|
Windows Potential Cloudflared Network Connection
|
Sysmon EventID 3
|
T1572
|
Hunting
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows Level RMM PowerShell Script Installer
|
Powershell Script Block Logging 4104
|
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Remote Access Software RMS Registry
|
Sysmon EventID 13
|
T1219
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Kerberos Coercion via DNS
|
Windows Event Log Security 5136, Windows Event Log Security 4662, Windows Event Log Security 5137
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Compromised Windows Host, Suspicious DNS Traffic, Kerberos Coercion with DNS
|
2026-05-13
|
|
Windows DNS Query Request To TinyUrl
|
Sysmon EventID 22
|
T1105
|
Anomaly
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Windows Proxy Via Netsh
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Windows RMM Tool Execution
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Remote Monitoring and Management Software, NetSupport RMM Tool Abuse, Suspicious User Agents
|
2026-05-13
|
|
Curl Execution with Percent Encoded URL
|
Sysmon EventID 1, Windows Event Log Security 4688, Sysmon for Linux EventID 1, CrowdStrike ProcessRollup2
|
T1027
T1105
|
Anomaly
|
Ingress Tool Transfer, Compromised Windows Host, Living Off The Land
|
2026-05-13
|
|
Windows DLL Module Loaded in Temp Dir
|
Sysmon EventID 7
|
T1105
|
Hunting
|
SolarWinds WHD RCE Post Exploitation, Lokibot, Interlock Rat
|
2026-05-13
|
|
Windows TOR Client Execution
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1090.003
|
Anomaly
|
Command And Control, Data Protection, Windows Post-Exploitation, Data Exfiltration, Compromised Windows Host
|
2026-05-13
|
|
Cisco NVM - Outbound Connection to Suspicious Port
|
Cisco Network Visibility Module Flow Data
|
T1571
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Detect Remote Access Software Usage Registry
|
Sysmon EventID 13
|
T1219
|
Anomaly
|
Command And Control, Cactus Ransomware, Seashell Blizzard, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, CISA AA24-241A, Gozi Malware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
BITSAdmin Download File
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
T1197
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Ingress Tool Transfer, DarkSide Ransomware, BITS Jobs, Scattered Spider, Gozi Malware, Hellcat Ransomware, Living Off The Land, APT37 Rustonotto and FadeStealer, Flax Typhoon
|
2026-05-13
|
|
Windows SSH Proxy Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
T1572
|
Anomaly
|
Hellcat Ransomware, ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Living Off The Land
|
2026-05-13
|
|
Windows Devtunnels Execution
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
LOLBAS With Network Traffic
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
TTP
|
Malicious Inno Setup Loader, GhostRedirector IIS Module and Rungan Backdoor, NetSupport RMM Tool Abuse, Fake CAPTCHA Campaigns, Hellcat Ransomware, Water Gamayun, Living Off The Land, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Cabinet File Extraction Via Expand
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
NetSupport RMM Tool Abuse, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Potential Cloudflared Tunnel Execution
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Mail Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
AgentTesla
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Persistence, Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Process Execution From RDP Share
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
Linux Ingress Tool Transfer Hunting
|
Sysmon for Linux EventID 1
|
T1105
|
Hunting
|
Ingress Tool Transfer, Axios Supply Chain Post Compromise, NPM Supply Chain Compromise, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows Curl Upload to Remote Destination
|
Cisco Network Visibility Module Flow Data, Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Ingress Tool Transfer, Cisco Network Visibility Module Analytics, Axios Supply Chain Post Compromise, PromptLock, NPM Supply Chain Compromise, Microsoft WSUS CVE-2025-59287, Compromised Windows Host
|
2026-07-14
|
|
Cisco NVM - Suspicious File Download via Headless Browser
|
Cisco Network Visibility Module Flow Data
|
T1059
T1105
|
TTP
|
Cisco Network Visibility Module Analytics, BlankGrabber Stealer
|
2026-07-14
|
|
File Download or Read to Pipe Execution
|
Sysmon EventID 1, Windows Event Log Security 4688, Sysmon for Linux EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Ingress Tool Transfer, Log4Shell CVE-2021-44228, NPM Supply Chain Compromise, Linux Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Windows Suspicious Defender Update Activity in INetCache
|
Sysmon EventID 23, Sysmon EventID 11
|
T1068
T1105
|
Anomaly
|
