|
Juniper Networks Remote Code Execution Exploit Detection
|
Suricata
|
T1059
T1105
T1190
|
TTP
|
Juniper JunOS Remote Code Execution
|
2026-05-13
|
|
CrushFTP Authentication Bypass Exploitation
|
CrushFTP
|
T1059.001
T1059.003
T1190
|
TTP
|
Hellcat Ransomware, CrushFTP Vulnerabilities
|
2026-09-08
|
|
AWS ECR Container Scanning Findings Low Informational Unknown
|
AWS CloudTrail DescribeImageScanFindings
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Microsoft Intune Mobile Apps
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Microsoft Intune Device Health Scripts
|
Azure Monitor Activity
|
T1021.007
T1072
T1105
T1202
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Kubernetes newly seen UDP edge
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
AWS ECR Container Scanning Findings Medium
|
AWS CloudTrail DescribeImageScanFindings
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes Previously Unseen Process
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Traffic on Network Edge
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
AWS ECR Container Upload Unknown User
|
AWS CloudTrail PutImage
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes Shell Running on Worker Node
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
O365 Threat Intelligence Suspicious File Detected
|
Office 365 Universal Audit Log
|
T1204.002
|
TTP
|
Office 365 Account Takeover, Ransomware Cloud, Azure Active Directory Account Takeover
|
2026-05-13
|
|
AWS Lambda UpdateFunctionCode
|
AWS CloudTrail
|
T1204
|
Hunting
|
Suspicious Cloud User Activities
|
2026-05-13
|
|
Kubernetes Unauthorized Access
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Process Running From New Path
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes DaemonSet Deployed
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
ASL AWS ECR Container Upload Outside Business Hours
|
ASL AWS CloudTrail
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
O365 SharePoint Malware Detection
|
Office 365 Universal Audit Log
|
T1204.002
|
TTP
|
Azure Active Directory Persistence, Office 365 Account Takeover, Ransomware Cloud
|
2026-05-13
|
|
Kubernetes Falco Shell Spawned
|
Kubernetes Falco
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Shell Running on Worker Node with CPU Activity
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Inbound Network Activity from Process
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Pod Created in Default Namespace
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Anomalous Outbound Network Activity from Process
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
AWS ECR Container Upload Outside Business Hours
|
AWS CloudTrail PutImage
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes newly seen TCP edge
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Microsoft Intune Manual Device Management
|
Azure Monitor Activity
|
T1021.007
T1072
T1529
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Kubernetes Pod With Host Network Attachment
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Previously Unseen Container Image Name
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Create or Update Privileged Pod
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Kubernetes Node Port Creation
|
Kubernetes Audit
|
T1204
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
AWS ECR Container Scanning Findings High
|
AWS CloudTrail DescribeImageScanFindings
|
T1204.003
|
TTP
|
Dev Sec Ops
|
2026-05-13
|
|
Microsoft Intune DeviceManagementConfigurationPolicies
|
Azure Monitor Activity
|
T1021.007
T1072
T1484
T1685
T1686
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
ASL AWS ECR Container Upload Unknown User
|
ASL AWS CloudTrail
|
T1204.003
|
Anomaly
|
Dev Sec Ops
|
2026-05-13
|
|
Kubernetes Cron Job Creation
|
Kubernetes Audit
|
T1053.007
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Python Network Traffic During Package Build
|
Sysmon EventID 1, Sysmon EventID 3
|
T1059.006
T1195.002
|
Anomaly
|
Malicious Python Package Installation, Compromised Windows Host, Command And Control, Ingress Tool Transfer
|
2026-08-21
|
|
MacOS LOLbin
|
Osquery Results
|
T1059.004
|
TTP
|
Living Off The Land, Axios Supply Chain Post Compromise, Hellcat Ransomware
|
2026-05-13
|
|
Windows Service Create SliverC2
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Compromised Windows Host, BishopFox Sliver Adversary Emulation Framework, Hellcat Ransomware
|
2026-05-13
|
|
Windows Hijack Execution Flow Version Dll Side Load
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
SolarWinds WHD RCE Post Exploitation, Malicious Inno Setup Loader, XWorm, Brute Ratel C4
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Name
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Ryuk Ransomware, 0bj3ctivity Stealer, Ransomware, Castle RAT, Scheduled Tasks, Windows Persistence Techniques, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Schedule Task with Rundll32 Command Trigger
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Living Off The Land, Compromised Windows Host, Trickbot, IcedID, Castle RAT, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows Developer-Signed MSIX Package Installation
|
Windows Event Log AppXDeployment-Server 855
|
T1204.002
T1553.005
|
Anomaly
|
MSIX Package Abuse
|
2026-05-13
|
|
MSI Module Loaded by Non-System Binary
|
Sysmon EventID 7
|
T1574.001
|
Hunting
|
Windows Privilege Escalation, Hermetic Wiper, Data Destruction
|
2026-05-13
|
|
Windows PowerShell ScheduleTask
|
Powershell Script Block Logging 4104
|
T1053.005
T1059.001
|
Anomaly
|
Scattered Spider, Scheduled Tasks, Starland RAT Campaign
|
2026-07-20
|
|
Windows Defender ASR Block Events
|
Windows Event Log Defender 1126, Windows Event Log Defender 1121, Windows Event Log Defender 1133, Windows Event Log Defender 1129, Windows Event Log Defender 1131
|
T1059
T1566.001
T1566.002
|
Anomaly
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Windows PowerShell Script TabExpansion Direct Call
|
Powershell Script Block Logging 4104
|
T1059.001
T1129
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
Cisco NVM - Suspicious Download From File Sharing Website
|
Cisco Network Visibility Module Flow Data
|
T1197
|
Anomaly
|
Cisco Network Visibility Module Analytics, BlankGrabber Stealer, APT37 Rustonotto and FadeStealer
|
2026-07-14
|
|
Windows Enable PowerShell Web Access
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
CISA AA24-241A, Malicious PowerShell
|
2026-05-13
|
|
Windows Anonymous Pipe Activity
|
Sysmon EventID 18, Sysmon EventID 17
|
T1559
|
Hunting
|
Castle RAT, SnappyBee, Interlock Rat, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Suspicious QEMU Execution
|
Sysmon EventID 1
|
T1001
T1036
T1204.002
T1564.006
|
TTP
|
Compromised Linux Host, Linux Post-Exploitation, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Linux Rootkit, Linux Living Off The Land
|
2026-05-13
|
|
Drop IcedID License dat
|
Sysmon EventID 11
|
T1204.002
|
