|
Juniper Networks Remote Code Execution Exploit Detection
|
Suricata
|
T1059
T1105
T1190
|
TTP
|
Juniper JunOS Remote Code Execution
|
2026-05-13
|
|
HTTP Duplicated Header
|
Suricata
|
T1071.001
T1190
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Rapid POST with Mixed Status Codes
|
Nginx Access
|
T1071.001
T1190
T1595
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Possible Request Smuggling
|
Suricata
|
T1071.001
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
Okta Non-Standard VPN Usage
|
Okta
|
T1078
T1090
T1572
|
TTP
|
Suspicious Okta Activity, Remote Employment Fraud
|
2026-05-13
|
|
Microsoft Intune Mobile Apps
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Microsoft Intune Device Health Scripts
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Windows Application Layer Protocol RMS Radmin Tool Namedpipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Linux Post-Exploitation, Linux Living Off The Land, Linux Privilege Escalation, Compromised Linux Host, VoidLink Cloud-Native Linux Malware, Linux Rootkit
|
2026-05-13
|
|
Windows Non-System Process Querying Definition Update
|
Sysmon EventID 22
|
T1068
T1071.001
|
Anomaly
|
Windows Privilege Escalation, BlueHammer, RedSun
|
2026-04-27
|
|
Windows Devtunnels Image Loaded
|
Sysmon EventID 7
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows AI Platform DNS Query
|
Sysmon EventID 22
|
T1071.004
|
Anomaly
|
PromptFlux, LAMEHUG, SesameOp
|
2026-05-13
|
|
Cisco NVM - Webserver Download From File Sharing Website
|
Cisco Network Visibility Module Flow Data
|
T1105
T1190
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Cisco NVM - Suspicious File Download via Headless Browser
|
Cisco Network Visibility Module Flow Data
|
T1059
T1105
|
TTP
|
BlankGrabber Stealer, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Powershell Commands from DNS TXT
|
Powershell Script Block Logging 4104
|
T1059.001
T1071.004
|
Anomaly
|
Malicious PowerShell, Command And Control, Suspicious DNS Traffic
|
2026-07-30
|
|
Windows Remote Access Software BRC4 Loaded Dll
|
Sysmon EventID 7
|
T1003
T1219
|
Anomaly
|
Brute Ratel C4
|
2026-05-13
|
|
Windows Suspicious Defender Update Activity in INetCache
|
Sysmon EventID 23, Sysmon EventID 11
|
T1068
T1105
|
Anomaly
|
Windows Persistence Techniques, BlueHammer
|
2026-07-20
|
|
Windows App Layer Protocol Qakbot NamedPipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows File Transfer Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
Hellcat Ransomware, AgentTesla, Snake Keylogger, Phantom Stealer
|
2026-06-25
|
|
Windows Level RMM PowerShell Script Installer
|
Powershell Script Block Logging 4104
|
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Download Files Using Telegram
|
Sysmon EventID 15
|
T1105
|
TTP
|
0bj3ctivity Stealer, Snake Keylogger, XMRig, Water Gamayun, Crypto Stealer, Phemedrone Stealer
|
2026-05-13
|
|
Windows Kerberos Coercion via DNS
|
Windows Event Log Security 5136, Windows Event Log Security 5137, Windows Event Log Security 4662
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS, Suspicious DNS Traffic, Compromised Windows Host
|
2026-05-13
|
|
Windows Mail Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
AgentTesla
|
2026-05-13
|
|
Cisco NVM - Outbound Connection to Suspicious Port
|
Cisco Network Visibility Module Flow Data
|
T1571
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Hellcat Ransomware, Malicious PowerShell
|
2026-05-13
|
|
Windows Visual Basic Commandline Compiler DNSQuery
|
Sysmon EventID 22
|
T1071.004
|
TTP
|
Lokibot
|
2026-05-13
|
|
Windows DNS Query Request To TinyUrl
|
Sysmon EventID 22
|
T1105
|
Anomaly
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Windows Short Lived DNS Record
|
Windows Event Log Security 5136, Windows Event Log Security 5137
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS, Suspicious DNS Traffic, Compromised Windows Host
|
2026-05-13
|
|
Windows DLL Module Loaded in Temp Dir
|
Sysmon EventID 7
|
T1105
|
Hunting
|
SolarWinds WHD RCE Post Exploitation, Lokibot, Interlock Rat
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
Medusa Ransomware, PHP-CGI RCE Attack on Japanese Organizations, Malicious PowerShell, MoonPeak
|
2026-05-13
|
|
