|
O365 ApplicationImpersonation Role Assigned
|
O365
|
T1098.002
|
TTP
|
Office 365 Collection Techniques, NOBELIUM Group, Office 365 Persistence Mechanisms
|
2026-05-13
|
|
O365 Privileged Role Assigned To Service Principal
|
Office 365 Universal Audit Log
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD Admin Consent Bypassed by Service Principal
|
Azure Active Directory Add app role assignment to service principal
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, NOBELIUM Group
|
2026-05-13
|
|
Okta Non-Standard VPN Usage
|
Okta
|
T1078
T1090
T1572
|
TTP
|
Suspicious Okta Activity, Remote Employment Fraud
|
2026-05-13
|
|
O365 Mailbox Read Access Granted to Application
|
O365 Update application.
|
T1098.003
T1114.002
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
Azure AD Service Principal Authentication
|
Azure Active Directory Sign-in activity
|
T1078.004
|
TTP
|
Azure Active Directory Account Takeover, NOBELIUM Group
|
2026-05-13
|
|
Azure Runbook Webhook Created
|
Azure Audit Create or Update an Azure Automation webhook
|
T1078.004
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Azure AD Service Principal Owner Added
|
Azure Active Directory Add owner to application
|
T1098
|
TTP
|
NOBELIUM Group, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence
|
2026-05-13
|
|
Azure AD Privileged Role Assigned
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
NOBELIUM Group, Azure Active Directory Persistence, Storm-0501 Ransomware, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD Application Administrator Role Assigned
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 Service Principal Privilege Escalation
|
O365 Add app role assignment grant to user.
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Office 365 Account Takeover
|
2026-05-13
|
|
AWS IAM Successful Group Deletion
|
AWS CloudTrail DeleteGroup
|
T1069.003
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
ASL AWS IAM Failure Group Deletion
|
ASL AWS CloudTrail
|
T1098
|
Anomaly
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
ASL AWS Create Policy Version to allow all resources
|
ASL AWS CloudTrail
|
T1078.004
|
TTP
|
AWS IAM Privilege Escalation, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 Privileged Role Assigned
|
Office 365 Universal Audit Log
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 FullAccessAsApp Permission Assigned
|
O365 Update application.
|
T1098.002
T1098.003
|
TTP
|
NOBELIUM Group, Office 365 Persistence Mechanisms
|
2026-05-13
|
|
AWS IAM Failure Group Deletion
|
AWS CloudTrail DeleteGroup
|
T1098
|
Anomaly
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD User ImmutableId Attribute Updated
|
Azure Active Directory Update user
|
T1098
|
TTP
|
Hellcat Ransomware, Azure Active Directory Persistence
|
2026-05-13
|
|
O365 Application Registration Owner Added
|
O365 Add owner to application.
|
T1098
|
TTP
|
NOBELIUM Group, Office 365 Persistence Mechanisms
|
2026-05-13
|
|
AWS Create Policy Version to allow all resources
|
AWS CloudTrail CreatePolicyVersion
|
T1078.004
|
TTP
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD Successful PowerShell Authentication
|
Azure Active Directory
|
T1078.004
T1586.003
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD Multiple AppIDs and UserAgents Authentication Spike
|
Azure Active Directory Sign-in activity
|
T1078
|
Anomaly
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD Service Principal Privilege Escalation
|
Azure Active Directory Add app role assignment to service principal
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
O365 Cross-Tenant Access Change
|
Office 365 Universal Audit Log
|
T1484.002
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
GCP Authentication Failed During MFA Challenge
|
Google Workspace login_failure
|
T1078.004
T1586.003
T1621
|
TTP
|
Scattered Lapsus$ Hunters, GCP Account Takeover
|
2026-05-13
|
|
Azure AD Authentication Failed During MFA Challenge
|
Azure Active Directory
|
T1078.004
T1586.003
T1621
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD Tenant Wide Admin Consent Granted
|
Azure Active Directory Consent to application
|
T1098.003
|
TTP
|
NOBELIUM Group, Azure Active Directory Persistence
|
2026-05-13
|
|
O365 Tenant Wide Admin Consent Granted
|
O365 Consent to application.
|
T1098.003
|
TTP
|
NOBELIUM Group, Office 365 Persistence Mechanisms
|
2026-05-13
|
|
O365 Security And Compliance Alert Triggered
|
|
T1078.004
|
TTP
|
Office 365 Account Takeover
|
2026-05-13
|
|
Azure AD PIM Role Assignment Activated
|
Azure Active Directory
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 Elevated Mailbox Permission Assigned
|
O365 Add-MailboxPermission
|
T1098.002
|
TTP
|
Office 365 Collection Techniques
|
2026-05-13
|
|
Azure AD User Enabled And Password Reset
|
Azure Active Directory Update user, Azure Active Directory Reset password (by admin), Azure Active Directory Enable account
|
T1098
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD New Federated Domain Added
|
Azure Active Directory Set domain authentication
|
T1484.002
|
TTP
|
Hellcat Ransomware, Azure Active Directory Persistence, Storm-0501 Ransomware, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
ASL AWS IAM Successful Group Deletion
|
ASL AWS CloudTrail
|
T1069.003
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
AWS IAM Delete Policy
|
AWS CloudTrail DeletePolicy
|
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD New MFA Method Registered
|
Azure Active Directory Update user
|
T1098.005
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 High Privilege Role Granted
|
O365 Add member to role.
|
T1098.003
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
O365 Application Available To Other Tenants
|
Office 365 Universal Audit Log
|
T1098.003
|
TTP
|
Azure Active Directory Account Takeover, Azure Active Directory Persistence, Data Exfiltration
|
2026-05-13
|
|
AWS SAML Update identity provider
|
AWS CloudTrail UpdateSAMLProvider
|
T1078
|
TTP
|
Cloud Federated Credential Abuse
|
2026-05-13
|
|
GCP Multiple Failed MFA Requests For User
|
Google Workspace
|
T1078.004
T1586.003
T1621
|
TTP
|
Scattered Lapsus$ Hunters, GCP Account Takeover
|
2026-05-13
|
|
ASL AWS SAML Update identity provider
|
ASL AWS CloudTrail
|
T1078
|
TTP
|
Cloud Federated Credential Abuse
|
2026-05-13
|
|
Azure AD FullAccessAsApp Permission Assigned
|
Azure Active Directory Update application
|
T1098.002
T1098.003
|
TTP
|
NOBELIUM Group, Azure Active Directory Persistence
|
2026-05-13
|
|
Azure AD New Custom Domain Added
|
Azure Active Directory Add unverified domain
|
T1484.002
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
O365 New MFA Method Registered
|
O365 Update user.
|
T1098.005
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
ASL AWS IAM Delete Policy
|
ASL AWS CloudTrail
|
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
GCP Successful Single-Factor Authentication
|
Google Workspace
|
T1078.004
T1586.003
|
TTP
|
Scattered Lapsus$ Hunters, GCP Account Takeover
|
2026-05-13
|
|
Geographic Improbable Location
|
Okta
|
T1078
|
Anomaly
|
Remote Employment Fraud
|
2026-05-13
|
|
AWS SetDefaultPolicyVersion
|
AWS CloudTrail SetDefaultPolicyVersion
|
T1078.004
|
TTP
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD Successful Single-Factor Authentication
|
Azure Active Directory
|
T1078.004
T1586.003
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
O365 Admin Consent Bypassed by Service Principal
|
O365 Add app role assignment to service principal.