Hunting
|
IcedID
|
2026-05-13
|
|
PowerShell Enable PowerShell Remoting
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Defender ASR Audit Events
|
Windows Event Log Defender 1134, Windows Event Log Defender 1126, Windows Event Log Defender 1125, Windows Event Log Defender 1122, Windows Event Log Defender 1132
|
T1059
T1566.001
T1566.002
|
Anomaly
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Powershell Fileless Process Injection via GetProcAddress
|
Powershell Script Block Logging 4104
|
T1055
T1059.001
|
TTP
|
Data Destruction, Hermetic Wiper, Malicious PowerShell, Hellcat Ransomware
|
2026-05-13
|
|
Powershell Execute COM Object
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Ransomware, Hermetic Wiper, Malicious PowerShell, Data Destruction
|
2026-05-13
|
|
Windows DLL Search Order Hijacking Hunt with Sysmon
|
Sysmon EventID 7
|
T1574.001
|
Hunting
|
Malicious Inno Setup Loader, Living Off The Land, Qakbot, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Unloading AMSI via Reflection
|
Powershell Script Block Logging 4104
|
T1059.001
T1685
|
TTP
|
Data Destruction, Hermetic Wiper, Malicious PowerShell
|
2026-05-13
|
|
Windows PowerShell Invoke-RestMethod IP Information Collection
|
Powershell Script Block Logging 4104
|
T1016
T1059.001
T1082
|
Anomaly
|
Water Gamayun
|
2026-05-13
|
|
Windows Powershell Cryptography Namespace
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Phantom Stealer, AsyncRAT, XWorm, VIP Keylogger
|
2026-06-25
|
|
MacOS AMOS Stealer - Virtual Machine Check Activity
|
Osquery Results
|
T1059.002
|
Anomaly
|
AMOS Stealer, Hellcat Ransomware
|
2026-05-13
|
|
Windows Scheduled Task DLL Module Loaded
|
Sysmon EventID 7
|
T1053
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
WinEvent Scheduled Task Created to Spawn Shell
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Compromised Windows Host, Ryuk Ransomware, 0bj3ctivity Stealer, Medusa Ransomware, Windows Error Reporting Service Elevation of Privilege Vulnerability, Ransomware, Winter Vivern, Castle RAT, SystemBC, Scheduled Tasks, Windows Persistence Techniques, CISA AA22-257A, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Unsigned DLL Side-Loading
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
SolarWinds WHD RCE Post Exploitation, Earth Alux, Derusbi, Warzone RAT, NjRAT, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Hidden Schedule Task Settings
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Compromised Windows Host, Hellcat Ransomware, Malicious Inno Setup Loader, Scheduled Tasks, CISA AA22-257A, Active Directory Discovery, Cactus Ransomware, Data Destruction, Industroyer2
|
2026-05-13
|
|
PowerShell Start or Stop Service
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Scattered Lapsus$ Hunters, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows SqlWriter SQLDumper DLL Sideload
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
APT29 Diplomatic Deceptions with WINELOADER
|
2026-05-13
|
|
PowerShell Environment Variable Execution
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
VIP Keylogger
|
2026-06-29
|
|
Detect Empire with PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Data Destruction, Hermetic Wiper, Malicious PowerShell, Hellcat Ransomware
|
2026-05-13
|
|
Detect Mimikatz With PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1003
T1059.001
|
TTP
|
CISA AA23-347A, Sandworm Tools, Hellcat Ransomware, Data Destruction, Scattered Spider, CISA AA22-264A, Hermetic Wiper, CISA AA22-320A, Malicious PowerShell
|
2026-05-13
|
|
Cisco NVM - Suspicious File Download via Headless Browser
|
Cisco Network Visibility Module Flow Data
|
T1059
T1105
|
TTP
|
Cisco Network Visibility Module Analytics, BlankGrabber Stealer
|
2026-07-14
|
|
Linux Magic SysRq Key Abuse
|
Linux Auditd Path, Linux Auditd Cwd
|
T1059.004
T1489
T1499
T1529
|
TTP
|
Compromised Linux Host
|
2026-05-13
|
|
Detect Certify With PowerShell Script Block Logging
|
Powershell Script Block Logging 4104
|
T1059.001
T1649
|
TTP
|
Windows Certificate Services, Malicious PowerShell
|
2026-05-13
|
|
Windows Suspicious C2 Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
TTP
|
Brute Ratel C4, Graceful Wipe Out Attack, BlackByte Ransomware, DarkSide Ransomware, Hellcat Ransomware, Remote Monitoring and Management Software, Storm-0501 Ransomware, Gozi Malware, Meterpreter, Trickbot, Tuoni, Cobalt Strike, LockBit Ransomware, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Powershell Commands from DNS TXT
|
Powershell Script Block Logging 4104
|
T1059.001
T1071.004
|
Anomaly
|
Suspicious DNS Traffic, Command And Control, Malicious PowerShell
|
2026-07-30
|
|
Windows WMI Impersonate Token
|
Sysmon EventID 10
|
T1047
|
Anomaly
|
Qakbot, Water Gamayun
|
2026-09-08
|
|
Linux Auditd Edit Cron Table Parameter
|
Linux Auditd Syscall
|
T1053.003
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land
|
2026-05-13
|
|
Powershell Load Module in Meterpreter
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
MetaSploit
|
2026-05-13
|
|
WMI Permanent Event Subscription
|
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Powershell Fileless Script Contains Base64 Encoded Content
|
Powershell Script Block Logging 4104
|
T1027
T1059.001
|
TTP
|
Medusa Ransomware, Hellcat Ransomware, XWorm, Phantom Stealer, Winter Vivern, Axios Supply Chain Post Compromise, AsyncRAT, VIP Keylogger, Hermetic Wiper, GhostRedirector IIS Module and Rungan Backdoor, MuddyWater, Microsoft WSUS CVE-2025-59287, APT37 Rustonotto and FadeStealer, Malicious PowerShell, 0bj3ctivity Stealer, IcedID, NjRAT, NetSupport RMM Tool Abuse, Salat Stealer, Data Destruction
|
2026-06-25
|
|
Linux Auditd Preload Hijack Library Calls
|
Linux Auditd Execve
|
T1574.006
|
TTP
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows BitDefender Submission Wizard DLL Sideloading
|
Sysmon EventID 7
|
T1574
|
TTP
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Cisco NVM - Installation of Typosquatted Python Package
|
Cisco Network Visibility Module Flow Data
|
T1059
|
TTP
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows AppX Deployment Full Trust Package Installation
|
Windows Event Log AppXDeployment-Server 400
|
T1204.002
T1553.005
|
Hunting
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows PowerShell Script Block With Malicious String
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Cisco Isovalent - Non Allowlisted Image Use
|
Cisco Isovalent Process Exec
|
T1204.003
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Linux Auditd Service Started
|
Linux Auditd Proctitle
|
T1569.002
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Cisco NVM - Browser Spawned Unix Shell with External Connection
|
Cisco Network Visibility Module Flow Data
|
T1059
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-09-02
|
|
Windows MSIX Package Interaction
|
Windows Event Log AppXPackaging 171
|
T1204.002
|
Hunting
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows PowerShell Get CIMInstance Remote Computer
