|
Juniper Networks Remote Code Execution Exploit Detection
|
Suricata
|
T1059
T1105
T1190
|
TTP
|
Juniper JunOS Remote Code Execution
|
2026-05-13
|
|
HTTP Duplicated Header
|
Suricata
|
T1071.001
T1190
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Rapid POST with Mixed Status Codes
|
Nginx Access
|
T1071.001
T1190
T1595
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Possible Request Smuggling
|
Suricata
|
T1071.001
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
Okta Non-Standard VPN Usage
|
Okta
|
T1078
T1090
T1572
|
TTP
|
Suspicious Okta Activity, Remote Employment Fraud
|
2026-05-13
|
|
Microsoft Intune Mobile Apps
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Microsoft Intune Device Health Scripts
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Windows Application Layer Protocol RMS Radmin Tool Namedpipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Linux Privilege Escalation, VoidLink Cloud-Native Linux Malware, Linux Rootkit, Linux Living Off The Land, Compromised Linux Host, Linux Post-Exploitation
|
2026-05-13
|
|
Windows Non-System Process Querying Definition Update
|
Sysmon EventID 22
|
T1068
T1071.001
|
Anomaly
|
RedSun, BlueHammer, Windows Privilege Escalation
|
2026-04-27
|
|
Windows Devtunnels Image Loaded
|
Sysmon EventID 7
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows AI Platform DNS Query
|
Sysmon EventID 22
|
T1071.004
|
Anomaly
|
LAMEHUG, SesameOp, PromptFlux
|
2026-05-13
|
|
Cisco NVM - Webserver Download From File Sharing Website
|
Cisco Network Visibility Module Flow Data
|
T1105
T1190
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Cisco NVM - Suspicious File Download via Headless Browser
|
Cisco Network Visibility Module Flow Data
|
T1059
T1105
|
TTP
|
BlankGrabber Stealer, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Powershell Commands from DNS TXT
|
Powershell Script Block Logging 4104
|
T1059.001
T1071.004
|
Anomaly
|
Command And Control, Suspicious DNS Traffic, Malicious PowerShell
|
2026-07-30
|
|
Windows Remote Access Software BRC4 Loaded Dll
|
Sysmon EventID 7
|
T1003
T1219
|
Anomaly
|
Brute Ratel C4
|
2026-05-13
|
|
Windows Suspicious Defender Update Activity in INetCache
|
Sysmon EventID 23, Sysmon EventID 11
|
T1068
T1105
|
Anomaly
|
BlueHammer, Windows Persistence Techniques
|
2026-07-20
|
|
Windows App Layer Protocol Qakbot NamedPipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows File Transfer Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
AgentTesla, Phantom Stealer, Snake Keylogger, Hellcat Ransomware
|
2026-06-25
|
|
Windows Level RMM PowerShell Script Installer
|
Powershell Script Block Logging 4104
|
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Download Files Using Telegram
|
Sysmon EventID 15
|
T1105
|
TTP
|
XMRig, 0bj3ctivity Stealer, Phemedrone Stealer, Snake Keylogger, Water Gamayun, Crypto Stealer
|
2026-05-13
|
|
Windows Kerberos Coercion via DNS
|
Windows Event Log Security 5136, Windows Event Log Security 4662, Windows Event Log Security 5137
|
T1071.004
T1187
T1557.001
|
TTP
|
Kerberos Coercion with DNS, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Suspicious DNS Traffic
|
2026-05-13
|
|
Windows Mail Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
AgentTesla
|
2026-05-13
|
|
Cisco NVM - Outbound Connection to Suspicious Port
|
Cisco Network Visibility Module Flow Data
|
T1571
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Hellcat Ransomware, Malicious PowerShell
|
2026-05-13
|
|
Windows Visual Basic Commandline Compiler DNSQuery
|
Sysmon EventID 22
|
T1071.004
|
TTP
|
Lokibot
|
2026-05-13
|
|
Windows DNS Query Request To TinyUrl
|
Sysmon EventID 22
|
T1105
|
Anomaly
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Windows Short Lived DNS Record
|
Windows Event Log Security 5136, Windows Event Log Security 5137
|
T1071.004
T1187
T1557.001
|
TTP
|
Kerberos Coercion with DNS, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Suspicious DNS Traffic
|
2026-05-13
|
|
Windows DLL Module Loaded in Temp Dir
|