|
T1098.003
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
O365 Mailbox Folder Read Permission Assigned
|
O365 ModifyFolderPermissions
|
T1098.002
|
TTP
|
Office 365 Collection Techniques
|
2026-05-13
|
|
AWS Successful Single-Factor Authentication
|
AWS CloudTrail ConsoleLogin
|
T1078.004
T1586.003
|
TTP
|
AWS Identity and Access Management Account Takeover
|
2026-05-13
|
|
GCP Detect gcploit framework
|
|
T1078
|
TTP
|
GCP Cross Account Activity
|
2026-05-13
|
|
O365 Service Principal New Client Credentials
|
O365
|
T1098.001
|
TTP
|
NOBELIUM Group, Office 365 Persistence Mechanisms
|
2026-05-13
|
|
Azure AD Global Administrator Role Assigned
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 Mailbox Folder Read Permission Granted
|
O365 ModifyFolderPermissions
|
T1098.002
|
TTP
|
Office 365 Collection Techniques
|
2026-05-13
|
|
Azure AD Multiple Failed MFA Requests For User
|
Azure Active Directory Sign-in activity
|
T1078.004
T1586.003
T1621
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD PIM Role Assigned
|
Azure Active Directory
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD Service Principal New Client Credentials
|
Azure Active Directory
|
T1098.001
|
TTP
|
NOBELIUM Group, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD Privileged Role Assigned to Service Principal
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, NOBELIUM Group, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
AWS Bedrock Invoke Model Access Denied
|
AWS CloudTrail
|
T1078
T1550
|
TTP
|
AWS Bedrock Security
|
2026-05-13
|
|
O365 Multiple AppIDs and UserAgents Authentication Spike
|
O365 UserLoginFailed, O365 UserLoggedIn
|
T1078
|
Anomaly
|
Office 365 Account Takeover
|
2026-05-13
|
|
Microsoft Intune DeviceManagementConfigurationPolicies
|
Azure Monitor Activity
|
T1021.007
T1072
T1484
T1685
T1686
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Kubernetes Cron Job Creation
|
Kubernetes Audit
|
T1053.007
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Windows Cloud Files Filter Log Created by Non-System Process
|
Sysmon EventID 11
|
T1068
|
TTP
|
Windows Privilege Escalation, RedSun
|
2026-05-01
|
|
Windows Scheduled Task with Suspicious Name
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Windows Persistence Techniques, 0bj3ctivity Stealer, APT37 Rustonotto and FadeStealer, Ransomware, Scheduled Tasks, Ryuk Ransomware, Castle RAT
|
2026-05-13
|
|
Schedule Task with Rundll32 Command Trigger
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Living Off The Land, Windows Persistence Techniques, Castle RAT, Scheduled Tasks, Compromised Windows Host, Trickbot, IcedID
|
2026-05-13
|
|
Windows AD DCShadow Privileges ACL Addition
|
Windows Event Log Security 5136
|
T1207
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Large Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
T1135
|
Anomaly
|
Active Directory Lateral Movement, Active Directory Privilege Escalation
|
2026-07-05
|
|
Windows PowerShell ScheduleTask
|
Powershell Script Block Logging 4104
|
T1053.005
T1059.001
|
Anomaly
|
Scattered Spider, Scheduled Tasks, Starland RAT Campaign
|
2026-07-20
|
|
Windows AD add Self to Group
|
Windows Event Log Security 4728
|
T1098
|
TTP
|
Medusa Ransomware, Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-06-01
|
|
Linux Auditd Nopasswd Entry In Sudoers File
|
Linux Auditd Proctitle
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques, Compromised Linux Host, Salt Typhoon
|
2026-05-13
|
|
Windows AD Short Lived Domain Account ServicePrincipalName
|
Windows Event Log Security 5136
|
T1098
|
TTP
|
Sneaky Active Directory Persistence Tricks, Interlock Ransomware
|
2026-05-13
|
|
Cisco Isovalent - Late Process Execution
|
Cisco Isovalent Process Exec
|
T1543
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows AD Same Domain SID History Addition
|
Windows Event Log Security 4738, Windows Event Log Security 4742
|
T1134.005
|
TTP
|
Windows Persistence Techniques, Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows Uncommon Remote Thread Creation In Browser Process
|
Sysmon EventID 8
|
T1055.001
|
Anomaly
|
Living Off The Land, IcedID, Qakbot
|
2026-06-29
|
|
Windows AD GPO Disabled
|
Windows Event Log Security 5136
|
T1484.001
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Python Site Hooks Creation During Package Installation
|
Sysmon EventID 1, Sysmon EventID 11
|
T1195.002
T1546
|
TTP
|
Windows Persistence Techniques, Malicious Python Package Installation, Compromised Windows Host
|
2026-08-21
|
|
Windows Suspicious Driver Loaded Path
|
Sysmon EventID 6
|
T1543.003
|
TTP
|
CISA AA22-320A, Interlock Ransomware, APT37 Rustonotto and FadeStealer, AgentTesla, Snake Keylogger, XMRig, BlackByte Ransomware
|
2026-05-13
|
|
Powershell Fileless Process Injection via GetProcAddress
|
Powershell Script Block Logging 4104
|
T1055
T1059.001
|
TTP
|
Hermetic Wiper, Hellcat Ransomware, Malicious PowerShell, Data Destruction
|
2026-05-13
|
|
Windows Vulnerable Driver Installed
|
Windows Event Log System 7045
|
T1543.003
|
TTP
|
Void Manticore, Windows Drivers
|
2026-09-08
|
|
Windows AD Dangerous User ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Powershell Execute COM Object
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Hermetic Wiper, Malicious PowerShell, Ransomware, Data Destruction
|
2026-05-13
|
|
Detect Baron Samedit CVE-2021-3156 Segfault
|
|
T1068
|
TTP
|
Baron Samedit CVE-2021-3156
|
2026-05-13
|
|
Linux Auditd Setuid Using Setcap Utility
|
Linux Auditd Execve
|
T1548.001
|
TTP
|
Linux Persistence Techniques, Compromised Linux Host, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Defender Threat Detected on Kernel Object Path
|
Windows Event Log Defender 1117, Windows Event Log Defender 1116
|
T1068
T1211
|
TTP
|
RoguePlanet
|
2026-08-18
|
|
Rundll32 Create Remote Thread To A Process
|
Sysmon EventID 8
|
T1055
|
TTP
|
Living Off The Land, IcedID
|
2026-06-29
|
|
Cisco Isovalent - Shell Execution
|
Cisco Isovalent Process Exec
|
T1543
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows MsMpEng Writing to System32
|
Sysmon EventID 15, Sysmon EventID 11
|
T1068
T1543.003
|
TTP
|
Windows Privilege Escalation, RedSun, BlueHammer, Windows Drivers
|
2026-04-27
|
|
Windows Admon Default Group Policy Object Modified
|
Windows Active Directory Admon
|
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Non-System Process Querying Definition Update
|
Sysmon EventID 22
|
T1068
T1071.001
|
Anomaly
|
Windows Privilege Escalation, BlueHammer, RedSun
|
2026-04-27
|
|
Windows Bluetooth Service Installed From Uncommon Location
|
Windows Event Log System 7045
|
T1036
T1543.003
|
Anomaly
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Linux Auditd Setuid Using Chmod Utility
|
Linux Auditd Proctitle
|
T1548.001
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Auditd Doas Conf File Creation
|
Linux Auditd Cwd, Linux Auditd Path
|
T1548.003
|
TTP
|
Linux Persistence Techniques, Compromised Linux Host, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Scheduled Task DLL Module Loaded
|
Sysmon EventID 7
|
T1053
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
WinEvent Scheduled Task Created to Spawn Shell
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Windows Persistence Techniques, CISA AA22-257A, 0bj3ctivity Stealer, Ransomware, Scheduled Tasks, Compromised Windows Host, Windows Error Reporting Service Elevation of Privilege Vulnerability, Winter Vivern, SystemBC, Ryuk Ransomware, China-Nexus Threat Activity, Medusa Ransomware, Castle RAT, Salt Typhoon
|
2026-05-13
|
|
Windows Hidden Schedule Task Settings
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Malicious Inno Setup Loader, CISA AA22-257A, Active Directory Discovery, Industroyer2, Hellcat Ransomware, Scheduled Tasks, Compromised Windows Host, Cactus Ransomware, Data Destruction
|
2026-05-13
|
|
Windows Service Create RemComSvc
|
Windows Event Log System 7045
|
T1543.003
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows AD Cross Domain SID History Addition
|
Windows Event Log Security 4738, Windows Event Log Security 4742
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows Suspicious C2 Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
TTP
|
DarkSide Ransomware, Graceful Wipe Out Attack, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, Storm-0501 Ransomware, LockBit Ransomware, Remote Monitoring and Management Software, Meterpreter, Trickbot, Tuoni, Gozi Malware, Cobalt Strike, BlackByte Ransomware, Brute Ratel C4
|
2026-05-13
|
|
Linux Auditd Sudo Or Su Execution
|
Linux Auditd Proctitle
|
T1548.003
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Azure PowerShell Module Installation Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1021.007
T1069.003
T1078
T1098
T1136.003
|
Anomaly
|
Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence
|
2026-05-13
|
|
Create Remote Thread In Shell Application
|
Sysmon EventID 8
|
T1055
|
TTP
|
IcedID, Warzone RAT, Qakbot
|
2026-06-29
|
|
Windows Multiple Accounts Disabled
|
Windows Event Log Security 4725
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Linux Auditd Edit Cron Table Parameter
|
Linux Auditd Syscall
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques, Compromised Linux Host
|
2026-05-13
|
|
Windows Suspicious Defender Update Activity in INetCache
|
Sysmon EventID 23, Sysmon EventID 11
|
T1068
T1105
|
Anomaly
|
Windows Persistence Techniques, BlueHammer
|
2026-07-20
|
|
Windows AD Dangerous Group ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Linux Auditd Unload Module Via Modprobe
|
Linux Auditd Execve
|
T1547.006
|
TTP