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Remote Process Instantiation via WMI and PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1047
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Cisco Isovalent - Pods Running Offensive Tools
|
Cisco Isovalent Process Exec
|
T1204.003
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows Powershell Logoff User via Quser
|
Powershell Script Block Logging 4104
|
T1059.001
T1531
|
Anomaly
|
Crypto Stealer
|
2026-06-29
|
|
Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
ValleyRAT, Water Gamayun
|
2026-05-13
|
|
Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File
|
Linux Auditd Path, Linux Auditd Cwd
|
T1053.003
|
Hunting
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows Powershell History File Deletion
|
Powershell Script Block Logging 4104
|
T1059.003
T1070.003
|
Anomaly
|
Medusa Ransomware
|
2026-05-13
|
|
Windows Unsigned MS DLL Side-Loading
|
Sysmon EventID 7
|
T1547
T1574.001
|
Anomaly
|
Earth Alux, APT29 Diplomatic Deceptions with WINELOADER, Derusbi, Salt Typhoon, China-Nexus Threat Activity, XWorm
|
2026-05-13
|
|
PowerShell Script Block With URL Chain
|
Powershell Script Block Logging 4104
|
T1059.001
T1105
|
TTP
|
Malicious PowerShell, Hellcat Ransomware
|
2026-05-13
|
|
Get-ForestTrust with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows PowerShell Invoke-Sqlcmd Execution
|
Powershell Script Block Logging 4104
|
T1059.001
T1059.003
|
Hunting
|
SQL Server Abuse, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows Process Accessing Windows Recall Directory
|
Windows Event Log Security 4663
|
T1059
T1119
|
Anomaly
|
Windows Post-Exploitation
|
2026-05-13
|
|
Windows PowerShell WMI Win32 ScheduledJob
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
PowerShell Domain Enumeration
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
CISA AA23-347A, Interlock Ransomware, Malicious PowerShell, Hermetic Wiper, Microsoft WSUS CVE-2025-59287, Data Destruction
|
2026-06-28
|
|
PowerShell 4104 Hunting
|
Powershell Script Block Logging 4104
|
T1003
T1059.001
T1689
|
Hunting
|
Medusa Ransomware, Hellcat Ransomware, Data Destruction, Phantom Stealer, Salt Typhoon, Cactus Ransomware, China-Nexus Threat Activity, Axios Supply Chain Post Compromise, PHP-CGI RCE Attack on Japanese Organizations, Interlock Ransomware, SystemBC, Hermetic Wiper, GhostRedirector IIS Module and Rungan Backdoor, CISA AA24-241A, CISA AA23-347A, DarkGate Malware, MuddyWater, Rhysida Ransomware, Lumma Stealer, Microsoft WSUS CVE-2025-59287, Flax Typhoon, Cleo File Transfer Software, APT37 Rustonotto and FadeStealer, Malicious PowerShell, Water Gamayun, 0bj3ctivity Stealer, Scattered Spider, Salat Stealer, Braodo Stealer, Starland RAT Campaign, XWorm
|
2026-09-03
|
|
Linux Auditd At Application Execution
|
Linux Auditd Syscall
|
T1053.002
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land
|
2026-05-13
|
|
Powershell Processing Stream Of Data
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
Medusa Ransomware, Hellcat Ransomware, MoonPeak, IcedID, XWorm, AsyncRAT, MuddyWater, Braodo Stealer, Malicious PowerShell, Salat Stealer, Hermetic Wiper, PXA Stealer, Data Destruction
|
2026-06-29
|
|
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
|
Cisco Network Visibility Module Flow Data
|
T1059.005
T1218.005
|
Anomaly
|
Cisco Network Visibility Module Analytics, BlankGrabber Stealer
|
2026-07-14
|
|
Windows Known GraphicalProton Loaded Modules
|
Sysmon EventID 7
|
T1574.001
|
Anomaly
|
CISA AA23-347A, Hellcat Ransomware, Water Gamayun
|
2026-05-13
|
|
PowerShell Invoke WmiExec Usage
|
Powershell Script Block Logging 4104
|
T1047
|
TTP
|
Scattered Lapsus$ Hunters, Suspicious WMI Use
|
2026-05-13
|
|
Malicious Powershell Executed As A Service
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Rhysida Ransomware, Compromised Windows Host, Malicious PowerShell
|
2026-05-13
|
|
PowerShell Invoke CIMMethod CIMSession
|
Powershell Script Block Logging 4104
|
T1047
|
Anomaly
|
Scattered Lapsus$ Hunters, Malicious PowerShell, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Cobalt Strike PowerShell Loader
|
Powershell Script Block Logging 4104
|
T1059.001
T1608
|
TTP
|
Cobalt Strike
|
2026-05-13
|
|
Sunburst Correlation DLL and Network Event
|
Sysmon EventID 7, Sysmon EventID 22
|
T1203
|
TTP
|
NOBELIUM Group
|
2026-05-13
|
|
MS Scripting Process Loading Ldap Module
|
Sysmon EventID 7
|
T1059.007
|
Anomaly
|
FIN7
|
2026-05-13
|
|
Linux Auditd Service Restarted
|
Linux Auditd Proctitle
|
T1053.006
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, AwfulShred, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction
|
2026-05-13
|
|
Linux Auditd Preload Hijack Via Preload File
|
Linux Auditd Path, Linux Auditd Cwd
|
T1574.006
|
TTP
|
Compromised Linux Host, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
WinEvent Scheduled Task Created Within Public Path
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Medusa Ransomware, Data Destruction, Quasar RAT, Prestige Ransomware, Windows Persistence Techniques, Salt Typhoon, China-Nexus Threat Activity, ValleyRAT, Winter Vivern, Ransomware, PlugX, AsyncRAT, SystemBC, Scheduled Tasks, Compromised Windows Host, CISA AA23-347A, Ryuk Ransomware, Active Directory Lateral Movement, Remcos, Castle RAT, APT37 Rustonotto and FadeStealer, Industroyer2, 0bj3ctivity Stealer, IcedID, Malicious Inno Setup Loader, CISA AA22-257A, XWorm
|
2026-05-13
|
|
Schedule Task with HTTP Command Arguments
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Living Off The Land, Compromised Windows Host, Hellcat Ransomware, Winter Vivern, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Powershell Creating Thread Mutex
|
Powershell Script Block Logging 4104
|
T1027.005
T1059.001
|
TTP
|
Malicious PowerShell, Water Gamayun
|
2026-05-13
|
|
Windows Powershell Import Applocker Policy
|
Powershell Script Block Logging 4104
|
T1059.001
T1685
|
Anomaly
|
Azorult
|
2026-06-29
|
|
Windows RMM Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
Anomaly
|
Cactus Ransomware, Remote Monitoring and Management Software, Ransomware, Gozi Malware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, GhostRedirector IIS Module and Rungan Backdoor, Seashell Blizzard, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
Randomly Generated Scheduled Task Name
|
Windows Event Log Security 4698
|
T1053.005
|
Hunting
|
Active Directory Lateral Movement, 0bj3ctivity Stealer, Scheduled Tasks, CISA AA22-257A
|
2026-05-13
|
|
WinEvent Windows Task Scheduler Event Action Started
|
Windows Event Log TaskScheduler 200, Windows Event Log TaskScheduler 201
|
T1053.005
|
Hunting
|
Qakbot, Sandworm Tools, DarkCrystal RAT, Windows Persistence Techniques, Prestige Ransomware, ValleyRAT, BlackSuit Ransomware, Winter Vivern, PlugX, AsyncRAT, SystemBC, Scheduled Tasks, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Remcos, Industroyer2, IcedID, Malicious Inno Setup Loader, CISA AA22-257A, Amadey, Data Destruction
