Service
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Scattered Lapsus$ Hunters, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows PowerShell Process With Malicious String
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Snake Malware Kernel Driver Comadmin
|
Sysmon EventID 11
|
T1547.006
|
TTP
|
Snake Malware
|
2026-05-13
|
|
Windows Modify Registry wuStatusServer
|
Sysmon EventID 13
|
T1112
|
Hunting
|
RedLine Stealer
|
2026-05-13
|
|
PowerShell Loading DotNET into Memory via Reflection
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Axios Supply Chain Post Compromise, Winter Vivern, AsyncRAT, VIP Keylogger, AgentTesla, Data Destruction, 0bj3ctivity Stealer, Malicious PowerShell, Hermetic Wiper, Hellcat Ransomware
|
2026-05-13
|
|
Detect SharpHound Command-Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
BlackSuit Ransomware, Ransomware, Windows Discovery Techniques
|
2026-05-13
|
|
Windows Multiple Users Remotely Failed To Authenticate From Host
|
Windows Event Log Security 4625
|
T1110.003
|
TTP
|
Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows High File Deletion Frequency
|
Sysmon EventID 26, Sysmon EventID 23
|
T1485
|
Anomaly
|
WhisperGate, Black Basta Ransomware, Sandworm Tools, APT37 Rustonotto and FadeStealer, Handala Wiper, ZOVWiper, Void Manticore, Swift Slicer, Data Destruction, Clop Ransomware, Medusa Ransomware, DarkCrystal RAT, DynoWiper, NailaoLocker Ransomware, Interlock Ransomware
|
2026-05-13
|
|
Allow Operation with Consent Admin
|
Sysmon EventID 13
|
T1548
|
TTP
|
Windows Registry Abuse, MoonPeak, Ransomware, Azorult
|
2026-05-13
|
|
Windows PowerShell Script From WindowsApps Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1204.002
|
TTP
|
Malicious PowerShell, MSIX Package Abuse
|
2026-05-13
|
|
Windows Netspy Network Scanner Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
T1595
|
Anomaly
|
Windows Discovery Techniques, Network Discovery
|
2026-05-13
|
|
Windows Theme File Creation in Unusual Location
|
Sysmon EventID 11
|
T1021.002
T1187
T1557.001
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Windows Steal Authentication Certificates CertUtil Backup
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1649
|
Anomaly
|
Windows Certificate Services, Storm-2460 CLFS Zero Day Exploitation
|
2026-05-13
|
|
Common Ransomware Extensions
|
Sysmon EventID 11
|
T1485
|
TTP
|
Black Basta Ransomware, Ransomware, Rhysida Ransomware, SamSam Ransomware, Clop Ransomware, LockBit Ransomware, Prestige Ransomware, Termite Ransomware, Ryuk Ransomware, Medusa Ransomware, NailaoLocker Ransomware, Interlock Ransomware
|
2026-05-13
|
|
Windows AppLocker Rare Application Launch Detection
|
|
T1218
|
Hunting
|
Windows AppLocker
|
2026-05-13
|
|
Windows PUA Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
Anomaly
|
IcedID, DarkSide Ransomware, DHS Report TA18-074A, Sandworm Tools, Seashell Blizzard, Rhysida Ransomware, VanHelsing Ransomware, Medusa Ransomware, SamSam Ransomware, Active Directory Lateral Movement, Volt Typhoon, Cactus Ransomware, CISA AA22-320A, HAFNIUM Group, BlackByte Ransomware, DarkGate Malware
|
2026-05-13
|
|
Windows Mock Trusted Directory MSC File Creation
|
Sysmon EventID 11
|
T1218.014
T1548.002
T1574
|
TTP
|
Windows Persistence Techniques, Windows Privilege Escalation
|
2026-05-13
|
|
Windows Password Managers Discovery
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1555.005
|
Anomaly
|
Scattered Spider, Scattered Lapsus$ Hunters, Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Windows Chromium Process Loaded Extension via Command-Line
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1185
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Powershell Remote Services Add TrustedHost
|
Powershell Script Block Logging 4104
|
T1021.006
|
TTP
|
DarkGate Malware
|
2026-05-13
|
|
Remcos RAT File Creation in Remcos Folder
|
Sysmon EventID 11
|
T1113
|
TTP
|
Remcos
|
2026-05-13
|
|
Windows Unusual Count Of Users Failed To Auth Using Kerberos
|
Windows Event Log Security 4771
|
T1110.003
|
Anomaly
|
