Linux Detections

Name Data Source Technique Type Analytic Story Date
Java Writing JSP File Sysmon for Linux EventID 1, Sysmon for Linux EventID 11 T1133 T1190 TTP SAP NetWeaver Exploitation, Spring4Shell CVE-2022-22965, SysAid On-Prem Software CVE-2023-47246 Vulnerability, Atlassian Confluence Server and Data Center CVE-2022-26134 2026-05-13
Linux Auditd Service Restarted Linux Auditd Proctitle T1053.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Scheduled Tasks, Data Destruction, Linux Living Off The Land, AwfulShred, Gomir 2026-05-13
Linux Auditd File Permission Modification Via Chmod Linux Auditd Proctitle T1222.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Axios Supply Chain Post Compromise, Compromised Linux Host, China-Nexus Threat Activity, Linux Living Off The Land, Salt Typhoon, XorDDos 2026-05-13
Linux Auditd Find Credentials From Password Stores Linux Auditd Execve T1555.005 TTP Linux Persistence Techniques, Linux Privilege Escalation, Hellcat Ransomware, Compromised Linux Host, Linux Living Off The Land, Scattered Lapsus$ Hunters 2026-05-13
Linux Auditd Add User Account Linux Auditd Proctitle T1136.001 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host 2026-05-13
Linux Auditd Unload Module Via Modprobe Linux Auditd Execve T1547.006 TTP Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Preload Hijack Library Calls Sysmon for Linux EventID 1 T1574.006 TTP Linux Persistence Techniques, Linux Privilege Escalation, China-Nexus Threat Activity, VoidLink Cloud-Native Linux Malware, Salt Typhoon 2026-05-13
Linux Obfuscated Files or Information Base64 Decode Sysmon for Linux EventID 1 T1027 Anomaly Linux Living Off The Land 2026-05-13
Linux Sudo OR Su Execution Sysmon for Linux EventID 1 T1548.003 Hunting Linux Persistence Techniques, Linux Privilege Escalation, VoidLink Cloud-Native Linux Malware 2026-05-13
Linux Auditd Base64 Decode Files Linux Auditd Execve T1140 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux RPM Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Visudo Utility Execution Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Linux Possible Access Or Modification Of sshd Config File Sysmon for Linux EventID 1 T1098.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux DD File Overwrite Sysmon for Linux EventID 1 T1485 TTP Data Destruction, Industroyer2 2026-05-13
Linux PHP Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Account Manipulation Of SSH Config and Keys Sysmon for Linux EventID 11 T1070.004 T1485 Anomaly Hellcat Ransomware, AcidRain 2026-05-13
Linux Auditd Possible Access To Credential Files Linux Auditd Proctitle T1003.008 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Axios Supply Chain Post Compromise, Compromised Linux Host, China-Nexus Threat Activity, Salt Typhoon 2026-05-13
Linux Doas Tool Execution Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Curl Execution with Percent Encoded URL CrowdStrike ProcessRollup2, Sysmon for Linux EventID 1, Sysmon EventID 1, Windows Event Log Security 4688 T1027 T1105 Anomaly Living Off The Land, Ingress Tool Transfer, Compromised Windows Host 2026-05-13
Linux Auditd Preload Hijack Library Calls Linux Auditd Execve T1574.006 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, China-Nexus Threat Activity, Salt Typhoon 2026-05-13
Linux Possible Append Command To Profile Config File Sysmon for Linux EventID 1 T1546.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Linux Busybox Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd At Application Execution Linux Auditd Syscall T1053.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Scheduled Tasks, Linux Living Off The Land 2026-05-13
Linux Cpulimit Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Data Transfer Size Limits Via Split Linux Auditd Execve T1030 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Hellcat Ransomware, Compromised Linux Host, Linux Living Off The Land 2026-05-13
