Command and Control Detections

Name Data Source Technique Type Analytic Story Date
Juniper Networks Remote Code Execution Exploit Detection Suricata T1059 T1105 T1190 TTP Juniper JunOS Remote Code Execution 2026-05-13
HTTP Duplicated Header Suricata T1071.001 T1190 Anomaly HTTP Request Smuggling 2026-05-13
HTTP Rapid POST with Mixed Status Codes Nginx Access T1071.001 T1190 T1595 Anomaly HTTP Request Smuggling 2026-05-13
HTTP Possible Request Smuggling Suricata T1071.001 TTP HTTP Request Smuggling 2026-05-13
Okta Non-Standard VPN Usage Okta T1078 T1090 T1572 TTP Remote Employment Fraud, Suspicious Okta Activity 2026-05-13
Microsoft Intune Mobile Apps Azure Monitor Activity T1021.007 T1072 T1105 T1202 Hunting Azure Active Directory Account Takeover 2026-05-13
Microsoft Intune Device Health Scripts Azure Monitor Activity T1021.007 T1072 T1105 T1202 Hunting Azure Active Directory Account Takeover 2026-05-13
Windows Application Layer Protocol RMS Radmin Tool Namedpipe Sysmon EventID 18, Sysmon EventID 17 T1071 TTP Azorult 2026-05-13
Windows Suspicious QEMU Execution Sysmon EventID 1 T1001 T1036 T1204.002 T1564.006 TTP Compromised Linux Host, Linux Post-Exploitation, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Linux Rootkit, Linux Living Off The Land 2026-05-13
Windows Non-System Process Querying Definition Update Sysmon EventID 22 T1068 T1071.001 Anomaly Windows Privilege Escalation, BlueHammer, RedSun 2026-04-27
Windows Devtunnels Image Loaded Sysmon EventID 7 T1090 Anomaly Reverse Network Proxy 2026-05-13
Windows AI Platform DNS Query Sysmon EventID 22 T1071.004 Anomaly SesameOp, PromptFlux, LAMEHUG 2026-05-13
Cisco NVM - Webserver Download From File Sharing Website Cisco Network Visibility Module Flow Data T1105 T1190 TTP Cisco Network Visibility Module Analytics, GhostRedirector IIS Module and Rungan Backdoor 2026-07-14
Cisco NVM - Suspicious File Download via Headless Browser Cisco Network Visibility Module Flow Data T1059 T1105 TTP Cisco Network Visibility Module Analytics, BlankGrabber Stealer 2026-07-14
Windows Powershell Commands from DNS TXT Powershell Script Block Logging 4104 T1059.001 T1071.004 Anomaly Suspicious DNS Traffic, Command And Control, Malicious PowerShell 2026-07-30
Windows Remote Access Software BRC4 Loaded Dll Sysmon EventID 7 T1003 T1219 Anomaly Brute Ratel C4 2026-05-13
Windows Suspicious Defender Update Activity in INetCache Sysmon EventID 23, Sysmon EventID 11 T1068 T1105 Anomaly Windows Persistence Techniques, BlueHammer 2026-07-20
Windows App Layer Protocol Qakbot NamedPipe Sysmon EventID 18, Sysmon EventID 17 T1071 Anomaly Qakbot 2026-05-13
Windows File Transfer Protocol In Non-Common Process Path Sysmon EventID 3 T1071.003 Anomaly Snake Keylogger, Phantom Stealer, Hellcat Ransomware, AgentTesla 2026-06-25
Windows Level RMM PowerShell Script Installer Powershell Script Block Logging 4104 T1219 Anomaly Remote Monitoring and Management Software 2026-05-13
Download Files Using Telegram Sysmon EventID 15 T1105 TTP Snake Keylogger, 0bj3ctivity Stealer, XMRig, Phemedrone Stealer, Crypto Stealer, Water Gamayun 2026-05-13
Windows Kerberos Coercion via DNS Windows Event Log Security 5137, Windows Event Log Security 4662, Windows Event Log Security 5136 T1071.004 T1187 T1557.001 TTP Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS 2026-05-13
Windows Mail Protocol In Non-Common Process Path Sysmon EventID 3 T1071.003 Anomaly AgentTesla 2026-05-13
Cisco NVM - Outbound Connection to Suspicious Port Cisco Network Visibility Module Flow Data T1571 Anomaly Cisco Network Visibility Module Analytics 2026-07-14
PowerShell Script Block With URL Chain Powershell Script Block Logging 4104 T1059.001 T1105 TTP Malicious PowerShell, Hellcat Ransomware 2026-05-13