Sysmon EventID 7
|
T1105
|
Hunting
|
Lokibot, SolarWinds WHD RCE Post Exploitation, Interlock Rat
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
Medusa Ransomware, PHP-CGI RCE Attack on Japanese Organizations, MoonPeak, Malicious PowerShell
|
2026-05-13
|
|
Windows App Layer Protocol Wermgr Connect To NamedPipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
Anomaly
|
RoguePlanet, Qakbot, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-08-18
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows SoftEther VPN Masquerading as Legitimate Binary
|
Sysmon EventID 1
|
T1036
T1572
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Flax Typhoon
|
2026-05-13
|
|
Windows RMM Tool Execution
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Suspicious User Agents, Remote Monitoring and Management Software, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Cisco Isovalent - Curl Execution With Insecure Flags
|
Cisco Isovalent Process Exec
|
T1105
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Azure Active Directory Account Takeover
|
2026-05-13
|
|
Windows Abused Web Services
|
Sysmon EventID 22
|
T1102
|
Anomaly
|
NjRAT, CISA AA24-241A, Malicious Inno Setup Loader, BlankGrabber Stealer
|
2026-05-13
|
|
Zeek x509 Certificate with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1573.002
T1587.002
T1588.004
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco SA - Access to Anonymizer Services
|
Cisco Secure Access DNS
|
T1090.003
|
Anomaly
|
Cisco Secure Access Analytics
|
2026-06-09
|
|
Cisco Secure Firewall - Repeated Malware Downloads
|
Cisco Secure Firewall Threat Defense File Event
|
T1027
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics, Hellcat Ransomware
|
2026-05-13
|
|
Windows Multi hop Proxy TOR Website Query
|
Sysmon EventID 22
|
T1071.003
|
Anomaly
|
AgentTesla, Interlock Ransomware
|
2026-05-13
|
|
Cisco Secure Firewall - High EVE Threat Confidence
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1041
T1071.001
T1105
T1573.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1027
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Malware File Downloaded
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Intrusion Events by Threat Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
ArcaneDoor, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Download Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows DNS Query Request by Telegram Bot API
|
Sysmon EventID 22
|
T1071.004
T1102.002
|
Anomaly
|
0bj3ctivity Stealer, Starland RAT Campaign, Phantom Stealer, VIP Keylogger, Crypto Stealer, BlankGrabber Stealer
|
2026-07-20
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1071
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Connection to File Sharing Domain
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1090.002
T1105
T1567.002
T1588.002
|
Anomaly
|
Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - File Download Over Uncommon Port
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco IOS XE Tunnel Interface Configuration
|
Cisco IOS Logs
|
T1090
T1572
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
Ollama Abnormal Network Connectivity
|
Ollama Server
|
T1571
|
Anomaly
|
Suspicious Ollama Activities
|
2026-05-13
|
|
HTTP Scripting Tool User Agent
|
Nginx Access
|
T1071.001
|
Anomaly
|
Suspicious User Agents, HTTP Request Smuggling
|
2026-06-15
|
|
HTTP Request to Reserved Name on IIS Server
|
Suricata
|
T1071.001
T1190
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
Detect Remote Access Software Usage URL
|
Palo Alto Network Threat
|
T1219
|
Anomaly
|
Interlock Ransomware, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, CISA AA24-241A, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
Windows Protocol Tunneling with Plink
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.004
T1572
|
TTP
|
CISA AA22-257A
|
2026-05-13
|
|
Detect Remote Access Software Usage Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1219
|
Anomaly
|
