|
Windows Potential Cloudflared Network Connection
|
Sysmon EventID 3
|
T1572
|
Hunting
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows Level RMM PowerShell Script Installer
|
Powershell Script Block Logging 4104
|
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Remote Access Software RMS Registry
|
Sysmon EventID 13
|
T1219
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Kerberos Coercion via DNS
|
Windows Event Log Security 5137, Windows Event Log Security 4662, Windows Event Log Security 5136
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Kerberos Coercion with DNS, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Windows DNS Query Request To TinyUrl
|
Sysmon EventID 22
|
T1105
|
Anomaly
|
Malicious Inno Setup Loader
|
2026-05-13
|
|
Windows Proxy Via Netsh
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Windows RMM Tool Execution
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Suspicious User Agents, Remote Monitoring and Management Software, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Curl Execution with Percent Encoded URL
|
Sysmon for Linux EventID 1, Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1027
T1105
|
Anomaly
|
Compromised Windows Host, Living Off The Land, Ingress Tool Transfer
|
2026-05-13
|
|
Windows DLL Module Loaded in Temp Dir
|
Sysmon EventID 7
|
T1105
|
Hunting
|
Lokibot, Interlock Rat, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows TOR Client Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090.003
|
Anomaly
|
Command And Control, Windows Post-Exploitation, Compromised Windows Host, Data Exfiltration, Data Protection
|
2026-05-13
|
|
Cisco NVM - Outbound Connection to Suspicious Port
|
Cisco Network Visibility Module Flow Data
|
T1571
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Detect Remote Access Software Usage Registry
|
Sysmon EventID 13
|
T1219
|
Anomaly
|
Insider Threat, Command And Control, Cactus Ransomware, Scattered Spider, Ransomware, Gozi Malware, Remote Monitoring and Management Software, CISA AA24-241A, Seashell Blizzard, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
BITSAdmin Download File
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
T1197
|
TTP
|
Flax Typhoon, GhostRedirector IIS Module and Rungan Backdoor, Ingress Tool Transfer, Scattered Spider, Living Off The Land, BITS Jobs, Gozi Malware, DarkSide Ransomware, Hellcat Ransomware, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows SSH Proxy Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
T1572
|
Anomaly
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows Devtunnels Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
LOLBAS With Network Traffic
|
Sysmon EventID 3
|
T1105
T1218
T1567
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns, Water Gamayun, Malicious Inno Setup Loader, Living Off The Land, Hellcat Ransomware, APT37 Rustonotto and FadeStealer, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Cabinet File Extraction Via Expand
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
APT37 Rustonotto and FadeStealer, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Potential Cloudflared Tunnel Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Mail Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
AgentTesla
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Azure Active Directory Account Takeover
|
2026-05-13
|
|
Windows Process Execution From RDP Share
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
Linux Ingress Tool Transfer Hunting
|
Sysmon for Linux EventID 1
|
T1105
|
Hunting
|
XorDDos, Ingress Tool Transfer, Linux Living Off The Land, Axios Supply Chain Post Compromise, NPM Supply Chain Compromise
|
2026-05-13
|
|
Windows Curl Upload to Remote Destination
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Cisco Network Visibility Module Flow Data
|
T1105
|
TTP
|
Cisco Network Visibility Module Analytics, Ingress Tool Transfer, Compromised Windows Host, Axios Supply Chain Post Compromise, PromptLock, NPM Supply Chain Compromise, Microsoft WSUS CVE-2025-59287