Windows Visual Basic Commandline Compiler DNSQuery Sysmon EventID 22 T1071.004 TTP Lokibot 2026-05-13
Windows DNS Query Request To TinyUrl Sysmon EventID 22 T1105 Anomaly Malicious Inno Setup Loader 2026-05-13
Windows Short Lived DNS Record Windows Event Log Security 5137, Windows Event Log Security 5136 T1071.004 T1187 T1557.001 TTP Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS 2026-05-13
Windows DLL Module Loaded in Temp Dir Sysmon EventID 7 T1105 Hunting SolarWinds WHD RCE Post Exploitation, Lokibot, Interlock Rat 2026-05-13
PowerShell WebRequest Using Memory Stream Powershell Script Block Logging 4104 T1027.011 T1059.001 T1105 TTP Malicious PowerShell, Medusa Ransomware, MoonPeak, PHP-CGI RCE Attack on Japanese Organizations 2026-05-13
Windows App Layer Protocol Wermgr Connect To NamedPipe Sysmon EventID 18, Sysmon EventID 17 T1071 Anomaly Windows Error Reporting Service Elevation of Privilege Vulnerability, RoguePlanet, Qakbot 2026-08-18
Windows Level RMM Watchdog Task Created Windows Event Log Security 4698 T1053 T1219 Anomaly Remote Monitoring and Management Software 2026-05-13
Windows SoftEther VPN Masquerading as Legitimate Binary Sysmon EventID 1 T1036 T1572 TTP Flax Typhoon, Linux Privilege Escalation, Linux Persistence Techniques 2026-05-13
Windows RMM Tool Execution Sysmon EventID 1 T1219 Anomaly Remote Monitoring and Management Software, NetSupport RMM Tool Abuse, Suspicious User Agents 2026-05-13
Cisco Isovalent - Curl Execution With Insecure Flags Cisco Isovalent Process Exec T1105 Anomaly Cisco Isovalent Suspicious Activity 2026-05-13
Cisco NVM - Osascript Network Connection for a Long Duration Cisco Network Visibility Module Flow Data T1059.002 T1071.001 Anomaly Cisco Network Visibility Module Analytics, Command And Control, MacOS Post-Exploitation 2026-09-18
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script Powershell Script Block Logging 4104 T1071.001 T1078 T1212 T1482 TTP Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Azure Active Directory Account Takeover 2026-05-13
Windows Abused Web Services Sysmon EventID 22 T1102 Anomaly Malicious Inno Setup Loader, BlankGrabber Stealer, NjRAT, CISA AA24-241A 2026-05-13
Zeek x509 Certificate with Punycode T1573 Hunting OpenSSL CVE-2022-3602 2026-05-13
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Cisco Secure Firewall Threat Defense Connection Event T1071.001 T1573.002 T1587.002 T1588.004 TTP Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco SA - Access to Anonymizer Services Cisco Secure Access DNS T1090.003 Anomaly Cisco Secure Access Analytics 2026-06-09
Cisco Secure Firewall - Repeated Malware Downloads Cisco Secure Firewall Threat Defense File Event T1027 T1105 Anomaly Cisco Secure Firewall Threat Defense Analytics, Hellcat Ransomware 2026-05-13
Windows Multi hop Proxy TOR Website Query Sysmon EventID 22 T1071.003 Anomaly Interlock Ransomware, AgentTesla 2026-05-13
Cisco Secure Firewall - High EVE Threat Confidence Cisco Secure Firewall Threat Defense Connection Event T1041 T1071.001 T1105 T1573.002 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts Cisco Secure Firewall Threat Defense Intrusion Event T1027 T1105 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - Malware File Downloaded Cisco Secure Firewall Threat Defense File Event T1105 T1203 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - Wget or Curl Download Cisco Secure Firewall Threat Defense Connection Event T1053.003 T1059 T1071.001 T1105 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt Cisco Secure Firewall Threat Defense Intrusion Event T1041 T1573.002 Anomaly Cisco Secure Firewall Threat Defense Analytics, Lumma Stealer 2026-05-13