Scattered Spider, Gozi Malware, Storm-0501 Ransomware, Cactus Ransomware, Interlock Ransomware, Scattered Lapsus$ Hunters, GhostRedirector IIS Module and Rungan Backdoor, Remote Monitoring and Management Software, Seashell Blizzard, CISA AA24-241A, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
LOLBAS Rare Network Connection
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
Anomaly
|
Hellcat Ransomware, Fake CAPTCHA Campaigns, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, Malicious Inno Setup Loader, Living Off The Land, Water Gamayun, NetSupport RMM Tool Abuse
|
2026-08-24
|
|
Detect Remote Access Software Usage Registry
|
Sysmon EventID 13
|
T1219
|
Anomaly
|
Scattered Spider, Gozi Malware, Cactus Ransomware, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, Seashell Blizzard, CISA AA24-241A, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
Windows Ldifde Directory Object Behavior
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1069.002
T1105
|
TTP
|
Volt Typhoon
|
2026-05-13
|
|
LOLBAS Network Connection On Uncommon Port
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
Anomaly
|
Hellcat Ransomware, Fake CAPTCHA Campaigns, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, Malicious Inno Setup Loader, Living Off The Land, Water Gamayun, NetSupport RMM Tool Abuse
|
2026-08-24
|
|
Windows Process Execution From RDP Share
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
BITSAdmin Download File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
T1197
|
TTP
|
Scattered Spider, Gozi Malware, Ingress Tool Transfer, BITS Jobs, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Flax Typhoon, DarkSide Ransomware, APT37 Rustonotto and FadeStealer, Living Off The Land
|
2026-05-13
|
|
Windows Curl Upload to Remote Destination
|
Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 1, Cisco Network Visibility Module Flow Data
|
T1105
|
TTP
|
Ingress Tool Transfer, Cisco Network Visibility Module Analytics, NPM Supply Chain Compromise, PromptLock, Axios Supply Chain Post Compromise, Compromised Windows Host, Microsoft WSUS CVE-2025-59287
|
2026-07-14
|
|
WinRAR Spawning Shell Application
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Compromised Windows Host, WinRAR Spoofing Attack CVE-2023-38831
|
2026-05-13
|
|
Linux Curl Upload File
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1105
|
TTP
|
Data Exfiltration, Ingress Tool Transfer, NPM Supply Chain Compromise, Linux Living Off The Land
|
2026-05-13
|
|
Linux Ingress Tool Transfer Hunting
|
Sysmon for Linux EventID 1
|
T1105
|
Hunting
|
Ingress Tool Transfer, NPM Supply Chain Compromise, Axios Supply Chain Post Compromise, Linux Living Off The Land, XorDDos
|
2026-05-13
|
|
Windows Proxy Via Registry
|
Sysmon EventID 13
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Curl Execution with Percent Encoded URL
|
Windows Event Log Security 4688, Sysmon EventID 1, Sysmon for Linux EventID 1, CrowdStrike ProcessRollup2
|
T1027
T1105
|
Anomaly
|
Compromised Windows Host, Ingress Tool Transfer, Living Off The Land
|
2026-05-13
|
|
Detect Remote Access Software Usage File
|
Sysmon EventID 11
|
T1219
|
Anomaly
|
Scattered Spider, Gozi Malware, Cactus Ransomware, Interlock Ransomware, Scattered Lapsus$ Hunters, GhostRedirector IIS Module and Rungan Backdoor, Remote Monitoring and Management Software, Seashell Blizzard, CISA AA24-241A, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
File Download or Read to Pipe Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, Sysmon for Linux EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Ingress Tool Transfer, NPM Supply Chain Compromise, Log4Shell CVE-2021-44228, Compromised Windows Host, Linux Living Off The Land
|
2026-09-01
|
|
Windows Ngrok Reverse Proxy Usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy, CISA AA24-241A, CISA AA22-320A
|
2026-05-13
|
|
Windows Proxy Via Netsh
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Windows Potential Cloudflared Network Connection
|
Sysmon EventID 3
|
T1572
|
Hunting