|
2026-07-14
|
|
Cisco NVM - Suspicious File Download via Headless Browser
|
Cisco Network Visibility Module Flow Data
|
T1059
T1105
|
TTP
|
Cisco Network Visibility Module Analytics, BlankGrabber Stealer
|
2026-07-14
|
|
File Download or Read to Pipe Execution
|
Sysmon for Linux EventID 1, Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
Ingress Tool Transfer, Compromised Windows Host, Linux Living Off The Land, Log4Shell CVE-2021-44228, NPM Supply Chain Compromise
|
2026-05-13
|
|
Windows Suspicious Defender Update Activity in INetCache
|
Sysmon EventID 23, Sysmon EventID 11
|
T1068
T1105
|
Anomaly
|
BlueHammer, Windows Persistence Techniques
|
2026-07-20
|
|
Windows Outlook Macro Security Modified
|
Sysmon EventID 13
|
T1008
T1137
|
TTP
|
NotDoor Malware, Windows Registry Abuse
|
2026-05-13
|
|
Windows Ldifde Directory Object Behavior
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
T1105
|
TTP
|
Volt Typhoon
|
2026-05-13
|
|
Potential Telegram API Request Via CommandLine
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1041
T1102.002
|
Anomaly
|
BlankGrabber Stealer, XMRig, 0bj3ctivity Stealer, Water Gamayun, Hellcat Ransomware
|
2026-05-13
|
|
WinRAR Spawning Shell Application
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
Compromised Windows Host, WinRAR Spoofing Attack CVE-2023-38831
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
PHP-CGI RCE Attack on Japanese Organizations, MoonPeak, Medusa Ransomware, Malicious PowerShell
|
2026-05-13
|
|
Download Files Using Telegram
|
Sysmon EventID 15
|
T1105
|
TTP
|
XMRig, 0bj3ctivity Stealer, Water Gamayun, Crypto Stealer, Phemedrone Stealer, Snake Keylogger
|
2026-05-13
|
|
Log4Shell CVE-2021-44228 Exploitation
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Log4Shell CVE-2021-44228, CISA AA22-320A
|
2026-05-13
|
|
Windows File Download Via CertUtil
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Cisco Network Visibility Module Flow Data
|
T1105
|
TTP
|
ProxyNotShell, Flax Typhoon, CISA AA22-277A, Cisco Network Visibility Module Analytics, Ingress Tool Transfer, Living Off The Land, Compromised Windows Host, DarkSide Ransomware, Forest Blizzard
|
2026-07-14
|
|
Windows Curl Download to Suspicious Path
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Cisco Network Visibility Module Flow Data
|
T1105
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Cisco Network Visibility Module Analytics, Ingress Tool Transfer, Starland RAT Campaign, China-Nexus Threat Activity, IcedID, Compromised Windows Host, Black Basta Ransomware, Forest Blizzard, Salt Typhoon, APT37 Rustonotto and FadeStealer, NPM Supply Chain Compromise
|
2026-07-20
|
|
Detect Remote Access Software Usage File
|
Sysmon EventID 11
|
T1219
|
Anomaly
|
GhostRedirector IIS Module and Rungan Backdoor, Insider Threat, Command And Control, Cactus Ransomware, Scattered Spider, Ransomware, Gozi Malware, Remote Monitoring and Management Software, Interlock Ransomware, CISA AA24-241A, Seashell Blizzard, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Linux Proxy Socks Curl
|
Sysmon for Linux EventID 1
|
T1090
T1095
|
TTP
|
Ingress Tool Transfer, Linux Living Off The Land
|
2026-06-04
|
|
Windows File Transfer Protocol In Non-Common Process Path
|
Sysmon EventID 3
|
T1071.003
|
Anomaly
|
Snake Keylogger, AgentTesla, Phantom Stealer, Hellcat Ransomware
|
2026-06-25
|
|
Windows Application Layer Protocol RMS Radmin Tool Namedpipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1071
|
TTP
|
Azorult
|
2026-05-13
|
|
Windows Devtunnels Image Loaded
|
Sysmon EventID 7
|
T1090
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Detect Remote Access Software Usage Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1219
|
Anomaly
|
