|
Juniper Networks Remote Code Execution Exploit Detection
|
Suricata
|
T1059
T1105
T1190
|
TTP
|
Juniper JunOS Remote Code Execution
|
2026-05-13
|
|
CrushFTP Authentication Bypass Exploitation
|
CrushFTP
|
T1059.001
T1059.003
T1190
|
TTP
|
CrushFTP Vulnerabilities, Hellcat Ransomware
|
2026-05-13
|
|
AWS ECR Container Scanning Findings Low Informational Unknown
|
AWS CloudTrail DescribeImageScanFindings
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Microsoft Intune Mobile Apps
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Microsoft Intune Device Health Scripts
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Kubernetes newly seen UDP edge
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
AWS ECR Container Scanning Findings Medium
|
AWS CloudTrail DescribeImageScanFindings
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes Previously Unseen Process
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Traffic on Network Edge
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
AWS ECR Container Upload Unknown User
|
AWS CloudTrail PutImage
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes Shell Running on Worker Node
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
O365 Threat Intelligence Suspicious File Detected
|
Office 365 Universal Audit Log
|
T1204.002
|
TTP
|
Office 365 Account Takeover, Ransomware Cloud, Azure Active Directory Account Takeover
|
2026-05-13
|
|
AWS Lambda UpdateFunctionCode
|
AWS CloudTrail
|
T1204
|
Hunting
|
Suspicious Cloud User Activities
|
2026-05-13
|
|
Kubernetes Unauthorized Access
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Process Running From New Path
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes DaemonSet Deployed
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
ASL AWS ECR Container Upload Outside Business Hours
|
ASL AWS CloudTrail
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
O365 SharePoint Malware Detection
|
Office 365 Universal Audit Log
|
T1204.002
|
TTP
|
Azure Active Directory Persistence, Office 365 Account Takeover, Ransomware Cloud
|
2026-05-13
|
|
Kubernetes Falco Shell Spawned
|
Kubernetes Falco
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Shell Running on Worker Node with CPU Activity
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Inbound Network Activity from Process
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Pod Created in Default Namespace
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Anomalous Outbound Network Activity from Process
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
AWS ECR Container Upload Outside Business Hours
|
AWS CloudTrail PutImage
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes newly seen TCP edge
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Microsoft Intune Manual Device Management
|
Azure Monitor Activity
|
T1021.007
T1072
T1529
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Kubernetes Pod With Host Network Attachment
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Previously Unseen Container Image Name
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Create or Update Privileged Pod
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Node Port Creation
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
AWS ECR Container Scanning Findings High
|
AWS CloudTrail DescribeImageScanFindings
|
T1204.003
|
TTP
|
Dev Sec Ops
|
2026-05-13
|
|
Microsoft Intune DeviceManagementConfigurationPolicies
|
Azure Monitor Activity
|
T1021.007
T1072
T1484
T1685
T1686
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
ASL AWS ECR Container Upload Unknown User
|
ASL AWS CloudTrail
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes Cron Job Creation
|
Kubernetes Audit
|
T1053.007
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Python Network Traffic During Package Build
|
Sysmon EventID 1, Sysmon EventID 3
|
T1059.006
T1195.002
|
Anomaly
|
Compromised Windows Host, Ingress Tool Transfer, Command And Control, Malicious Python Package Installation
|
2026-08-21
|
|
MacOS LOLbin
|
Osquery Results
|
T1059.004
|
TTP
|
Axios Supply Chain Post Compromise, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows Service Create SliverC2
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Compromised Windows Host, Hellcat Ransomware, BishopFox Sliver Adversary Emulation Framework
|
2026-05-13
|
|
Windows Hijack Execution Flow Version Dll Side Load
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
Brute Ratel C4, XWorm, Malicious Inno Setup Loader, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Name
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Scheduled Tasks, Castle RAT, 0bj3ctivity Stealer, Windows Persistence Techniques, APT37 Rustonotto and FadeStealer, Ryuk Ransomware, Ransomware
|
2026-05-13
|
|
Schedule Task with Rundll32 Command Trigger
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Scheduled Tasks, Castle RAT, IcedID, Windows Persistence Techniques, Compromised Windows Host, Trickbot, Living Off The Land
|
2026-05-13
|
|
Windows Developer-Signed MSIX Package Installation
|
Windows Event Log AppXDeployment-Server 855
|
T1204.002
T1553.005
|
Anomaly
|
MSIX Package Abuse
|
2026-05-13
|
|
MSI Module Loaded by Non-System Binary
|
Sysmon EventID 7
|
T1574.001
|
Hunting
|
Data Destruction, Windows Privilege Escalation, Hermetic Wiper
|
2026-05-13
|
|
Windows PowerShell ScheduleTask
|
Powershell Script Block Logging 4104
|
T1053.005
T1059.001
|
Anomaly
|
Scheduled Tasks, Scattered Spider, Starland RAT Campaign
|
2026-07-20
|
|
Windows Defender ASR Block Events
|
Windows Event Log Defender 1126, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1133, Windows Event Log Defender 1121
|
T1059
T1566.001
T1566.002
|
Anomaly
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Windows PowerShell Script TabExpansion Direct Call
|
Powershell Script Block Logging 4104
|
T1059.001
T1129
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
Cisco NVM - Suspicious Download From File Sharing Website
|
Cisco Network Visibility Module Flow Data
|
T1197
|
Anomaly
|
BlankGrabber Stealer, Cisco Network Visibility Module Analytics, APT37 Rustonotto and FadeStealer
|
2026-07-14
|
|
Windows Enable PowerShell Web Access
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
CISA AA24-241A, Malicious PowerShell
|
2026-05-13
|
|
Windows Anonymous Pipe Activity
|
Sysmon EventID 17, Sysmon EventID 18
|
T1559
|
Hunting
|
Castle RAT, Salt Typhoon, Interlock Rat, SnappyBee, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Linux Privilege Escalation, VoidLink Cloud-Native Linux Malware, Linux Rootkit, Linux Living Off The Land, Compromised Linux Host, Linux Post-Exploitation
|
2026-05-13
|
|
Drop IcedID License dat
|
Sysmon EventID 11
|
T1204.002
|
Hunting
|
IcedID
|
2026-05-13
|
|
PowerShell Enable PowerShell Remoting
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Defender ASR Audit Events
|
Windows Event Log Defender 1125, Windows Event Log Defender 1134, Windows Event Log Defender 1132, Windows Event Log Defender 1122, Windows Event Log Defender 1126
|
T1059
T1566.001
T1566.002
|
Anomaly
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Powershell Fileless Process Injection via GetProcAddress
|
Powershell Script Block Logging 4104
|
T1055
T1059.001
|
TTP
|
Data Destruction, Malicious PowerShell, Hermetic Wiper, Hellcat Ransomware
|
2026-05-13
|
|
Powershell Execute COM Object
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Ransomware, Data Destruction, Hermetic Wiper, Malicious PowerShell
|
2026-05-13
|
|
Windows DLL Search Order Hijacking Hunt with Sysmon
|
Sysmon EventID 7
|
T1574.001
|
Hunting
|
Windows Defense Evasion Tactics, Malicious Inno Setup Loader, Qakbot, Living Off The Land
|
2026-05-13
|
|
Unloading AMSI via Reflection
|
Powershell Script Block Logging 4104
|
T1059.001
T1685
|
TTP
|
Data Destruction, Hermetic Wiper, Malicious PowerShell
|
2026-05-13
|
|
Windows PowerShell Invoke-RestMethod IP Information Collection
|
Powershell Script Block Logging 4104
|
T1016
T1059.001
T1082
|
Anomaly
|
Water Gamayun
|
2026-05-13