Windows App Layer Protocol Wermgr Connect To NamedPipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
Anomaly
|
RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability, Qakbot
|
2026-08-18
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows SoftEther VPN Masquerading as Legitimate Binary
|
Sysmon EventID 1
|
T1036
T1572
|
TTP
|
Flax Typhoon, Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Windows RMM Tool Execution
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Suspicious User Agents, Remote Monitoring and Management Software, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Cisco Isovalent - Curl Execution With Insecure Flags
|
Cisco Isovalent Process Exec
|
T1105
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Cisco NVM - Osascript Network Connection for a Long Duration
|
Cisco Network Visibility Module Flow Data
|
T1059.002
T1071.001
|
Anomaly
|
MacOS Post-Exploitation, Command And Control, Cisco Network Visibility Module Analytics
|
2026-09-18
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence
|
2026-05-13
|
|
Windows Abused Web Services
|
Sysmon EventID 22
|
T1102
|
Anomaly
|
Malicious Inno Setup Loader, BlankGrabber Stealer, CISA AA24-241A, NjRAT
|
2026-05-13
|
|
Zeek x509 Certificate with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1573.002
T1587.002
T1588.004
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco SA - Access to Anonymizer Services
|
Cisco Secure Access DNS
|
T1090.003
|
Anomaly
|
Cisco Secure Access Analytics
|
2026-06-09
|
|
Cisco Secure Firewall - Repeated Malware Downloads
|
Cisco Secure Firewall Threat Defense File Event
|
T1027
T1105
|
Anomaly
|
Hellcat Ransomware, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows Multi hop Proxy TOR Website Query
|
Sysmon EventID 22
|
T1071.003
|
Anomaly
|
AgentTesla, Interlock Ransomware
|
2026-05-13
|
|
Cisco Secure Firewall - High EVE Threat Confidence
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1041
T1071.001
T1105
T1573.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1027
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Malware File Downloaded
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Intrusion Events by Threat Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
ArcaneDoor, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Download Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows DNS Query Request by Telegram Bot API
|
Sysmon EventID 22
|
T1071.004
T1102.002
|
Anomaly
|
BlankGrabber Stealer, Starland RAT Campaign, 0bj3ctivity Stealer, VIP Keylogger, Crypto Stealer, Phantom Stealer
|
2026-07-20
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1071
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Connection to File Sharing Domain
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1090.002
T1105
T1567.002
T1588.002
|
Anomaly
|
Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - File Download Over Uncommon Port
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco IOS XE Tunnel Interface Configuration
|
Cisco IOS Logs
|
T1090
T1572
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
Ollama Abnormal Network Connectivity
|
Ollama Server
|
T1571
|
Anomaly
|
Suspicious Ollama Activities
|
2026-05-13
|
|
HTTP Scripting Tool User Agent
|
Nginx Access
|
T1071.001
|
Anomaly
|
Suspicious User Agents, HTTP Request Smuggling
|
2026-06-15
|
|
HTTP Request to Reserved Name on IIS Server
|
Suricata
|
T1071.001
T1190
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
Detect Remote Access Software Usage URL
|
Palo Alto Network Threat
|
T1219
|
Anomaly
|
Command And Control, Interlock Ransomware, Remote Monitoring and Management Software, Ransomware, Scattered Lapsus$ Hunters, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
Windows Protocol Tunneling with Plink
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.004
T1572
|
TTP
|
CISA AA22-257A
|
2026-05-13
|
|
Detect Remote Access Software Usage Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1219
|
Anomaly
|
Command And Control, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Seashell Blizzard, Storm-0501 Ransomware, Ransomware, Cactus Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Gozi Malware, Scattered Lapsus$ Hunters, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