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 1, Cisco Network Visibility Module Flow Data
|
T1059.001
T1105
|
Anomaly
|
Cisco Network Visibility Module Analytics, Tuoni, HAFNIUM Group, NPM Supply Chain Compromise, IcedID, Data Destruction, Phemedrone Stealer, Winter Vivern, Hermetic Wiper, Ingress Tool Transfer, Malicious PowerShell, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, XWorm, StealC Stealer, PHP-CGI RCE Attack on Japanese Organizations, Microsoft WSUS CVE-2025-59287, SysAid On-Prem Software CVE-2023-47246 Vulnerability, SolarWinds WHD RCE Post Exploitation, NetSupport RMM Tool Abuse
|
2026-07-14
|
|
Windows Outlook Macro Security Modified
|
Sysmon EventID 13
|
T1008
T1137
|
TTP
|
Windows Registry Abuse, NotDoor Malware
|
2026-05-13
|
|
Living Off The Land Detection
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Detect Certify Command Line Arguments
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
T1649
|
TTP
|
Compromised Windows Host, Ingress Tool Transfer, Windows Certificate Services
|
2026-05-13
|
|
Windows Potential Cloudflared Tunnel Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows SSH Proxy Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
T1572
|
Anomaly
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Linux Proxy Socks Curl
|
Sysmon for Linux EventID 1
|
T1090
T1095
|
TTP
|
Ingress Tool Transfer, Linux Living Off The Land
|
2026-06-04
|
|
Windows Cabinet File Extraction Via Expand
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
APT37 Rustonotto and FadeStealer, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Log4Shell CVE-2021-44228 Exploitation
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
CISA AA22-320A, Log4Shell CVE-2021-44228
|
2026-05-13
|
|
Windows File Download Via CertUtil
|
Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 1, Cisco Network Visibility Module Flow Data
|
T1105
|
TTP
|
ProxyNotShell, Ingress Tool Transfer, Cisco Network Visibility Module Analytics, Flax Typhoon, DarkSide Ransomware, Compromised Windows Host, CISA AA22-277A, Living Off The Land, Forest Blizzard
|
2026-07-14
|
|
Linux Ngrok Reverse Proxy Usage
|
Sysmon for Linux EventID 1
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Socat Remote TCP Connection with Local Echo Disabled
|
Osquery Results, Sysmon for Linux EventID 1
|
T1059
T1572
|
Anomaly
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Detect Remote Access Software Usage FileInfo
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Scattered Spider, Gozi Malware, Cactus Ransomware, Interlock Ransomware, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, Seashell Blizzard, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
Socat Network Listener Binding an Executable
|
Osquery Results, Sysmon for Linux EventID 1
|
T1059
T1572
|
TTP
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Windows Remote Access Software RMS Registry
|
Sysmon EventID 13
|
T1219
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows SQL Spawning CertUtil
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Storm-2460 CLFS Zero Day Exploitation, Flax Typhoon, SQL Server Abuse
|
2026-05-13
|
|
Windows Credential Target Information Structure in Commandline
|
Sysmon EventID 1
|
T1071.004
T1187
T1557.001
|
TTP
|
Kerberos Coercion with DNS, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Suspicious DNS Traffic
|
2026-05-13
|
|
Potential Telegram API Request Via CommandLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1041
T1102.002
|
Anomaly
|
XMRig, Hellcat Ransomware, 0bj3ctivity Stealer, Water Gamayun, BlankGrabber Stealer
|
2026-05-13
|
|
Linux Ingress Tool Transfer with Curl
|
Sysmon for Linux EventID 1
|
T1105
|
Anomaly
|
XorDDos, Ingress Tool Transfer, NPM Supply Chain Compromise, Linux Living Off The Land
|
2026-05-13
|
|
Windows Curl Download to Suspicious Path
|
Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 1, Cisco Network Visibility Module Flow Data
|
T1105
|
TTP
|