Cisco Secure Firewall - Intrusion Events by Threat Activity Cisco Secure Firewall Threat Defense Intrusion Event T1041 T1573.002 Anomaly Cisco Secure Firewall Threat Defense Analytics, ArcaneDoor 2026-05-13
Cisco Secure Firewall - Lumma Stealer Download Attempt Cisco Secure Firewall Threat Defense Intrusion Event T1041 T1573.002 Anomaly Cisco Secure Firewall Threat Defense Analytics, Lumma Stealer 2026-05-13
Windows DNS Query Request by Telegram Bot API Sysmon EventID 22 T1071.004 T1102.002 Anomaly 0bj3ctivity Stealer, VIP Keylogger, Starland RAT Campaign, BlankGrabber Stealer, Crypto Stealer, Phantom Stealer 2026-07-20
Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall Threat Defense Connection Event T1021 T1055 T1059.001 T1105 T1219 T1571 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - High Volume of Intrusion Events Per Host Cisco Secure Firewall Threat Defense Intrusion Event T1059 T1071 T1595.002 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - Connection to File Sharing Domain Cisco Secure Firewall Threat Defense Connection Event T1071.001 T1090.002 T1105 T1567.002 T1588.002 Anomaly Cisco Secure Firewall Threat Defense Analytics, Scattered Lapsus$ Hunters 2026-05-13
Cisco Secure Firewall - File Download Over Uncommon Port Cisco Secure Firewall Threat Defense File Event T1105 T1571 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco Secure Firewall - High Priority Intrusion Classification Cisco Secure Firewall Threat Defense Intrusion Event T1003 T1071 T1078 T1190 T1203 TTP Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Cisco IOS XE Tunnel Interface Configuration Cisco IOS Logs T1090 T1572 Anomaly Salt Typhoon 2026-05-20
Ollama Abnormal Network Connectivity Ollama Server T1571 Anomaly Suspicious Ollama Activities 2026-05-13
HTTP Scripting Tool User Agent Nginx Access T1071.001 Anomaly Suspicious User Agents, HTTP Request Smuggling 2026-06-15
HTTP Request to Reserved Name on IIS Server Suricata T1071.001 T1190 TTP HTTP Request Smuggling 2026-05-13
Detect Remote Access Software Usage URL Palo Alto Network Threat T1219 Anomaly Remote Monitoring and Management Software, Ransomware, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, Insider Threat, CISA AA24-241A 2026-05-13
Windows Protocol Tunneling with Plink CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1021.004 T1572 TTP CISA AA22-257A 2026-05-13
Detect Remote Access Software Usage Process CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1219 Anomaly Cactus Ransomware, Remote Monitoring and Management Software, Ransomware, Gozi Malware, Scattered Spider, Storm-0501 Ransomware, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, GhostRedirector IIS Module and Rungan Backdoor, Seashell Blizzard, Insider Threat, CISA AA24-241A 2026-05-13
LOLBAS Rare Network Connection Sysmon EventID 3 T1105 T1218 T1567 Anomaly Living Off The Land, Hellcat Ransomware, NetSupport RMM Tool Abuse, Malicious Inno Setup Loader, GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns, APT37 Rustonotto and FadeStealer, Water Gamayun 2026-08-24
Detect Remote Access Software Usage Registry Sysmon EventID 13 T1219 Anomaly Cactus Ransomware, Remote Monitoring and Management Software, Ransomware, Gozi Malware, Scattered Spider, Scattered Lapsus$ Hunters, Command And Control, Seashell Blizzard, Insider Threat, CISA AA24-241A 2026-05-13
Windows Ldifde Directory Object Behavior CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1069.002 T1105 TTP Volt Typhoon 2026-05-13
LOLBAS Network Connection On Uncommon Port Sysmon EventID 3 T1105 T1218 T1567 Anomaly Living Off The Land, Hellcat Ransomware, NetSupport RMM Tool Abuse, Malicious Inno Setup Loader, GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns, APT37 Rustonotto and FadeStealer, Water Gamayun 2026-08-24