LOLBAS Rare Network Connection
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
Anomaly
|
Living Off The Land, Malicious Inno Setup Loader, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, NetSupport RMM Tool Abuse, Water Gamayun, GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns
|
2026-08-24
|
|
Detect Remote Access Software Usage Registry
|
Sysmon EventID 13
|
T1219
|
Anomaly
|
Command And Control, Scattered Spider, Remote Monitoring and Management Software, Seashell Blizzard, Ransomware, Cactus Ransomware, Gozi Malware, Scattered Lapsus$ Hunters, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
Windows Ldifde Directory Object Behavior
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
T1105
|
TTP
|
Volt Typhoon
|
2026-05-13
|
|
LOLBAS Network Connection On Uncommon Port
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
Anomaly
|
Living Off The Land, Malicious Inno Setup Loader, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, NetSupport RMM Tool Abuse, Water Gamayun, GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns
|
2026-08-24
|
|
Windows Process Execution From RDP Share
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
BITSAdmin Download File
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
T1197
|
TTP
|
Living Off The Land, DarkSide Ransomware, Scattered Spider, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, Ingress Tool Transfer, Flax Typhoon, BITS Jobs, GhostRedirector IIS Module and Rungan Backdoor, Gozi Malware
|
2026-05-13
|
|
Windows Curl Upload to Remote Destination
|
Cisco Network Visibility Module Flow Data, CrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688
|
T1105
|
TTP
|
Microsoft WSUS CVE-2025-59287, NPM Supply Chain Compromise, Compromised Windows Host, Ingress Tool Transfer, Cisco Network Visibility Module Analytics, PromptLock, Axios Supply Chain Post Compromise
|
2026-07-14
|
|
WinRAR Spawning Shell Application
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
WinRAR Spoofing Attack CVE-2023-38831, Compromised Windows Host
|
2026-05-13
|
|
Linux Curl Upload File
|
Sysmon for Linux EventID 1, Cisco Isovalent Process Exec
|
T1105
|
TTP
|
NPM Supply Chain Compromise, Data Exfiltration, Linux Living Off The Land, Ingress Tool Transfer
|
2026-05-13
|
|
Linux Ingress Tool Transfer Hunting
|
Sysmon for Linux EventID 1
|
T1105
|
Hunting
|
Linux Living Off The Land, NPM Supply Chain Compromise, Ingress Tool Transfer, XorDDos, Axios Supply Chain Post Compromise
|
2026-05-13
|
|
Windows Proxy Via Registry
|
Sysmon EventID 13
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Curl Execution with Percent Encoded URL
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Sysmon for Linux EventID 1, Windows Event Log Security 4688
|
T1027
T1105
|
Anomaly
|
Living Off The Land, Ingress Tool Transfer, Compromised Windows Host
|
2026-05-13
|
|
Windows Process Accessing IronLanguages Repository On GitHub
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1059
T1105
|
Anomaly
|
Fake CAPTCHA Campaigns, Windows Post-Exploitation, Ingress Tool Transfer, Compromised Windows Host
|
2026-09-16
|
|
Detect Remote Access Software Usage File
|
Sysmon EventID 11
|
T1219
|
Anomaly
|
Command And Control, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Seashell Blizzard, Ransomware, Cactus Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Gozi Malware, Scattered Lapsus$ Hunters, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
File Download or Read to Pipe Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Sysmon for Linux EventID 1, Windows Event Log Security 4688
|
T1105
|
TTP
|
Log4Shell CVE-2021-44228, Linux Living Off The Land, NPM Supply Chain Compromise, Ingress Tool Transfer, Compromised Windows Host
|
2026-09-01
|
|
Windows Ngrok Reverse Proxy Usage
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy, CISA AA22-320A, CISA AA24-241A
|
2026-05-13
|
|
Windows Finger.exe Connecting to a Remote Host
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1071
|
TTP
|
Living Off The Land, Windows Post-Exploitation, Command And Control, Compromised Windows Host, Fake CAPTCHA Campaigns
|
2026-09-16
|
|
Windows Proxy Via Netsh