Linux Service File Created In Systemd Directory Sysmon for Linux EventID 11 T1053.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, China-Nexus Threat Activity, Scheduled Tasks, Linux Living Off The Land, VoidLink Cloud-Native Linux Malware, Gomir 2026-05-13
Linux Auditd Sysmon Service Stop Linux Auditd Service Stop T1489 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Potential password in username Linux Secure T1078.003 T1552.001 Hunting Credential Dumping, Insider Threat 2026-05-13
Linux Service Started Or Enabled Sysmon for Linux EventID 1 T1053.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, Gomir 2026-05-13
Linux Docker Root Directory Mount Sysmon for Linux EventID 1 T1611 TTP Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Hardware Addition Swapoff Linux Auditd Execve T1200 Anomaly Compromised Linux Host, Data Destruction, Scattered Lapsus$ Hunters, AwfulShred 2026-05-13
Linux Auditd Shred Overwrite Command Linux Auditd Proctitle T1485 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Data Destruction, Industroyer2, AwfulShred 2026-05-13
Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File Linux Auditd Path, Linux Auditd Cwd T1053.003 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Scheduled Tasks, Linux Living Off The Land, XorDDos 2026-05-13
Linux Edit Cron Table Parameter Sysmon for Linux EventID 1 T1053.003 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land 2026-05-13
Linux Add User Account Cisco Isovalent Process Exec, Sysmon for Linux EventID 1 T1136.001 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Cisco Isovalent Suspicious Activity 2026-05-13
Linux Telnet Authentication Bypass Sysmon for Linux EventID 1 T1548 TTP Telnetd CVE-2026-24061 2026-05-13
Linux Doas Conf File Creation Sysmon for Linux EventID 11 T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Linux Auditd Doas Conf File Creation Linux Auditd Path, Linux Auditd Cwd T1548.003 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host 2026-05-13
Linux OpenVPN Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Deletion Of Cron Jobs Sysmon for Linux EventID 11 T1070.004 T1485 Anomaly AcidRain, Data Destruction, AcidPour 2026-05-13
Linux Possible Append Command To At Allow Config File Sysmon for Linux EventID 1 T1053.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks 2026-05-13
Linux Possible Append Cronjob Entry on Existing Cronjob File Sysmon for Linux EventID 1 T1053.003 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, XorDDos 2026-05-13
Linux Auditd Whoami User Discovery Linux Auditd Syscall T1033 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, QuietVault, Linux Living Off The Land 2026-05-13
Linux Node Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Setuid Using Chmod Utility Sysmon for Linux EventID 1 T1548.001 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Composer Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Edit Cron Table Parameter Linux Auditd Syscall T1053.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Scheduled Tasks, Linux Living Off The Land 2026-05-13
Linux Service Restarted Sysmon for Linux EventID 1 T1053.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Data Destruction, Linux Living Off The Land, AwfulShred, Gomir 2026-05-13
Linux Auditd Kernel Module Enumeration Linux Auditd Syscall T1014 T1082 Anomaly Linux Rootkit, XorDDos, Compromised Linux Host 2026-05-13
Linux Install Kernel Module Using Modprobe Utility Sysmon for Linux EventID 1 T1547.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit, China-Nexus Threat Activity, VoidLink Cloud-Native Linux Malware 2026-05-13
Linux SSH Remote Services Script Execute Sysmon for Linux EventID 1 T1021.004 TTP Hellcat Ransomware, VoidLink Cloud-Native Linux Malware, Linux Living Off The Land 2026-05-13
Linux Decode Base64 to Shell Cisco Isovalent Process Exec, Sysmon for Linux EventID 1 T1027 T1059.004 TTP Cisco Isovalent Suspicious Activity, Linux Living Off The Land 2026-05-13