|
|
Windows Powershell Cryptography Namespace
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
AsyncRAT, Phantom Stealer, XWorm, VIP Keylogger
|
2026-06-25
|
|
MacOS AMOS Stealer - Virtual Machine Check Activity
|
Osquery Results
|
T1059.002
|
Anomaly
|
AMOS Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Windows Scheduled Task DLL Module Loaded
|
Sysmon EventID 7
|
T1053
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
WinEvent Scheduled Task Created to Spawn Shell
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Scheduled Tasks, Castle RAT, Salt Typhoon, SystemBC, 0bj3ctivity Stealer, Windows Error Reporting Service Elevation of Privilege Vulnerability, Windows Persistence Techniques, Compromised Windows Host, China-Nexus Threat Activity, Medusa Ransomware, Ryuk Ransomware, Winter Vivern, Ransomware, CISA AA22-257A
|
2026-05-13
|
|
Windows Unsigned DLL Side-Loading
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
NjRAT, Salt Typhoon, Warzone RAT, China-Nexus Threat Activity, SolarWinds WHD RCE Post Exploitation, Earth Alux, Derusbi
|
2026-05-13
|
|
Windows Hidden Schedule Task Settings
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Scheduled Tasks, Cactus Ransomware, Hellcat Ransomware, Industroyer2, Data Destruction, Compromised Windows Host, Malicious Inno Setup Loader, CISA AA22-257A, Active Directory Discovery
|
2026-05-13
|
|
PowerShell Start or Stop Service
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Active Directory Lateral Movement, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Windows SqlWriter SQLDumper DLL Sideload
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
APT29 Diplomatic Deceptions with WINELOADER
|
2026-05-13
|
|
PowerShell Environment Variable Execution
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
VIP Keylogger
|
2026-06-29
|
|
Detect Empire with PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Data Destruction, Malicious PowerShell, Hermetic Wiper, Hellcat Ransomware
|
2026-05-13
|
|
Detect Mimikatz With PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1003
T1059.001
|
TTP
|
Scattered Spider, Malicious PowerShell, Hellcat Ransomware, CISA AA23-347A, CISA AA22-320A, Data Destruction, Sandworm Tools, Hermetic Wiper, CISA AA22-264A
|
2026-05-13
|
|
Cisco NVM - Suspicious File Download via Headless Browser
|
Cisco Network Visibility Module Flow Data
|
T1059
T1105
|
TTP
|
BlankGrabber Stealer, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Linux Magic SysRq Key Abuse
|
Linux Auditd Cwd, Linux Auditd Path
|
T1059.004
T1489
T1499
T1529
|
TTP
|
Compromised Linux Host
|
2026-05-13
|
|
Detect Certify With PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1059.001
T1649
|
TTP
|
Malicious PowerShell, Windows Certificate Services
|
2026-05-13
|
|
Windows Suspicious C2 Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
TTP
|
Gozi Malware, Storm-0501 Ransomware, Hellcat Ransomware, Remote Monitoring and Management Software, LockBit Ransomware, Tuoni, APT37 Rustonotto and FadeStealer, DarkSide Ransomware, Brute Ratel C4, Meterpreter, Trickbot, BlackByte Ransomware, Graceful Wipe Out Attack, Cobalt Strike
|
2026-05-13
|
|
Windows Powershell Commands from DNS TXT
|
Powershell Script Block Logging 4104
|
T1059.001
T1071.004
|
Anomaly
|
Command And Control, Suspicious DNS Traffic, Malicious PowerShell
|
2026-07-30
|
|
Windows WMI Impersonate Token
|
Sysmon EventID 10
|
T1047
|
Anomaly
|
Qakbot, Water Gamayun
|
2026-05-13
|
|
Linux Auditd Edit Cron Table Parameter
|
Linux Auditd Syscall
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, Compromised Linux Host
|
2026-05-13
|
|
Powershell Load Module in Meterpreter
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
MetaSploit
|
2026-05-13
|
|
WMI Permanent Event Subscription
|
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Powershell Fileless Script Contains Base64 Encoded Content
|
Powershell Script Block Logging 4104
|
T1027
T1059.001
|
TTP
|
Axios Supply Chain Post Compromise, Phantom Stealer, VIP Keylogger, AsyncRAT, IcedID, Hellcat Ransomware, Data Destruction, Salat Stealer, Medusa Ransomware, Winter Vivern, Hermetic Wiper, Malicious PowerShell, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, MuddyWater, XWorm, NjRAT, 0bj3ctivity Stealer, Microsoft WSUS CVE-2025-59287, NetSupport RMM Tool Abuse
|
2026-06-25
|
|
Linux Auditd Preload Hijack Library Calls
|
Linux Auditd Execve
|
T1574.006
|
TTP
|
Linux Privilege Escalation, Salt Typhoon, Linux Persistence Techniques, China-Nexus Threat Activity, Compromised Linux Host
|
2026-05-13
|
|
Windows BitDefender Submission Wizard DLL Sideloading
|
Sysmon EventID 7
|
T1574
|
TTP
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Cisco NVM - Installation of Typosquatted Python Package
|
Cisco Network Visibility Module Flow Data
|
T1059
|
TTP
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows AppX Deployment Full Trust Package Installation
|
Windows Event Log AppXDeployment-Server 400
|
T1204.002
T1553.005
|
Hunting
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows PowerShell Script Block With Malicious String
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Cisco Isovalent - Non Allowlisted Image Use
|
Cisco Isovalent Process Exec
|
T1204.003
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Linux Auditd Service Started
|
Linux Auditd Proctitle
|
T1569.002
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Cisco NVM - Browser Spawned Unix Shell with External Connection
|
Cisco Network Visibility Module Flow Data
|
T1059
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-09-02
|
|
Windows MSIX Package Interaction
|
Windows Event Log AppXPackaging 171
|
T1204.002
|
Hunting
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows PowerShell Get CIMInstance Remote Computer
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Remote Process Instantiation via WMI and PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1047
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Cisco Isovalent - Pods Running Offensive Tools
|
Cisco Isovalent Process Exec
|
T1204.003
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows Powershell Logoff User via Quser
|
Powershell Script Block Logging 4104
|
T1059.001
T1531
|
Anomaly
|
Crypto Stealer
|
2026-06-29
|
|
Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
ValleyRAT, Water Gamayun
|
2026-05-13
|
|
Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File
|
Linux Auditd Cwd, Linux Auditd Path
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, Compromised Linux Host, XorDDos
|
2026-05-13
|
|
Windows Powershell History File Deletion
|
Powershell Script Block Logging 4104
|
T1059.003
T1070.003
|
Anomaly
|
Medusa Ransomware
|
2026-05-13
|
|
Windows Unsigned MS DLL Side-Loading
|
Sysmon EventID 7
|
T1547
T1574.001
|
Anomaly
|
Salt Typhoon, APT29 Diplomatic Deceptions with WINELOADER, China-Nexus Threat Activity, XWorm, Earth Alux, Derusbi
|
2026-05-13
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Hellcat Ransomware, Malicious PowerShell
|
2026-05-13
|
|
Get-ForestTrust with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows PowerShell Invoke-Sqlcmd Execution
|
Powershell Script Block Logging 4104
|
T1059.001
T1059.003
|
Hunting
|
GhostRedirector IIS Module and Rungan Backdoor, SQL Server Abuse
|
2026-05-13
|
|
Windows Process Accessing Windows Recall Directory
|
Windows Event Log Security 4663
|
T1059
T1119
|
Anomaly
|
Windows Post-Exploitation
|
2026-05-13
|
|
Windows PowerShell WMI Win32 ScheduledJob
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
PowerShell Domain Enumeration
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Interlock Ransomware, Malicious PowerShell, CISA AA23-347A, Data Destruction, Microsoft WSUS CVE-2025-59287, Hermetic Wiper
|
2026-06-28
|
|
PowerShell 4104 Hunting
|
Powershell Script Block Logging 4104
|
T1003
T1059.001
T1689
|
Hunting
|