|
2026-05-13
|
|
Windows AppX Deployment Package Installation Success
|
Windows Event Log AppXDeployment-Server 854
|
T1204.002
|
Anomaly
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows DLL Side-Loading In Calc
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
Earth Alux, Qakbot
|
2026-05-13
|
|
Windows Scheduled Task Created in a Group Policy Object
|
Windows Event Log Security 5145
|
T1053.005
T1484.001
|
TTP
|
Living Off The Land, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows GrimResource - MMC Process Accessing APDS DLL
|
Windows Event Log Security 4663
|
T1059.007
T1218.014
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
MS Scripting Process Loading WMI Module
|
Sysmon EventID 7
|
T1059.007
|
Anomaly
|
FIN7
|
2026-05-13
|
|
Powershell COM Hijacking InprocServer32 Modification
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Windows Unsigned DLL Side-Loading In Same Process Path
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Derusbi, PlugX, Malicious Inno Setup Loader, DarkGate Malware, NailaoLocker Ransomware, SnappyBee, Lokibot, Salt Typhoon, China-Nexus Threat Activity, XWorm
|
2026-05-13
|
|
Windows Defender ASR Rules Stacking
|
Windows Event Log Defender 1134, Windows Event Log Defender 1126, Windows Event Log Defender 1121, Windows Event Log Defender 1133, Windows Event Log Defender 5007, Windows Event Log Defender 1125, Windows Event Log Defender 1122, Windows Event Log Defender 1129, Windows Event Log Defender 1131
|
T1059
T1566.001
T1566.002
|
Hunting
|
Windows Attack Surface Reduction
|
2026-05-13
|
|
Cisco NVM - Susp Script From Archive Triggering Network Activity
|
Cisco Network Visibility Module Flow Data
|
T1059.005
T1204.002
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Remote Image Load
|
Sysmon EventID 7
|
T1059
T1068
T1129
T1203
|
Anomaly
|
Ransomware, LockBit Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows Suspicious Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
TTP
|
Brute Ratel C4, Graceful Wipe Out Attack, BlackByte Ransomware, Hellcat Ransomware, APT37 Rustonotto and FadeStealer, Remote Monitoring and Management Software, Trickbot, Gozi Malware, Meterpreter, Tuoni, Cobalt Strike, LockBit Ransomware, DarkSide Ransomware
|
2026-05-13
|
|
Windows MSExchange Management Mailbox Cmdlet Usage
|
|
T1059.001
|
Anomaly
|
ProxyNotShell, Scattered Spider, BlackByte Ransomware, ProxyShell
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Command
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Ryuk Ransomware, Ransomware, Quasar RAT, Scheduled Tasks, Windows Persistence Techniques, Seashell Blizzard, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Executable in Loaded Modules
|
Sysmon EventID 7
|
T1129
|
TTP
|
NjRAT, Lokibot
|
2026-05-13
|
|
Recon Using WMI Class
|
Powershell Script Block Logging 4104
|
T1059.001
T1592
|
Anomaly
|
Qakbot, MoonPeak, Scattered Spider, Axios Supply Chain Post Compromise, AsyncRAT, Malicious Inno Setup Loader, Quasar RAT, VIP Keylogger, Malicious PowerShell, BlankGrabber Stealer, Hermetic Wiper, LockBit Ransomware, Data Destruction, Industroyer2
|
2026-05-13
|
|
PowerShell WebRequest Using Memory Stream
|
Powershell Script Block Logging 4104
|
T1027.011
T1059.001
T1105
|
TTP
|
Malicious PowerShell, Medusa Ransomware, MoonPeak, PHP-CGI RCE Attack on Japanese Organizations
|
2026-05-13
|
|
Windows SQL Server Extended Procedure DLL Loading Hunt
|
Windows Event Log Application 8128
|
T1059.009
T1505.001
|
Hunting
|
SQL Server Abuse
|
2026-05-13
|
|
Windows Software Discovery Via PowerShell
|
Powershell Script Block Logging 4104
|
T1012
T1059.001
T1518
|
Anomaly
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows Content Copied from Browser was Executed
|
Sysmon EventID 24, Sysmon EventID 13
|
T1059.001
T1059.003
T1202
|
TTP
|
Fake CAPTCHA Campaigns
|
2026-09-07
|
|
Windows Service Created with Suspicious Service Name
|
Windows Event Log System 7045
|
T1569.002
|
Anomaly
|
Brute Ratel C4, Active Directory Lateral Movement, CISA AA23-347A, Qakbot, Gh0st RAT, PlugX, Tuoni, Snake Malware, Clop Ransomware, Flax Typhoon
|
2026-05-13
|
|
Short Lived Scheduled Task
|
Windows Event Log Security 4698, Windows Event Log Security 4699
|
T1053.005
|
Anomaly
|
Active Directory Lateral Movement, CISA AA23-347A, Compromised Windows Host, Scheduled Tasks, CISA AA22-257A
|
2026-07-07
|
|
Windows AppX Deployment Unsigned Package Installation
|
Windows Event Log AppXDeployment-Server 855
|
T1204.002
T1553.005
|
TTP
|
MSIX Package Abuse
|
2026-05-13
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Windows Service Created with Suspicious Service Path
|
Windows Event Log System 7045
|
T1569.002
|
TTP
|
Brute Ratel C4, Active Directory Lateral Movement, Qakbot, CISA AA23-347A, Derusbi, Gh0st RAT, APT37 Rustonotto and FadeStealer, PlugX, Snake Malware, Clop Ransomware, Crypto Stealer, Salt Typhoon, Flax Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows PowerShell MSIX Package Installation
|
Powershell Script Block Logging 4104
|
T1059.001
T1547.001
|
TTP
|
MSIX Package Abuse, Malicious PowerShell
|
2026-05-13
|
|
PowerShell PInvoke Process Injection API Chain
|
Powershell Script Block Logging 4104
|
T1055.001
T1055.003
T1055.004
T1055.012
T1055.013
T1059.001
T1620
|
TTP
|
VIP Keylogger, Phantom Stealer
|
2026-06-25
|
|
Cisco NVM - Osascript Network Connection for a Long Duration
|
Cisco Network Visibility Module Flow Data
|
T1059.002
T1071.001
|
Anomaly
|
Cisco Network Visibility Module Analytics, Command And Control, MacOS Post-Exploitation
|
2026-09-18
|
|
WMI Temporary Event Subscription
|
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Windows Known Abused DLL Loaded Suspiciously
|
Sysmon EventID 7
|
T1574.001
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Living Off The Land, Windows Defense Evasion Tactics
|
2026-05-13
|
|
PowerShell Loading DotNET into Memory via Reflection
|
Powershell Script Block Logging 4104
|
T1059.001
|
Anomaly
|
0bj3ctivity Stealer, Hellcat Ransomware, Winter Vivern, Data Destruction, Axios Supply Chain Post Compromise, AsyncRAT, VIP Keylogger, Hermetic Wiper, AgentTesla, Malicious PowerShell
|
2026-06-29
|
|
Powershell Using memory As Backing Store
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
Medusa Ransomware, MoonPeak, IcedID, Salat Stealer, Malicious PowerShell, Hermetic Wiper, Data Destruction
|
2026-06-08
|
|
Cisco Isovalent - Cron Job Creation
|
Cisco Isovalent Process Exec
|
T1053.003
T1053.007
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Exchange PowerShell Module Usage
|
Powershell Script Block Logging 4104
|
T1059.001
|
TTP
|
BlackByte Ransomware, CISA AA22-277A, ProxyNotShell, Scattered Spider, CISA AA22-264A, ProxyShell
|
2026-05-13
|
|
Windows Default Cobalt Strike PowerShell Beacon
|
Powershell Script Block Logging 4104
|
T1059.001
T1204.002
|
TTP
|
Cobalt Strike
|
2026-05-13
|
|
GetLocalUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Active Directory Discovery, Malicious PowerShell