Linux Ingress Tool Transfer Hunting Sysmon for Linux EventID 1 T1105 Hunting Axios Supply Chain Post Compromise, Ingress Tool Transfer, Linux Living Off The Land, NPM Supply Chain Compromise, XorDDos 2026-05-13
Linux Auditd Find Ssh Private Keys Linux Auditd Execve T1552.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Hellcat Ransomware, Compromised Linux Host, Linux Living Off The Land 2026-05-13
Linux Auditd Disable Or Modify System Firewall Linux Auditd Service Stop T1686 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Doas Tool Execution Linux Auditd Syscall T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host 2026-05-13
Linux Csvtool Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux NOPASSWD Entry In Sudoers File Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity 2026-05-13
Linux Auditd File Permissions Modification Via Chattr Linux Auditd Execve T1222.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux File Creation In Init Boot Directory Sysmon for Linux EventID 11 T1037.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, China-Nexus Threat Activity, Backdoor Pingpong, XorDDos 2026-05-13
Linux Deletion Of Services Sysmon for Linux EventID 11 T1070.004 T1485 TTP AcidRain, Data Destruction, AcidPour, AwfulShred 2026-05-13
Linux Persistence and Privilege Escalation Risk Behavior T1548 Correlation Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Linux Octave Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Deletion of SSL Certificate Sysmon for Linux EventID 11 T1070.004 T1485 Anomaly AcidRain, AcidPour 2026-05-13
Linux Emacs Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Auditd Service Stop Linux Auditd Service Stop T1489 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Setuid Using Setcap Utility Linux Auditd Execve T1548.001 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host 2026-05-13
File Download or Read to Pipe Execution CrowdStrike ProcessRollup2, Sysmon for Linux EventID 1, Sysmon EventID 1, Windows Event Log Security 4688 T1105 TTP Ingress Tool Transfer, Linux Living Off The Land, Compromised Windows Host, Log4Shell CVE-2021-44228, NPM Supply Chain Compromise 2026-05-13
Linux Make Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Database File And Directory Discovery Linux Auditd Execve T1083 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Possible Access Or Modification Of Sshd Config File Linux Auditd Path, Linux Auditd Cwd T1098.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Find Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Disable Services Sysmon for Linux EventID 1 T1489 TTP Data Destruction, Industroyer2, AwfulShred 2026-05-13
Linux Shred Overwrite Command Sysmon for Linux EventID 1 T1485 TTP Linux Persistence Techniques, Linux Privilege Escalation, Data Destruction, Industroyer2, AwfulShred 2026-05-13
Linux Auditd Change File Owner To Root Linux Auditd Proctitle T1222.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Sudo Or Su Execution Linux Auditd Proctitle T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host 2026-05-13
Linux Impair Defenses Process Kill Sysmon for Linux EventID 1 T1685 Hunting Scattered Lapsus$ Hunters, Data Destruction, AwfulShred 2026-05-13
Linux Change File Owner To Root Sysmon for Linux EventID 1 T1222.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux pkexec Privilege Escalation Sysmon for Linux EventID 1 T1068 TTP Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Insert Kernel Module Using Insmod Utility Linux Auditd Syscall T1547.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit, Compromised Linux Host, XorDDos 2026-05-13
Linux Common Process For Elevation Control Sysmon for Linux EventID 1 T1548.001 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Axios Supply Chain Post Compromise, China-Nexus Threat Activity, Linux Living Off The Land, Salt Typhoon 2026-05-13