Active Directory Kerberos Attacks, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows Forest Discovery with GetForestDomain
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows MMC Loaded Script Engine DLL
|
Sysmon EventID 7
|
T1620
|
Anomaly
|
XML Runner Loader
|
2026-05-13
|
|
Windows IIS Components Module Failed to Load
|
Windows Event Log Application 2282
|
T1505.004
|
Anomaly
|
IIS Components
|
2026-05-13
|
|
Clear Unallocated Sector Using Cipher App
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070.004
|
TTP
|
Scattered Spider, Compromised Windows Host, Ransomware
|
2026-05-13
|
|
Windows Impair Defense Change Win Defender Tracing Level
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Mimikatz Crypto Export File Extensions
|
Sysmon EventID 11
|
T1649
|
Anomaly
|
CISA AA23-347A, Windows Certificate Services, Sandworm Tools
|
2026-05-13
|
|
Samsam Test File Write
|
Sysmon EventID 11
|
T1486
|
TTP
|
SamSam Ransomware
|
2026-05-13
|
|
Windows Modify Registry Disable Win Defender Raw Write Notif
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
CISA AA23-347A, Azorult
|
2026-05-13
|
|
Windows Chromium Browser No Security Sandbox Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
|
TTP
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Windows Steal Authentication Certificates Certificate Request
|
Windows Event Log Security 4886
|
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows System Remote Discovery With Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1033
|
Hunting
|
Medusa Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Creation of Shadow Copy with wmic and powershell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.003
|
TTP
|
Living Off The Land, Credential Dumping, Compromised Windows Host, Volt Typhoon
|
2026-05-13
|
|
Windows Known GraphicalProton Loaded Modules
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
Water Gamayun, CISA AA23-347A, Hellcat Ransomware
|
2026-05-13
|
|
Headless Browser Mockbin or Mocky Request
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1564.003
|
TTP
|
Forest Blizzard, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
SLUI RunAs Elevated
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, DarkSide Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Windows Disable or Modify Tools Via Taskkill
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Crypto Stealer, NjRAT, BlankGrabber Stealer, PXA Stealer
|
2026-05-13
|
|
Windows MSTSC RDP Commandline
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
|
Anomaly
|
Medusa Ransomware, Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows SQL Server Critical Procedures Enabled
|
Windows Event Log Application 15457
|
T1505.001
|
TTP
|
SQL Server Abuse
|
2026-05-13
|
|
Windows Common Abused Cmd Shell Risk Behavior
|
|
T1016
T1033
T1049
T1059
T1222
T1529
|
Correlation
|
Qakbot, Windows Defense Evasion Tactics, Disabling Security Tools, Sandworm Tools, FIN7, Windows Post-Exploitation, Volt Typhoon, DarkCrystal RAT, Azorult, Microsoft WSUS CVE-2025-59287, Netsh Abuse, CISA AA23-347A
|
2026-05-13
|
|
Windows PowerView Unconstrained Delegation Discovery
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Rhysida Ransomware, Active Directory Kerberos Attacks, CISA AA23-347A
|
2026-05-13
|
|
Suspicious MSBuild Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1127.001
|
TTP
|
Living Off The Land, Storm-2460 CLFS Zero Day Exploitation, Trusted Developer Utilities Proxy Execution MSBuild
|
2026-05-13
|
|
Windows Modify Registry DontShowUI
|
Sysmon EventID 13
|
T1112
|
TTP
|
DarkGate Malware
|
2026-05-13
|
|
Regsvr32 Silent and Install Param Dll Loading
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.010
|
Anomaly
|
AsyncRAT, Suspicious Regsvr32 Activity, Data Destruction, Remcos, Hermetic Wiper, Living Off The Land
|
2026-05-13
|
|
Windows Vulnerable Driver Installed
|
Windows Event Log System 7045
|
T1543.003
|
TTP
|
Windows Drivers, Void Manticore
|
2026-05-13
|
|
Windows File Association Modification via Ftype
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Anomaly
|
Windows File Extension and Association Abuse