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Windows Potential Cloudflared Network Connection
|
Sysmon EventID 3
|
T1572
|
Hunting
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
Cisco Network Visibility Module Flow Data, CrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688
|
T1059.001
T1105
|
Anomaly
|
Microsoft WSUS CVE-2025-59287, Malicious PowerShell, Cisco Network Visibility Module Analytics, GhostRedirector IIS Module and Rungan Backdoor, SysAid On-Prem Software CVE-2023-47246 Vulnerability, StealC Stealer, NPM Supply Chain Compromise, Tuoni, Data Destruction, IcedID, XWorm, APT37 Rustonotto and FadeStealer, SolarWinds WHD RCE Post Exploitation, NetSupport RMM Tool Abuse, Ingress Tool Transfer, Winter Vivern, PHP-CGI RCE Attack on Japanese Organizations, Phemedrone Stealer, HAFNIUM Group, Hermetic Wiper
|
2026-07-14
|
|
Windows Outlook Macro Security Modified
|
Sysmon EventID 13
|
T1008
T1137
|
TTP
|
NotDoor Malware, Windows Registry Abuse
|
2026-05-13
|
|
Living Off The Land Detection
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Detect Certify Command Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
T1649
|
TTP
|
Windows Certificate Services, Ingress Tool Transfer, Compromised Windows Host
|
2026-05-13
|
|
Windows Potential Cloudflared Tunnel Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows SSH Proxy Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
T1572
|
Anomaly
|
Living Off The Land, Hellcat Ransomware, ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Linux Proxy Socks Curl
|
Sysmon for Linux EventID 1
|
T1090
T1095
|
TTP
|
Linux Living Off The Land, Ingress Tool Transfer
|
2026-06-04
|
|
Windows Cabinet File Extraction Via Expand
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
APT37 Rustonotto and FadeStealer, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Log4Shell CVE-2021-44228 Exploitation
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Log4Shell CVE-2021-44228, CISA AA22-320A
|
2026-05-13
|
|
Windows File Download Via CertUtil
|
Cisco Network Visibility Module Flow Data, CrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688
|
T1105
|
TTP
|
Living Off The Land, DarkSide Ransomware, Forest Blizzard, Ingress Tool Transfer, Flax Typhoon, Compromised Windows Host, Cisco Network Visibility Module Analytics, ProxyNotShell, CISA AA22-277A
|
2026-07-14
|
|
Linux Ngrok Reverse Proxy Usage
|
Sysmon for Linux EventID 1
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Socat Remote TCP Connection with Local Echo Disabled
|
Sysmon for Linux EventID 1, Osquery Results
|
T1059
T1572
|
Anomaly
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Detect Remote Access Software Usage FileInfo
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Command And Control, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Seashell Blizzard, Ransomware, Cactus Ransomware, Gozi Malware, Scattered Lapsus$ Hunters, Insider Threat
|
2026-05-13
|
|
Socat Network Listener Binding an Executable
|
Sysmon for Linux EventID 1, Osquery Results
|
T1059
T1572
|
TTP
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Windows Remote Access Software RMS Registry
|
Sysmon EventID 13
|
T1219
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows SQL Spawning CertUtil
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
Flax Typhoon, SQL Server Abuse, Storm-2460 CLFS Zero Day Exploitation
|
2026-05-13
|
|
Windows Credential Target Information Structure in Commandline
|
Sysmon EventID 1
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS, Suspicious DNS Traffic, Compromised Windows Host
|
2026-05-13
|
|
Potential Telegram API Request Via CommandLine
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1041
T1102.002
|
Anomaly
|
BlankGrabber Stealer, 0bj3ctivity Stealer, Hellcat Ransomware, XMRig, Water Gamayun
|
2026-05-13
|
|
Linux Ingress Tool Transfer with Curl
|
Sysmon for Linux EventID 1
|
T1105
|
Anomaly
|
NPM Supply Chain Compromise, XorDDos, Linux Living Off The Land, Ingress Tool Transfer
|
2026-05-13
|
|
Windows Curl Download to Suspicious Path
|
Cisco Network Visibility Module Flow Data, CrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688
|
T1105
|
TTP
|