GhostRedirector IIS Module and Rungan Backdoor, Insider Threat, Command And Control, Cactus Ransomware, Scattered Spider, Storm-0501 Ransomware, Ransomware, Gozi Malware, Remote Monitoring and Management Software, Interlock Ransomware, CISA AA24-241A, Seashell Blizzard, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Ngrok Reverse Proxy Usage
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1090
T1102
T1572
|
Anomaly
|
CISA AA22-320A, Reverse Network Proxy, CISA AA24-241A
|
2026-05-13
|
|
Linux Ngrok Reverse Proxy Usage
|
Sysmon for Linux EventID 1
|
T1090
T1102
T1572
|
Anomaly
|
Reverse Network Proxy
|
2026-05-13
|
|
Windows App Layer Protocol Wermgr Connect To NamedPipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Hellcat Ransomware, Malicious PowerShell
|
2026-05-13
|
|
Windows AI Platform DNS Query
|
Sysmon EventID 22
|
T1071.004
|
Anomaly
|
LAMEHUG, SesameOp, PromptFlux
|
2026-05-13
|
|
Windows Ingress Tool Transfer Using Explorer
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
Windows Proxy Via Registry
|
Sysmon EventID 13
|
T1090.001
|
Anomaly
|
Volt Typhoon
|
2026-05-13
|
|
Detect Remote Access Software Usage FileInfo
|
Sysmon EventID 1
|
T1219
|
Anomaly
|
Insider Threat, Command And Control, Cactus Ransomware, Scattered Spider, Ransomware, Gozi Malware, Remote Monitoring and Management Software, Interlock Ransomware, Seashell Blizzard, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Compromised Linux Host, Linux Privilege Escalation, Linux Living Off The Land, VoidLink Cloud-Native Linux Malware, Linux Post-Exploitation, Linux Rootkit
|
2026-05-13
|
|
Windows SoftEther VPN Masquerading as Legitimate Binary
|
Sysmon EventID 1
|
T1036
T1572
|
TTP
|
Flax Typhoon, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Cisco Isovalent - Curl Execution With Insecure Flags
|
Cisco Isovalent Process Exec
|
T1105
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Detect Certify Command Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
T1649
|
TTP
|
Compromised Windows Host, Ingress Tool Transfer, Windows Certificate Services
|
2026-05-13
|
|
Windows Powershell Commands from DNS TXT
|
Powershell Script Block Logging 4104
|
T1059.001
T1071.004
|
Anomaly
|
Suspicious DNS Traffic, Malicious PowerShell, Command And Control
|
2026-07-30
|
|
Suspicious Curl Network Connection
|
Sysmon for Linux EventID 1, Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Silver Sparrow, Ingress Tool Transfer, Linux Living Off The Land, Hellcat Ransomware, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Cisco Network Visibility Module Flow Data
|
T1059.001
T1105
|
Anomaly
|
Data Destruction, Cisco Network Visibility Module Analytics, Ingress Tool Transfer, PHP-CGI RCE Attack on Japanese Organizations, SolarWinds WHD RCE Post Exploitation, APT37 Rustonotto and FadeStealer, NPM Supply Chain Compromise, Malicious PowerShell, StealC Stealer, HAFNIUM Group, SysAid On-Prem Software CVE-2023-47246 Vulnerability, IcedID, Tuoni, GhostRedirector IIS Module and Rungan Backdoor, Phemedrone Stealer, Winter Vivern, NetSupport RMM Tool Abuse, Microsoft WSUS CVE-2025-59287, XWorm, Hermetic Wiper
|
2026-07-14
|
|
Windows PowGoop Beacon Decoding
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows App Layer Protocol Qakbot NamedPipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1071
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows SQL Spawning CertUtil
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1105
|
TTP
|
Flax Typhoon, Storm-2460 CLFS Zero Day Exploitation, SQL Server Abuse
|
2026-05-13
|
|
Windows Short Lived DNS Record
|
Windows Event Log Security 5137, Windows Event Log Security 5136
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Kerberos Coercion with DNS, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Windows Non-System Process Querying Definition Update
|
Sysmon EventID 22
|
T1068
T1071.001
|
Anomaly
|
BlueHammer, Windows Privilege Escalation, RedSun
|
2026-04-27
|
|
Linux Ingress Tool Transfer with Curl
|
Sysmon for Linux EventID 1
|
T1105
|
Anomaly
|