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Auditd Unix Shell Configuration Modification
|
Linux Auditd Cwd, Linux Auditd Path
|
T1546.004
|
TTP
|
QuietVault, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques, Compromised Linux Host
|
2026-05-13
|
|
Windows Driver Load Non-Standard Path
|
Windows Event Log System 7045
|
T1014
T1068
|
TTP
|
CISA AA22-320A, AgentTesla, Windows Drivers, BlackSuit Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Print Spooler Failed to Load a Plug-in
|
Windows Event Log Printservice 808, Windows Event Log Printservice 4909
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows Process Injection into Commonly Abused Processes
|
Sysmon EventID 10
|
T1055.002
|
Anomaly
|
SAP NetWeaver Exploitation, BishopFox Sliver Adversary Emulation Framework, Earth Alux, APT37 Rustonotto and FadeStealer
|
2026-09-08
|
|
Detect Baron Samedit CVE-2021-3156
|
|
T1068
|
TTP
|
Baron Samedit CVE-2021-3156
|
2026-05-13
|
|
Windows AD Object Owner Updated
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD GPO New CSE Addition
|
Windows Event Log Security 5136
|
T1222.001
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Multiple Accounts Deleted
|
Windows Event Log Security 4726
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Spoolsv Writing a DLL - Sysmon
|
Sysmon EventID 11
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Cisco Isovalent - Nsenter Usage in Kubernetes Pod
|
Cisco Isovalent Process Exec
|
T1543
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Python PTH File Creation During Package Installation
|
Sysmon EventID 1, Sysmon EventID 11
|
T1195.002
T1546
|
Anomaly
|
Windows Persistence Techniques, Malicious Python Package Installation, Compromised Windows Host
|
2026-08-21
|
|
Cisco Isovalent - Potential Escape to Host
|
Cisco Isovalent Process Exec
|
T1611
|
Anomaly
|
VoidLink Cloud-Native Linux Malware, Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows Access Token Winlogon Duplicate Handle In Uncommon Path
|
Sysmon EventID 10
|
T1134.001
|
Anomaly
|
PathWiper, Brute Ratel C4
|
2026-09-08
|
|
Powershell Remote Thread To Known Windows Process
|
Sysmon EventID 8
|
T1055
|
TTP
|
Trickbot
|
2026-07-01
|
|
Windows Admon Group Policy Object Created
|
Windows Active Directory Admon
|
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Linux Auditd Install Kernel Module Using Modprobe Utility
|
Linux Auditd Syscall
|
T1547.006
|
Anomaly
|
Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques, Compromised Linux Host, Linux Rootkit
|
2026-05-13
|
|
Windows DnsAdmins New Member Added
|
Windows Event Log Security 4732
|
T1098
|
TTP
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Trickbot Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1055
|
TTP
|
Hellcat Ransomware, Trickbot
|
2026-05-13
|
|
Windows Admin Password Changed by Non-Admin
|
Windows Event Log Security 4723
|
T1068
T1543.003
|
TTP
|
Windows Privilege Escalation, BlueHammer
|
2026-04-27
|
|
Windows AD Self DACL Assignment
|
Windows Event Log Security 5136
|
T1098
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Handle Duplication in Known UAC-Bypass Binaries
|
Sysmon EventID 10
|
T1134.001
|
Anomaly
|
Castle RAT
|
2026-09-08
|
|
Linux Malformed Auth Entry
|
Linux Secure
|
T1068
|
Anomaly
|
Linux Privilege Escalation
|
2026-05-06
|
|
Detect WMI Event Subscription Persistence
|
Sysmon EventID 20
|
T1546.003
|
TTP
|
Suspicious WMI Use, Hellcat Ransomware
|
2026-05-13
|
|
Windows AD Domain Replication ACL Addition
|
Windows Event Log Security 5136
|
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Linux Auditd Insert Kernel Module Using Insmod Utility
|
Linux Auditd Syscall
|
T1547.006
|
Anomaly
|
Linux Privilege Escalation, XorDDos, Linux Persistence Techniques, Compromised Linux Host, Linux Rootkit
|
2026-05-13
|
|
Linux Auditd Kernel Module Using Rmmod Utility
|
Linux Auditd Syscall
|
T1547.006
|
TTP
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Builtin Account Name Was Changed
|
Windows Event Log Security 4781
|
T1036.010
T1078.003
|
TTP
|
Compromised Windows Host, Windows Defense Evasion Tactics
|
2026-08-24
|
|
Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
ValleyRAT, Water Gamayun
|
2026-05-13
|
|
Windows Multiple Account Passwords Changed
|
Windows Event Log Security 4724
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Windows Potato Privilege Escalation Tool Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File
|
Linux Auditd Cwd, Linux Auditd Path
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, XorDDos, Linux Persistence Techniques, Compromised Linux Host
|
2026-05-13
|
|
Windows Suspicious Defender Engine or Signature Files Created
|
Sysmon EventID 11
|
T1068
|
Anomaly
|
Windows Privilege Escalation, BlueHammer
|
2026-04-27
|
|
Windows PowerView AD Access Control List Enumeration
|
Powershell Script Block Logging 4104
|
T1069
T1078.002
|
TTP
|
Rhysida Ransomware, Active Directory Privilege Escalation, Active Directory Discovery
|
2026-05-13
|
|
Windows Unsigned MS DLL Side-Loading
|
Sysmon EventID 7
|
T1547
T1574.001
|
Anomaly
|
XWorm, Derusbi, Earth Alux, APT29 Diplomatic Deceptions with WINELOADER, China-Nexus Threat Activity, Salt Typhoon
|
2026-05-13
|
|
Cisco NVM - Suspicious Network Connection From Process With No Args
|
Cisco Network Visibility Module Flow Data
|
T1055
T1218
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Linux Auditd Possible Access Or Modification Of Sshd Config File
|
Linux Auditd Cwd, Linux Auditd Path
|
T1098.004
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Event Triggered Image File Execution Options Injection
|
Windows Event Log Application 3000
|
T1546.012
|
Hunting
|
Windows Persistence Techniques
|
2026-05-13
|
|
Loading Of Dynwrapx Module
|
Sysmon EventID 7
|
T1055.001
|
TTP
|
AsyncRAT, Remcos
|
2026-05-13
|
|
Spoolsv Suspicious Process Access
|
Sysmon EventID 10
|
T1068
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows AD Domain Root ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
UAC Bypass MMC Load Unsigned Dll
|
Sysmon EventID 7
|
T1218.014
T1548.002
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows MSI Rollback Script Deleted By Non-Msiexec Process
|
Sysmon EventID 26, Sysmon EventID 23
|
T1068
T1218.007
|
TTP
|
Windows Privilege Escalation
|
2026-07-20
|
|
Linux Pedit Offset Out Of Bounds
|
Linux Messages Syslog
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-07-06
|
|
Windows Process Injection Remote Thread
|
Sysmon EventID 8
|
T1055.002
|
TTP
|
Graceful Wipe Out Attack, Qakbot, Water Gamayun, Earth Alux, Vidar Stealer, Warzone RAT, Phantom Stealer
|
2026-08-14
|
|
Linux Auditd At Application Execution
|
Linux Auditd Syscall
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques, Compromised Linux Host
|
2026-05-13
|
|
Suspicious Kerberos Service Ticket Request
|
Windows Event Log Security 4769
|
T1078.002
|
TTP
|
Active Directory Kerberos Attacks, Active Directory Privilege Escalation, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Windows Default Group Policy Object Modified
|
Windows Event Log Security 5136
|
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Cisco NVM - Non-Network Binary Making Network Connection
|
Cisco Network Visibility Module Flow Data
|
T1036
T1055
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Detect Baron Samedit CVE-2021-3156 via OSQuery
|
|
T1068
|
TTP
|
Baron Samedit CVE-2021-3156
|
2026-05-13
|
|
Unusual Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
|
Hunting
|
Scattered Lapsus$ Hunters, Active Directory Kerberos Attacks, Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux Auditd Service Restarted
|
Linux Auditd Proctitle
|
T1053.006
|
Anomaly
|
Gomir, Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques, Data Destruction, Compromised Linux Host, AwfulShred
|
2026-05-13
|
|
Windows Increase in User Modification Activity
|
Windows Event Log Security 4720
|
T1098
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
WinEvent Scheduled Task Created Within Public Path
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Remcos, Compromised Windows Host, Ryuk Ransomware, Prestige Ransomware, China-Nexus Threat Activity, Medusa Ransomware, Industroyer2, 0bj3ctivity Stealer, Data Destruction, IcedID, Salt Typhoon, CISA AA23-347A, XWorm, CISA AA22-257A, APT37 Rustonotto and FadeStealer, Scheduled Tasks, Winter Vivern, SystemBC, Castle RAT, ValleyRAT, Malicious Inno Setup Loader, AsyncRAT, Windows Persistence Techniques, Ransomware, Quasar RAT, PlugX, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux Dirty Frag Kernel Privilege Escalation
|
Linux Auditd Syscall
|
T1068
T1548.001
|
TTP
|
Linux Privilege Escalation
|
2026-07-06
|
|
Schedule Task with HTTP Command Arguments
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Living Off The Land, Windows Persistence Techniques, Hellcat Ransomware, Scheduled Tasks, Winter Vivern, Compromised Windows Host
|
2026-05-13
|
|
Windows RMM Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
Anomaly
|
Command And Control, Interlock Ransomware, Scattered Spider, Remote Monitoring and Management Software, Seashell Blizzard, Ransomware, Cactus Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Gozi Malware, Scattered Lapsus$ Hunters, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
Randomly Generated Scheduled Task Name
|
Windows Event Log Security 4698
|
T1053.005
|
Hunting
|
Scheduled Tasks, 0bj3ctivity Stealer, CISA AA22-257A, Active Directory Lateral Movement
|
2026-05-13
|
|
WinEvent Windows Task Scheduler Event Action Started
|
Windows Event Log TaskScheduler 201, Windows Event Log TaskScheduler 200
|
T1053.005
|
Hunting
|