|
2026-05-13
|
|
Windows PUA Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
Anomaly
|
Active Directory Lateral Movement, HAFNIUM Group, BlackByte Ransomware, DarkSide Ransomware, Medusa Ransomware, Sandworm Tools, IcedID, DarkGate Malware, Rhysida Ransomware, SamSam Ransomware, VanHelsing Ransomware, CISA AA22-320A, Volt Typhoon, Seashell Blizzard, DHS Report TA18-074A, Cactus Ransomware
|
2026-05-13
|
|
Cisco NVM - Curl Execution With Insecure Flags
|
Cisco Network Visibility Module Flow Data
|
T1197
|
Anomaly
|
Cisco Network Visibility Module Analytics, PromptLock, Microsoft WSUS CVE-2025-59287
|
2026-07-14
|
|
Windows Error Report Created in ReportQueue Manually
|
Sysmon EventID 11
|
T1053.005
T1068
|
Anomaly
|
Windows Privilege Escalation, RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-08-18
|
|
GetWmiObject User Account with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Active Directory Discovery, Winter Vivern, Malicious PowerShell
|
2026-05-13
|
|
Python PYTHONPATH Modification During Package Installation
|
Sysmon EventID 1, Sysmon EventID 13
|
T1195.002
T1574.007
|
TTP
|
Compromised Windows Host, Suspicious Windows Registry Activities, Malicious Python Package Installation, Windows Persistence Techniques, Windows Registry Abuse
|
2026-08-21
|
|
Windows Snake Malware Service Create
|
Windows Event Log System 7045
|
T1547.006
T1569.002
|
TTP
|
Compromised Windows Host, Snake Malware
|
2026-05-13
|
|
Cisco Secure Firewall - Privileged Command Execution via HTTP
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1505.003
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics, Salt Typhoon
|
2026-05-13
|
|
Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics, Citrix NetScaler ADC and NetScaler Gateway CVE-2025-5777
|
2026-05-13
|
|
Cisco Secure Firewall - Blocked Connection
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1018
T1046
T1110
T1203
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Possibly Compromised Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1203
T1587.001
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Lumma Stealer Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1027
T1190
T1204
T1210
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics, Lumma Stealer
|
2026-05-13
|
|
Suspicious Process DNS Query Known Abuse Web Services
|
Sysmon EventID 22
|
T1059.005
|
TTP
|
Snake Keylogger, RedLine Stealer, Remcos, Malicious Inno Setup Loader, Meduza Stealer, Braodo Stealer, Phemedrone Stealer, BlankGrabber Stealer, PXA Stealer, WhisperGate, Cactus Ransomware, Data Destruction
|
2026-05-13
|
|
Cisco Secure Firewall - Malware File Downloaded
|
Cisco Secure Firewall Threat Defense File Event
|
T1105
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Binary File Type Download
|
Cisco Secure Firewall Threat Defense File Event
|
T1059
T1203
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Repeated Blocked Connections
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1018
T1046
T1110
T1203
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Suspicious Process With Discord DNS Query
|
Sysmon EventID 22
|
T1059.005
|
Anomaly
|
Phantom Stealer, BlankGrabber Stealer, PXA Stealer, WhisperGate, Cactus Ransomware, Data Destruction
|
2026-06-25
|
|
Detect Windows DNS SIGRed via Splunk Stream
|
|
T1203
|
TTP
|
Windows DNS SIGRed CVE-2020-1350
|
2026-05-13
|
|
Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003.001
T1059.001
T1190
T1210
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1059
T1071
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
MCP Prompt Injection
|
MCP Server
|
T1059
|
TTP
|
Suspicious MCP Activities
|
2026-05-13
|
|
MCP Filesystem Server Suspicious Extension Write
|
MCP Server
|
T1059
|
Hunting
|
Suspicious MCP Activities
|
2026-05-13
|
|
ESXi Reverse Shell Patterns
|
VMWare ESXi Syslog
|
T1059
|
TTP
|
Black Basta Ransomware, ESXi Post Compromise
|
2026-05-13
|
|
Ollama Suspicious Prompt Injection Jailbreak
|
Ollama Server
|
T1059
T1190
|
Anomaly
|
Suspicious Ollama Activities
|
2026-05-13
|
|
Cisco IOS XE Guestshell Activation and Destroy
|
Cisco IOS Logs
|
T1059
T1611
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
PTC Windchill Gateway Command Execution
|
Windchill Log4j
|
T1005
T1059
T1190
|
Anomaly
|
PTC Windchill Exploitation
|
2026-06-14
|
|
Cisco IOS XE Request Platform Package Describe Shell Pattern
|
Cisco IOS Logs
|
T1059
T1190
|
TTP
|
Salt Typhoon
|
2026-05-20
|
|
PTC Windchill GW READY OK Probe
|
Windchill Log4j
|
T1059
T1190
|
Anomaly
|
PTC Windchill Exploitation
|
2026-06-14
|
|
Kubernetes Process with Resource Ratio Anomalies
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Inbound to Outbound Network IO Ratio
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Anomalous Inbound Outbound Network IO
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Kubernetes Process with Anomalous Resource Utilisation
|
|
T1204
|
Anomaly
|
Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring
|
2026-05-13
|
|
Risk Rule for Dev Sec Ops by Repository
|
|
T1204.003
|
Correlation
|
Dev Sec Ops
|
2026-05-13
|
|
Windows Explorer LNK Exploit Process Launch With Padding
|
Sysmon EventID 1, Windows Event Log Security 4688
|
T1059.001
T1204.002
|
TTP
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Windows SQLCMD Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
|
Hunting
|
SQL Server Abuse, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Windows WMI Reconnaissance Class Query
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Linux Suspicious Docker Build Command Execution
|
Sysmon for Linux EventID 1
|
T1610
|
Anomaly
|
Linux Post-Exploitation
|
2026-07-08
|
|
Windows Explorer.exe Spawning PowerShell or Cmd
|
Sysmon EventID 1, Windows Event Log Security 4688
|
T1059.001
T1204.002
|
Hunting
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day
|
2026-05-13
|
|
Windows Scheduled Task with Highest Privileges
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Compromised Windows Host, CISA AA23-347A, RedLine Stealer, NetSupport RMM Tool Abuse, AsyncRAT, Castle RAT, Quasar RAT, Scheduled Tasks, XWorm
|
2026-05-13
|
|
Wermgr Process Spawned CMD Or Powershell Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
TTP
|
Qakbot, Trickbot
|
2026-05-13
|
|
Malicious PowerShell Process With Obfuscation Techniques
|
Sysmon EventID 1
|
T1059.001
|
TTP
|
Hellcat Ransomware, Malicious PowerShell, Hermetic Wiper, GhostRedirector IIS Module and Rungan Backdoor, Data Destruction
|
2026-05-13
|
|
Linux Possible System Binary Backdoor
|
Sysmon for Linux EventID 11
|
T1036
T1059.004
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
ETW Registry Disabled
|
Sysmon EventID 13
|
T1127
T1685
|
TTP
|
CISA AA23-347A, Windows Privilege Escalation, Hermetic Wiper, Windows Persistence Techniques, Windows Registry Abuse, Data Destruction
|
2026-05-13
|
|
Conti Common Exec parameter
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204
|
TTP
|
Ransomware, Compromised Windows Host, Hellcat Ransomware