|
2026-05-13
|
|
Scheduled Task Creation on Remote Endpoint using At
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.002
|
TTP
|
Living Off The Land, Scheduled Tasks, 0bj3ctivity Stealer, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Bypass UAC via Pkgmgr Tool
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1548.002
|
Anomaly
|
Warzone RAT
|
2026-05-13
|
|
GetWmiObject Ds Computer with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1018
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Esentutl SAM Copy
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.002
|
Hunting
|
Credential Dumping, Living Off The Land
|
2026-05-13
|
|
Windows ISO LNK File Creation
|
Sysmon EventID 11
|
T1204.001
T1566.001
|
Hunting
|
Qakbot, Brute Ratel C4, APT37 Rustonotto and FadeStealer, Warzone RAT, AgentTesla, Azorult, Amadey, Remcos, IcedID, Gozi Malware, Spearphishing Attachments
|
2026-05-13
|
|
Windows Remote Service Rdpwinst Tool Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
|
TTP
|
Windows RDP Artifacts and Defense Evasion, Scattered Lapsus$ Hunters, Compromised Windows Host, Azorult
|
2026-05-13
|
|
Remote Process Instantiation via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Suspicious WMI Use, Ransomware, China-Nexus Threat Activity, Salt Typhoon, Void Manticore, Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Windows Account Access Removal via Logoff Exec
|
Sysmon EventID 1
|
T1059.001
T1531
|
Anomaly
|
Crypto Stealer
|
2026-05-13
|
|
Windows Archived Collected Data In TEMP Folder
|
Sysmon EventID 11
|
T1560
|
Anomaly
|
Braodo Stealer, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows InstallUtil Remote Network Connection
|
Cisco Network Visibility Module Flow Data, Sysmon EventID 1, Sysmon EventID 3
|
T1218.004
|
Anomaly
|
Living Off The Land, Compromised Windows Host, Cisco Network Visibility Module Analytics, Signed Binary Proxy Execution InstallUtil
|
2026-05-13
|
|
Windows Audit Policy Auditing Option Modified - Registry
|
Sysmon EventID 13
|
T1547.014
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows Multiple Users Failed To Authenticate Using Kerberos
|
Windows Event Log Security 4771
|
T1110.003
|
TTP
|
Active Directory Kerberos Attacks, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows PowerShell Module File Created
|
Sysmon EventID 11
|
T1059.001
T1129
T1574
|
Anomaly
|
Windows Persistence Techniques, Malicious PowerShell
|
2026-05-13
|
|
Dump LSASS via comsvcs DLL
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.001
|
TTP
|
CISA AA22-264A, Compromised Windows Host, Credential Dumping, Flax Typhoon, Scattered Lapsus$ Hunters, Volt Typhoon, Hellcat Ransomware, Data Destruction, HAFNIUM Group, Prestige Ransomware, CISA AA22-257A, Industroyer2, Living Off The Land, Suspicious Rundll32 Activity
|
2026-05-13
|
|
ETW Registry Disabled
|
Sysmon EventID 13
|
T1127
T1685
|
TTP
|
Windows Persistence Techniques, Windows Registry Abuse, Data Destruction, Windows Privilege Escalation, Hermetic Wiper, CISA AA23-347A
|
2026-05-13
|
|
Windows Process Accessing Windows Recall Directory
|
Windows Event Log Security 4663
|
T1059
T1119
|
Anomaly
|
Windows Post-Exploitation
|
2026-05-13
|
|
Disable Windows SmartScreen Protection
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, CISA AA23-347A
|
2026-05-13
|
|
File with Samsam Extension
|
Sysmon EventID 11
|
N/A
|
TTP
|
SamSam Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Outlook Macro Created by Suspicious Process
|
Sysmon EventID 11
|
T1059.005
T1137
|
TTP
|
NotDoor Malware
|
2026-05-13
|
|
Windows Modify Registry NoChangingWallPaper
|
Sysmon EventID 13
|
T1112
|
TTP
|
Rhysida Ransomware
|
2026-05-13
|
|
SilentCleanup UAC Bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, MoonPeak
|
2026-05-13
|
|
Windows Unusual File Creation in Confluence Directory
|
Sysmon EventID 11
|
T1190
T1608.001
T1608.002
|
Anomaly
|
Confluence Data Center and Confluence Server Vulnerabilities, CVE-2023-22515 Privilege Escalation Vulnerability Confluence Data Center and Server
|
2026-05-13
|
|