Remcos, DarkCrystal RAT, Prestige Ransomware, Industroyer2, BlackSuit Ransomware, Data Destruction, IcedID, CISA AA24-241A, Amadey, CISA AA22-257A, Qakbot, SolarWinds WHD RCE Post Exploitation, Scheduled Tasks, Winter Vivern, SystemBC, ValleyRAT, Malicious Inno Setup Loader, Windows Persistence Techniques, AsyncRAT, Sandworm Tools, PlugX
|
2026-05-13
|
|
Windows Scheduled Task Created in a Group Policy Object
|
Windows Event Log Security 5145
|
T1053.005
T1484.001
|
TTP
|
Living Off The Land, Windows Persistence Techniques, Scheduled Tasks
|
2026-05-13
|
|
Windows AD ServicePrincipalName Added To Domain Account
|
Windows Event Log Security 5136
|
T1098
|
TTP
|
Sneaky Active Directory Persistence Tricks, Interlock Ransomware
|
2026-05-13
|
|
Windows Increase in Group or Object Modification Activity
|
Windows Event Log Security 4663
|
T1098
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Powershell COM Hijacking InprocServer32 Modification
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Linux Auditd Copy Fail Privilege Escalation
|
Linux Auditd Syscall
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-05-13
|
|
Windows Remote Image Load
|
Sysmon EventID 7
|
T1059
T1068
T1129
T1203
|
Anomaly
|
Ransomware, LockBit Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows KrbRelayUp Service Creation
|
Windows Event Log System 7045
|
T1543.003
|
TTP
|
Local Privilege Escalation With KrbRelayUp, Compromised Windows Host
|
2026-05-13
|
|
Suspicious Computer Account Name Change
|
Windows Event Log Security 4781
|
T1078.002
|
TTP
|
sAMAccountName Spoofing and Domain Controller Impersonation, Scattered Lapsus$ Hunters, Active Directory Privilege Escalation, Compromised Windows Host
|
2026-05-13
|
|
Windows Suspicious Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
TTP
|
DarkSide Ransomware, Graceful Wipe Out Attack, APT37 Rustonotto and FadeStealer, Hellcat Ransomware, LockBit Ransomware, Remote Monitoring and Management Software, Meterpreter, Trickbot, Tuoni, Gozi Malware, Cobalt Strike, BlackByte Ransomware, Brute Ratel C4
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Command
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Windows Persistence Techniques, SolarWinds WHD RCE Post Exploitation, APT37 Rustonotto and FadeStealer, Seashell Blizzard, Ransomware, Scheduled Tasks, Quasar RAT, Ryuk Ransomware
|
2026-05-13
|
|
Windows AD SID History Attribute Modified
|
Windows Event Log Security 5136
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Cloud Files Filter Loaded by Uncommon Process
|
Sysmon EventID 7
|
T1543.003
|
Anomaly
|
BlueHammer, RedSun
|
2026-05-18
|
|
Windows Access Token Manipulation Winlogon Duplicate Token Handle
|
Sysmon EventID 10
|
T1134.001
|
Hunting
|
Brute Ratel C4
|
2026-09-08
|
|
Linux Binary Launched Process with Null Argv
|
Linux Messages Syslog
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-07-17
|
|
Unusual Number of Remote Endpoint Authentication Events
|
Windows Event Log Security 4624
|
T1078
|
Hunting
|
Active Directory Privilege Escalation, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Vulnerable Driver Loaded
|
Sysmon EventID 6
|
T1543.003
|
Hunting
|
Void Manticore, BlackByte Ransomware, Windows Drivers
|
2026-05-13
|
|
Clop Ransomware Known Service Name
|
Windows Event Log System 7045
|
T1543
|
TTP
|
Clop Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Windows AD Dangerous Deny ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Suspicious PlistBuddy Usage via OSquery
|
Osquery Results
|
T1543.001
|
TTP
|
Silver Sparrow
|
2026-05-13
|
|
Windows Driver Inventory
|
|
T1068
|
Hunting
|
Windows Drivers
|
2026-05-13
|
|
Windows AD GPO Deleted
|
Windows Event Log Security 5136
|
T1484.001
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Short Lived Scheduled Task
|
Windows Event Log Security 4698, Windows Event Log Security 4699
|
T1053.005
|
Anomaly
|
CISA AA22-257A, Scheduled Tasks, Compromised Windows Host, Active Directory Lateral Movement, CISA AA23-347A
|
2026-07-07
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Randomly Generated Windows Service Name
|
Windows Event Log System 7045
|
T1543.003
|
Hunting
|
Active Directory Lateral Movement, BlackSuit Ransomware
|
2026-05-13
|
|
Windows VSSVC Process Accessing Defender Engine
|
Sysmon EventID 10
|
T1068
|
TTP
|
Windows Privilege Escalation, RedSun
|
2026-05-01
|
|
Windows Group Policy Object Created
|
Windows Event Log Security 5136, Windows Event Log Security 5137
|
T1078.002
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows AD Privileged Group Modification
|
Windows Event Log Security 4728
|
T1098
|
TTP
|
Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Cisco Isovalent - Kprobe Spike
|
Cisco Isovalent Process Kprobe
|
T1068
|
Hunting
|
VoidLink Cloud-Native Linux Malware, Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows PowerShell MSIX Package Installation
|
Powershell Script Block Logging 4104
|
T1059.001
T1547.001
|
TTP
|
Malicious PowerShell, MSIX Package Abuse
|
2026-05-13
|
|
PowerShell PInvoke Process Injection API Chain
|
Powershell Script Block Logging 4104
|
T1055.001
T1055.003
T1055.004
T1055.012
T1055.013
T1059.001
T1620
|
TTP
|
VIP Keylogger, Phantom Stealer
|
2026-06-25
|
|
Windows Drivers Loaded by Signature
|
Sysmon EventID 6
|
T1014
T1068
|
Hunting
|
AgentTesla, CISA AA22-320A, BlackByte Ransomware, Windows Drivers
|
2026-05-13
|
|
Windows Suspicious Burst of Password Changes
|
Windows Event Log Security 4724, Windows Event Log Security 4723
|
T1068
|
TTP
|
Windows Privilege Escalation, BlueHammer
|
2026-04-29
|
|
Linux Auditd Possible Setuid Execve Privesc
|
Linux Auditd Execve
|
T1068
|
Anomaly
|
Linux Privilege Escalation
|
2026-07-06
|
|
Suspicious Ticket Granting Ticket Request
|
Windows Event Log Security 4781, Windows Event Log Security 4768
|
T1078.002
|
Hunting
|
Active Directory Kerberos Attacks, Active Directory Privilege Escalation, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Linux PF_ALG Registration Outside of Boot Window
|
Linux Messages Syslog
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-07-17
|
|
Linux Auditd Possible Access To Sudoers File
|
Linux Auditd Cwd, Linux Auditd Path
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques, Compromised Linux Host, Salt Typhoon
|
2026-05-13
|
|
Windows AD Hidden OU Creation
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
WMI Permanent Event Subscription - Sysmon
|
Sysmon EventID 21
|
T1546.003
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Linux Suspicious Namespace Creation
|
Linux Auditd Syscall, Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-05-12
|
|
Windows AD AdminSDHolder ACL Modified
|
Windows Event Log Security 5136
|
T1546
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD Domain Root ACL Deletion
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Cisco Isovalent - Cron Job Creation
|
Cisco Isovalent Process Exec
|
T1053.003
T1053.007
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence
|
2026-05-13
|
|
Spoolsv Suspicious Loaded Modules
|
Sysmon EventID 7
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows Privilege Escalation System Process Without System Parent
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, BlackSuit Ransomware
|
2026-05-13
|
|
Windows AD Privileged Account SID History Addition
|
Windows Event Log Security 4738, Windows Event Log Security 4742
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks, Compromised Windows Host
|
2026-05-13
|
|
Windows PUA Named Pipe
|
Sysmon EventID 17, Sysmon EventID 18
|
T1021.002
T1055
T1559
|
Anomaly
|
VanHelsing Ransomware, DarkSide Ransomware, CISA AA22-320A, Sandworm Tools, Seashell Blizzard, DHS Report TA18-074A, Cactus Ransomware, HAFNIUM Group, Rhysida Ransomware, Volt Typhoon, DarkGate Malware, Medusa Ransomware, SamSam Ransomware, IcedID, BlackByte Ransomware, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux Auditd Doas Tool Execution
|
Linux Auditd Syscall
|
T1548.003
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Access Token Manipulation SeDebugPrivilege
|
Windows Event Log Security 4703
|
T1134.002
|
Anomaly
|
Lokibot, GhostRedirector IIS Module and Rungan Backdoor, China-Nexus Threat Activity, WinDealer RAT, Vidar Stealer, Tuoni, Salt Typhoon, CISA AA23-347A, Meduza Stealer, DarkGate Malware, ValleyRAT, AsyncRAT, PathWiper, SnappyBee, Derusbi, PlugX, Gh0st RAT, Scattered Lapsus$ Hunters, Salat Stealer, Brute Ratel C4
|
2026-08-14
|
|
Windows Error Report Created in ReportQueue Manually
|
Sysmon EventID 11
|
T1053.005
T1068
|
Anomaly
|
Windows Privilege Escalation, RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-08-18
|
|
Print Spooler Adding A Printer Driver
|
Windows Event Log Printservice 316
|
T1547.012
|
TTP
|
PrintNightmare CVE-2021-34527, Black Basta Ransomware
|
2026-05-13
|
|
Windows Snake Malware Service Create
|
Windows Event Log System 7045
|
T1547.006
T1569.002
|
TTP
|
Snake Malware, Compromised Windows Host
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco IOS XE WebUI Login From IOSd Local Port
|
Cisco IOS Logs
|
T1078
T1190
|
TTP
|
Salt Typhoon
|
2026-05-19
|
|
AWS Bedrock Claude Unusually Large Prompts
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-08
|
|
AWS Bedrock Claude High Risk Filesystem and Exec Tool Invocation
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
Cisco ASA - User Privilege Level Change
|
Cisco ASA Logs
|
T1078.003
T1098
|
Anomaly
|
ArcaneDoor, Suspicious Cisco Adaptive Security Appliance Activity
|
2026-05-13
|
|
Splunk User Enumeration Attempt
|
Splunk
|
T1078
|
TTP
|
Splunk Vulnerabilities
|
2026-05-14
|
|
ESXi Account Modified
|
VMWare ESXi Syslog
|
T1078
T1098
T1136.001
|
Anomaly
|