Windows Process Execution From RDP Share CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1021.001 T1059 T1105 Anomaly Hidden Cobra Malware 2026-05-13
BITSAdmin Download File CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1105 T1197 TTP Living Off The Land, BITS Jobs, APT37 Rustonotto and FadeStealer, Ingress Tool Transfer, Hellcat Ransomware, Gozi Malware, Scattered Spider, GhostRedirector IIS Module and Rungan Backdoor, Flax Typhoon, DarkSide Ransomware 2026-05-13
Windows Curl Upload to Remote Destination CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1 T1105 TTP Compromised Windows Host, Ingress Tool Transfer, Cisco Network Visibility Module Analytics, Axios Supply Chain Post Compromise, NPM Supply Chain Compromise, Microsoft WSUS CVE-2025-59287, PromptLock 2026-07-14
WinRAR Spawning Shell Application CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1105 TTP WinRAR Spoofing Attack CVE-2023-38831, Compromised Windows Host 2026-05-13
Linux Curl Upload File Cisco Isovalent Process Exec, Sysmon for Linux EventID 1 T1105 TTP Ingress Tool Transfer, Data Exfiltration, NPM Supply Chain Compromise, Linux Living Off The Land 2026-05-13
Linux Ingress Tool Transfer Hunting Sysmon for Linux EventID 1 T1105 Hunting Ingress Tool Transfer, Axios Supply Chain Post Compromise, NPM Supply Chain Compromise, XorDDos, Linux Living Off The Land 2026-05-13
Windows Proxy Via Registry Sysmon EventID 13 T1090.001 Anomaly Volt Typhoon 2026-05-13
Curl Execution with Percent Encoded URL Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon for Linux EventID 1 T1027 T1105 Anomaly Ingress Tool Transfer, Living Off The Land, Compromised Windows Host 2026-05-13
Windows Process Accessing IronLanguages Repository On GitHub CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1059 T1105 Anomaly Ingress Tool Transfer, Compromised Windows Host, Windows Post-Exploitation, Fake CAPTCHA Campaigns 2026-09-16
Detect Remote Access Software Usage File Sysmon EventID 11 T1219 Anomaly Cactus Ransomware, Remote Monitoring and Management Software, Ransomware, Gozi Malware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, GhostRedirector IIS Module and Rungan Backdoor, Seashell Blizzard, Insider Threat, CISA AA24-241A 2026-05-13
File Download or Read to Pipe Execution Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon for Linux EventID 1 T1105 TTP Compromised Windows Host, Log4Shell CVE-2021-44228, Ingress Tool Transfer, NPM Supply Chain Compromise, Linux Living Off The Land 2026-09-01
Windows Ngrok Reverse Proxy Usage CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1090 T1102 T1572 Anomaly Reverse Network Proxy, CISA AA24-241A, CISA AA22-320A 2026-05-13
Windows Finger.exe Connecting to a Remote Host CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1071 TTP Living Off The Land, Compromised Windows Host, Command And Control, Fake CAPTCHA Campaigns, Windows Post-Exploitation 2026-09-16
Windows Proxy Via Netsh CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1090.001 Anomaly Volt Typhoon 2026-05-13
Windows Potential Cloudflared Network Connection Sysmon EventID 3 T1572 Hunting Reverse Network Proxy 2026-05-13
Windows File Download Via PowerShell CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1 T1059.001 T1105 Anomaly HAFNIUM Group, Data Destruction, Tuoni, Cisco Network Visibility Module Analytics, Winter Vivern, PHP-CGI RCE Attack on Japanese Organizations, Hermetic Wiper, GhostRedirector IIS Module and Rungan Backdoor, SolarWinds WHD RCE Post Exploitation, Ingress Tool Transfer, SysAid On-Prem Software CVE-2023-47246 Vulnerability, Phemedrone Stealer, Microsoft WSUS CVE-2025-59287, APT37 Rustonotto and FadeStealer, Malicious PowerShell, StealC Stealer, IcedID, NetSupport RMM Tool Abuse, NPM Supply Chain Compromise, XWorm 2026-07-14