Scattered Spider, Axios Supply Chain Post Compromise, SystemBC, CISA AA23-347A, Phantom Stealer, China-Nexus Threat Activity, Rhysida Ransomware, Cactus Ransomware, Interlock Ransomware, Hellcat Ransomware, Braodo Stealer, Data Destruction, Salat Stealer, Lumma Stealer, Medusa Ransomware, Hermetic Wiper, Salt Typhoon, Malicious PowerShell, GhostRedirector IIS Module and Rungan Backdoor, DarkGate Malware, APT37 Rustonotto and FadeStealer, Water Gamayun, XWorm, MuddyWater, Cleo File Transfer Software, 0bj3ctivity Stealer, PHP-CGI RCE Attack on Japanese Organizations, Flax Typhoon, Starland RAT Campaign, CISA AA24-241A, Microsoft WSUS CVE-2025-59287
|
2026-09-03
|
|
Linux Auditd At Application Execution
|
Linux Auditd Syscall
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, Compromised Linux Host
|
2026-05-13
|
|
Powershell Processing Stream Of Data
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
MoonPeak, IcedID, Malicious PowerShell, Hellcat Ransomware, Braodo Stealer, Data Destruction, MuddyWater, PXA Stealer, Medusa Ransomware, Salat Stealer, Hermetic Wiper, AsyncRAT, XWorm
|
2026-06-29
|
|
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
|
Cisco Network Visibility Module Flow Data
|
T1059.005
T1218.005
|
Anomaly
|
BlankGrabber Stealer, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Known GraphicalProton Loaded Modules
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
CISA AA23-347A, Water Gamayun, Hellcat Ransomware
|
2026-05-13
|
|
PowerShell Invoke WmiExec Usage
|
Powershell Script Block Logging 4104
|
T1047
|
TTP
|
Suspicious WMI Use, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Malicious Powershell Executed As A Service
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Compromised Windows Host, Malicious PowerShell, Rhysida Ransomware
|
2026-05-13
|
|
PowerShell Invoke CIMMethod CIMSession
|
Powershell Script Block Logging 4104
|
T1047
|
Anomaly
|
Active Directory Lateral Movement, Scattered Lapsus$ Hunters, Malicious PowerShell
|
2026-05-13
|
|
Windows Cobalt Strike PowerShell Loader
|
Powershell Script Block Logging 4104
|
T1059.001
T1608
|
TTP
|
Cobalt Strike
|
2026-05-13
|
|
Sunburst Correlation DLL and Network Event
|
Sysmon EventID 7, Sysmon EventID 22
|
T1203
|
TTP
|
NOBELIUM Group
|
2026-05-13
|
|
MS Scripting Process Loading Ldap Module
|
Sysmon EventID 7
|
T1059.007
|
Anomaly
|
FIN7
|
2026-05-13
|
|
Linux Auditd Service Restarted
|
Linux Auditd Proctitle
|
T1053.006
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Data Destruction, AwfulShred, Linux Living Off The Land, Compromised Linux Host, Gomir
|
2026-05-13
|
|
Linux Auditd Preload Hijack Via Preload File
|
Linux Auditd Cwd, Linux Auditd Path
|
T1574.006
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Living Off The Land, Compromised Linux Host
|
2026-05-13
|
|
WinEvent Scheduled Task Created Within Public Path
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Castle RAT, SystemBC, Industroyer2, CISA AA23-347A, Windows Persistence Techniques, China-Nexus Threat Activity, Ryuk Ransomware, Malicious Inno Setup Loader, AsyncRAT, CISA AA22-257A, IcedID, Active Directory Lateral Movement, Data Destruction, Winter Vivern, Medusa Ransomware, Ransomware, Scheduled Tasks, Salt Typhoon, Quasar RAT, APT37 Rustonotto and FadeStealer, Compromised Windows Host, XWorm, Prestige Ransomware, 0bj3ctivity Stealer, ValleyRAT, PlugX, Remcos
|
2026-05-13
|
|
Schedule Task with HTTP Command Arguments
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Scheduled Tasks, Hellcat Ransomware, Windows Persistence Techniques, Compromised Windows Host, Winter Vivern, Living Off The Land
|
2026-05-13
|
|
Powershell Creating Thread Mutex
|
Powershell Script Block Logging 4104
|
T1027.005
T1059.001
|
TTP
|
Water Gamayun, Malicious PowerShell
|
2026-05-13
|
|
Windows Powershell Import Applocker Policy
|
Powershell Script Block Logging 4104
|
T1059.001
T1685
|
Anomaly
|
Azorult
|
2026-06-29
|
|
Windows RMM Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
Anomaly
|
Scattered Spider, Gozi Malware, Cactus Ransomware, Interlock Ransomware, Scattered Lapsus$ Hunters, GhostRedirector IIS Module and Rungan Backdoor, Remote Monitoring and Management Software, Seashell Blizzard, CISA AA24-241A, Ransomware, Insider Threat, Command And Control
|
2026-05-13
|
|
Randomly Generated Scheduled Task Name
|
Windows Event Log Security 4698
|
T1053.005
|
Hunting
|
Scheduled Tasks, Active Directory Lateral Movement, 0bj3ctivity Stealer, CISA AA22-257A
|
2026-05-13
|
|
WinEvent Windows Task Scheduler Event Action Started
|
Windows Event Log TaskScheduler 200, Windows Event Log TaskScheduler 201
|
T1053.005
|
Hunting
|
SystemBC, Industroyer2, Windows Persistence Techniques, Sandworm Tools, Malicious Inno Setup Loader, AsyncRAT, CISA AA22-257A, IcedID, Data Destruction, Winter Vivern, Scheduled Tasks, Amadey, Prestige Ransomware, BlackSuit Ransomware, ValleyRAT, CISA AA24-241A, DarkCrystal RAT, Qakbot, PlugX, SolarWinds WHD RCE Post Exploitation, Remcos
|
2026-05-13
|
|
Windows AppX Deployment Package Installation Success
|
Windows Event Log AppXDeployment-Server 854
|
T1204.002
|
Anomaly
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows DLL Side-Loading In Calc
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
Qakbot, Earth Alux
|
2026-05-13
|
|
Windows Scheduled Task Created in a Group Policy Object
|
Windows Event Log Security 5145
|
T1053.005
T1484.001
|
TTP
|
Scheduled Tasks, Living Off The Land, Windows Persistence Techniques
|
2026-05-13
|
|
Windows GrimResource - MMC Process Accessing APDS DLL
|
Windows Event Log Security 4663
|
T1059.007
T1218.014
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
MS Scripting Process Loading WMI Module
|
Sysmon EventID 7
|
T1059.007
|
Anomaly
|
FIN7
|
2026-05-13
|
|
Powershell COM Hijacking InprocServer32 Modification
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Unsigned DLL Side-Loading In Same Process Path
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
Salt Typhoon, NailaoLocker Ransomware, Lokibot, SnappyBee, DarkGate Malware, China-Nexus Threat Activity, Malicious Inno Setup Loader, PlugX, XWorm, SolarWinds WHD RCE Post Exploitation, Derusbi
|
2026-05-13
|
|
Windows Defender ASR Rules Stacking
|
Windows Event Log Defender 1125, Windows Event Log Defender 1126, Windows Event Log Defender 1134, Windows Event Log Defender 5007, Windows Event Log Defender 1129, Windows Event Log Defender 1131, Windows Event Log Defender 1122, Windows Event Log Defender 1133, Windows Event Log Defender 1121
|
T1059
T1566.001
T1566.002
|
Hunting
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Cisco NVM - Susp Script From Archive Triggering Network Activity
|
Cisco Network Visibility Module Flow Data
|
T1059.005
T1204.002
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Remote Image Load
|
Sysmon EventID 7
|
T1059
T1068
T1129
T1203
|
Anomaly
|
Ransomware, LockBit Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows Suspicious Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
TTP
|
Gozi Malware, Hellcat Ransomware, Remote Monitoring and Management Software, LockBit Ransomware, Tuoni, DarkSide Ransomware, APT37 Rustonotto and FadeStealer, Brute Ratel C4, Meterpreter, Trickbot, BlackByte Ransomware, Graceful Wipe Out Attack, Cobalt Strike
|
2026-05-13
|
|
Windows MSExchange Management Mailbox Cmdlet Usage
|
|
T1059.001
|
Anomaly
|
ProxyNotShell, Scattered Spider, BlackByte Ransomware, ProxyShell
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Command
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Scheduled Tasks, Quasar RAT, Seashell Blizzard, Windows Persistence Techniques, APT37 Rustonotto and FadeStealer, Ryuk Ransomware, Ransomware, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows Executable in Loaded Modules
|
Sysmon EventID 7
|
T1129
|
TTP
|
NjRAT, Lokibot
|
2026-05-13
|
|
Recon Using WMI Class
|
Powershell Script Block Logging 4104
|
T1059.001
T1592
|
Anomaly
|
Scattered Spider, MoonPeak, Quasar RAT, Malicious PowerShell, Axios Supply Chain Post Compromise, Industroyer2, LockBit Ransomware, VIP Keylogger, Data Destruction, Malicious Inno Setup Loader, Qakbot, Hermetic Wiper, AsyncRAT, BlankGrabber Stealer
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