BlueHammer, Windows Persistence Techniques
|
2026-07-20
|
|
Windows Outlook Macro Security Modified
|
Sysmon EventID 13
|
T1008
T1137
|
TTP
|
NotDoor Malware, Windows Registry Abuse
|
2026-05-13
|
|
Windows Ldifde Directory Object Behavior
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1069.002
T1105
|
TTP
|
Volt Typhoon
|
2026-05-13
|
|
Potential Telegram API Request Via CommandLine
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1041
T1102.002
|
Anomaly
|
0bj3ctivity Stealer, BlankGrabber Stealer, Hellcat Ransomware, Water Gamayun, XMRig
|
2026-05-13
|
|
WinRAR Spawning Shell Application
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
WinRAR Spoofing Attack CVE-2023-38831, Compromised Windows Host
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
Malicious PowerShell, MoonPeak, Medusa Ransomware, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Download Files Using Telegram
|
Sysmon EventID 15
|
T1105
|
TTP
|
Crypto Stealer, 0bj3ctivity Stealer, Snake Keylogger, Phemedrone Stealer, Water Gamayun, XMRig
|
2026-05-13
|
|
Log4Shell CVE-2021-44228 Exploitation
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Log4Shell CVE-2021-44228, CISA AA22-320A
|
2026-05-13
|
|
Windows File Download Via CertUtil
|
Cisco Network Visibility Module Flow Data, Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Ingress Tool Transfer, DarkSide Ransomware, Cisco Network Visibility Module Analytics, Forest Blizzard, ProxyNotShell, Living Off The Land, CISA AA22-277A, Compromised Windows Host, Flax Typhoon
|
2026-07-14
|
|
Windows Curl Download to Suspicious Path
|
Cisco Network Visibility Module Flow Data, Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Cisco Network Visibility Module Analytics, Ingress Tool Transfer, Forest Blizzard, Salt Typhoon, China-Nexus Threat Activity, Black Basta Ransomware, IcedID, NPM Supply Chain Compromise, Starland RAT Campaign, Compromised Windows Host, APT37 Rustonotto and FadeStealer
|
2026-07-20
|
|
Detect Remote Access Software Usage File
|
Sysmon EventID 11
|
T1219
|
Anomaly
|
Command And Control, Cactus Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Seashell Blizzard, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, CISA AA24-241A, Gozi Malware, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
Linux Proxy Socks Curl
|
Sysmon for Linux EventID 1
|
T1090
T1095
|
TTP
|
Linux Living Off The Land, Ingress Tool Transfer
|
2026-06-04
|
|
Windows File Transfer Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
Phantom Stealer, Hellcat Ransomware, Snake Keylogger, AgentTesla
|
2026-06-25
|
|
Windows Application Layer Protocol RMS Radmin Tool Namedpipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Devtunnels Image Loaded
|
Sysmon EventID 7
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Detect Remote Access Software Usage Process
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1219
|
Anomaly
|
Command And Control, Cactus Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Seashell Blizzard, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, CISA AA24-241A, Storm-0501 Ransomware, Gozi Malware, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
Windows Ngrok Reverse Proxy Usage
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1090
T1102
T1572
|
Anomaly
|
CISA AA22-320A, CISA AA24-241A, Reverse Network Proxy
|
2026-05-13
|
|
Linux Ngrok Reverse Proxy Usage
|
Sysmon for Linux EventID 1
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows App Layer Protocol Wermgr Connect To NamedPipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Malicious PowerShell, Hellcat Ransomware
|
2026-05-13
|
|
Windows AI Platform DNS Query
|
Sysmon EventID 22
|
T1071.004
|
Anomaly
|
PromptFlux, LAMEHUG, SesameOp
|
2026-05-13
|
|
Windows Ingress Tool Transfer Using Explorer
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
Windows Proxy Via Registry
|
Sysmon EventID 13
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Detect Remote Access Software Usage FileInfo
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Command And Control, Cactus Ransomware, Seashell Blizzard, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, Gozi Malware, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Linux Post-Exploitation, VoidLink Cloud-Native Linux Malware, Linux Rootkit, Linux Living Off The Land, Compromised Linux Host, Linux Privilege Escalation
|
2026-05-13
|
|
Windows SoftEther VPN Masquerading as Legitimate Binary
|
Sysmon EventID 1
|
T1036
T1572
|
TTP
|
Linux Persistence Techniques, Linux Privilege Escalation, Flax Typhoon
|
2026-05-13
|
|
Cisco Isovalent - Curl Execution With Insecure Flags
|
Cisco Isovalent Process Exec
|
T1105
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Detect Certify Command Line Arguments
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