Windows Outlook Macro Security Modified Sysmon EventID 13 T1008 T1137 TTP Windows Registry Abuse, NotDoor Malware 2026-05-13
Living Off The Land Detection T1059 T1105 T1133 T1190 Correlation Living Off The Land, Hellcat Ransomware 2026-05-13
Detect Certify Command Line Arguments CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1105 T1649 TTP Ingress Tool Transfer, Compromised Windows Host, Windows Certificate Services 2026-05-13
Windows Potential Cloudflared Tunnel Execution CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1572 Anomaly Reverse Network Proxy 2026-05-13
Windows SSH Proxy Command CrowdStrike ProcessRollup2, Sysmon EventID 1 T1059.001 T1105 T1572 Anomaly ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Living Off The Land, Hellcat Ransomware 2026-05-13
Linux Proxy Socks Curl Sysmon for Linux EventID 1 T1090 T1095 TTP Ingress Tool Transfer, Linux Living Off The Land 2026-06-04
Windows Cabinet File Extraction Via Expand CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1105 TTP NetSupport RMM Tool Abuse, APT37 Rustonotto and FadeStealer 2026-05-13
Log4Shell CVE-2021-44228 Exploitation T1059 T1105 T1133 T1190 Correlation Log4Shell CVE-2021-44228, CISA AA22-320A 2026-05-13
Windows File Download Via CertUtil CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1 T1105 TTP Living Off The Land, Compromised Windows Host, Ingress Tool Transfer, ProxyNotShell, CISA AA22-277A, Cisco Network Visibility Module Analytics, Flax Typhoon, DarkSide Ransomware, Forest Blizzard 2026-07-14
Linux Ngrok Reverse Proxy Usage Sysmon for Linux EventID 1 T1090 T1102 T1572 Anomaly Reverse Network Proxy 2026-05-13
Socat Remote TCP Connection with Local Echo Disabled Sysmon for Linux EventID 1, Osquery Results T1059 T1572 Anomaly MacOS Post-Exploitation 2026-08-27
Detect Remote Access Software Usage FileInfo Sysmon EventID 1 T1219 Anomaly Remote Monitoring and Management Software, Ransomware, Gozi Malware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, Seashell Blizzard, Insider Threat, Cactus Ransomware 2026-05-13
Socat Network Listener Binding an Executable Sysmon for Linux EventID 1, Osquery Results T1059 T1572 TTP MacOS Post-Exploitation 2026-08-27
Windows Remote Access Software RMS Registry Sysmon EventID 13 T1219 TTP Azorult 2026-05-13
Windows SQL Spawning CertUtil CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1105 TTP SQL Server Abuse, Flax Typhoon, Storm-2460 CLFS Zero Day Exploitation 2026-05-13
Windows Credential Target Information Structure in Commandline Sysmon EventID 1 T1071.004 T1187 T1557.001 TTP Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS 2026-05-13
Potential Telegram API Request Via CommandLine CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1041 T1102.002 Anomaly 0bj3ctivity Stealer, Hellcat Ransomware, XMRig, BlankGrabber Stealer, Water Gamayun 2026-05-13
Linux Ingress Tool Transfer with Curl Sysmon for Linux EventID 1 T1105 Anomaly Ingress Tool Transfer, NPM Supply Chain Compromise, XorDDos, Linux Living Off The Land 2026-05-13
Windows Curl Download to Suspicious Path CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1 T1105 TTP Compromised Windows Host, Ingress Tool Transfer, Cisco Network Visibility Module Analytics, IcedID, China-Nexus Threat Activity, Starland RAT Campaign, Black Basta Ransomware, NPM Supply Chain Compromise, GhostRedirector IIS Module and Rungan Backdoor, Salt Typhoon, APT37 Rustonotto and FadeStealer, Forest Blizzard 2026-07-20
Windows TOR Client Execution CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1090.003 Anomaly Data Protection, Compromised Windows Host, Data Exfiltration, Command And Control, Windows Post-Exploitation 2026-05-13