ESXi Post Compromise, Black Basta Ransomware
|
2026-05-13
|
|
PingID Mismatch Auth Source and Verification Response
|
PingID
|
T1098.005
T1556.006
T1621
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
ESXi User Granted Admin Role
|
VMWare ESXi Syslog
|
T1078
T1098
|
TTP
|
ESXi Post Compromise, Black Basta Ransomware
|
2026-05-13
|
|
Okta Successful Single Factor Authentication
|
Okta
|
T1078.004
T1586.003
T1621
|
Anomaly
|
Okta Account Takeover
|
2026-05-13
|
|
AWS Bedrock Claude Hostile Prompt Sentiment
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
M365 Copilot Application Usage Pattern Anomalies
|
M365 Copilot Graph API
|
T1078
|
Anomaly
|
Suspicious Microsoft 365 Copilot Activities
|
2026-05-13
|
|
AWS Bedrock Claude Possible Prompt Injection
|
AWS Bedrock Claude
|
T1055
|
Hunting
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
PingID New MFA Method Registered For User
|
PingID
|
T1098.005
T1556.006
T1621
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
Cisco IOS XE Guestshell Activation and Destroy
|
Cisco IOS Logs
|
T1059
T1611
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
PingID New MFA Method After Credential Reset
|
PingID
|
T1098.005
T1556.006
T1621
|
TTP
|
Scattered Lapsus$ Hunters, Compromised User Account
|
2026-05-13
|
|
AWS Bedrock Claude Sensitive Data in Prompts
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
Zoom High Video Latency
|
|
T1078
|
Anomaly
|
Remote Employment Fraud
|
2026-05-13
|
|
Cisco ASA - New Local User Account Created
|
Cisco ASA Logs
|
T1078.003
T1136.001
|
Anomaly
|
Suspicious Cisco Adaptive Security Appliance Activity
|
2026-05-13
|
|
Okta Phishing Detection with FastPass Origin Check
|
Okta
|
T1078.001
T1556
|
TTP
|
Okta Account Takeover
|
2026-05-13
|
|
Cisco IOS XE WebUI Programmatic Configuration
|
Cisco IOS Logs
|
T1078
T1190
|
Anomaly
|
Salt Typhoon
|
2026-09-08
|
|
ESXi Shared or Stolen Root Account
|
VMWare ESXi Syslog
|
T1078
|
Anomaly
|
ESXi Post Compromise, Black Basta Ransomware
|
2026-05-13
|
|
Okta ThreatInsight Threat Detected
|
Okta
|
T1078.004
|
Anomaly
|
Okta Account Takeover
|
2026-05-13
|
|
ESXi External Root Login Activity
|
VMWare ESXi Syslog
|
T1078
|
Anomaly
|
ESXi Post Compromise, Black Basta Ransomware
|
2026-05-13
|
|
M365 Copilot Session Origin Anomalies
|
M365 Copilot Graph API
|
T1078
|
Anomaly
|
Suspicious Microsoft 365 Copilot Activities
|
2026-05-13
|
|
AWS Bedrock Claude excessive use of tokens
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
PingID Multiple Failed MFA Requests For User
|
PingID
|
T1078
T1110
T1621
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
Okta Suspicious Activity Reported
|
Okta
|
T1078.001
|
TTP
|
Okta Account Takeover
|
2026-05-13
|
|
VMWare Aria Operations Exploit Attempt
|
Palo Alto Network Threat
|
T1068
T1133
T1190
T1210
|
TTP
|
VMware Aria Operations vRealize CVE-2023-20887
|
2026-05-13
|
|
Microsoft SharePoint Server Elevation of Privilege
|
Suricata
|
T1068
|
Anomaly
|
Microsoft SharePoint Server Elevation of Privilege CVE-2023-29357
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen IP Address
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen Country
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Cloud Instance Modified By Previously Unseen User
|
AWS CloudTrail
|
T1078.004
|
Anomaly
|
Suspicious Cloud Instance Activities
|
2026-05-13
|
|
Cloud Compute Instance Created By Previously Unseen User
|
AWS CloudTrail
|
T1078.004
|
Anomaly
|
Cloud Cryptomining
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen City
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Cloud API Calls From Previously Unseen User Roles
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud User Activities
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen Region
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Monitor Registry Keys for Print Monitors
|
Sysmon EventID 13
|
T1547.010
|
TTP
|
Suspicious Windows Registry Activities, Windows Persistence Techniques, Windows Registry Abuse
|
2026-05-13
|
|
Windows Bypass UAC via Pkgmgr Tool
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1548.002
|
Anomaly
|
Warzone RAT
|
2026-05-13
|
|
Linux Insert Kernel Module Using Insmod Utility
|
Sysmon for Linux EventID 1
|
T1547.006
|
Anomaly
|
Linux Persistence Techniques, XorDDos, Linux Privilege Escalation, Linux Rootkit
|
2026-05-13
|
|
Linux c89 Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Usermod Root UID Set
|
Sysmon for Linux EventID 1
|
T1078
T1098
T1548.001
|
TTP
|
Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation
|
2026-07-08
|
|
Windows Remote Assistance Spawning Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
Unusual Processes, Compromised Windows Host
|
2026-05-13
|
|
Windows Audit Policy Auditing Option Modified - Registry
|
Sysmon EventID 13
|
T1547.014
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows COM Hijacking InprocServer32 Modification
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1546.015
|
TTP
|
Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Linux Doas Tool Execution
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Scheduled Task with Highest Privileges
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
TTP
|
AsyncRAT, XWorm, SolarWinds WHD RCE Post Exploitation, RedLine Stealer, NetSupport RMM Tool Abuse, Scheduled Tasks, Quasar RAT, Compromised Windows Host, Castle RAT, CISA AA23-347A
|
2026-05-13
|
|
FodHelper UAC Bypass
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1112
T1548.002
|
TTP
|
BlankGrabber Stealer, Windows Defense Evasion Tactics, Compromised Windows Host, IcedID, ValleyRAT
|
2026-05-13
|
|
Linux File Creation In Profile Directory
|
Sysmon for Linux EventID 11
|
T1546.004
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Possible Access Or Modification Of sshd Config File
|
Sysmon for Linux EventID 1
|
T1098.004
|
Anomaly
|
Linux Persistence Techniques, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Possible Nimbuspwn Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation
|
2026-07-08
|
|
Linux GDB Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Service Initiation on Remote Endpoint
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543.003
|
TTP
|
Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Linux OpenVPN Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows New Default File Association Value Set
|
Sysmon EventID 13
|
T1546.001
|
Hunting
|
Windows Persistence Techniques, Windows Privilege Escalation, Prestige Ransomware, Hermetic Wiper, Data Destruction, Windows Registry Abuse
|
2026-05-13
|
|
Linux Suspicious GCC Invocation Building Init Shared Object
|
Sysmon for Linux EventID 1
|
T1027.004
T1068
T1129
T1608
|
TTP
|
Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation
|
2026-07-08
|
|
Windows Local LLM Framework Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-07-15
|
|
Linux Gem Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Entra User Management Via Azure CLI
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1078.004
T1098
T1136
|
Anomaly
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Screensaver Event Trigger Execution
|
Sysmon EventID 13
|
T1546.002
|
TTP
|
Windows Persistence Techniques, Windows Privilege Escalation, Hermetic Wiper, Data Destruction, Windows Registry Abuse
|
2026-05-13
|
|
Windows Rasautou DLL Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055.001
T1218
|
TTP
|
Windows Defense Evasion Tactics, Hellcat Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Windows Process With NamedPipe CommandLine
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
Anomaly
|
Windows Defense Evasion Tactics
|
2026-07-08
|
|
DLLHost with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Storm-2460 CLFS Zero Day Exploitation, Graceful Wipe Out Attack, Cactus Ransomware, Earth Alux, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
SLUI Spawning a Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, DarkSide Ransomware, Compromised Windows Host
|
2026-05-13
|
|
NET Profiler UAC bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Compatibility Telemetry Tampering Through Registry
|
Sysmon EventID 13
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Guest Account Enabled Via Net.EXE
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1078.001
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Service Create with Tscon
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543.003
T1563.002
|
TTP
|
Windows RDP Artifacts and Defense Evasion, Active Directory Lateral Movement, Compromised Windows Host
|
2026-05-13
|
|
Services Escalate Exe
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1548
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, Cobalt Strike, BlackByte Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Windows Defender MpClient.dll Loaded by Non-Defender Process
|
Sysmon EventID 7
|
T1068
|
Anomaly
|
RoguePlanet
|
2026-08-19
|
|
Scheduled Task Creation on Remote Endpoint using At
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.002
|
TTP
|
Living Off The Land, 0bj3ctivity Stealer, Scheduled Tasks, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Change File Association Command To Notepad
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1546.001
|
TTP
|
Compromised Windows Host, Prestige Ransomware
|
2026-05-13
|
|
Schtasks Run Task On Demand
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053
|
Anomaly
|
CISA AA22-257A, Qakbot, Industroyer2, XMRig, Scheduled Tasks, Medusa Ransomware, Data Destruction
|
2026-05-13
|
|
Spoolsv Writing a DLL
|
Sysmon EventID 1, Windows Event Log Security 4688, Sysmon EventID 11
|
T1547.012