Medusa Ransomware, PHP-CGI RCE Attack on Japanese Organizations, MoonPeak, Malicious PowerShell
|
2026-05-13
|
|
Windows SQL Server Extended Procedure DLL Loading Hunt
|
Windows Event Log Application 8128
|
T1059.009
T1505.001
|
Hunting
|
SQL Server Abuse
|
2026-05-13
|
|
Windows Software Discovery Via PowerShell
|
Powershell Script Block Logging 4104
|
T1012
T1059.001
T1518
|
Anomaly
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows Content Copied from Browser was Executed
|
Sysmon EventID 13, Sysmon EventID 24
|
T1059.001
T1059.003
T1202
|
TTP
|
Fake CAPTCHA Campaigns
|
2026-09-07
|
|
Windows Service Created with Suspicious Service Name
|
Windows Event Log System 7045
|
T1569.002
|
Anomaly
|
Clop Ransomware, Active Directory Lateral Movement, CISA AA23-347A, Tuoni, Flax Typhoon, Gh0st RAT, Brute Ratel C4, Qakbot, PlugX, Snake Malware
|
2026-05-13
|
|
Short Lived Scheduled Task
|
Windows Event Log Security 4699, Windows Event Log Security 4698
|
T1053.005
|
Anomaly
|
Scheduled Tasks, Active Directory Lateral Movement, CISA AA23-347A, Compromised Windows Host, CISA AA22-257A
|
2026-07-07
|
|
Windows AppX Deployment Unsigned Package Installation
|
Windows Event Log AppXDeployment-Server 855
|
T1204.002
T1553.005
|
TTP
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Service Created with Suspicious Service Path
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Salt Typhoon, Clop Ransomware, CISA AA23-347A, Active Directory Lateral Movement, Gh0st RAT, Flax Typhoon, APT37 Rustonotto and FadeStealer, Brute Ratel C4, China-Nexus Threat Activity, Qakbot, PlugX, Crypto Stealer, Snake Malware, Derusbi
|
2026-05-13
|
|
Windows PowerShell MSIX Package Installation
|
Powershell Script Block Logging 4104
|
T1059.001
T1547.001
|
TTP
|
MSIX Package Abuse, Malicious PowerShell
|
2026-05-13
|
|
PowerShell PInvoke Process Injection API Chain
|
Powershell Script Block Logging 4104
|
T1055.001
T1055.003
T1055.004
T1055.012
T1055.013
T1059.001
T1620
|
TTP
|
Phantom Stealer, VIP Keylogger
|
2026-06-25
|
|
WMI Temporary Event Subscription
|
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Windows Known Abused DLL Loaded Suspiciously
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
Windows Defense Evasion Tactics, SolarWinds WHD RCE Post Exploitation, Living Off The Land
|
2026-05-13
|
|
PowerShell Loading DotNET into Memory via Reflection
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
AgentTesla, Axios Supply Chain Post Compromise, Malicious PowerShell, Hellcat Ransomware, 0bj3ctivity Stealer, VIP Keylogger, Data Destruction, Winter Vivern, Hermetic Wiper, AsyncRAT
|
2026-06-29
|
|
Powershell Using memory As Backing Store
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
MoonPeak, IcedID, Malicious PowerShell, Data Destruction, Salat Stealer, Medusa Ransomware, Hermetic Wiper
|
2026-06-08
|
|
Cisco Isovalent - Cron Job Creation
|
Cisco Isovalent Process Exec
|
T1053.003
T1053.007
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Exchange PowerShell Module Usage
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
ProxyNotShell, Scattered Spider, ProxyShell, CISA AA22-277A, BlackByte Ransomware, CISA AA22-264A
|
2026-05-13
|
|
Windows Default Cobalt Strike PowerShell Beacon
|
Powershell Script Block Logging 4104
|
T1059.001
T1204.002
|
TTP
|
Cobalt Strike
|
2026-05-13
|
|
GetLocalUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Active Directory Discovery, Malicious PowerShell
|
2026-05-13
|
|
Windows PUA Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
Anomaly
|
SamSam Ransomware, Cactus Ransomware, IcedID, VanHelsing Ransomware, Active Directory Lateral Movement, CISA AA22-320A, Seashell Blizzard, DarkGate Malware, DarkSide Ransomware, HAFNIUM Group, Rhysida Ransomware, Medusa Ransomware, Sandworm Tools, BlackByte Ransomware, DHS Report TA18-074A, Volt Typhoon
|
2026-05-13
|
|
Cisco NVM - Curl Execution With Insecure Flags
|
Cisco Network Visibility Module Flow Data
|
T1197
|
Anomaly
|
Microsoft WSUS CVE-2025-59287, Cisco Network Visibility Module Analytics, PromptLock
|
2026-07-14
|
|
Windows Error Report Created in ReportQueue Manually
|
Sysmon EventID 11
|
T1053.005
T1068
|
Anomaly
|
Windows Error Reporting Service Elevation of Privilege Vulnerability, RoguePlanet, Windows Privilege Escalation
|
2026-08-18
|
|
GetWmiObject User Account with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Winter Vivern, Active Directory Discovery, Malicious PowerShell
|
2026-05-13
|
|
Python PYTHONPATH Modification During Package Installation
|
Sysmon EventID 1, Sysmon EventID 13
|
T1195.002
T1574.007
|
TTP
|
Windows Registry Abuse, Windows Persistence Techniques, Compromised Windows Host, Malicious Python Package Installation, Suspicious Windows Registry Activities
|
2026-08-21
|
|
Windows Snake Malware Service Create
|
Windows Event Log System 7045
|
T1547.006
T1569.002
|
TTP
|
Compromised Windows Host, Snake Malware
|
2026-05-13
|
|
Cisco Secure Firewall - Privileged Command Execution via HTTP
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1505.003
|
Anomaly
|
Salt Typhoon, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1203
|
TTP
|
Citrix NetScaler ADC and NetScaler Gateway CVE-2025-5777, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Blocked Connection
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1018
T1046
T1110
T1203
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Possibly Compromised Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1203
T1587.001
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1027
T1190
T1204
T1210
|
TTP
|
Lumma Stealer, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Suspicious Process DNS Query Known Abuse Web Services
|
Sysmon EventID 22
|
T1059.005
|
TTP
|
Meduza Stealer, Cactus Ransomware, Braodo Stealer, WhisperGate, Data Destruction, Phemedrone Stealer, Malicious Inno Setup Loader, PXA Stealer, Snake Keylogger, RedLine Stealer, BlankGrabber Stealer, Remcos
|
2026-05-13
|
|
Cisco Secure Firewall - Malware File Downloaded
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Binary File Type Download
|
Cisco Secure Firewall Threat Defense File Event
|
T1059
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Repeated Blocked Connections
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1018
T1046
T1110
T1203
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Suspicious Process With Discord DNS Query
|
Sysmon EventID 22
|
T1059.005
|
Anomaly
|
Cactus Ransomware, WhisperGate, Data Destruction, Phantom Stealer, PXA Stealer, BlankGrabber Stealer
|
2026-06-25
|
|
Detect Windows DNS SIGRed via Splunk Stream
|
|
T1203
|
TTP
|
Windows DNS SIGRed CVE-2020-1350
|
2026-05-13
|
|
Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003.001
T1059.001
T1190
T1210
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1071
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
MCP Prompt Injection
|
MCP Server
|
T1059
|
TTP
|
Suspicious MCP Activities
|
2026-05-13
|
|
MCP Filesystem Server Suspicious Extension Write
|
MCP Server
|
T1059
|
Hunting
|
Suspicious MCP Activities
|
2026-05-13
|
|
ESXi Reverse Shell Patterns
|
VMWare ESXi Syslog
|
T1059
|
TTP
|
Black Basta Ransomware, ESXi Post Compromise
|
2026-05-13
|
|
Ollama Suspicious Prompt Injection Jailbreak
|
Ollama Server
|
T1059
T1190
|
Anomaly
|
Suspicious Ollama Activities
|
2026-05-13
|
|
Cisco IOS XE Guestshell Activation and Destroy
|
Cisco IOS Logs
|
T1059
T1611
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
PTC Windchill Gateway Command Execution
|
Windchill Log4j
|
T1005
T1059
T1190
|
Anomaly
|
PTC Windchill Exploitation
|
2026-06-14
|
|
Cisco IOS XE Request Platform Package Describe Shell Pattern
|
Cisco IOS Logs
|
T1059
T1190
|
TTP
|
Salt Typhoon
|
2026-05-20
|
|
PTC Windchill GW READY OK Probe
|
Windchill Log4j
|
T1059
T1190
|
Anomaly
|
PTC Windchill Exploitation
|
2026-06-14
|
|
Kubernetes Process with Resource Ratio Anomalies
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Inbound to Outbound Network IO Ratio
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Inbound Outbound Network IO