|
2026-05-13
|
|
Windows ISO LNK File Creation
|
Sysmon EventID 11
|
T1204.001
T1566.001
|
Hunting
|
Brute Ratel C4, Azorult, Qakbot, Spearphishing Attachments, IcedID, Warzone RAT, Remcos, Gozi Malware, AgentTesla, Amadey, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows Suspect Process With Authentication Traffic
|
Sysmon EventID 3
|
T1087.002
T1204.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Linux Suspicious GCC Invocation Building Init Shared Object
|
Sysmon for Linux EventID 1
|
T1027.004
T1068
T1129
T1608
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Set Custom DNS ServerLevelPlugin Via Dnscmd
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Suspicious Process Executed From Container File
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.008
T1204.002
|
TTP
|
Snake Keylogger, Remcos, Unusual Processes, GhostRedirector IIS Module and Rungan Backdoor, Amadey, APT37 Rustonotto and FadeStealer, Water Gamayun
|
2026-07-09
|
|
Windows DLL Side-Loading Process Child Of Calc
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574.001
|
Anomaly
|
Earth Alux, Qakbot
|
2026-05-13
|
|
Powershell Defender Threat Actions Set to Allow
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
|
TTP
|
Salat Stealer
|
2026-05-12
|
|
Nishang PowershellTCPOneLine
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
|
TTP
|
HAFNIUM Group, Cleo File Transfer Software
|
2026-05-13
|
|
Windows Compatibility Telemetry Tampering Through Registry
|
Sysmon EventID 13
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Service Creation Using Registry Entry
|
Sysmon EventID 13
|
T1574.011
|
Anomaly
|
SolarWinds WHD RCE Post Exploitation, Brute Ratel C4, Active Directory Lateral Movement, CISA AA23-347A, Derusbi, Gh0st RAT, PlugX, Suspicious Windows Registry Activities, SnappyBee, Salt Typhoon, Windows Persistence Techniques, Crypto Stealer, Windows Registry Abuse, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Mustang Panda USB Tool Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1020
T1204.002
T1574.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows WinRAR Launched Outside Default Installation Directory
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Remote Process Instantiation via WMI
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
TTP
|
Active Directory Lateral Movement, CISA AA23-347A, Void Manticore, Ransomware, Suspicious WMI Use, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Scheduled Task Creation on Remote Endpoint using At
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.002
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, 0bj3ctivity Stealer, Scheduled Tasks
|
2026-05-13
|
|
Schtasks Run Task On Demand
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053
|
Anomaly
|
Qakbot, Medusa Ransomware, XMRig, Scheduled Tasks, CISA AA22-257A, Data Destruction, Industroyer2
|
2026-05-13
|
|
Windows PowerShell FakeCAPTCHA Clipboard Execution
|
CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1059.003
T1204.001
|
TTP
|
Cisco Network Visibility Module Analytics, NetSupport RMM Tool Abuse, Interlock Ransomware, Scattered Lapsus$ Hunters, Fake CAPTCHA Campaigns
|
2026-07-14
|
|
Windows WinDBG Spawning AutoIt3
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
TTP
|
Compromised Windows Host, DarkGate Malware
|
2026-05-13
|
|
Windows PowerShell Script From WindowsApps Directory
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1204.002
|
TTP
|
MSIX Package Abuse, Malicious PowerShell
|
2026-05-13
|
|
Windows AutoIt3 Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
TTP
|
Crypto Stealer, Handala Wiper, DarkGate Malware, Void Manticore
|
2026-05-13
|
|
Windows Enable Win32 ScheduledJob via Registry
|
Sysmon EventID 13
|
T1053.005
|
Anomaly
|
Active Directory Lateral Movement, Scheduled Tasks
|
2026-05-13
|
|
Clop Common Exec Parameter
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204
|
TTP
|
Compromised Windows Host, Clop Ransomware
|
2026-05-13
|
|
Windows WMI Process And Service List
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
Anomaly
|
Windows Post-Exploitation, Prestige Ransomware
|
2026-05-13
|
|
Batch File Write to System32
|
Sysmon EventID 11
|
T1204.002
|
Anomaly
|
Compromised Windows Host, SamSam Ransomware
|
2026-07-02
|
|
Detect Path Interception By Creation Of program exe
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574.009
|
TTP
|
Scattered Lapsus$ Hunters, Windows Persistence Techniques
|
2026-05-13
|
|
Scheduled Task Initiation on Remote Endpoint
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, Medusa Ransomware, Scheduled Tasks, Seashell Blizzard
|
2026-05-13
|
|
Windows Suspicious Child Process of Consent.EXE
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
T1068
T1548.002
|
Anomaly
|
Windows Privilege Escalation, Unusual Processes
|
2026-07-30
|
|
MacOS Osascript Executing Interactive Shell
|
Osquery Results
|
T1059.002
T1059.004
|
Anomaly
|
MacOS Post-Exploitation
|
2026-09-18
|
|
Detect Prohibited Applications Spawning cmd exe
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
|
Hunting
|
NOBELIUM Group, Suspicious Zoom Child Processes, Suspicious MSHTA Activity, Suspicious Command-Line Executions
|
2026-05-13
|
|
Scheduled Task Deleted Or Created via CMD
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
Anomaly
|
Qakbot, Sandworm Tools, Trickbot, Medusa Ransomware, RedLine Stealer, DarkCrystal RAT, Quasar RAT, Prestige Ransomware, Windows Persistence Techniques, Salt Typhoon, China-Nexus Threat Activity, NOBELIUM Group, ShrinkLocker, ValleyRAT, Winter Vivern, PlugX, AsyncRAT, Scheduled Tasks, Amadey, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Azorult, CISA AA23-347A, Remcos, Rhysida Ransomware, Phemedrone Stealer, Lokibot, APT37 Rustonotto and FadeStealer, Living Off The Land, 0bj3ctivity Stealer, MoonPeak, NjRAT, Scattered Spider, NetSupport RMM Tool Abuse, CISA AA22-257A, AgentTesla, DHS Report TA18-074A, XWorm
|
2026-05-13
|
|
Windows Process Execution From RDP Share
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.001
T1059
T1105
|
Anomaly
|
Hidden Cobra Malware
|
2026-05-13
|
|
BITSAdmin Download File
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1105
T1197
|
TTP
|
Living Off The Land, BITS Jobs, APT37 Rustonotto and FadeStealer, Ingress Tool Transfer, Hellcat Ransomware, Gozi Malware, Scattered Spider, GhostRedirector IIS Module and Rungan Backdoor, Flax Typhoon, DarkSide Ransomware
|
2026-05-13
|
|
Windows Identify Protocol Handlers
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
Hunting
|
Living Off The Land
|
2026-05-13
|
|
Windows File Association Modification via Ftype
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
|
Anomaly
|
Windows File Extension and Association Abuse
|
2026-05-13
|
|
MacOS Osascript Displaying Suspicious User Prompt
|
Osquery Results
|
T1056.002
T1059.002
|
Anomaly
|
MacOS Privilege Escalation
|
2026-08-31
|
|
Suspicious Linux Discovery Commands
|
Sysmon for Linux EventID 1