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527, Compromised Windows Host
|
2026-05-13
|
|
Windows Enable Win32 ScheduledJob via Registry
|
Sysmon EventID 13
|
T1053.005
|
Anomaly
|
Scheduled Tasks, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Privilege Escalation User Process Spawn System Process
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, BlackSuit Ransomware, GhostRedirector IIS Module and Rungan Backdoor, Compromised Windows Host
|
2026-05-13
|
|
Linux Apparmor Bypass Via Aaexec
|
Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-06-30
|
|
Scheduled Task Initiation on Remote Endpoint
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
TTP
|
Living Off The Land, Seashell Blizzard, Scheduled Tasks, Medusa Ransomware, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Suspicious Child Process of Consent.EXE
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1059
T1068
T1548.002
|
Anomaly
|
Windows Privilege Escalation, Unusual Processes
|
2026-07-30
|
|
Suspicious DLLHost no Command Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
Cactus Ransomware, Cobalt Strike, BlackByte Ransomware, Graceful Wipe Out Attack
|
2026-05-13
|
|
Scheduled Task Deleted Or Created via CMD
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
Anomaly
|
Lokibot, Remcos, AgentTesla, Azorult, DarkCrystal RAT, Prestige Ransomware, China-Nexus Threat Activity, Medusa Ransomware, RedLine Stealer, 0bj3ctivity Stealer, Trickbot, NjRAT, CISA AA24-241A, Salt Typhoon, CISA AA23-347A, Amadey, XWorm, CISA AA22-257A, Qakbot, SolarWinds WHD RCE Post Exploitation, Scattered Spider, APT37 Rustonotto and FadeStealer, NetSupport RMM Tool Abuse, Scheduled Tasks, Winter Vivern, DHS Report TA18-074A, ValleyRAT, Rhysida Ransomware, Living Off The Land, AsyncRAT, Windows Persistence Techniques, ShrinkLocker, Sandworm Tools, Quasar RAT, Phemedrone Stealer, MoonPeak, PlugX, NOBELIUM Group
|
2026-05-13
|
|
Linux pkexec Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Shim Database File Creation
|
Sysmon EventID 11
|
T1546.011
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Suspicious PlistBuddy Usage
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543.001
|
TTP
|
Silver Sparrow
|
2026-05-13
|
|
MacOS LoginHook Persistence
|
Osquery Results
|
T1037.002
|
TTP
|
MacOS Post-Exploitation
|
2026-05-13
|
|
SearchProtocolHost with no Command Line with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Hellcat Ransomware, Compromised Windows Host, Cactus Ransomware, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
SilentCleanup UAC Bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Registry Abuse, MoonPeak, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Privilege Escalation Suspicious Process Elevation
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, GhostRedirector IIS Module and Rungan Backdoor, BlackSuit Ransomware
|
2026-05-13
|
|
Linux Service Started Or Enabled
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Gomir, Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Process Injection In Non-Service SearchIndexer
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
Qakbot
|
2026-05-13
|
|
Wscript Or Cscript Suspicious Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
T1134.004
T1543
|
Anomaly
|
XWorm, Remcos, ShrinkLocker, FIN7, Starland RAT Campaign, 0bj3ctivity Stealer, MuddyWater, WhisperGate, VIP Keylogger, Unusual Processes, NjRAT, Data Destruction, Axios Supply Chain Post Compromise
|
2026-07-20
|
|
Linux Service Restarted
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Gomir, Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques, Data Destruction, AwfulShred
|
2026-05-13
|
|
Linux UDEV Rule Created
|
Sysmon for Linux EventID 11
|
T1037
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation
|
2026-07-08
|
|
Windows SCCM Smsexec Spawned a Suspicious Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
T1574.001
|
Anomaly
|
Windows Privilege Escalation
|
2026-08-24
|
|
Linux Add Files In Known Crontab Directories
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, XorDDos, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Scheduled Task Created Via XML
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
Anomaly
|
Malicious Inno Setup Loader, Lokibot, Scheduled Tasks, Winter Vivern, MoonPeak, CISA AA23-347A
|
2026-05-13
|
|
Windows ComputerDefaults Spawning a Process
|
Sysmon EventID 1
|
T1548.002
|
TTP
|
Castle RAT, BlankGrabber Stealer
|
2026-05-13
|
|
Linux Possible Cronjob Modification With Editor
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, XorDDos, Linux Persistence Techniques
|
2026-05-13
|
|
Windows UAC Bypass Suspicious Escalation Behavior
|
Sysmon EventID 1
|
T1548.002
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, Compromised Windows Host
|
2026-05-13
|
|
Runas Execution in CommandLine
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1134.001
|
Hunting
|
Windows Privilege Escalation, Data Destruction, Hermetic Wiper, Quasar RAT
|
2026-05-13
|
|
Linux At Allow Config File Creation
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Linux Persistence Techniques, Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Emacs Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Possible Lateral Movement PowerShell Spawn
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1021.003
T1021.006
T1047
T1053.005
T1059.001
T1218.014
T1543.003
|
Anomaly
|
Microsoft WSUS CVE-2025-59287, Malicious PowerShell, CISA AA24-241A, Scheduled Tasks, Hermetic Wiper, Data Destruction, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux Telnet Authentication Bypass
|
Sysmon for Linux EventID 1
|
T1548
|
TTP
|
Telnetd CVE-2026-24061
|
2026-05-13
|
|
Registry Keys Used For Privilege Escalation
|
Sysmon EventID 13
|
T1546.012
|
TTP
|
Windows Privilege Escalation, Suspicious Windows Registry Activities, Cloud Federated Credential Abuse, Hermetic Wiper, Data Destruction, Windows Registry Abuse
|
2026-05-13
|
|
Active Directory Privilege Escalation Identified
|
|
T1484
|
Correlation
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Sdclt UAC Bypass
|
Sysmon EventID 13, Sysmon EventID 12
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Suspicious XDG Autostart
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Winhlp32 Spawning a Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
Remcos, Compromised Windows Host
|
2026-05-13
|
|
Linux Docker Root Directory Mount
|
Sysmon for Linux EventID 1
|
T1611
|
TTP
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Schtasks Create Run As System
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
TTP
|
Windows Persistence Techniques, Qakbot, SolarWinds WHD RCE Post Exploitation, Scheduled Tasks, Medusa Ransomware, Castle RAT
|
2026-05-13
|
|
GPUpdate with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Hellcat Ransomware, Compromised Windows Host, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
Linux Visudo Utility Execution
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Default Group Policy Object Modified with GPME
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks, Active Directory Privilege Escalation
|
2026-05-13
|
|
Linux Find Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Csvtool Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows List ENV Variables Via SET Command From Uncommon Parent
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows MOF Event Triggered Execution via WMI
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1546.003
|
TTP
|
Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Notepad with no Command Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
BishopFox Sliver Adversary Emulation Framework
|
2026-05-13
|
|
Windows AppCertDLL Modification Via Command Line
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1546.009
|
Anomaly
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-07-27
|
|
Linux File Creation In System Generator Directory
|
Sysmon for Linux EventID 11
|
T1037.005
T1547
|
Anomaly
|
Linux Persistence Techniques
|
2026-07-08
|
|
Windows Suspicious Process File Path
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1036.005
T1543
|
TTP
|
Lokibot, Remcos, SesameOp, AgentTesla, WhisperGate, Azorult, GhostRedirector IIS Module and Rungan Backdoor, Earth Alux, DarkCrystal RAT, Volt Typhoon, Prestige Ransomware, Swift Slicer, China-Nexus Threat Activity, RedLine Stealer, StealC Stealer, Handala Wiper, Industroyer2, Trickbot, Vidar Stealer, NailaoLocker Ransomware, Data Destruction, IcedID, PromptLock, BlackByte Ransomware, Axios Supply Chain Post Compromise, CISA AA23-347A, Salt Typhoon, Amadey, Meduza Stealer, XWorm, Phantom Stealer, Qakbot, Graceful Wipe Out Attack, LockBit Ransomware, Void Manticore, Starland RAT Campaign, XMRig, Water Gamayun, SystemBC, Warzone RAT, DarkGate Malware, Double Zero Destructor, Castle RAT, ValleyRAT, Rhysida Ransomware, Malicious Inno Setup Loader, AsyncRAT, Chaos Ransomware, Interlock Ransomware, SnappyBee, VIP Keylogger, RoguePlanet, Quasar RAT, Phemedrone Stealer, MoonPeak, PlugX, Hermetic Wiper, Interlock Rat, Brute Ratel C4
|
2026-09-01
|
|
Windows Process Execution in Temp Dir
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1036.005
T1543
|
Anomaly
|
Lokibot, Remcos, XWorm, PathWiper, SesameOp, Qakbot, AgentTesla, RoguePlanet, Ransomware, Trickbot, Ryuk Ransomware, NjRAT, PromptLock, Axios Supply Chain Post Compromise, Salat Stealer, Gh0st RAT
|
2026-09-01
|
|
Linux File Created In Kernel Driver Directory
|
Sysmon for Linux EventID 11
|
T1547.006
|
Anomaly
|
Linux Rootkit, Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Schtasks scheduling job on remote system
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