Salt Typhoon, Ingress Tool Transfer, Cisco Network Visibility Module Analytics, NPM Supply Chain Compromise, IcedID, Black Basta Ransomware, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, Starland RAT Campaign, Compromised Windows Host, China-Nexus Threat Activity, Forest Blizzard
|
2026-07-20
|
|
Windows TOR Client Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090.003
|
Anomaly
|
Data Exfiltration, Windows Post-Exploitation, Compromised Windows Host, Data Protection, Command And Control
|
2026-05-13
|
|
Suspicious Curl Network Connection
|
Windows Event Log Security 4688, Sysmon EventID 1, Sysmon for Linux EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Ingress Tool Transfer, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, Silver Sparrow, Linux Living Off The Land
|
2026-05-13
|
|
Windows Ingress Tool Transfer Using Explorer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
Windows Devtunnels Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows PowGoop Beacon Decoding
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
TOR Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Palo Alto Network Traffic
|
T1090.003
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics, Interlock Ransomware, NOBELIUM Group, Ransomware, Prohibited Traffic Allowed or Protocol Mismatch, Command And Control
|
2026-05-13
|
|
HTTP Malware User Agent
|
Suricata
|
T1071.001
|
TTP
|
Meduza Stealer, Lokibot, Suspicious User Agents, Lumma Stealer, RedLine Stealer, Crypto Stealer
|
2026-05-13
|
|
HTTP RMM User Agent
|
Suricata
|
T1071.001
T1219
|
Anomaly
|
Suspicious User Agents, Remote Monitoring and Management Software
|
2026-05-13
|
|
SSL Certificates with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
HTTP PUA User Agent
|
Suricata
|
T1071.001
|
Anomaly
|
BlackSuit Ransomware, Local Privilege Escalation With KrbRelayUp, Cactus Ransomware, Suspicious User Agents
|
2026-05-13
|
|
Detect Large ICMP Traffic
|
Palo Alto Network Traffic, Cisco Secure Access Firewall
|
T1095
|
TTP
|
Backdoor Pingpong, China-Nexus Threat Activity, Command And Control, Cisco Secure Access Analytics
|
2026-05-13
|
|
Excessive DNS Failures
|
|
T1071.004
|
Anomaly
|
Command And Control, Suspicious DNS Traffic
|
2026-05-13
|
|
Cisco Secure Firewall - Remote Access Software Usage Traffic
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1219
|
Anomaly
|
Scattered Spider, Cisco Secure Firewall Threat Defense Analytics, Interlock Ransomware, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
Detect Remote Access Software Usage DNS
|
Sysmon EventID 22
|
T1219
|
Anomaly
|
Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, CISA AA24-241A, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
HTTP C2 Framework User Agent
|
Suricata
|
T1071.001
|
TTP
|
Malicious PowerShell, Tuoni, Spearphishing Attachments, Brute Ratel C4, Meterpreter, Suspicious User Agents, BishopFox Sliver Adversary Emulation Framework, Cobalt Strike
|
2026-05-13
|
|
Ngrok Reverse Proxy on Network
|
Sysmon EventID 22
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy, CISA AA24-241A, CISA AA22-320A
|
2026-05-13
|
|
DNS Kerberos Coercion
|
Suricata, Sysmon EventID 22
|
T1071.004
T1187
T1557.001
|
TTP
|
Kerberos Coercion with DNS, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Suspicious DNS Traffic
|
2026-05-13
|
|
Detect Remote Access Software Usage Traffic
|
Palo Alto Network Traffic
|
T1219
|
Anomaly
|
Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Remote Monitoring and Management Software, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
Detect Outbound SMB Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall
|
T1071.002
|
TTP
|
Hidden Cobra Malware, Cisco Secure Firewall Threat Defense Analytics, NOBELIUM Group, Cisco Secure Access Analytics, DHS Report TA18-074A
|
2026-05-13
|
|
LOLBAS With Network Traffic
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
TTP
|
Hellcat Ransomware, Fake CAPTCHA Campaigns, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, Malicious Inno Setup Loader, Living Off The Land, Water Gamayun, NetSupport RMM Tool Abuse
|
2026-08-24
|