Windows Computer Account Changed to Domain Controller
|
Windows Event Log Security 4742
|
T1136.002
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Modify Registry Delete Firewall Rules
|
Sysmon EventID 12
|
T1112
|
TTP
|
CISA AA24-241A, NetSupport RMM Tool Abuse, ShrinkLocker
|
2026-05-13
|
|
Change To Safe Mode With Network Config
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1490
|
TTP
|
BlackMatter Ransomware, Black Basta Ransomware
|
2026-05-13
|
|
Windows Unusual NTLM Authentication Users By Source
|
NTLM Operational 8006, NTLM Operational 8005, NTLM Operational 8004
|
T1110.003
|
Anomaly
|
Active Directory Password Spraying
|
2026-05-13
|
|
Detect MSHTA Url in Command Line
|
Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.005
|
TTP
|
Compromised Windows Host, Suspicious MSHTA Activity, APT37 Rustonotto and FadeStealer, XWorm, Cisco Network Visibility Module Analytics, NetSupport RMM Tool Abuse, Lumma Stealer, Living Off The Land
|
2026-05-13
|
|
Executable File Written in Administrative SMB Share
|
Windows Event Log Security 5145
|
T1021.002
|
TTP
|
IcedID, Compromised Windows Host, Graceful Wipe Out Attack, VanHelsing Ransomware, Active Directory Lateral Movement, Data Destruction, Prestige Ransomware, Hermetic Wiper, Trickbot, Industroyer2, BlackSuit Ransomware
|
2026-05-13
|
|
Windows Product Key Registry Query
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
High Process Termination Frequency
|
Sysmon EventID 5
|
T1486
|
Anomaly
|
Rhysida Ransomware, Crypto Stealer, Clop Ransomware, LockBit Ransomware, Termite Ransomware, BlackByte Ransomware, Medusa Ransomware, Snake Keylogger, NailaoLocker Ransomware, Hellcat Ransomware, Interlock Ransomware
|
2026-05-13
|
|
Windows DiskCryptor Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1486
|
Hunting
|
Ransomware
|
2026-05-13
|
|
GetWmiObject DS User with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Service Create with Tscon
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.003
T1563.002
|
TTP
|
Windows RDP Artifacts and Defense Evasion, Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
GetDomainGroup with PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Detect Certipy File Modifications
|
Sysmon EventID 11
|
T1560
T1649
|
TTP
|
Windows Certificate Services, Ingress Tool Transfer, Data Exfiltration
|
2026-05-13
|
|
Suspicious Image Creation In Appdata Folder
|
Sysmon EventID 11, Sysmon EventID 1
|
T1113
|
TTP
|
Remcos, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Remote Process Instantiation via WinRM and PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.006
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Registry Keys Used For Privilege Escalation
|
Sysmon EventID 13
|
T1546.012
|
TTP
|
Windows Registry Abuse, Data Destruction, Windows Privilege Escalation, Hermetic Wiper, Cloud Federated Credential Abuse, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Rundll32 CreateRemoteThread In Browser
|
Sysmon EventID 8
|
T1055
|
TTP
|
Living Off The Land, IcedID
|
2026-05-13
|
|
Windows Service Creation Using Registry Entry
|
Sysmon EventID 13
|
T1574.011
|
Anomaly
|
Brute Ratel C4, SnappyBee, China-Nexus Threat Activity, Crypto Stealer, Windows Persistence Techniques, Salt Typhoon, Active Directory Lateral Movement, SolarWinds WHD RCE Post Exploitation, Windows Registry Abuse, Derusbi, Gh0st RAT, PlugX, CISA AA23-347A, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Windows ESX Admins Group Creation via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1136.001
T1136.002
|
TTP
|
VMware ESXi AD Integration Authentication Bypass CVE-2024-37085
|
2026-05-13
|
|
Windows DISM Remove Defender
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
TTP
|
Windows Defense Evasion Tactics, CISA AA23-347A, Compromised Windows Host
|
2026-05-13
|
|
Fsutil Zeroing File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1070
|
TTP
|
LockBit Ransomware, Ransomware
|
2026-05-13
|
|
Powershell Fileless Script Contains Base64 Encoded Content
|
Powershell Script Block Logging 4104
|
T1027
T1059.001
|
TTP
|