Ingress Tool Transfer, XorDDos, Linux Living Off The Land, NPM Supply Chain Compromise
|
2026-05-13
|
|
Windows Protocol Tunneling with Plink
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.004
T1572
|
TTP
|
CISA AA22-257A
|
2026-05-13
|
|
Windows Visual Basic Commandline Compiler DNSQuery
|
Sysmon EventID 22
|
T1071.004
|
TTP
|
Lokibot
|
2026-05-13
|
|
Living Off The Land Detection
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Linux Curl Upload File
|
Sysmon for Linux EventID 1, Cisco Isovalent Process Exec
|
T1105
|
TTP
|
Data Exfiltration, Linux Living Off The Land, Ingress Tool Transfer, NPM Supply Chain Compromise
|
2026-05-13
|
|
Windows Remote Access Software BRC4 Loaded Dll
|
Sysmon EventID 7
|
T1003
T1219
|
Anomaly
|
Brute Ratel C4
|
2026-05-13
|
|
Cisco NVM - Webserver Download From File Sharing Website
|
Cisco Network Visibility Module Flow Data
|
T1105
T1190
|
TTP
|
Cisco Network Visibility Module Analytics, GhostRedirector IIS Module and Rungan Backdoor
|
2026-07-14
|
|
Windows Credential Target Information Structure in Commandline
|
Sysmon EventID 1
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Kerberos Coercion with DNS, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Juniper Networks Remote Code Execution Exploit Detection
|
Suricata
|
T1059
T1105
T1190
|
TTP
|
Juniper JunOS Remote Code Execution
|
2026-05-13
|
|
HTTP Duplicated Header
|
Suricata
|
T1071.001
T1190
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
Detect Remote Access Software Usage URL
|
Palo Alto Network Threat
|
T1219
|
Anomaly
|
Insider Threat, Command And Control, Ransomware, Remote Monitoring and Management Software, Interlock Ransomware, CISA AA24-241A, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
HTTP Request to Reserved Name on IIS Server
|
Suricata
|
T1071.001
T1190
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Rapid POST with Mixed Status Codes
|
Nginx Access
|
T1071.001
T1190
T1595
|
Anomaly
|
HTTP Request Smuggling
|
2026-05-13
|
|
HTTP Scripting Tool User Agent
|
Nginx Access
|
T1071.001
|
Anomaly
|
HTTP Request Smuggling, Suspicious User Agents
|
2026-06-15
|
|
HTTP Possible Request Smuggling
|
Suricata
|
T1071.001
|
TTP
|
HTTP Request Smuggling
|
2026-05-13
|
|
Cisco IOS XE Tunnel Interface Configuration
|
Cisco IOS Logs
|
T1090
T1572
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
Ollama Abnormal Network Connectivity
|
Ollama Server
|
T1571
|
Anomaly
|
Suspicious Ollama Activities
|
2026-05-13
|
|
Microsoft Intune Device Health Scripts
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Microsoft Intune Mobile Apps
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Okta Non-Standard VPN Usage
|
Okta
|
T1078
T1090
T1572
|
TTP
|
Suspicious Okta Activity, Remote Employment Fraud
|
2026-05-13
|
|
Windows Multi hop Proxy TOR Website Query
|
Sysmon EventID 22
|
T1071.003
|
Anomaly
|
AgentTesla, Interlock Ransomware
|
2026-05-13
|
|
HTTP RMM User Agent
|
Suricata
|
T1071.001
T1219
|
Anomaly
|
Suspicious User Agents, Remote Monitoring and Management Software
|
2026-05-13
|
|
HTTP Malware User Agent
|
Suricata
|
T1071.001
|
TTP
|
RedLine Stealer, Crypto Stealer, Suspicious User Agents, Meduza Stealer, Lumma Stealer, Lokibot
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
HTTP C2 Framework User Agent
|
Suricata
|
T1071.001
|
TTP
|
Malicious PowerShell, Cobalt Strike, Spearphishing Attachments, Brute Ratel C4, Meterpreter, BishopFox Sliver Adversary Emulation Framework, Suspicious User Agents, Tuoni
|
2026-05-13
|
|
Detect Remote Access Software Usage DNS
|
Sysmon EventID 22
|
T1219
|
Anomaly
|
Insider Threat, Command And Control, Scattered Spider, Ransomware, Remote Monitoring and Management Software, Interlock Ransomware, CISA AA24-241A, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1027
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Detect Large ICMP Traffic
|
Palo Alto Network Traffic, Cisco Secure Access Firewall
|
T1095
|
TTP
|