TTP
|
Living Off The Land, Scheduled Tasks, Quasar RAT, Compromised Windows Host, Phemedrone Stealer, Prestige Ransomware, NOBELIUM Group, Active Directory Lateral Movement, RedLine Stealer
|
2026-05-13
|
|
Impacket Lateral Movement Commandline Parameters
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Industroyer2, Storm-0501 Ransomware, WhisperGate, Compromised Windows Host, Gozi Malware, Prestige Ransomware, Volt Typhoon, Data Destruction, CISA AA22-277A, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Privilege Escalation Attempt Via MSI Rollback
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Windows Scheduled Task Service Spawned Shell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
T1059
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Allow Operation with Consent Admin
|
Sysmon EventID 13
|
T1548
|
TTP
|
Azorult, MoonPeak, Ransomware, Windows Registry Abuse
|
2026-05-13
|
|
Linux APT Privilege Escalation
|
Sysmon for Linux EventID 1, Cisco Isovalent Process Exec
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux MySQL Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Possible Append Cronjob Entry on Existing Cronjob File
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, XorDDos, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Wermgr Spawning System Integrity Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
T1134.001
|
TTP
|
Windows Privilege Escalation, RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-08-18
|
|
Windows Process Injection Wermgr Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
Anomaly
|
RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability, Qakbot
|
2026-08-18
|
|
Potential password in username
|
Linux Secure
|
T1078.003
T1552.001
|
Hunting
|
Credential Dumping, Insider Threat
|
2026-05-13
|
|
Overwriting Accessibility Binaries
|
Sysmon EventID 11
|
T1546.008
|
TTP
|
Hermetic Wiper, Windows Privilege Escalation, Data Destruction, Flax Typhoon
|
2026-05-13
|
|
Detect Excessive Account Lockouts From Endpoint
|
|
T1078.002
|
Anomaly
|
Active Directory Password Spraying
|
2026-05-13
|
|
Linux Persistence and Privilege Escalation Risk Behavior
|
|
T1548
|
Correlation
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
WSReset UAC Bypass
|
Sysmon EventID 13, Sysmon EventID 12
|
T1548.002
|
TTP
|
Living Off The Land, Windows Registry Abuse, MoonPeak, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Crontab Enumeration
|
Sysmon for Linux EventID 1, Cisco Isovalent Process Exec
|
T1053.003
|
Hunting
|
Gomir, Industroyer2, Scheduled Tasks, Linux Living Off The Land, Cisco Isovalent Suspicious Activity, Linux Privilege Escalation, Linux Persistence Techniques, Data Destruction, VoidLink Cloud-Native Linux Malware
|
2026-09-03
|
|
Linux Busybox Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Service File Created In Systemd Directory
|
Sysmon for Linux EventID 11
|
T1053.006
|
Anomaly
|
Gomir, Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware
|
2026-05-13
|
|
Windows NorthStar C2 Agent Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1204.002
T1547.001
T1608
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Linux Cpulimit Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux At Application Execution
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Cisco Isovalent Suspicious Activity, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Linux Octave Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Node Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Possible Access To Sudoers File
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
China-Nexus Threat Activity, Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon
|
2026-05-13
|
|
Active Setup Registry Autostart
|
Sysmon EventID 13
|
T1547.014
|
TTP
|
Windows Privilege Escalation, Windows Persistence Techniques, Data Destruction, Hermetic Wiper
|
2026-05-13
|
|
Windows Compatibility Telemetry Suspicious Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Registry BootExecute Modification
|
Sysmon EventID 13
|
T1542
T1547.001
|
TTP
|
Windows BootKits
|
2026-05-13
|
|
Windows Boot or Logon Autostart Execution In Startup Folder
|
Sysmon EventID 11
|
T1547.001
|
Anomaly
|
PromptFlux, XWorm, BlankGrabber Stealer, Chaos Ransomware, Interlock Ransomware, APT37 Rustonotto and FadeStealer, Phantom Stealer, Starland RAT Campaign, Quasar RAT, Crypto Stealer, Gozi Malware, NjRAT, RedLine Stealer
|
2026-07-20
|
|
Windows Registry Delete Task SD
|
Sysmon EventID 12
|
T1053.005
T1685
|
Anomaly
|
Windows Persistence Techniques, Scheduled Tasks, Windows Registry Abuse
|
2026-05-13
|
|
Linux MOTD Script Added
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Registry Keys for Creating SHIM Databases
|
Sysmon EventID 13
|
T1546.011
|
TTP
|
Suspicious Windows Registry Activities, Windows Persistence Techniques, Windows Registry Abuse
|
2026-05-13
|
|
Linux GNU Awk Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Setuid Using Setcap Utility
|
Sysmon for Linux EventID 1
|
T1548.001
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Windows DISM Install PowerShell Web Access
|
Sysmon EventID 1, Windows Event Log Security 4688
|
T1548.002
|
TTP
|
CISA AA24-241A
|
2026-05-13
|
|
Short Lived Windows Accounts
|
Windows Event Log System 4720, Windows Event Log System 4726
|
T1078.003
T1136.001
|
TTP
|
GhostRedirector IIS Module and Rungan Backdoor, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux File Creation In Init Boot Directory
|
Sysmon for Linux EventID 11
|
T1037.004
|
Anomaly
|
Linux Privilege Escalation, XorDDos, Backdoor Pingpong, China-Nexus Threat Activity, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Parent PID Spoofing with Explorer
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1134.004
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host
|
2026-05-13
|
|
Linux Sqlite3 Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Remote Create Service
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543.003
|
Anomaly
|
BlackSuit Ransomware, Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Linux Edit Cron Table Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Linux Persistence Techniques, Scheduled Tasks, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Sudo OR Su Execution
|
Sysmon for Linux EventID 1
|
T1548.003
|
Hunting
|
Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Service Creation on Remote Endpoint
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543.003
|
TTP
|
SnappyBee, CISA AA23-347A, China-Nexus Threat Activity, Active Directory Lateral Movement, Salt Typhoon
|
2026-05-13
|
|
Windows Snake Malware Kernel Driver Comadmin
|
Sysmon EventID 11
|
T1547.006
|
TTP
|
Snake Malware
|
2026-05-13
|
|
Linux Possible GSM Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1068
|
Anomaly
|
Linux Privilege Escalation
|
2026-07-08
|
|
Suspicious GPUpdate no Command Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
Hellcat Ransomware, Cobalt Strike, BlackByte Ransomware, Graceful Wipe Out Attack
|
2026-05-13
|
|
Windows Suspicious Child Process of TieringEngineService.exe
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
|
TTP
|
Windows Privilege Escalation, RedSun
|
2026-05-01
|
|
Linux Make Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Impacket Lateral Movement smbexec CommandLine Parameters
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Industroyer2, WhisperGate, Compromised Windows Host, Volt Typhoon, Prestige Ransomware, Data Destruction, CISA AA22-277A, Active Directory Lateral Movement
|
2026-05-13
|
|
Spoolsv Spawning Rundll32
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1547.012
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527, Compromised Windows Host
|
2026-05-13
|
|
Windows AD DSRM Account Changes
|
Sysmon EventID 13
|
T1098
|
TTP
|
Windows Persistence Techniques, Scattered Lapsus$ Hunters, Sneaky Active Directory Persistence Tricks, Windows Registry Abuse
|
2026-05-13
|
|
Linux SSH Authorized Keys Modification
|
Sysmon for Linux EventID 1
|
T1098.004
|
Anomaly
|
Hellcat Ransomware, VoidLink Cloud-Native Linux Malware, Linux Living Off The Land
|
2026-05-13
|
|
Linux Possible Append Command To At Allow Config File
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Linux Persistence Techniques, Scheduled Tasks, Linux Privilege Escalation
|
2026-05-13
|
|
Services LOLBAS Execution Process Spawn
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1543.003
|
TTP
|
Living Off The Land, Qakbot, Hellcat Ransomware, Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Disabling Remote User Account Control
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Remcos, Windows Defense Evasion Tactics, Suspicious Windows Registry Activities, AgentTesla, Azorult, Windows Registry Abuse
|
2026-05-13
|
|
Time Provider Persistence Registry
|
Sysmon EventID 13
|
T1547.003
|
TTP
|
Windows Persistence Techniques, Windows Privilege Escalation, Hermetic Wiper, Data Destruction, Windows Registry Abuse
|
2026-07-08
|
|
Linux PHP Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Phantom DLL Created on Disk
|
Sysmon EventID 11
|
T1068
T1574.001
|
TTP
|
Windows Privilege Escalation, RoguePlanet, Windows Defense Evasion Tactics
|
2026-08-20
|
|
Linux Composer Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
LLM Model File Creation
|
Sysmon EventID 11
|
T1543
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-07-15
|
|
Detect Excessive User Account Lockouts
|
|
T1078.003
|
Anomaly
|
Scattered Lapsus$ Hunters, Active Directory Password Spraying
|
2026-05-13
|
|