IcedID, Axios Supply Chain Post Compromise, XWorm, Winter Vivern, AsyncRAT, APT37 Rustonotto and FadeStealer, NjRAT, MuddyWater, VIP Keylogger, Data Destruction, 0bj3ctivity Stealer, Malicious PowerShell, Microsoft WSUS CVE-2025-59287, Hermetic Wiper, Medusa Ransomware, NetSupport RMM Tool Abuse, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows AppLocker Privilege Escalation via Unauthorized Bypass
|
|
T1218
|
TTP
|
Windows AppLocker
|
2026-05-13
|
|
GetWmiObject User Account with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Malicious PowerShell, Active Directory Discovery, Winter Vivern
|
2026-05-13
|
|
Windows Impair Defense Add Xml Applocker Rules
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Hunting
|
Azorult
|
2026-05-13
|
|
Windows User Discovery Via Net
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.001
|
Hunting
|
Medusa Ransomware, Active Directory Discovery, Sandworm Tools
|
2026-05-13
|
|
Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials
|
Windows Event Log Security 4648
|
T1110.003
|
Anomaly
|
Insider Threat, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows Default Rdp File Deletion
|
Sysmon EventID 26, Sysmon EventID 23
|
T1070.004
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows AD AdminSDHolder ACL Modified
|
Windows Event Log Security 5136
|
T1546
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Powershell Creating Thread Mutex
|
Powershell Script Block Logging 4104
|
T1027.005
T1059.001
|
TTP
|
Water Gamayun, Malicious PowerShell
|
2026-05-13
|
|
Windows Autostart Execution LSASS Driver Registry Modification
|
Sysmon EventID 13
|
T1547.008
|
TTP
|
Windows Registry Abuse
|
2026-05-13
|
|
Spoolsv Spawning Rundll32
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Compromised Windows Host, Black Basta Ransomware
|
2026-05-13
|
|
Windows Service Stop By Deletion
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1489
|
Hunting
|
Crypto Stealer, Graceful Wipe Out Attack, Azorult
|
2026-05-13
|
|
Windows Handle Duplication in Known UAC-Bypass Binaries
|
Sysmon EventID 10
|
T1134.001
|
Anomaly
|
Castle RAT
|
2026-05-13
|
|
Detect AzureHound Command-Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Compromised Windows Host, Windows Discovery Techniques
|
2026-05-13
|
|
PowerShell Domain Enumeration
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Data Destruction, Malicious PowerShell, Hermetic Wiper, Microsoft WSUS CVE-2025-59287, CISA AA23-347A, Interlock Ransomware
|
2026-05-13
|
|
Windows DLL Search Order Hijacking Hunt with Sysmon
|
Sysmon EventID 7
|
T1574.001
|
Hunting
|
Qakbot, Windows Defense Evasion Tactics, Malicious Inno Setup Loader, Living Off The Land
|
2026-05-13
|
|
Sqlite Module In Temp Folder
|
Sysmon EventID 11
|
T1005
|
TTP
|
Lokibot, IcedID
|
2026-05-13
|
|
Windows Rdp AutomaticDestinations Deletion
|
Sysmon EventID 26, Sysmon EventID 23
|
T1070.004
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion
|
2026-05-13
|
|
Windows Multiple Users Failed To Authenticate From Host Using NTLM
|
Windows Event Log Security 4776
|
T1110.003
|
TTP
|
Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows Chromium Browser with Custom User Data Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497
|
Anomaly
|
Lokibot, Malicious Inno Setup Loader, StealC Stealer
|
2026-05-13
|
|
Windows NirSoft Utilities
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1588.002
|
Hunting
|
Data Destruction, WhisperGate
|
2026-05-13
|
|
Windows AppLocker Execution from Uncommon Locations
|
|
T1218
|
Hunting
|
Windows AppLocker
|
2026-05-13
|
|
Windows Potential Web Shell Creation For VMware Workspace ONE
|
Sysmon EventID 11
|
T1505.003
|
Anomaly
|
VMware Aria Operations vRealize CVE-2023-20887, VMware ESXi AD Integration Authentication Bypass CVE-2024-37085, VMware Server Side Injection and Privilege Escalation
|
2026-05-13
|
|
Detect SharpHound Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Ransomware, Windows Discovery Techniques
|
2026-05-13
|
|
SchCache Change By App Connect And Create ADSI Object
|
Sysmon EventID 11
|
T1087.002
|
Anomaly
|
