Network Detections

Name Data Source Technique Type Analytic Story Date
Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download Cisco Network Visibility Module Flow Data T1218.005 Anomaly Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Susp Script From Archive Triggering Network Activity Cisco Network Visibility Module Flow Data T1059.005 T1204.002 Anomaly Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Outbound Connection to Suspicious Port Cisco Network Visibility Module Flow Data T1571 Anomaly Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Suspicious Network Connection to IP Lookup Service API Cisco Network Visibility Module Flow Data T1016 T1590.005 Anomaly BlankGrabber Stealer, Cisco Network Visibility Module Analytics, Castle RAT 2026-05-13
Cisco NVM - Curl Execution With Insecure Flags Cisco Network Visibility Module Flow Data T1197 Anomaly Cisco Network Visibility Module Analytics, Microsoft WSUS CVE-2025-59287, PromptLock 2026-05-13
Cisco NVM - Suspicious File Download via Headless Browser Cisco Network Visibility Module Flow Data T1059 T1105 TTP BlankGrabber Stealer, Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Suspicious Network Connection From Process With No Args Cisco Network Visibility Module Flow Data T1055 T1218 Anomaly Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Non-Network Binary Making Network Connection Cisco Network Visibility Module Flow Data T1036 T1055 Anomaly Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Suspicious Network Connection Initiated via MsXsl Cisco Network Visibility Module Flow Data T1220 Anomaly Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Cisco Network Visibility Module Flow Data T1059.005 T1218.005 Anomaly BlankGrabber Stealer, Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Installation of Typosquatted Python Package Cisco Network Visibility Module Flow Data T1059 TTP Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Suspicious Download From File Sharing Website Cisco Network Visibility Module Flow Data T1197 Anomaly BlankGrabber Stealer, Cisco Network Visibility Module Analytics, APT37 Rustonotto and FadeStealer 2026-05-13
Cisco NVM - Rclone Execution With Network Activity Cisco Network Visibility Module Flow Data T1567.002 Anomaly Scattered Lapsus$ Hunters, Cisco Network Visibility Module Analytics 2026-05-13
Cisco NVM - Webserver Download From File Sharing Website Cisco Network Visibility Module Flow Data T1105 T1190 TTP GhostRedirector IIS Module and Rungan Backdoor, Cisco Network Visibility Module Analytics 2026-05-13
Juniper Networks Remote Code Execution Exploit Detection Suricata T1059 T1105 T1190 TTP Juniper JunOS Remote Code Execution 2026-05-13
VMWare Aria Operations Exploit Attempt Palo Alto Network Threat T1068 T1133 T1190 T1210 TTP VMware Aria Operations vRealize CVE-2023-20887 2026-05-13
Fortinet Appliance Auth bypass Palo Alto Network Threat T1133 T1190 TTP CVE-2022-40684 Fortinet Appliance Auth bypass 2026-05-13
Detect Remote Access Software Usage URL Palo Alto Network Threat T1219 Anomaly CISA AA24-241A, Ransomware, Insider Threat, Command And Control, Remote Monitoring and Management Software, Scattered Lapsus$ Hunters, Interlock Ransomware 2026-05-13
Citrix ADC Exploitation CVE-2023-3519 Palo Alto Network Threat T1190 Hunting CISA AA24-241A, Citrix Netscaler ADC CVE-2023-3519 2026-05-13
Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 Palo Alto Network Threat T1133 T1190 TTP Fortinet FortiNAC CVE-2022-39952, Hellcat Ransomware 2026-05-13
Confluence Unauthenticated Remote Code Execution CVE-2022-26134 Palo Alto Network Threat T1133 T1190 T1505 TTP Confluence Data Center and Confluence Server Vulnerabilities, Atlassian Confluence Server and Data Center CVE-2022-26134 2026-05-13
VMware Workspace ONE Freemarker Server-side Template Injection Palo Alto Network Threat T1133 T1190 Anomaly VMware Server Side Injection and Privilege Escalation 2026-05-13
VMware Server Side Template Injection Hunt Palo Alto Network Threat T1133 T1190 Hunting VMware Server Side Injection and Privilege Escalation 2026-05-13
Ollama Abnormal Network Connectivity Ollama Server T1571 Anomaly Suspicious Ollama Activities 2026-05-13
Cisco Duo Policy Allow Network Bypass 2FA Cisco Duo Administrator T1556 TTP Cisco Duo Suspicious Activity 2026-05-13
Prohibited Network Traffic Allowed Cisco Secure Firewall Threat Defense Connection Event T1048 TTP Command And Control, Prohibited Traffic Allowed or Protocol Mismatch, Cisco Secure Firewall Threat Defense Analytics, Ransomware 2026-05-13
Cisco Secure Firewall - Bits Network Activity Cisco Secure Firewall Threat Defense Connection Event N/A Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Remote Desktop Network Traffic Zeek Conn T1021.001 Anomaly Active Directory Lateral Movement, Hidden Cobra Malware, Windows RDP Artifacts and Defense Evasion, SamSam Ransomware, Ryuk Ransomware 2026-05-13
Detect Large ICMP Traffic Palo Alto Network Traffic, Cisco Secure Access Firewall T1095 TTP China-Nexus Threat Activity, Command And Control, Cisco Secure Access Analytics, Backdoor Pingpong 2026-05-13
TOR Traffic Palo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection Event T1090.003 TTP Cisco Secure Firewall Threat Defense Analytics, Ransomware, NOBELIUM Group, Command And Control, Prohibited Traffic Allowed or Protocol Mismatch, Interlock Ransomware 2026-05-13
Detect Software Download To Network Device T1542.005 TTP Router and Infrastructure Security 2026-05-13
F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 Palo Alto Network Threat T1133 T1190 TTP CISA AA24-241A, F5 BIG-IP Vulnerability CVE-2022-1388 2026-05-13
Detect Remote Access Software Usage Traffic Palo Alto Network Traffic T1219 Anomaly Scattered Spider, Ransomware, Insider Threat, Command And Control, Remote Monitoring and Management Software, Scattered Lapsus$ Hunters, Interlock Ransomware 2026-05-13
Cisco Network Interface Modifications Cisco IOS Logs T1021 T1133 T1556 Anomaly Cisco Smart Install Remote Code Execution CVE-2018-0171 2026-05-13
Detect IPv6 Network Infrastructure Threats Cisco IOS Logs T1200 T1498 T1557.002 TTP Router and Infrastructure Security, Scattered Lapsus$ Hunters 2026-05-13
Hosts receiving high volume of network traffic from email server T1114.002 Anomaly Collection and Staging 2026-05-13
Detect Outbound LDAP Traffic Palo Alto Network Traffic, Cisco Secure Access Firewall, Cisco Secure Firewall Threat Defense Connection Event T1059 T1190 Hunting Cisco Secure Firewall Threat Defense Analytics, Cisco Secure Access Analytics, Log4Shell CVE-2021-44228 2026-05-13