Starland RAT Campaign, APT37 Rustonotto and FadeStealer, Compromised Windows Host, Cisco Network Visibility Module Analytics, Ingress Tool Transfer, GhostRedirector IIS Module and Rungan Backdoor, NPM Supply Chain Compromise, Black Basta Ransomware, China-Nexus Threat Activity, IcedID, Forest Blizzard, Salt Typhoon
|
2026-07-20
|
|
Windows TOR Client Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090.003
|
Anomaly
|
Command And Control, Windows Post-Exploitation, Compromised Windows Host, Data Exfiltration, Data Protection
|
2026-05-13
|
|
Suspicious Curl Network Connection
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Sysmon for Linux EventID 1, Windows Event Log Security 4688
|
T1105
|
TTP
|
Silver Sparrow, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, Linux Living Off The Land, Ingress Tool Transfer, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Ingress Tool Transfer Using Explorer
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
Windows Devtunnels Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows PowGoop Beacon Decoding
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
TOR Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Palo Alto Network Traffic
|
T1090.003
|
TTP
|
Command And Control, Cisco Secure Firewall Threat Defense Analytics, Interlock Ransomware, Ransomware, NOBELIUM Group, Prohibited Traffic Allowed or Protocol Mismatch
|
2026-05-13
|
|
HTTP Malware User Agent
|
Suricata
|
T1071.001
|
TTP
|
Meduza Stealer, Lokibot, Crypto Stealer, Suspicious User Agents, Lumma Stealer, RedLine Stealer
|
2026-05-13
|
|
HTTP RMM User Agent
|
Suricata
|
T1071.001
T1219
|
Anomaly
|
Remote Monitoring and Management Software, Suspicious User Agents
|
2026-05-13
|
|
SSL Certificates with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
HTTP PUA User Agent
|
Suricata
|
T1071.001
|
Anomaly
|
Local Privilege Escalation With KrbRelayUp, Cactus Ransomware, Suspicious User Agents, BlackSuit Ransomware
|
2026-05-13
|
|
Detect Large ICMP Traffic
|
Cisco Secure Access Firewall, Palo Alto Network Traffic
|
T1095
|
TTP
|
China-Nexus Threat Activity, Cisco Secure Access Analytics, Command And Control, Backdoor Pingpong
|
2026-05-13
|
|
Excessive DNS Failures
|
|
T1071.004
|
Anomaly
|
Command And Control, Suspicious DNS Traffic
|
2026-05-13
|
|
Cisco Secure Firewall - Remote Access Software Usage Traffic
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1219
|
Anomaly
|
Command And Control, Cisco Secure Firewall Threat Defense Analytics, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Ransomware, Scattered Lapsus$ Hunters, Insider Threat
|
2026-05-13
|
|
Detect Remote Access Software Usage DNS
|
Sysmon EventID 22
|
T1219
|
Anomaly
|
Command And Control, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Ransomware, Scattered Lapsus$ Hunters, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
HTTP C2 Framework User Agent
|
Suricata
|
T1071.001
|
TTP
|
Spearphishing Attachments, Malicious PowerShell, Meterpreter, BishopFox Sliver Adversary Emulation Framework, Suspicious User Agents, Tuoni, Cobalt Strike, Brute Ratel C4
|
2026-05-13
|
|
Ngrok Reverse Proxy on Network
|
Sysmon EventID 22
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy, CISA AA22-320A, CISA AA24-241A
|
2026-05-13
|
|
DNS Kerberos Coercion
|
Sysmon EventID 22, Suricata
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS, Suspicious DNS Traffic, Compromised Windows Host
|
2026-09-08
|
|
Detect Remote Access Software Usage Traffic
|
Palo Alto Network Traffic
|
T1219
|
Anomaly
|
Command And Control, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Ransomware, Scattered Lapsus$ Hunters, Insider Threat
|
2026-05-13
|
|
Detect Outbound SMB Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall
|
T1071.002
|
TTP
|
Hidden Cobra Malware, Cisco Secure Firewall Threat Defense Analytics, DHS Report TA18-074A, Cisco Secure Access Analytics, NOBELIUM Group
|
2026-05-13
|
|
LOLBAS With Network Traffic
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
TTP
|
Living Off The Land, Malicious Inno Setup Loader, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, NetSupport RMM Tool Abuse, Water Gamayun, GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns
|
2026-08-24
|