BlackMatter Ransomware
|
2026-05-13
|
|
Windows Explorer LNK Exploit Process Launch With Padding
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1204.002
|
TTP
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Windows Steal Authentication Certificates Certificate Issued
|
Windows Event Log Security 4887
|
T1649
|
Anomaly
|
Windows Certificate Services
|
2026-05-13
|
|
Windows Service Created with Suspicious Service Path
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Qakbot, Brute Ratel C4, APT37 Rustonotto and FadeStealer, China-Nexus Threat Activity, Crypto Stealer, Salt Typhoon, Active Directory Lateral Movement, Snake Malware, Clop Ransomware, Derusbi, Gh0st RAT, Flax Typhoon, PlugX, CISA AA23-347A
|
2026-05-13
|
|
Unknown Process Using The Kerberos Protocol
|
Sysmon EventID 1, Sysmon EventID 3
|
T1550
|
TTP
|
Active Directory Kerberos Attacks, BlackSuit Ransomware
|
2026-05-13
|
|
Windows Defender ASR Rules Stacking
|
Windows Event Log Defender 1121, Windows Event Log Defender 1133, Windows Event Log Defender 1134, Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 5007, Windows Event Log Defender 1131, Windows Event Log Defender 1122, Windows Event Log Defender 1129
|
T1059
T1566.001
T1566.002
|
Hunting
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Wmiprvse LOLBAS Execution Process Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Credential Dumping via Symlink to Shadow Copy
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1003.003
|
TTP
|
Credential Dumping, Compromised Windows Host
|
2026-05-13
|
|
Windows Modify System Firewall with Notable Process Path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1686
|
TTP
|
Medusa Ransomware, NjRAT, Compromised Windows Host
|
2026-05-13
|
|
Windows WinPEAS PowerShell Script Execution
|
Powershell Script Block Logging 4104
|
T1007
T1016
T1033
T1082
T1590
T1592.002
T1592.004
T1615
|
TTP
|
Windows Post-Exploitation
|
2026-05-13
|
|
Windows Remote Access Software BRC4 Loaded Dll
|
Sysmon EventID 7
|
T1003
T1219
|
Anomaly
|
Brute Ratel C4
|
2026-05-13
|
|
Local Account Discovery With Wmic
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1087.001
|
Hunting
|
Active Directory Discovery, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows WMIC Shadowcopy Delete
|
Sysmon EventID 1
|
T1490
|
Anomaly
|
Suspicious WMI Use, Volt Typhoon, Cactus Ransomware
|
2026-05-13
|
|
Windows ScManager Security Descriptor Tampering Via Sc.EXE
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1569.002
|
TTP
|
Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Windows Impair Defenses Disable AV AutoStart via Registry
|
Sysmon EventID 13
|
T1112
|
TTP
|
Scattered Lapsus$ Hunters, ValleyRAT
|
2026-05-13
|
|
Ryuk Test Files Detected
|
Sysmon EventID 11
|
T1486
|
TTP
|
Ryuk Ransomware
|
2026-05-13
|
|
Windows Set Network Profile Category to Private via Registry
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
Secret Blizzard
|
2026-05-13
|
|
Windows Credential Access From Browser Password Store
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Braodo Stealer, SnappyBee, Meduza Stealer, China-Nexus Threat Activity, VIP Keylogger, Scattered Lapsus$ Hunters, Salt Typhoon, Earth Alux, PXA Stealer, StealC Stealer, Malicious Inno Setup Loader, MoonPeak, 0bj3ctivity Stealer, Quasar RAT, Snake Keylogger, Scattered Spider, BlankGrabber Stealer
|
2026-05-13
|
|
Local LLM Framework DNS Query
|
Sysmon EventID 22
|
T1590
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-05-13
|
|
Windows Driver Load Non-Standard Path
|
Windows Event Log System 7045
|
T1014
T1068
|
TTP
|
Windows Drivers, AgentTesla, CISA AA22-320A, BlackByte Ransomware, BlackSuit Ransomware
|
2026-05-13
|
|
PetitPotam Network Share Access Request
|
Windows Event Log Security 5145
|
T1187
|
TTP
|
PetitPotam NTLM Relay on Active Directory Certificate Services
|
2026-05-13
|
|
Windows Modify Registry LongPathsEnabled
|
Sysmon EventID 13
|
T1112
|
Anomaly
|
BlackByte Ransomware
|
2026-05-13
|
|
Verclsid CLSID Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.012
|
Hunting
|
Unusual Processes
|