T1649
|
TTP
|
Ingress Tool Transfer, Compromised Windows Host, Windows Certificate Services
|
2026-05-13
|
|
Suspicious Curl Network Connection
|
Sysmon EventID 1, Windows Event Log Security 4688, Sysmon for Linux EventID 1, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Ingress Tool Transfer, Hellcat Ransomware, Linux Living Off The Land, Silver Sparrow, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
Cisco Network Visibility Module Flow Data, Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1059.001
T1105
|
Anomaly
|
Data Destruction, Malicious PowerShell, APT37 Rustonotto and FadeStealer, GhostRedirector IIS Module and Rungan Backdoor, Ingress Tool Transfer, XWorm, HAFNIUM Group, Hermetic Wiper, Phemedrone Stealer, SysAid On-Prem Software CVE-2023-47246 Vulnerability, StealC Stealer, PHP-CGI RCE Attack on Japanese Organizations, Cisco Network Visibility Module Analytics, NetSupport RMM Tool Abuse, SolarWinds WHD RCE Post Exploitation, IcedID, NPM Supply Chain Compromise, Microsoft WSUS CVE-2025-59287, Tuoni, Winter Vivern
|
2026-07-14
|
|
Windows PowGoop Beacon Decoding
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows App Layer Protocol Qakbot NamedPipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows SQL Spawning CertUtil
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1105
|
TTP
|
Storm-2460 CLFS Zero Day Exploitation, Flax Typhoon, SQL Server Abuse
|
2026-05-13
|
|
Windows Short Lived DNS Record
|
Windows Event Log Security 5136, Windows Event Log Security 5137
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Compromised Windows Host, Suspicious DNS Traffic, Kerberos Coercion with DNS
|
2026-05-13
|
|
Windows Non-System Process Querying Definition Update
|
Sysmon EventID 22
|
T1068
T1071.001
|
Anomaly
|
Windows Privilege Escalation, BlueHammer, RedSun
|
2026-04-27
|
|
Linux Ingress Tool Transfer with Curl
|
Sysmon for Linux EventID 1
|
T1105
|
Anomaly
|
Linux Living Off The Land, Ingress Tool Transfer, NPM Supply Chain Compromise, XorDDos
|
2026-05-13
|
|
Windows Protocol Tunneling with Plink
|
Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
|
T1021.004
T1572
|
TTP
|
CISA AA22-257A
|
2026-05-13
|
|
Windows Visual Basic Commandline Compiler DNSQuery
|
Sysmon EventID 22
|
T1071.004
|
TTP
|
Lokibot
|
2026-05-13
|
|
Living Off The Land Detection
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Hellcat Ransomware, Living Off The Land
|
2026-05-13
|
|
Linux Curl Upload File
|
Sysmon for Linux EventID 1, Cisco Isovalent Process Exec
|
T1105
|
TTP
|
Linux Living Off The Land, Data Exfiltration, Ingress Tool Transfer, NPM Supply Chain Compromise
|
2026-05-13
|
|
Windows Remote Access Software BRC4 Loaded Dll
|
Sysmon EventID 7
|
T1003
T1219
|
Anomaly
|
Brute Ratel C4
|
2026-05-13
|
|
Cisco NVM - Webserver Download From File Sharing Website
|
Cisco Network Visibility Module Flow Data
|
T1105
T1190
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Credential Target Information Structure in Commandline
|
Sysmon EventID 1
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Compromised Windows Host, Suspicious DNS Traffic, Kerberos Coercion with DNS
|
2026-05-13
|
|
Juniper Networks Remote Code Execution Exploit Detection
|
Suricata
|
T1059
T1105
T1190
|
TTP
|
Juniper JunOS Remote Code Execution
|
2026-05-13
|
|
HTTP Duplicated Header
|
Suricata
|
T1071.001
T1190
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
Detect Remote Access Software Usage URL
|
Palo Alto Network Threat
|
T1219
|
Anomaly
|
Command And Control, Ransomware, Scattered Lapsus$ Hunters, CISA AA24-241A, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
HTTP Request to Reserved Name on IIS Server
|
Suricata
|
T1071.001
T1190
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Rapid POST with Mixed Status Codes
|
Nginx Access
|
T1071.001
T1190
T1595
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Scripting Tool User Agent
|
Nginx Access
|
T1071.001
|
Anomaly
|
HTTP Request Smuggling, Suspicious User Agents
|
2026-06-15
|
|
HTTP Possible Request Smuggling
|
Suricata
|
T1071.001
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
Cisco IOS XE Tunnel Interface Configuration
|
Cisco IOS Logs
|
T1090
T1572
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
Ollama Abnormal Network Connectivity
|
Ollama Server
|
T1571
|
Anomaly
|
Suspicious Ollama Activities
|
2026-05-13
|
|
Microsoft Intune Device Health Scripts
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Microsoft Intune Mobile Apps
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Okta Non-Standard VPN Usage
|
Okta
|
T1078
T1090
T1572
|
TTP
|
Suspicious Okta Activity, Remote Employment Fraud
|
2026-05-13
|
|
Windows Multi hop Proxy TOR Website Query
|
Sysmon EventID 22
|
T1071.003
|
Anomaly
|
Interlock Ransomware, AgentTesla
|
2026-05-13