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Process with Anomalous Resource Utilisation
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Risk Rule for Dev Sec Ops by Repository
|
|
T1204.003
|
Correlation
|
Dev Sec Ops
|
2026-05-13
|
|
Windows Explorer LNK Exploit Process Launch With Padding
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1204.002
|
TTP
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Windows SQLCMD Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Hunting
|
GhostRedirector IIS Module and Rungan Backdoor, SQL Server Abuse
|
2026-05-13
|
|
Windows WMI Reconnaissance Class Query
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Linux Suspicious Docker Build Command Execution
|
Sysmon for Linux EventID 1
|
T1610
|
Anomaly
|
Linux Post-Exploitation
|
2026-07-08
|
|
Windows Explorer.exe Spawning PowerShell or Cmd
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1204.002
|
Hunting
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Windows Scheduled Task with Highest Privileges
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Scheduled Tasks, Castle RAT, Quasar RAT, CISA AA23-347A, Compromised Windows Host, RedLine Stealer, AsyncRAT, XWorm, SolarWinds WHD RCE Post Exploitation, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Wermgr Process Spawned CMD Or Powershell Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Trickbot, Qakbot
|
2026-05-13
|
|
Malicious PowerShell Process With Obfuscation Techniques
|
Sysmon EventID 1
|
T1059.001
|
TTP
|
Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Malicious PowerShell, Data Destruction, Hermetic Wiper
|
2026-05-13
|
|
Linux Possible System Binary Backdoor
|
Sysmon for Linux EventID 11
|
T1036
T1059.004
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
ETW Registry Disabled
|
Sysmon EventID 13
|
T1127
T1685
|
TTP
|
Windows Registry Abuse, CISA AA23-347A, Windows Privilege Escalation, Windows Persistence Techniques, Data Destruction, Hermetic Wiper
|
2026-05-13
|
|
Conti Common Exec parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
TTP
|
Ransomware, Compromised Windows Host, Hellcat Ransomware
|
2026-05-13
|
|
Windows ISO LNK File Creation
|
Sysmon EventID 11
|
T1204.001
T1566.001
|
Hunting
|
Amadey, AgentTesla, Gozi Malware, Azorult, IcedID, Spearphishing Attachments, Warzone RAT, APT37 Rustonotto and FadeStealer, Brute Ratel C4, Qakbot, Remcos
|
2026-05-13
|
|
Windows Suspect Process With Authentication Traffic
|
Sysmon EventID 3
|
T1087.002
T1204.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Linux Suspicious GCC Invocation Building Init Shared Object
|
Sysmon for Linux EventID 1
|
T1027.004
T1068
T1129
T1608
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Set Custom DNS ServerLevelPlugin Via Dnscmd
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Suspicious Process Executed From Container File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.008
T1204.002
|
TTP
|
Amadey, GhostRedirector IIS Module and Rungan Backdoor, Unusual Processes, APT37 Rustonotto and FadeStealer, Snake Keylogger, Water Gamayun, Remcos
|
2026-07-09
|
|
Windows DLL Side-Loading Process Child Of Calc
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.001
|
Anomaly
|
Qakbot, Earth Alux
|
2026-05-13
|
|
Powershell Defender Threat Actions Set to Allow
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
TTP
|
Salat Stealer
|
2026-05-12
|
|
Nishang PowershellTCPOneLine
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
TTP
|
Cleo File Transfer Software, HAFNIUM Group
|
2026-05-13
|
|
Windows Compatibility Telemetry Tampering Through Registry
|
Sysmon EventID 13
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Service Creation Using Registry Entry
|
Sysmon EventID 13
|
T1574.011
|
Anomaly
|
Salt Typhoon, Windows Registry Abuse, CISA AA23-347A, Active Directory Lateral Movement, Gh0st RAT, SnappyBee, Windows Persistence Techniques, Brute Ratel C4, China-Nexus Threat Activity, PlugX, Crypto Stealer, SolarWinds WHD RCE Post Exploitation, Suspicious Windows Registry Activities, Derusbi
|
2026-05-13
|
|
Windows Mustang Panda USB Tool Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1020
T1204.002
T1574.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows WinRAR Launched Outside Default Installation Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Remote Process Instantiation via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Salt Typhoon, Suspicious WMI Use, Void Manticore, CISA AA23-347A, Active Directory Lateral Movement, China-Nexus Threat Activity, Ransomware
|
2026-05-13
|
|
Scheduled Task Creation on Remote Endpoint using At
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.002
|
TTP
|
Scheduled Tasks, Active Directory Lateral Movement, 0bj3ctivity Stealer, Living Off The Land
|
2026-05-13
|
|
Schtasks Run Task On Demand
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053
|
Anomaly
|
Scheduled Tasks, XMRig, Industroyer2, Data Destruction, Medusa Ransomware, Qakbot, CISA AA22-257A
|
2026-05-13
|
|
Windows PowerShell FakeCAPTCHA Clipboard Execution
|
Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 1, Cisco Network Visibility Module Flow Data
|
T1059.001
T1059.003
T1204.001
|
TTP
|
Cisco Network Visibility Module Analytics, Interlock Ransomware, Fake CAPTCHA Campaigns, Scattered Lapsus$ Hunters, NetSupport RMM Tool Abuse
|
2026-07-14
|
|
Windows WinDBG Spawning AutoIt3
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Compromised Windows Host, DarkGate Malware
|
2026-05-13
|
|
Windows PowerShell Script From WindowsApps Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1204.002
|
TTP
|
MSIX Package Abuse, Malicious PowerShell
|
2026-05-13
|
|
Windows AutoIt3 Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Crypto Stealer, Handala Wiper, Void Manticore, DarkGate Malware
|
2026-05-13
|
|
Windows Enable Win32 ScheduledJob via Registry
|
Sysmon EventID 13
|
T1053.005
|
Anomaly
|
Scheduled Tasks, Active Directory Lateral Movement
|
2026-05-13
|
|
Clop Common Exec Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
TTP
|
Clop Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Windows WMI Process And Service List
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Anomaly
|
Prestige Ransomware, Windows Post-Exploitation
|
2026-05-13
|
|
Batch File Write to System32
|
Sysmon EventID 11
|
T1204.002
|
Anomaly
|
Compromised Windows Host, SamSam Ransomware
|
2026-07-02
|
|
Detect Path Interception By Creation Of program exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.009
|
TTP
|
Scattered Lapsus$ Hunters, Windows Persistence Techniques
|
2026-05-13
|
|
Scheduled Task Initiation on Remote Endpoint
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Scheduled Tasks, Active Directory Lateral Movement, Seashell Blizzard, Medusa Ransomware, Living Off The Land
|
2026-05-13
|
|
Windows Suspicious Child Process of Consent.EXE
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
T1068
T1548.002
|
Anomaly
|
Unusual Processes, Windows Privilege Escalation
|
2026-07-30
|
|
Detect Prohibited Applications Spawning cmd exe
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Hunting
|
Suspicious MSHTA Activity, Suspicious Zoom Child Processes, Suspicious Command-Line Executions, NOBELIUM Group
|
2026-05-13
|
|
Scheduled Task Deleted Or Created via CMD
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
Anomaly
|
Scattered Spider, CISA AA23-347A, Lokibot, Windows Persistence Techniques, Rhysida Ransomware, Sandworm Tools, China-Nexus Threat Activity, AsyncRAT, CISA AA22-257A, ShrinkLocker, MoonPeak, Remcos, Winter Vivern, Medusa Ransomware, Phemedrone Stealer, Scheduled Tasks, Salt Typhoon, Quasar RAT, APT37 Rustonotto and FadeStealer, Trickbot, RedLine Stealer, XWorm, Amadey, AgentTesla, NjRAT, Azorult, Prestige Ransomware, 0bj3ctivity Stealer, NOBELIUM Group, CISA AA24-241A, ValleyRAT, DarkCrystal RAT, Qakbot, Living Off The Land, PlugX, DHS Report TA18-074A, SolarWinds WHD RCE Post Exploitation, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Process Execution From RDP Share
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