2026-05-13
|
|
Disable AMSI Through Registry
|
Sysmon EventID 13
|
T1685
|
TTP
|
Windows Registry Abuse, CISA AA23-347A, Ransomware
|
2026-05-13
|
|
Windows CrowdStrike Agent Registry Key Removal
|
Sysmon EventID 12
|
T1685
|
Anomaly
|
Security Solution Tampering, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Modify Registry ValleyRAT C2 Config
|
Sysmon EventID 13
|
T1112
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
Windows SOAPHound Binary Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Compromised Windows Host, Windows Discovery Techniques
|
2026-05-13
|
|
Windows Credential Target Information Structure in Commandline
|
Sysmon EventID 1
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS
|
2026-05-13
|
|
Windows EDRSilencer Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685
|
Anomaly
|
Security Solution Tampering
|
2026-05-13
|
|
Wsmprovhost LOLBAS Execution Process Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.006
|
TTP
|
CISA AA24-241A, Hellcat Ransomware, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Audit Policy Disabled via Auditpol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1685.001
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Suspicious SQLite3 LSQuarantine Behavior
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1074
|
TTP
|
Silver Sparrow
|
2026-05-13
|
|
Nishang PowershellTCPOneLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
TTP
|
HAFNIUM Group, Cleo File Transfer Software
|
2026-05-13
|
|
Windows Multiple Users Failed To Authenticate From Process
|
Windows Event Log Security 4625
|
T1110.003
|
TTP
|
Insider Threat, Volt Typhoon, Active Directory Password Spraying
|
2026-05-13
|
|
Windows RDP File Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
T1598.002
|
TTP
|
Windows RDP Artifacts and Defense Evasion, Spearphishing Attachments, Interlock Ransomware
|
2026-05-13
|
|
Windows DisableAntiSpyware Registry
|
Sysmon EventID 13
|
T1685
|
TTP
|
CISA AA22-264A, Windows Defense Evasion Tactics, Ryuk Ransomware, SolarWinds WHD RCE Post Exploitation, Windows Registry Abuse, Azorult, CISA AA23-347A, RedLine Stealer
|
2026-05-13
|
|
Windows PowerShell Script TabExpansion Direct Call
|
Powershell Script Block Logging 4104
|
T1059.001
T1129
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
CHCP Command Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
IcedID, Crypto Stealer, Forest Blizzard, Interlock Rat, Quasar RAT, Azorult
|
2026-05-13
|
|
Sc exe Manipulating Windows Services
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1543.003
|
TTP
|
Windows Drivers, Disabling Security Tools, DHS Report TA18-074A, Crypto Stealer, Windows Persistence Techniques, Orangeworm Attack Group, Azorult, Windows Service Abuse, Scattered Spider, NOBELIUM Group
|
2026-05-13
|
|
Processes launching netsh
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1686
|
Anomaly
|
Disabling Security Tools, DHS Report TA18-074A, Volt Typhoon, Azorult, Snake Keylogger, Netsh Abuse, ShrinkLocker, Hellcat Ransomware
|
2026-05-13
|
|
Attempt To Add Certificate To Untrusted Store
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1553.004
|
Anomaly
|
Disabling Security Tools
|
2026-05-13
|
|
Windows IIS Server PSWA Console Access
|
Windows IIS
|
T1190
|
Hunting
|
CISA AA24-241A
|
2026-05-13
|
|
Windows Exchange Autodiscover SSRF Abuse
|
Windows IIS
|
T1133
T1190
|
TTP
|
ProxyNotShell, Seashell Blizzard, ProxyShell, BlackByte Ransomware
|
2026-05-13
|
|
Windows SharePoint Spinstall0 GET Request
|
Suricata
|
T1190
T1505.003
T1552
|
TTP
|
Microsoft SharePoint Vulnerabilities
|
2026-05-13
|
|
Windows SharePoint ToolPane Endpoint Exploitation Attempt
|
Suricata
|
T1190
T1505.003
|
TTP
|
Microsoft SharePoint Vulnerabilities
|
2026-05-13
|
|
Detect Password Spray Attempts
|
Windows Event Log Security 4625
|
T1110.003
|
TTP
|
Compromised User Account, Active Directory Password Spraying
|
2026-05-13
|
|
No Windows Updates in a time frame
|
|
N/A
|
Hunting
|
Monitor for Updates
|
2026-05-13
|
|
Detect HTML Help Spawn Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1218.001