|
|
HTTP RMM User Agent
|
Suricata
|
T1071.001
T1219
|
Anomaly
|
Remote Monitoring and Management Software, Suspicious User Agents
|
2026-05-13
|
|
HTTP Malware User Agent
|
Suricata
|
T1071.001
|
TTP
|
Crypto Stealer, RedLine Stealer, Lokibot, Suspicious User Agents, Lumma Stealer, Meduza Stealer
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
HTTP C2 Framework User Agent
|
Suricata
|
T1071.001
|
TTP
|
Meterpreter, Suspicious User Agents, Tuoni, Brute Ratel C4, Cobalt Strike, Malicious PowerShell, Spearphishing Attachments, BishopFox Sliver Adversary Emulation Framework
|
2026-05-13
|
|
Detect Remote Access Software Usage DNS
|
Sysmon EventID 22
|
T1219
|
Anomaly
|
Command And Control, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, CISA AA24-241A, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1027
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Detect Large ICMP Traffic
|
Palo Alto Network Traffic, Cisco Secure Access Firewall
|
T1095
|
TTP
|
Command And Control, China-Nexus Threat Activity, Backdoor Pingpong, Cisco Secure Access Analytics
|
2026-05-13
|
|
HTTP PUA User Agent
|
Suricata
|
T1071.001
|
Anomaly
|
Suspicious User Agents, Local Privilege Escalation With KrbRelayUp, Cactus Ransomware, BlackSuit Ransomware
|
2026-05-13
|
|
Cisco Secure Firewall - Intrusion Events by Threat Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
ArcaneDoor, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
TOR Traffic
|
Palo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection Event
|
T1090.003
|
TTP
|
Command And Control, Ransomware, Prohibited Traffic Allowed or Protocol Mismatch, Cisco Secure Firewall Threat Defense Analytics, Interlock Ransomware, NOBELIUM Group
|
2026-05-13
|
|
Zeek x509 Certificate with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
SSL Certificates with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
Cisco Secure Firewall - Remote Access Software Usage Traffic
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1219
|
Anomaly
|
Command And Control, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, Cisco Secure Firewall Threat Defense Analytics, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
Cisco Secure Firewall - Malware File Downloaded
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows DNS Query Request by Telegram Bot API
|
Sysmon EventID 22
|
T1071.004
T1102.002
|
Anomaly
|
Phantom Stealer, Crypto Stealer, 0bj3ctivity Stealer, BlankGrabber Stealer, VIP Keylogger, Starland RAT Campaign
|
2026-07-20
|
|
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1573.002
T1587.002
T1588.004
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Detect Remote Access Software Usage Traffic
|
Palo Alto Network Traffic
|
T1219
|
Anomaly
|
Command And Control, Ransomware, Scattered Lapsus$ Hunters, Scattered Spider, Interlock Ransomware, Remote Monitoring and Management Software, Insider Threat
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Download Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High EVE Threat Confidence
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1041
T1071.001
T1105
T1573.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Repeated Malware Downloads
|
Cisco Secure Firewall Threat Defense File Event
|
T1027
T1105
|
Anomaly
|
Hellcat Ransomware, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows Abused Web Services
|
Sysmon EventID 22
|
T1102
|
Anomaly
|
Malicious Inno Setup Loader, CISA AA24-241A, NjRAT, BlankGrabber Stealer
|
2026-05-13
|
|
Ngrok Reverse Proxy on Network
|
Sysmon EventID 22
|
T1090
T1102
T1572
|
Anomaly
|
CISA AA22-320A, CISA AA24-241A, Reverse Network Proxy
|
2026-05-13
|
|
Cisco Secure Firewall - File Download Over Uncommon Port
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Detect Outbound SMB Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall
|
T1071.002
|
TTP
|
DHS Report TA18-074A, Cisco Secure Access Analytics, Cisco Secure Firewall Threat Defense Analytics, NOBELIUM Group, Hidden Cobra Malware
|
2026-05-13
|
|
DNS Kerberos Coercion
|
Sysmon EventID 22, Suricata
|
T1071.004
T1187
T1557.001
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Compromised Windows Host, Suspicious DNS Traffic, Kerberos Coercion with DNS
|
2026-05-13
|
|
Cisco Secure Firewall - Connection to File Sharing Domain
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1090.002
T1105
T1567.002
T1588.002
|
Anomaly
|
Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Excessive DNS Failures
|
|
T1071.004
|
Anomaly
|
Command And Control, Suspicious DNS Traffic
|
2026-05-13
|
|
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1071
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco SA - Access to Anonymizer Services
|
Cisco Secure Access DNS
|
T1090.003
|
Anomaly
|
Cisco Secure Access Analytics
|
2026-06-09
|