|
T1059.004
|
TTP
|
VoidLink Cloud-Native Linux Malware, Linux Post-Exploitation
|
2026-05-13
|
|
Ryuk Wake on LAN Command
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
|
TTP
|
Compromised Windows Host, Ryuk Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Linux Service Started Or Enabled
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, Gomir
|
2026-05-13
|
|
MacOS Osascript Executing JavaScript Code With ObjC
|
Osquery Results
|
T1059.002
T1059.007
|
Anomaly
|
MacOS Post-Exploitation
|
2026-09-18
|
|
Linux Service Restarted
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation, AwfulShred, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction
|
2026-05-13
|
|
Windows SCCM Smsexec Spawned a Suspicious Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
T1574.001
|
Anomaly
|
Windows Privilege Escalation
|
2026-08-24
|
|
Linux Add Files In Known Crontab Directories
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows Scheduled Task Created Via XML
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
Anomaly
|
CISA AA23-347A, MoonPeak, Winter Vivern, Malicious Inno Setup Loader, Lokibot, Scheduled Tasks
|
2026-05-13
|
|
Linux Possible Cronjob Modification With Editor
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Suspicious msbuild path
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.003
T1127.001
|
TTP
|
Graceful Wipe Out Attack, Living Off The Land, BlackByte Ransomware, Trusted Developer Utilities Proxy Execution MSBuild, Storm-2460 CLFS Zero Day Exploitation, Masquerading - Rename System Utilities, Cobalt Strike
|
2026-05-13
|
|
Windows Known Abused DLL Created
|
Sysmon EventID 11
|
T1574.001
|
Anomaly
|
Living Off The Land, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux At Allow Config File Creation
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Suspicious Privileged Container Execution
|
Sysmon for Linux EventID 1
|
T1059.004
T1610
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Possible Lateral Movement PowerShell Spawn
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1021.003
T1021.006
T1047
T1053.005
T1059.001
T1218.014
T1543.003
|
Anomaly
|
Active Directory Lateral Movement, Malicious PowerShell, Scheduled Tasks, Hermetic Wiper, Microsoft WSUS CVE-2025-59287, CISA AA24-241A, Data Destruction
|
2026-05-13
|
|
Remote WMI Command Attempt
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
TTP
|
Graceful Wipe Out Attack, Living Off The Land, CISA AA23-347A, IcedID, Suspicious WMI Use, Volt Typhoon
|
2026-05-13
|
|
Set Default PowerShell Execution Policy To Unrestricted or Bypass
|
Sysmon EventID 13
|
T1059.001
|
TTP
|
SolarWinds WHD RCE Post Exploitation, HAFNIUM Group, Credential Dumping, Data Destruction, DarkGate Malware, SystemBC, Hermetic Wiper, Starland RAT Campaign, Malicious PowerShell
|
2026-07-20
|
|
Windows Suspicious VMWare Tools Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
TTP
|
China-Nexus Threat Activity, ESXi Post Compromise
|
2026-05-13
|
|
Linux Suspicious XDG Autostart
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Process Accessing IronLanguages Repository On GitHub
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
T1105
|
Anomaly
|
Ingress Tool Transfer, Compromised Windows Host, Windows Post-Exploitation, Fake CAPTCHA Campaigns
|
2026-09-16
|
|
Windows Command and Scripting Interpreter Hunting Path Traversal
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
Hunting
|
Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Schtasks Create Run As System
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Qakbot, Medusa Ransomware, Castle RAT, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows TinyCC Shellcode Execution
|
Sysmon EventID 1, Windows Event Log Security 4688
|
T1027
T1036
T1059.003
|
TTP
|
Lotus Blossom Chrysalis Backdoor
|
2026-09-01
|
|
Windows User Execution Malicious URL Shortcut File
|
Sysmon EventID 11
|
T1204.002
|
Anomaly
|
Snake Keylogger, NjRAT, Chaos Ransomware, Quasar RAT, APT37 Rustonotto and FadeStealer, XWorm
|
2026-05-13
|
|
Windows Advanced Installer MSIX with AI_STUBS Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204.002
T1218
T1553.005
|
TTP
|
MSIX Package Abuse
|
2026-05-13
|
|
Schtasks scheduling job on remote system
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, NOBELIUM Group, Compromised Windows Host, RedLine Stealer, Quasar RAT, Phemedrone Stealer, Scheduled Tasks, Prestige Ransomware
|
2026-05-13
|
|
Impacket Lateral Movement Commandline Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Active Directory Lateral Movement, Compromised Windows Host, CISA AA22-277A, Storm-0501 Ransomware, Gozi Malware, Prestige Ransomware, WhisperGate, Volt Typhoon, Data Destruction, Industroyer2
|
2026-05-13
|
|
Windows Scheduled Task Service Spawned Shell
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1053.005
T1059
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows File Download Via PowerShell
|
CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1105
|
Anomaly
|
HAFNIUM Group, Data Destruction, Tuoni, Cisco Network Visibility Module Analytics, Winter Vivern, PHP-CGI RCE Attack on Japanese Organizations, Hermetic Wiper, GhostRedirector IIS Module and Rungan Backdoor, SolarWinds WHD RCE Post Exploitation, Ingress Tool Transfer, SysAid On-Prem Software CVE-2023-47246 Vulnerability, Phemedrone Stealer, Microsoft WSUS CVE-2025-59287, APT37 Rustonotto and FadeStealer, Malicious PowerShell, StealC Stealer, IcedID, NetSupport RMM Tool Abuse, NPM Supply Chain Compromise, XWorm
|
2026-07-14
|
|
Linux Shell Pseudo Device Reverse Shell
|
Sysmon for Linux EventID 1
|
T1048.003
T1059
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation, Command And Control
|
2026-07-08
|
|
Jscript Execution Using Cscript App
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.007
|
Anomaly
|
Remcos, FIN7
|
2026-08-31
|
|
Linux Possible Append Cronjob Entry on Existing Cronjob File
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Linux Netcat Outbound Connection
|
Sysmon for Linux EventID 3
|
T1059.004
|
Anomaly
|
Compromised Linux Host, Data Exfiltration, Command And Control, Linux Post-Exploitation
|
2026-07-08
|
|
Suspicious microsoft workflow compiler rename
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.003
T1127
|
Hunting
|
Graceful Wipe Out Attack, Living Off The Land, BlackByte Ransomware, Trusted Developer Utilities Proxy Execution, Masquerading - Rename System Utilities, Cobalt Strike
|
2026-05-13
|
|
Excessive Usage Of SC Service Utility
|
Sysmon EventID 1
|
T1569.002
|
Anomaly
|
Azorult, Ransomware, Crypto Stealer
|
2026-05-13
|
|
Windows Binary Execution from an Archive
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1204.002
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Remote Process Instantiation via WMI and PowerShell
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
TTP
|
Active Directory Lateral Movement, Compromised Windows Host
|
2026-05-13
|
|
Linux Crontab Enumeration