Linux Auditd Copy Fail Privilege Escalation Linux Auditd Syscall T1068 TTP Linux Privilege Escalation 2026-05-13
Linux Indicator Removal Service File Deletion Sysmon for Linux EventID 1 T1070.004 Anomaly Data Destruction, AwfulShred 2026-05-13
Linux Sudoers Tmp File Creation Sysmon for Linux EventID 11 T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity 2026-05-13
Linux Adding Crontab Using List Parameter Sysmon for Linux EventID 1 T1053.003 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Data Destruction, Linux Living Off The Land, Industroyer2, VoidLink Cloud-Native Linux Malware, Cisco Isovalent Suspicious Activity, Gomir 2026-05-13
Linux Suspicious React or Next.js Child Process Sysmon for Linux EventID 1 T1059.004 T1190 TTP React2Shell 2026-05-13
Linux Deletion Of Init Daemon Script Sysmon for Linux EventID 11 T1070.004 T1485 TTP AcidRain, Data Destruction, AcidPour 2026-05-13
Linux Puppet Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Setuid Using Chmod Utility Linux Auditd Proctitle T1548.001 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Possible Access To Sudoers File Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity 2026-05-13
Linux Auditd Preload Hijack Via Preload File Linux Auditd Path, Linux Auditd Cwd T1574.006 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Linux Living Off The Land, VoidLink Cloud-Native Linux Malware 2026-05-13
Linux Possible Cronjob Modification With Editor Sysmon for Linux EventID 1 T1053.003 Hunting Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, XorDDos 2026-05-13
Linux Auditd Unix Shell Configuration Modification Linux Auditd Path, Linux Auditd Cwd T1546.004 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, QuietVault, Linux Living Off The Land 2026-05-13
Linux System Network Discovery Sysmon for Linux EventID 1, Osquery Results T1016 Anomaly Network Discovery, VoidLink Cloud-Native Linux Malware, Data Destruction, Industroyer2 2026-05-13
Web or Application Server Spawning a Shell Sysmon for Linux EventID 1, Sysmon EventID 1 T1133 T1190 TTP Cleo File Transfer Software, SysAid On-Prem Software CVE-2023-47246 Vulnerability, SAP NetWeaver Exploitation, Data Destruction, CISA AA22-257A, HAFNIUM Group, ProxyNotShell, Spring4Shell CVE-2022-22965, Microsoft WSUS CVE-2025-59287, ProxyShell, BlackByte Ransomware, Hermetic Wiper, CISA AA22-264A, Flax Typhoon, Microsoft SharePoint Vulnerabilities, PHP-CGI RCE Attack on Japanese Organizations, Log4Shell CVE-2021-44228, GhostRedirector IIS Module and Rungan Backdoor, WS FTP Server Critical Vulnerabilities 2026-05-13
Linux Docker Shell Execution Sysmon for Linux EventID 1 T1059.013 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Kernel Module Using Rmmod Utility Linux Auditd Syscall T1547.006 TTP Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Auditd Daemon Shutdown Linux Auditd Daemon End T1685.004 Anomaly Compromised Linux Host 2026-05-13
Linux Auditd Data Destruction Command Linux Auditd Proctitle T1485 TTP Compromised Linux Host, Data Destruction, AwfulShred 2026-05-13
Linux Auditd Install Kernel Module Using Modprobe Utility Linux Auditd Syscall T1547.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit, Compromised Linux Host, China-Nexus Threat Activity 2026-05-13
Linux AWK Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux File Created In Kernel Driver Directory Sysmon for Linux EventID 11 T1547.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit 2026-05-13
Linux Auditd System Network Configuration Discovery Linux Auditd Syscall T1016 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux File Creation In Profile Directory Sysmon for Linux EventID 11 T1546.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Linux Proxy Socks Curl Sysmon for Linux EventID 1 T1090 T1095 TTP Ingress Tool Transfer, Linux Living Off The Land 2026-05-13
Linux Auditd AI CLI Permission Override Activated Linux Auditd Proctitle T1480 Anomaly QuietVault 2026-05-13