Backdoor Pingpong, China-Nexus Threat Activity, Cisco Secure Access Analytics, Command And Control
|
2026-05-13
|
|
HTTP PUA User Agent
|
Suricata
|
T1071.001
|
Anomaly
|
Suspicious User Agents, BlackSuit Ransomware, Cactus Ransomware, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Cisco Secure Firewall - Intrusion Events by Threat Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics, ArcaneDoor
|
2026-05-13
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
TOR Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Palo Alto Network Traffic
|
T1090.003
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics, Command And Control, Prohibited Traffic Allowed or Protocol Mismatch, Ransomware, Interlock Ransomware, NOBELIUM Group
|
2026-05-13
|
|
Zeek x509 Certificate with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
SSL Certificates with Punycode
|
|
T1573
|
Hunting
|
OpenSSL CVE-2022-3602
|
2026-05-13
|
|
Cisco Secure Firewall - Remote Access Software Usage Traffic
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1219
|
Anomaly
|
Insider Threat, Cisco Secure Firewall Threat Defense Analytics, Command And Control, Scattered Spider, Ransomware, Remote Monitoring and Management Software, Interlock Ransomware, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Cisco Secure Firewall - Malware File Downloaded
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows DNS Query Request by Telegram Bot API
|
Sysmon EventID 22
|
T1071.004
T1102.002
|
Anomaly
|
BlankGrabber Stealer, 0bj3ctivity Stealer, Starland RAT Campaign, Phantom Stealer, Crypto Stealer, VIP Keylogger
|
2026-07-20
|
|
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1573.002
T1587.002
T1588.004
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Detect Remote Access Software Usage Traffic
|
Palo Alto Network Traffic
|
T1219
|
Anomaly
|
Insider Threat, Command And Control, Scattered Spider, Ransomware, Remote Monitoring and Management Software, Interlock Ransomware, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Download Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1041
T1573.002
|
Anomaly
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High EVE Threat Confidence
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1041
T1071.001
T1105
T1573.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Repeated Malware Downloads
|
Cisco Secure Firewall Threat Defense File Event
|
T1027
T1105
|
Anomaly
|
Hellcat Ransomware, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Windows Abused Web Services
|
Sysmon EventID 22
|
T1102
|
Anomaly
|
BlankGrabber Stealer, CISA AA24-241A, NjRAT, Malicious Inno Setup Loader
|
2026-05-13
|
|
Ngrok Reverse Proxy on Network
|
Sysmon EventID 22
|
T1090
T1102
T1572
|
Anomaly
|
CISA AA22-320A, Reverse Network Proxy, CISA AA24-241A
|
2026-05-13
|
|
Cisco Secure Firewall - File Download Over Uncommon Port
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Detect Outbound SMB Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Cisco Secure Access Firewall
|
T1071.002
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics, Hidden Cobra Malware, NOBELIUM Group, Cisco Secure Access Analytics, DHS Report TA18-074A
|
2026-05-13
|
|
DNS Kerberos Coercion
|
Suricata, Sysmon EventID 22
|
T1071.004
T1187
T1557.001
|
TTP
|
Suspicious DNS Traffic, Compromised Windows Host, Kerberos Coercion with DNS, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Cisco Secure Firewall - Connection to File Sharing Domain
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1071.001
T1090.002
T1105
T1567.002
T1588.002
|
Anomaly
|
Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Excessive DNS Failures
|
|
T1071.004
|
Anomaly
|
Suspicious DNS Traffic, Command And Control
|
2026-05-13
|
|
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1071
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco SA - Access to Anonymizer Services
|
Cisco Secure Access DNS
|
T1090.003
|
Anomaly
|
Cisco Secure Access Analytics
|
2026-06-09
|