|
TTP
|
Compromised Windows Host, APT37 Rustonotto and FadeStealer, AgentTesla, Living Off The Land, Suspicious Compiled HTML Activity
|
2026-05-13
|
|
Email files written outside of the Outlook directory
|
Sysmon EventID 11
|
T1114.001
|
TTP
|
Collection and Staging
|
2026-05-13
|
|
Azure AD Successful PowerShell Authentication
|
Azure Active Directory
|
T1078.004
T1586.003
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
3CX Supply Chain Attack Network Indicators
|
Sysmon EventID 22
|
T1195.002
|
TTP
|
3CX Supply Chain Attack
|
2026-05-13
|
|
Windows Multi hop Proxy TOR Website Query
|
Sysmon EventID 22
|
T1071.003
|
Anomaly
|
AgentTesla, Interlock Ransomware
|
2026-05-13
|
|
Windows Remote Desktop Network Bruteforce Attempt
|
Sysmon EventID 3, Cisco Secure Access Firewall
|
T1110.001
|
Anomaly
|
Windows RDP Artifacts and Defense Evasion, Cisco Secure Access Analytics, SamSam Ransomware, Ryuk Ransomware, Compromised User Account
|
2026-05-13
|
|
DNS Query Length With High Standard Deviation
|
Sysmon EventID 22
|
T1048.003
|
Anomaly
|
Command And Control, Suspicious DNS Traffic, Hidden Cobra Malware
|
2026-05-13
|
|
Wermgr Process Connecting To IP Check Web Services
|
Sysmon EventID 22
|
T1590.005
|
TTP
|
Trickbot
|
2026-05-13
|
|
Detect Remote Access Software Usage DNS
|
Sysmon EventID 22
|
T1219
|
Anomaly
|
CISA AA24-241A, Ransomware, Insider Threat, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, Command And Control, Scattered Spider, Interlock Ransomware
|
2026-05-13
|
|
Detect DNS Query to Decommissioned S3 Bucket
|
Sysmon EventID 22
|
T1485
|
Anomaly
|
Data Destruction, AWS S3 Bucket Security Monitoring
|
2026-05-13
|
|
Windows DNS Query Request by Telegram Bot API
|
Sysmon EventID 22
|
T1071.004
T1102.002
|
Anomaly
|
Crypto Stealer, 0bj3ctivity Stealer, BlankGrabber Stealer, VIP Keylogger
|
2026-05-13
|
|
Suspicious Process With Discord DNS Query
|
Sysmon EventID 22
|
T1059.005
|
Anomaly
|
WhisperGate, PXA Stealer, Cactus Ransomware, Data Destruction, BlankGrabber Stealer
|
2026-05-13
|
|
Rundll32 DNSQuery
|
Sysmon EventID 22
|
T1218.011
|
TTP
|
Living Off The Land, IcedID
|
2026-05-13
|
|
Windows Gather Victim Network Info Through Ip Check Web Services
|
Sysmon EventID 22
|
T1590.005
|
Anomaly
|
Water Gamayun, Snake Keylogger, Meduza Stealer, Castle RAT, Handala Wiper, VIP Keylogger, PXA Stealer, Void Manticore, 0bj3ctivity Stealer, Quasar RAT, Azorult, Phemedrone Stealer, DarkCrystal RAT, BlankGrabber Stealer
|
2026-05-13
|
|
Suspicious Process DNS Query Known Abuse Web Services
|
Sysmon EventID 22
|
T1059.005
|
TTP
|
WhisperGate, Braodo Stealer, Meduza Stealer, Phemedrone Stealer, PXA Stealer, Malicious Inno Setup Loader, Data Destruction, Cactus Ransomware, Remcos, Snake Keylogger, BlankGrabber Stealer, RedLine Stealer
|
2026-05-13
|
|
Windows AD Replication Service Traffic
|
|
T1003.006
T1207
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD Rogue Domain Controller Network Activity
|
|
T1207
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Abused Web Services
|
Sysmon EventID 22
|
T1102
|
Anomaly
|
NjRAT, BlankGrabber Stealer, CISA AA24-241A, Malicious Inno Setup Loader
|
2026-05-13
|
|
Ngrok Reverse Proxy on Network
|
Sysmon EventID 22
|
T1090
T1102
T1572
|
Anomaly
|
CISA AA22-320A, CISA AA24-241A, Reverse Network Proxy
|
2026-05-13
|
|
Detect Windows DNS SIGRed via Zeek
|
|
T1203
|
TTP
|
Windows DNS SIGRed CVE-2020-1350
|
2026-05-13
|
|
Detect hosts connecting to dynamic domain providers
|
Sysmon EventID 22
|
T1189
|
TTP
|
Suspicious DNS Traffic, Dynamic DNS, DNS Hijacking, Command And Control, Data Protection, Prohibited Traffic Allowed or Protocol Mismatch
|
2026-05-13
|
|
DNS Kerberos Coercion
|
Sysmon EventID 22, Suricata
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS
|
2026-05-13
|
|
Windows Spearphishing Attachment Connect To None MS Office Domain
|
Sysmon EventID 22
|
T1566.001
|
Hunting
|
MuddyWater, Spearphishing Attachments, AsyncRAT
|
2026-05-13
|
|
Detect Windows DNS SIGRed via Splunk Stream
|
|
T1203
|
TTP
|
Windows DNS SIGRed CVE-2020-1350
|
2026-05-13
|