Linux Add Files In Known Crontab Directories Sysmon for Linux EventID 11 T1053.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, XorDDos 2026-05-13
Linux GNU Awk Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Auditd Virtual Disk File And Directory Discovery Linux Auditd Execve T1083 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Deleting Critical Directory Using RM Command Sysmon for Linux EventID 1 T1485 TTP Data Destruction, Industroyer2, AwfulShred 2026-05-13
Linux Ruby Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
GitHub Workflow File Creation or Modification Sysmon for Linux EventID 11, Sysmon EventID 11 T1195 T1554 T1574.006 Hunting NPM Supply Chain Compromise 2026-05-13
Linux Auditd File And Directory Discovery Linux Auditd Execve T1083 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Auditd Daemon Abort Linux Auditd Daemon Abort T1685.004 Anomaly Compromised Linux Host 2026-05-13
Linux Stdout Redirection To Dev Null File Sysmon for Linux EventID 1 T1686 Anomaly Data Destruction, Cyclops Blink, Industroyer2 2026-05-13
Linux Ngrok Reverse Proxy Usage Sysmon for Linux EventID 1 T1090 T1102 T1572 Anomaly Reverse Network Proxy 2026-05-13
Linux System Reboot Via System Request Key Sysmon for Linux EventID 1 T1529 TTP Data Destruction, AwfulShred 2026-05-13
Linux Auditd Possible Access To Sudoers File Linux Auditd Path, Linux Auditd Cwd T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, China-Nexus Threat Activity, Salt Typhoon 2026-05-13
Linux Auditd Data Transfer Size Limits Via Split Syscall Linux Auditd Syscall T1030 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Osquery Service Stop Linux Auditd Service Stop T1489 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Clipboard Data Copy Linux Auditd Execve T1115 Anomaly Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Indicator Removal Clear Cache Sysmon for Linux EventID 1 T1070 TTP Data Destruction, AwfulShred 2026-05-13
Linux Gem Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux c89 Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Insert Kernel Module Using Insmod Utility Sysmon for Linux EventID 1 T1547.006 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit, XorDDos 2026-05-13
Linux Auditd Private Keys and Certificate Enumeration Linux Auditd Execve T1552.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Service Started Linux Auditd Proctitle T1569.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Find Credentials From Password Managers Linux Auditd Execve T1555.005 TTP Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, Linux Living Off The Land, Scattered Lapsus$ Hunters 2026-05-13
Linux Magic SysRq Key Abuse Linux Auditd Path, Linux Auditd Cwd T1059.004 T1489 T1499 T1529 TTP Compromised Linux Host 2026-05-13
Linux Gdrive Binary Activity Sysmon for Linux EventID 1 T1567 TTP China-Nexus Threat Activity 2026-05-13
Linux Iptables Firewall Modification Sysmon for Linux EventID 1 T1686 Anomaly China-Nexus Threat Activity, Backdoor Pingpong, Sandworm Tools, Cyclops Blink 2026-05-13
Linux Data Destruction Command Sysmon for Linux EventID 1 T1485 TTP Data Destruction, AwfulShred 2026-05-13
Linux Clipboard Data Copy Sysmon for Linux EventID 1 T1115 Anomaly Linux Living Off The Land 2026-05-13
Linux APT Privilege Escalation Cisco Isovalent Process Exec, Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Suspicious Linux Discovery Commands Sysmon for Linux EventID 1 T1059.004 TTP Linux Post-Exploitation, VoidLink Cloud-Native Linux Malware 2026-05-13
Linux Auditd Dd File Overwrite Linux Auditd Proctitle T1485 TTP Data Destruction, Industroyer2, Compromised Linux Host 2026-05-13
Suspicious Curl Network Connection CrowdStrike ProcessRollup2, Sysmon for Linux EventID 1, Sysmon EventID 1, Windows Event Log Security 4688 T1105 TTP Hellcat Ransomware, Ingress Tool Transfer, APT37 Rustonotto and FadeStealer, Linux Living Off The Land, GhostRedirector IIS Module and Rungan Backdoor, Silver Sparrow 2026-05-13