Suspicious SearchProtocolHost no Command Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Hellcat Ransomware, Cactus Ransomware, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
Linux Possible Privilege Escalation via PYTHONPATH
|
Sysmon for Linux EventID 11
|
T1068
T1574.007
|
TTP
|
Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation
|
2026-07-08
|
|
Linux Common Process For Elevation Control
|
Sysmon for Linux EventID 1
|
T1548.001
|
Hunting
|
Linux Living Off The Land, Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques, Axios Supply Chain Post Compromise, Salt Typhoon
|
2026-05-13
|
|
Windows Service Create Kernel Mode Driver
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
T1543.003
|
TTP
|
CISA AA22-320A, Windows Drivers
|
2026-05-13
|
|
Linux Setuid Using Chmod Utility
|
Sysmon for Linux EventID 1
|
T1548.001
|
Anomaly
|
Linux Persistence Techniques, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Ghostscript Exploitation
|
Sysmon for Linux EventID 1
|
T1059
T1068
T1204.002
T1566
|
TTP
|
Unusual Processes, Linux Post-Exploitation, Linux Living Off The Land, Suspicious Command-Line Executions
|
2026-09-01
|
|
CMD Echo Pipe - Escalation
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1059.003
T1543.003
|
TTP
|
Compromised Windows Host, Cobalt Strike, BlackByte Ransomware, Graceful Wipe Out Attack
|
2026-05-13
|
|
Linux Ruby Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Registry Keys Used For Persistence
|
Sysmon EventID 13
|
T1547.001
|
TTP
|
Lokibot, Remcos, Azorult, Cactus Ransomware, DarkCrystal RAT, China-Nexus Threat Activity, Suspicious MSHTA Activity, RedLine Stealer, 0bj3ctivity Stealer, Sneaky Active Directory Persistence Tricks, Snake Keylogger, WinDealer RAT, BlackSuit Ransomware, NjRAT, Emotet Malware DHS Report TA18-201A, IcedID, Axios Supply Chain Post Compromise, BlackByte Ransomware, Salt Typhoon, CISA AA23-347A, Amadey, Phantom Stealer, XWorm, Qakbot, APT37 Rustonotto and FadeStealer, MuddyWater, Starland RAT Campaign, NetSupport RMM Tool Abuse, DHS Report TA18-074A, SystemBC, Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns, Warzone RAT, DarkGate Malware, Castle RAT, ValleyRAT, AsyncRAT, Windows Persistence Techniques, Chaos Ransomware, Interlock Ransomware, Suspicious Windows Registry Activities, SnappyBee, Ransomware, Quasar RAT, Derusbi, MoonPeak, Gh0st RAT, Salat Stealer, Braodo Stealer, Windows Registry Abuse
|
2026-07-20
|
|
Linux Install Kernel Module Using Modprobe Utility
|
Sysmon for Linux EventID 1
|
T1547.006
|
Anomaly
|
Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Rootkit
|
2026-05-13
|
|
Child Processes of Spoolsv exe
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
|
TTP
|
Hermetic Wiper, Windows Privilege Escalation, Data Destruction
|
2026-05-13
|
|
Windows Mock Trusted Directory MSC File Creation
|
Sysmon EventID 11
|
T1218.014
T1548.002
T1574
|
TTP
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-05-13
|
|
Windows System File on Disk
|
Sysmon EventID 11
|
T1068
|
Hunting
|
CISA AA22-264A, Windows Drivers, Crypto Stealer
|
2026-05-13
|
|
Linux NOPASSWD Entry In Sudoers File
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
China-Nexus Threat Activity, Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon
|
2026-05-13
|
|
Linux AWK Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux c99 Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows AD DSRM Password Reset
|
Windows Event Log Security 4794
|
T1098
|
TTP
|
Scattered Lapsus$ Hunters, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AppCertDLL Modification Via Registry
|
Sysmon EventID 13
|
T1546.009
|
Anomaly
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-07-27
|
|
Linux Puppet Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Possible Ssh Key File Creation
|
Sysmon for Linux EventID 11
|
T1098.004
|
Anomaly
|
Linux Persistence Techniques, Hellcat Ransomware, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows UAC Bypass Suspicious Child Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1548.002
|
TTP
|
Living Off The Land, Castle RAT, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Shim Database Installation With Suspicious Parameters
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1546.011
|
TTP
|
Windows Persistence Techniques, Compromised Windows Host
|
2026-05-13
|
|
Suspicious Scheduled Task from Public Directory
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
Anomaly
|
Lokibot, Azorult, Ryuk Ransomware, DarkCrystal RAT, China-Nexus Threat Activity, Medusa Ransomware, Crypto Stealer, CISA AA24-241A, Salt Typhoon, CISA AA23-347A, XWorm, SolarWinds WHD RCE Post Exploitation, Scattered Spider, APT37 Rustonotto and FadeStealer, NetSupport RMM Tool Abuse, Scheduled Tasks, Living Off The Land, Malicious Inno Setup Loader, Windows Persistence Techniques, Ransomware, Quasar RAT, MoonPeak
|
2026-05-13
|
|
Linux Doas Conf File Creation
|
Sysmon for Linux EventID 11
|
T1548.003
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-05-13
|
|
Disable UAC Remote Restriction
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Suspicious Windows Registry Activities, Windows Registry Abuse, CISA AA23-347A, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Sudoers Tmp File Creation
|
Sysmon for Linux EventID 11
|
T1548.003
|
Anomaly
|
China-Nexus Threat Activity, Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon
|
2026-05-13
|
|
Schtasks used for forcing a reboot
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1053.005
|
TTP
|
Scheduled Tasks, Windows Persistence Techniques, Ransomware
|
2026-05-13
|
|
MacOS Kextload Usage
|
Osquery Results
|
T1543
|
TTP
|
MacOS Persistence Techniques, MacOS Privilege Escalation
|
2026-05-13
|
|
Windows Autostart Execution LSASS Driver Registry Modification
|
Sysmon EventID 13
|
T1547.008
|
TTP
|
Windows Registry Abuse
|
2026-05-13
|
|
Linux RPM Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Eventvwr UAC Bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, IcedID, ValleyRAT, Windows Registry Abuse
|
2026-05-13
|
|
Windows Registry Modification for Safe Mode Persistence
|
Sysmon EventID 13
|
T1547.001
|
TTP
|
Ransomware, Windows Drivers, Windows Registry Abuse
|
2026-05-13
|
|
Impacket Lateral Movement WMIExec Commandline Parameters
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Industroyer2, Storm-0501 Ransomware, WhisperGate, Compromised Windows Host, Gozi Malware, Prestige Ransomware, Volt Typhoon, Data Destruction, CISA AA22-277A, Active Directory Lateral Movement
|
2026-05-13
|
|
Linux Possible Append Command To Profile Config File
|
Sysmon for Linux EventID 1
|
T1546.004
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation
|
2026-08-12
|
|
Svchost LOLBAS Execution Process Spawn
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1053.005
|
TTP
|
Living Off The Land, Hellcat Ransomware, Scheduled Tasks, Active Directory Lateral Movement
|
2026-07-27
|
|
SLUI RunAs Elevated
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, DarkSide Ransomware, Compromised Windows Host
|
2026-05-13
|
|
Windows Security Support Provider Reg Query
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1547.005
|
Anomaly
|
Sneaky Active Directory Persistence Tricks, Windows Post-Exploitation, Prestige Ransomware
|
2026-05-13
|
|
Print Processor Registry Autostart
|
Sysmon EventID 13
|
T1547.012
|
TTP
|
Windows Privilege Escalation, Windows Persistence Techniques, Data Destruction, Hermetic Wiper
|
2026-05-13
|
|
Logon Script Event Trigger Execution
|
Sysmon EventID 13
|
T1037.001
|
TTP
|
Windows Persistence Techniques, Windows Privilege Escalation, VIP Keylogger, Hermetic Wiper, Data Destruction
|
2026-05-13
|
|
Cisco IOS Suspicious Privileged Account Creation
|
Cisco IOS Logs
|
T1078
T1136
|
Anomaly
|
Cisco Smart Install Remote Code Execution CVE-2018-0171
|
2026-05-13
|
|
Cisco Privileged Account Creation with Suspicious SSH Activity
|
|
T1021.004
T1078
T1136
|
Correlation
|
Cisco Secure Firewall Threat Defense Analytics, Salt Typhoon
|
2026-05-13
|
|
Cisco Privileged Account Creation with HTTP Command Execution
|
|
T1021.004
T1078
T1136
|
Correlation
|
Cisco Secure Firewall Threat Defense Analytics, Salt Typhoon
|
2026-05-13
|
|
Cisco Configuration Archive Logging Analysis
|
Cisco IOS Logs
|
T1098
T1505.003
T1685
|
Hunting
|
Cisco Smart Install Remote Code Execution CVE-2018-0171
|
2026-05-13
|
|
Okta New API Token Created
|
Okta
|
T1078.001
|
TTP
|
Okta Account Takeover, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Okta New Device Enrolled on Account
|
Okta
|
T1098.005
|
TTP
|
Okta Account Takeover, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Okta Risk Threshold Exceeded
|
Okta
|
T1078
T1110
|
Correlation
|
Okta Account Takeover, Okta MFA Exhaustion, Suspicious Okta Activity
|
2026-05-13
|
|
Okta Authentication Failed During MFA Challenge
|
Okta
|
T1078.004
T1586.003
T1621
|
TTP
|
Okta Account Takeover, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
XMRIG Driver Loaded
|
Sysmon EventID 6
|
T1543.003
|
TTP
|
CISA AA22-320A, XMRig, Crypto Stealer
|
2026-09-08
|
|
Windows Process Injection into Notepad
|
Sysmon EventID 10
|
T1055.002
|
Anomaly
|
APT37 Rustonotto and FadeStealer, BishopFox Sliver Adversary Emulation Framework, Earth Alux
|
2026-09-21
|
|
First Time Seen Child Process of Zoom
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1068
|
Anomaly
|
Suspicious Zoom Child Processes
|
2026-05-13
|
|
Linux Adding Crontab Using List Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Gomir, Industroyer2, Scheduled Tasks, Linux Living Off The Land, Cisco Isovalent Suspicious Activity, Linux Privilege Escalation, Linux Persistence Techniques, Data Destruction, VoidLink Cloud-Native Linux Malware
|
2026-09-03
|