BITSAdmin Download File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1105
T1197
|
TTP
|
Scattered Spider, Gozi Malware, Ingress Tool Transfer, BITS Jobs, Hellcat Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Flax Typhoon, DarkSide Ransomware, APT37 Rustonotto and FadeStealer, Living Off The Land
|
2026-05-13
|
|
Windows Identify Protocol Handlers
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Hunting
|
Living Off The Land
|
2026-05-13
|
|
Windows File Association Modification via Ftype
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Anomaly
|
Windows File Extension and Association Abuse
|
2026-05-13
|
|
MacOS Osascript Displaying Suspicious User Prompt
|
Osquery Results
|
T1056.002
T1059.002
|
Anomaly
|
MacOS Privilege Escalation
|
2026-08-31
|
|
Suspicious Linux Discovery Commands
|
Sysmon for Linux EventID 1
|
T1059.004
|
TTP
|
VoidLink Cloud-Native Linux Malware, Linux Post-Exploitation
|
2026-05-13
|
|
Ryuk Wake on LAN Command
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
TTP
|
Compromised Windows Host, Ryuk Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Linux Service Started Or Enabled
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, Gomir
|
2026-05-13
|
|
Linux Service Restarted
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Data Destruction, AwfulShred, Linux Living Off The Land, Gomir
|
2026-05-13
|
|
Windows SCCM Smsexec Spawned a Suspicious Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1068
T1574.001
|
Anomaly
|
Windows Privilege Escalation
|
2026-08-24
|
|
Linux Add Files In Known Crontab Directories
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, XorDDos
|
2026-05-13
|
|
Windows Scheduled Task Created Via XML
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
Anomaly
|
Scheduled Tasks, MoonPeak, CISA AA23-347A, Lokibot, Winter Vivern, Malicious Inno Setup Loader
|
2026-05-13
|
|
Linux Possible Cronjob Modification With Editor
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, XorDDos
|
2026-05-13
|
|
Suspicious msbuild path
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1127.001
|
TTP
|
Trusted Developer Utilities Proxy Execution MSBuild, Storm-2460 CLFS Zero Day Exploitation, Masquerading - Rename System Utilities, Living Off The Land, BlackByte Ransomware, Graceful Wipe Out Attack, Cobalt Strike
|
2026-05-13
|
|
Windows Known Abused DLL Created
|
Sysmon EventID 11
|
T1574.001
|
Anomaly
|
Windows Defense Evasion Tactics, Living Off The Land
|
2026-05-13
|
|
Linux At Allow Config File Creation
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Suspicious Privileged Container Execution
|
Sysmon for Linux EventID 1
|
T1059.004
T1610
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Possible Lateral Movement PowerShell Spawn
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
T1021.006
T1047
T1053.005
T1059.001
T1218.014
T1543.003
|
Anomaly
|
Scheduled Tasks, Malicious PowerShell, Active Directory Lateral Movement, Data Destruction, CISA AA24-241A, Microsoft WSUS CVE-2025-59287, Hermetic Wiper
|
2026-05-13
|
|
Remote WMI Command Attempt
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
IcedID, Suspicious WMI Use, CISA AA23-347A, Living Off The Land, Graceful Wipe Out Attack, Volt Typhoon
|
2026-05-13
|
|
Set Default PowerShell Execution Policy To Unrestricted or Bypass
|
Sysmon EventID 13
|
T1059.001
|
TTP
|
Credential Dumping, Malicious PowerShell, SystemBC, DarkGate Malware, HAFNIUM Group, Starland RAT Campaign, Data Destruction, Hermetic Wiper, SolarWinds WHD RCE Post Exploitation
|
2026-07-20
|
|
Windows Suspicious VMWare Tools Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
China-Nexus Threat Activity, ESXi Post Compromise
|
2026-05-13
|
|
Linux Suspicious XDG Autostart
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Command and Scripting Interpreter Hunting Path Traversal
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Hunting
|
Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Schtasks Create Run As System
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Scheduled Tasks, Castle RAT, Windows Persistence Techniques, Medusa Ransomware, Qakbot, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Windows TinyCC Shellcode Execution
|
Windows Event Log Security 4688, Sysmon EventID 1
|
T1027
T1036
T1059.003
|
TTP
|
Lotus Blossom Chrysalis Backdoor
|
2026-09-01
|
|
Windows User Execution Malicious URL Shortcut File
|
Sysmon EventID 11
|
T1204.002
|
Anomaly
|
NjRAT, Quasar RAT, APT37 Rustonotto and FadeStealer, Snake Keylogger, Chaos Ransomware, XWorm
|
2026-05-13
|
|
Windows Advanced Installer MSIX with AI_STUBS Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
T1218
T1553.005
|
TTP
|
MSIX Package Abuse
|
2026-05-13
|
|
Schtasks scheduling job on remote system
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Scheduled Tasks, Quasar RAT, Active Directory Lateral Movement, Prestige Ransomware, NOBELIUM Group, Compromised Windows Host, Phemedrone Stealer, Living Off The Land, RedLine Stealer
|
2026-05-13
|
|
Impacket Lateral Movement Commandline Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Gozi Malware, Storm-0501 Ransomware, Industroyer2, Active Directory Lateral Movement, Prestige Ransomware, WhisperGate, Data Destruction, Compromised Windows Host, CISA AA22-277A, Graceful Wipe Out Attack, Volt Typhoon
|
2026-05-13
|
|
Windows Scheduled Task Service Spawned Shell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
T1059
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Sysmon EventID 1, Cisco Network Visibility Module Flow Data
|
T1059.001
T1105
|
Anomaly
|
Cisco Network Visibility Module Analytics, Tuoni, HAFNIUM Group, NPM Supply Chain Compromise, IcedID, Data Destruction, Phemedrone Stealer, Winter Vivern, Hermetic Wiper, Ingress Tool Transfer, Malicious PowerShell, GhostRedirector IIS Module and Rungan Backdoor, APT37 Rustonotto and FadeStealer, XWorm, StealC Stealer, PHP-CGI RCE Attack on Japanese Organizations, Microsoft WSUS CVE-2025-59287, SysAid On-Prem Software CVE-2023-47246 Vulnerability, SolarWinds WHD RCE Post Exploitation, NetSupport RMM Tool Abuse
|
2026-07-14
|
|
Linux Shell Pseudo Device Reverse Shell
|
Sysmon for Linux EventID 1
|
T1048.003
T1059
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques, Compromised Linux Host, Command And Control, Linux Post-Exploitation
|
2026-07-08
|
|
Jscript Execution Using Cscript App
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.007
|
Anomaly
|
FIN7, Remcos
|
2026-08-31
|
|
Linux Possible Append Cronjob Entry on Existing Cronjob File
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, XorDDos
|
2026-05-13
|
|
Linux Netcat Outbound Connection
|
Sysmon for Linux EventID 3
|
T1059.004
|
Anomaly
|
Compromised Linux Host, Data Exfiltration, Command And Control, Linux Post-Exploitation
|
2026-07-08
|
|
Suspicious microsoft workflow compiler rename
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1127
|
Hunting
|
Masquerading - Rename System Utilities, Living Off The Land, BlackByte Ransomware, Trusted Developer Utilities Proxy Execution, Graceful Wipe Out Attack, Cobalt Strike
|
2026-05-13
|
|
Excessive Usage Of SC Service Utility
|
Sysmon EventID 1
|
T1569.002
|
Anomaly
|
Ransomware, Crypto Stealer, Azorult
|
2026-05-13
|
|
Windows Binary Execution from an Archive
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Remote Process Instantiation via WMI and PowerShell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Compromised Windows Host, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux Crontab Enumeration
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Industroyer2, VoidLink Cloud-Native Linux Malware, Data Destruction, Linux Living Off The Land, Gomir, Cisco Isovalent Suspicious Activity
|
2026-09-03
|
|
Linux Service File Created In Systemd Directory
|
Sysmon for Linux EventID 11
|
T1053.006
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, China-Nexus Threat Activity, Linux Living Off The Land, Gomir
|
2026-05-13
|
|
Windows XLL File Creation Outside of Typical Location
|
Sysmon EventID 11
|