Suspicious Curl Network Connection Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon for Linux EventID 1 T1105 TTP Hellcat Ransomware, Ingress Tool Transfer, Linux Living Off The Land, GhostRedirector IIS Module and Rungan Backdoor, Silver Sparrow, APT37 Rustonotto and FadeStealer 2026-05-13
Windows Ingress Tool Transfer Using Explorer CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1105 Anomaly DarkCrystal RAT 2026-05-13
Windows Devtunnels Execution CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1 T1090 Anomaly Reverse Network Proxy 2026-05-13
Windows PowGoop Beacon Decoding CrowdStrike ProcessRollup2, Sysmon EventID 1 T1001 T1059.001 TTP Compromised Windows Host 2026-05-13
TOR Traffic Cisco Secure Firewall Threat Defense Connection Event, Palo Alto Network Traffic T1090.003 TTP NOBELIUM Group, Prohibited Traffic Allowed or Protocol Mismatch, Ransomware, Interlock Ransomware, Command And Control, Cisco Secure Firewall Threat Defense Analytics 2026-05-13
HTTP Malware User Agent Suricata T1071.001 TTP RedLine Stealer, Meduza Stealer, Crypto Stealer, Lokibot, Lumma Stealer, Suspicious User Agents 2026-05-13
HTTP RMM User Agent Suricata T1071.001 T1219 Anomaly Remote Monitoring and Management Software, Suspicious User Agents 2026-05-13
SSL Certificates with Punycode T1573 Hunting OpenSSL CVE-2022-3602 2026-05-13
HTTP PUA User Agent Suricata T1071.001 Anomaly BlackSuit Ransomware, Local Privilege Escalation With KrbRelayUp, Cactus Ransomware, Suspicious User Agents 2026-05-13
Detect Large ICMP Traffic Cisco Secure Access Firewall, Palo Alto Network Traffic T1095 TTP Command And Control, China-Nexus Threat Activity, Backdoor Pingpong, Cisco Secure Access Analytics 2026-05-13
Excessive DNS Failures T1071.004 Anomaly Suspicious DNS Traffic, Command And Control 2026-05-13
Cisco Secure Firewall - Remote Access Software Usage Traffic Cisco Secure Firewall Threat Defense Connection Event T1219 Anomaly Remote Monitoring and Management Software, Ransomware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, Cisco Secure Firewall Threat Defense Analytics, Insider Threat 2026-05-13
Detect Remote Access Software Usage DNS Sysmon EventID 22 T1219 Anomaly Remote Monitoring and Management Software, Ransomware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, Insider Threat, CISA AA24-241A 2026-05-13
HTTP C2 Framework User Agent Suricata T1071.001 TTP Brute Ratel C4, Spearphishing Attachments, Tuoni, Meterpreter, BishopFox Sliver Adversary Emulation Framework, Suspicious User Agents, Cobalt Strike, Malicious PowerShell 2026-05-13
Ngrok Reverse Proxy on Network Sysmon EventID 22 T1090 T1102 T1572 Anomaly Reverse Network Proxy, CISA AA24-241A, CISA AA22-320A 2026-05-13
DNS Kerberos Coercion Suricata, Sysmon EventID 22 T1071.004 T1187 T1557.001 TTP Suspicious DNS Traffic, Compromised Windows Host, Local Privilege Escalation With KrbRelayUp, Kerberos Coercion with DNS 2026-09-08
Detect Remote Access Software Usage Traffic Palo Alto Network Traffic T1219 Anomaly Remote Monitoring and Management Software, Ransomware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, Insider Threat 2026-05-13
Detect Outbound SMB Traffic Cisco Secure Access Firewall, Cisco Secure Firewall Threat Defense Connection Event T1071.002 TTP NOBELIUM Group, Cisco Secure Firewall Threat Defense Analytics, Hidden Cobra Malware, DHS Report TA18-074A, Cisco Secure Access Analytics 2026-05-13
LOLBAS With Network Traffic Sysmon EventID 3 T1105 T1218 T1567 TTP Living Off The Land, Hellcat Ransomware, NetSupport RMM Tool Abuse, Malicious Inno Setup Loader, GhostRedirector IIS Module and Rungan Backdoor, Fake CAPTCHA Campaigns, APT37 Rustonotto and FadeStealer, Water Gamayun 2026-08-24