Linux High Frequency Of File Deletion In Etc Folder Sysmon for Linux EventID 11 T1070.004 T1485 Anomaly AcidRain, Data Destruction 2026-05-13
Linux At Allow Config File Creation Sysmon for Linux EventID 11 T1053.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land 2026-05-13
Linux GDB Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Hardware Addition SwapOff Sysmon for Linux EventID 1 T1200 Anomaly Scattered Lapsus$ Hunters, Data Destruction, AwfulShred 2026-05-13
Linux Auditd Add User Account Type Linux Auditd Add User T1136.001 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux High Frequency Of File Deletion In Boot Folder Sysmon for Linux EventID 11 T1070.004 T1485 TTP AcidPour, Data Destruction, Industroyer2 2026-05-13
Linux Sqlite3 Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux Ingress Tool Transfer with Curl Sysmon for Linux EventID 1 T1105 Anomaly NPM Supply Chain Compromise, Linux Living Off The Land, XorDDos, Ingress Tool Transfer 2026-05-13
Shai-Hulud 2 Exfiltration Artifact Files Sysmon for Linux EventID 11, Sysmon EventID 11 T1074.001 T1195.002 T1552.001 TTP NPM Supply Chain Compromise 2026-05-13
Shai-Hulud Workflow File Creation or Modification Sysmon for Linux EventID 11, Sysmon EventID 11 T1195 T1554 T1574.006 TTP NPM Supply Chain Compromise 2026-05-13
Linux Possible Access To Credential Files Sysmon for Linux EventID 1 T1003.008 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, China-Nexus Threat Activity, Salt Typhoon, XorDDos 2026-05-13
Linux Auditd Stop Services Linux Auditd Service Stop T1489 Hunting Compromised Linux Host, Data Destruction, Industroyer2, AwfulShred 2026-05-13
Linux At Application Execution Sysmon for Linux EventID 1 T1053.002 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, Cisco Isovalent Suspicious Activity 2026-05-13
Linux Kworker Process In Writable Process Path Sysmon for Linux EventID 1 T1036.004 Hunting Cyclops Blink, Sandworm Tools 2026-05-13
Linux Curl Upload File Cisco Isovalent Process Exec, Sysmon for Linux EventID 1 T1105 TTP Data Exfiltration, NPM Supply Chain Compromise, Ingress Tool Transfer, Linux Living Off The Land 2026-05-13
Linux Auditd Nopasswd Entry In Sudoers File Linux Auditd Proctitle T1548.003 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Compromised Linux Host, China-Nexus Threat Activity, Salt Typhoon 2026-05-13
Linux Setuid Using Setcap Utility Sysmon for Linux EventID 1 T1548.001 Anomaly Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Linux Kernel Module Enumeration Sysmon for Linux EventID 1 T1014 T1082 Anomaly Linux Rootkit, XorDDos 2026-05-13
Linux Auditd Hidden Files And Directories Creation Linux Auditd Execve T1083 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Linux Living Off The Land, Compromised Linux Host 2026-05-13
Linux Auditd Auditd Daemon Start Linux Auditd Daemon Start T1685.004 Anomaly Compromised Linux Host 2026-05-13
Linux Unix Shell Enable All SysRq Functions Sysmon for Linux EventID 1 T1059.004 Anomaly Data Destruction, AwfulShred 2026-05-13
Linux c99 Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13
Linux SSH Authorized Keys Modification Sysmon for Linux EventID 1 T1098.004 Anomaly Hellcat Ransomware, VoidLink Cloud-Native Linux Malware, Linux Living Off The Land 2026-05-13
Linux Medusa Rootkit Sysmon for Linux EventID 11 T1014 T1589.001 TTP China-Nexus Threat Activity, VoidLink Cloud-Native Linux Malware, Hellcat Ransomware, Medusa Rootkit 2026-05-13
Linux Stop Services Sysmon for Linux EventID 1 T1489 TTP Data Destruction, Industroyer2, AwfulShred 2026-05-13
Linux Possible Ssh Key File Creation Sysmon for Linux EventID 11 T1098.004 Anomaly Linux Persistence Techniques, Linux Privilege Escalation, Hellcat Ransomware, Linux Living Off The Land 2026-05-13
Linux MySQL Privilege Escalation Sysmon for Linux EventID 1 T1548.003 Anomaly Linux Privilege Escalation, Linux Living Off The Land 2026-05-13