T1059
T1129
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Windows TeamCity Payload Execution from Temp Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
T1190
T1505.003
|
TTP
|
JetBrains TeamCity Vulnerabilities, JetBrains TeamCity Unauthenticated RCE
|
2026-05-13
|
|
Living Off The Land Detection
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows Apache Benchmark Binary
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
MetaSploit
|
2026-05-13
|
|
Windows NorthStar C2 Agent Execution
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
T1547.001
T1608
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
MacOS AppleScript Shell Execution and Compilation
|
Osquery Results
|
T1059.002
|
Anomaly
|
MacOS Post-Exploitation
|
2026-09-03
|
|
Linux At Application Execution
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land, Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Vbscript Execution Using Wscript App
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.005
|
TTP
|
AsyncRAT, FIN7, Remcos
|
2026-05-13
|
|
Windows MSC EvilTwin Directory Path Manipulation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.005
T1203
T1218
|
TTP
|
Windows Defense Evasion Tactics, Living Off The Land, Water Gamayun
|
2026-05-13
|
|
Windows WMI Process Call Create
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
Hunting
|
Cactus Ransomware, IcedID, Suspicious WMI Use, CISA AA23-347A, Qakbot, Volt Typhoon
|
2026-05-13
|
|
Windows Compatibility Telemetry Suspicious Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Potential AppDomainManager Hijack Artifacts Creation
|
Sysmon EventID 11
|
T1574.014
|
Anomaly
|
SesameOp
|
2026-05-13
|
|
Windows Registry Delete Task SD
|
Sysmon EventID 12
|
T1053.005
T1685
|
Anomaly
|
Scheduled Tasks, Windows Registry Abuse, Windows Persistence Techniques
|
2026-05-13
|
|
Windows SSH Proxy Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1105
T1572
|
Anomaly
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows PaperCut NG Spawn Shell
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
T1133
T1190
|
TTP
|
Compromised Windows Host, PaperCut MF NG Vulnerability
|
2026-05-13
|
|
Execute Javascript With Jscript COM CLSID
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.005
|
TTP
|
Ransomware
|
2026-05-13
|
|
Linux MOTD Script Added
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Excessive distinct processes from Windows Temp
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
Meterpreter
|
2026-05-13
|
|
Reg exe Manipulating Windows Services Registry Keys
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.011
|
TTP
|
Living Off The Land, Windows Persistence Techniques, Windows Service Abuse
|
2026-05-13
|
|
Malicious PowerShell Process - Execution Policy Bypass
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Anomaly
|
Salt Typhoon, 0bj3ctivity Stealer, APT37 Rustonotto and FadeStealer, HAFNIUM Group, Starland RAT Campaign, China-Nexus Threat Activity, MuddyWater, DarkCrystal RAT, AsyncRAT, DHS Report TA18-074A, BlankGrabber Stealer, XWorm, Volt Typhoon
|
2026-07-20
|
|
Windows Command and Scripting Interpreter Path Traversal Exec
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
TTP
|
Compromised Windows Host, Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Binary Executed from Shared Memory Directory
|
Sysmon for Linux EventID 1
|
T1059
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
BITS Job Persistence
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1197
|
TTP
|
BITS Jobs, Living Off The Land
|
2026-05-13
|
|
Windows Common Abused Cmd Shell Risk Behavior
|
|
T1016
T1033
T1049
T1059
T1222
T1529
|
Correlation
|
Netsh Abuse, Azorult, Windows Defense Evasion Tactics, Disabling Security Tools, CISA AA23-347A, Windows Post-Exploitation, Sandworm Tools, FIN7, Qakbot, DarkCrystal RAT, Microsoft WSUS CVE-2025-59287, Volt Typhoon
|
2026-05-13
|
|
Linux Edit Cron Table Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Windows ScManager Security Descriptor Tampering Via Sc.EXE
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1569.002
|
TTP
|
Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Log4Shell CVE-2021-44228 Exploitation
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
CISA AA22-320A, Log4Shell CVE-2021-44228
|
2026-05-13
|
|
Excessive number of taskhost processes
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059
|
Anomaly
|
Meterpreter
|
2026-05-13
|
|
Suspicious MSBuild Rename
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1036.003
T1127.001
|
Hunting
|
Trusted Developer Utilities Proxy Execution MSBuild, Storm-2460 CLFS Zero Day Exploitation, Masquerading - Rename System Utilities, Living Off The Land, BlackByte Ransomware, Graceful Wipe Out Attack, Cobalt Strike
|
2026-05-13
|
|
Windows Crowdstrike RTR Script Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Anomaly
|
Suspicious MSHTA Activity, Cobalt Strike, Living Off The Land, Malicious PowerShell
|
2026-05-13
|
|
Windows Suspicious React or Next.js Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1059.003
T1190
|
TTP
|
React2Shell
|
2026-05-13
|
|
Windows PowerShell Process Implementing Manual Base64 Decoder
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1027.010
T1059.001
|
Anomaly
|
Deobfuscate-Decode Files or Information, Compromised Windows Host
|
2026-05-13
|
|
First Time Seen Running Windows Service
|
Windows Event Log System 7036
|
T1569.002
|
Anomaly
|
Orangeworm Attack Group, Windows Service Abuse, NOBELIUM Group
|
2026-05-13
|
|
Suspicious MSBuild Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1127.001
|
TTP
|
Trusted Developer Utilities Proxy Execution MSBuild, Storm-2460 CLFS Zero Day Exploitation, Living Off The Land
|
2026-05-13
|
|
Impacket Lateral Movement smbexec CommandLine Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Industroyer2, Active Directory Lateral Movement, Prestige Ransomware, WhisperGate, Data Destruction, Compromised Windows Host, CISA AA22-277A, Graceful Wipe Out Attack, Volt Typhoon
|
2026-05-13
|
|
Linux Docker Shell Execution
|
Sysmon for Linux EventID 1
|
T1059.013
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Msmpeng Application DLL Side Loading
|
Sysmon EventID 11
|
T1574.001
|
TTP
|
Ransomware, Revil Ransomware
|
2026-05-13
|
|
CMD Carry Out String Command Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Hunting
|
CISA AA23-347A, Log4Shell CVE-2021-44228, Rhysida Ransomware, Malicious Inno Setup Loader, Chaos Ransomware, AsyncRAT, IcedID, Gh0st RAT, Data Destruction, Winter Vivern, Hermetic Wiper, ProxyNotShell, Quasar RAT, Warzone RAT, DarkGate Malware, WhisperGate, RedLine Stealer, Crypto Stealer, NjRAT, Azorult, Interlock Rat, StealC Stealer, 0bj3ctivity Stealer, DarkCrystal RAT, Qakbot, Living Off The Land, PlugX
|
2026-05-13
|
|
Windows DLL Search Order Hijacking with iscsicpl
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.001
|
TTP
|
Compromised Windows Host, Windows Defense Evasion Tactics, Living Off The Land
|
2026-05-13
|
|
Windows Command Shell DCRat ForkBomb Payload
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
TTP
|
Compromised Windows Host, DarkCrystal RAT
|
2026-05-13
|
|
Socat Remote TCP Connection with Local Echo Disabled
|
Osquery Results, Sysmon for Linux EventID 1
|
T1059
T1572
|
Anomaly
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Revil Common Exec Parameter
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
TTP
|
Ransomware, Revil Ransomware
|
2026-05-13
|
|
Windows PowerShell Process With Malicious String
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Linux Possible Append Command To At Allow Config File
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Socat Network Listener Binding an Executable
|
Osquery Results, Sysmon for Linux EventID 1
|
T1059
T1572
|
TTP
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Process Execution via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Windows PowerShell Module File Created
|
Sysmon EventID 11
|
T1059.001
T1129
T1574
|
Anomaly
|
Windows Persistence Techniques, Malicious PowerShell
|
2026-05-13
|
|
Windows Phantom DLL Created on Disk
|
Sysmon EventID 11
|
T1068
T1574.001
|
TTP
|
RoguePlanet, Windows Defense Evasion Tactics, Windows Privilege Escalation
|
2026-08-20
|
|
Windows Rundll32 Execution With Log.DLL
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574
|
Anomaly
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Windows TeamCity Plugin Installed
|
Sysmon EventID 11
|
T1059
T1190
T1505.003
|
Anomaly
|
JetBrains TeamCity Vulnerabilities, JetBrains TeamCity Unauthenticated RCE
|
2026-05-13
|
|
Windows Masquerading Explorer As Child Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.001
|
TTP
|
Compromised Windows Host, Qakbot, Water Gamayun
|
2026-05-13
|
|
Linux Possible Privilege Escalation via PYTHONPATH
|
Sysmon for Linux EventID 11
|
T1068
T1574.007
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Linux Ghostscript Exploitation
|
Sysmon for Linux EventID 1
|
T1059
T1068
T1204.002
T1566
|
TTP
|
Unusual Processes, Suspicious Command-Line Executions, Linux Living Off The Land, Linux Post-Exploitation
|
2026-09-01
|
|
CMD Echo Pipe - Escalation
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
Suspicious microsoft workflow compiler usage
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1127
|
TTP
|
Trusted Developer Utilities Proxy Execution, Living Off The Land
|
2026-05-13
|
|
Windows SCCM Adsource DLL Was Planted In SMS Provider Directory
|
Sysmon EventID 11
|
T1574.002
|
TTP
|
Windows Privilege Escalation
|
2026-08-20
|
|
GitHub Workflow File Creation or Modification
|
Sysmon for Linux EventID 11, Sysmon EventID 11
|
T1195
T1554
T1574.006
|
Hunting
|
NPM Supply Chain Compromise
|
2026-05-13
|
|
Detection of tools built by NirSoft
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1072
|
Anomaly
|
Emotet Malware DHS Report TA18-201A
|
2026-05-13
|
|
Windows Universal Data Link File Creation
|
Sysmon EventID 11
|
T1204.002
T1566.001
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Detect Rare Executables
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204
|
Anomaly
|
Salt Typhoon, Unusual Processes, SnappyBee, China-Nexus Threat Activity, Rhysida Ransomware, Crypto Stealer
|
2026-05-13
|
|
Wmiprvse LOLBAS Execution Process Spawn
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Mock Trusted Directory MSC File Creation
|
Sysmon EventID 11
|
T1218.014
T1548.002
T1574
|
TTP
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-05-13
|
|
PowerShell Start-BitsTransfer
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1197
|
TTP
|
Gozi Malware, BITS Jobs
|
2026-05-13
|
|
Detect Use of cmd exe to Launch Script Interpreters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.003
|
Anomaly
|
Emotet Malware DHS Report TA18-201A, Suspicious Command-Line Executions, Azorult
|
2026-05-13
|
|
Linux Decode Base64 to Shell
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1027
T1059.004
|
TTP
|
Linux Living Off The Land, Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Detect Renamed PSExec
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1569.002
|
Hunting
|
Salt Typhoon, SamSam Ransomware, Cactus Ransomware, VanHelsing Ransomware, Active Directory Lateral Movement, CISA AA22-320A, DarkGate Malware, DarkSide Ransomware, HAFNIUM Group, China-Nexus Threat Activity, Medusa Ransomware, Rhysida Ransomware, Sandworm Tools, BlackByte Ransomware, DHS Report TA18-074A
|
2026-05-13
|
|
Windows Powershell RemoteSigned File
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
|
Anomaly
|
Amadey
|
2026-05-13
|
|
MSBuild Suspicious Spawned By Script Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1127.001
|
TTP
|
Trusted Developer Utilities Proxy Execution MSBuild, Storm-2460 CLFS Zero Day Exploitation
|
2026-05-13
|
|
Windows Account Access Removal via Logoff Exec
|
Sysmon EventID 1
|
T1059.001
T1531
|
Anomaly
|
Crypto Stealer
|
2026-05-13
|
|
Windows Shell Process from CrushFTP
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.001
T1059.003
T1190
T1505
|
TTP
|
CrushFTP Vulnerabilities
|
2026-05-13
|
|
Suspicious Scheduled Task from Public Directory
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
Anomaly
|
Scattered Spider, CISA AA23-347A, Lokibot, Windows Persistence Techniques, China-Nexus Threat Activity, Ryuk Ransomware, Malicious Inno Setup Loader, MoonPeak, Medusa Ransomware, Ransomware, Scheduled Tasks, Salt Typhoon, Quasar RAT, APT37 Rustonotto and FadeStealer, Crypto Stealer, XWorm, Azorult, CISA AA24-241A, DarkCrystal RAT, Living Off The Land, SolarWinds WHD RCE Post Exploitation, NetSupport RMM Tool Abuse
|
2026-05-13
|
|
Windows Outlook Macro Created by Suspicious Process
|
Sysmon EventID 11
|
T1059.005
T1137
|
TTP
|
NotDoor Malware
|
2026-05-13
|
|
Windows Get-Variable.EXE Execution from WindowsApps Folder
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1574.008
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Linux Unix Shell Enable All SysRq Functions
|
Sysmon for Linux EventID 1
|
T1059.004
|
Anomaly
|
Data Destruction, AwfulShred
|
2026-05-13
|
|
Linux Preload Hijack Library Calls
|
Sysmon for Linux EventID 1
|
T1574.006
|
TTP
|
Linux Privilege Escalation, Salt Typhoon, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, China-Nexus Threat Activity
|
2026-05-13
|
|
Schtasks used for forcing a reboot
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Ransomware, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows Cmdline Tool Execution From Non-Shell Process
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1059.007
|
Anomaly
|
Gozi Malware, Tuoni, CISA AA23-347A, Gh0st RAT, DarkGate Malware, Rhysida Ransomware, Medusa Ransomware, FIN7, Qakbot, CISA AA22-277A, Water Gamayun, BlankGrabber Stealer, Volt Typhoon, SolarWinds WHD RCE Post Exploitation
|
2026-05-13
|
|
Process Writing DynamicWrapperX
|
Sysmon EventID 11
|
T1059
T1559.001
|
Hunting
|
Remcos
|
2026-05-13
|
|
Linux Suspicious React or Next.js Child Process
|
Sysmon for Linux EventID 1
|
T1059.004
T1190
|
TTP
|
React2Shell
|
2026-05-13
|
|
Impacket Lateral Movement WMIExec Commandline Parameters
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Gozi Malware, Storm-0501 Ransomware, Industroyer2, Active Directory Lateral Movement, Prestige Ransomware, WhisperGate, Data Destruction, Compromised Windows Host, CISA AA22-277A, Graceful Wipe Out Attack, Volt Typhoon
|
2026-05-13
|
|
Single Letter Process On Endpoint
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
|
TTP
|
DHS Report TA18-074A, Compromised Windows Host
|
2026-05-13
|
|
Svchost LOLBAS Execution Process Spawn
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Scheduled Tasks, Active Directory Lateral Movement, Living Off The Land, Hellcat Ransomware
|
2026-07-27
|
|
Shai-Hulud Workflow File Creation or Modification
|
Sysmon for Linux EventID 11, Sysmon EventID 11
|
T1195
T1554
T1574.006
|
TTP
|
NPM Supply Chain Compromise
|
2026-05-13
|
|
Script Execution via WMI
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1047
|
TTP
|
Suspicious WMI Use, Scattered Spider
|
2026-05-13
|
|
Windows EFI Volume Mount Attempt Via Mountvol
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1204.002
T1542
T1688
|
Anomaly
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Service Execution RemCom
|
Windows Event Log Security 4688, Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1569.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows PowGoop Beacon Decoding
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Detect Outbound LDAP Traffic
|
Cisco Secure Firewall Threat Defense Connection Event, Palo Alto Network Traffic, Cisco Secure Access Firewall
|
T1059
T1190
|
Hunting
|
Cisco Secure Access Analytics, Cisco Secure Firewall Threat Defense Analytics, Log4Shell CVE-2021-44228
|
2026-05-13
|
|
Detect Windows DNS SIGRed via Zeek
|
|
T1203
|
TTP
|
Windows DNS SIGRed CVE-2020-1350
|
2026-05-13
|
|
Linux Adding Crontab Using List Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Industroyer2, VoidLink Cloud-Native Linux Malware, Data Destruction, Linux Living Off The Land, Gomir, Cisco Isovalent Suspicious Activity
|
2026-09-03
|