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Cisco Isovalent Suspicious Activity, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction, Industroyer2
|
2026-09-03
|
|
Linux Service File Created In Systemd Directory
|
Sysmon for Linux EventID 11
|
T1053.006
|
Anomaly
|
Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, China-Nexus Threat Activity, Gomir
|
2026-05-13
|
|
Windows XLL File Creation Outside of Typical Location
|
Sysmon EventID 11
|
T1059
T1129
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Windows TeamCity Payload Execution from Temp Directory
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
T1190
T1505.003
|
TTP
|
JetBrains TeamCity Vulnerabilities, JetBrains TeamCity Unauthenticated RCE
|
2026-05-13
|
|
Living Off The Land Detection
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows Apache Benchmark Binary
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
Anomaly
|
MetaSploit
|
2026-05-13
|
|
Windows NorthStar C2 Agent Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204.002
T1547.001
T1608
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
MacOS AppleScript Shell Execution and Compilation
|
Osquery Results
|
T1059.002
|
Anomaly
|
MacOS Post-Exploitation
|
2026-09-03
|
|
Linux At Application Execution
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Cisco Isovalent Suspicious Activity, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land
|
2026-05-13
|
|
Vbscript Execution Using Wscript App
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.005
|
TTP
|
Remcos, AsyncRAT, FIN7
|
2026-05-13
|
|
Windows MSC EvilTwin Directory Path Manipulation
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.005
T1203
T1218
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, Water Gamayun
|
2026-05-13
|
|
Windows WMI Process Call Create
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
Hunting
|
CISA AA23-347A, Qakbot, IcedID, Suspicious WMI Use, Volt Typhoon, Cactus Ransomware
|
2026-05-13
|
|
Windows Compatibility Telemetry Suspicious Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Potential AppDomainManager Hijack Artifacts Creation
|
Sysmon EventID 11
|
T1574.014
|
Anomaly
|
SesameOp
|
2026-05-13
|
|
Windows Registry Delete Task SD
|
Sysmon EventID 12
|
T1053.005
T1685
|
Anomaly
|
Windows Registry Abuse, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows SSH Proxy Command
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.001
T1105
T1572
|
Anomaly
|
ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day, Living Off The Land, Hellcat Ransomware
|
2026-05-13
|
|
Windows PaperCut NG Spawn Shell
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
T1133
T1190
|
TTP
|
Compromised Windows Host, PaperCut MF NG Vulnerability
|
2026-05-13
|
|
Execute Javascript With Jscript COM CLSID
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.005
|
TTP
|
Ransomware
|
2026-05-13
|
|
Linux MOTD Script Added
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Node.exe Executing JS Script In Immediate Folder
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.007
|
TTP
|
Compromised Windows Host, Windows Post-Exploitation, Fake CAPTCHA Campaigns
|
2026-09-16
|
|
Excessive distinct processes from Windows Temp
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
Anomaly
|
Meterpreter
|
2026-05-13
|
|
Reg exe Manipulating Windows Services Registry Keys
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574.011
|
TTP
|
Living Off The Land, Windows Service Abuse, Windows Persistence Techniques
|
2026-05-13
|
|
Malicious PowerShell Process - Execution Policy Bypass
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
|
Anomaly
|
HAFNIUM Group, 0bj3ctivity Stealer, APT37 Rustonotto and FadeStealer, AsyncRAT, DarkCrystal RAT, MuddyWater, BlankGrabber Stealer, Starland RAT Campaign, Volt Typhoon, Salt Typhoon, DHS Report TA18-074A, China-Nexus Threat Activity, XWorm
|
2026-07-20
|
|
Windows Command and Scripting Interpreter Path Traversal Exec
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
TTP
|
Compromised Windows Host, Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Binary Executed from Shared Memory Directory
|
Sysmon for Linux EventID 1
|
T1059
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
BITS Job Persistence
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1197
|
TTP
|
Living Off The Land, BITS Jobs
|
2026-05-13
|
|
Windows Common Abused Cmd Shell Risk Behavior
|
|
T1016
T1033
T1049
T1059
T1222
T1529
|
Correlation
|
Azorult, Qakbot, Netsh Abuse, Sandworm Tools, Windows Defense Evasion Tactics, CISA AA23-347A, DarkCrystal RAT, Disabling Security Tools, Microsoft WSUS CVE-2025-59287, Volt Typhoon, Windows Post-Exploitation, FIN7
|
2026-05-13
|
|
Linux Edit Cron Table Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Windows ScManager Security Descriptor Tampering Via Sc.EXE
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1569.002
|
TTP
|
Defense Evasion or Unauthorized Access Via SDDL Tampering
|
2026-05-13
|
|
Log4Shell CVE-2021-44228 Exploitation
|
|
T1059
T1105
T1133
T1190
|
Correlation
|
Log4Shell CVE-2021-44228, CISA AA22-320A
|
2026-05-13
|
|
Excessive number of taskhost processes
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
|
Anomaly
|
Meterpreter
|
2026-05-13
|
|
Suspicious MSBuild Rename
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.003
T1127.001
|
Hunting
|
Graceful Wipe Out Attack, Living Off The Land, BlackByte Ransomware, Trusted Developer Utilities Proxy Execution MSBuild, Storm-2460 CLFS Zero Day Exploitation, Masquerading - Rename System Utilities, Cobalt Strike
|
2026-05-13
|
|
Windows Crowdstrike RTR Script Execution
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.001
|
Anomaly
|
Living Off The Land, Cobalt Strike, Malicious PowerShell, Suspicious MSHTA Activity
|
2026-05-13
|
|
Windows Suspicious React or Next.js Child Process
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.001
T1059.003
T1190
|
TTP
|
React2Shell
|
2026-05-13
|
|
Windows PowerShell Process Implementing Manual Base64 Decoder
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1027.010
T1059.001
|
Anomaly
|
Compromised Windows Host, Deobfuscate-Decode Files or Information
|
2026-05-13
|
|
First Time Seen Running Windows Service
|
Windows Event Log System 7036
|
T1569.002
|
Anomaly
|
Orangeworm Attack Group, NOBELIUM Group, Windows Service Abuse
|
2026-05-13
|
|
Suspicious MSBuild Spawn
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1127.001
|
TTP
|
Living Off The Land, Storm-2460 CLFS Zero Day Exploitation, Trusted Developer Utilities Proxy Execution MSBuild
|
2026-05-13
|
|
Impacket Lateral Movement smbexec CommandLine Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Active Directory Lateral Movement, Compromised Windows Host, CISA AA22-277A, Prestige Ransomware, WhisperGate, Volt Typhoon, Data Destruction, Industroyer2
|
2026-05-13
|
|
Linux Docker Shell Execution
|
Sysmon for Linux EventID 1
|
T1059.013
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Msmpeng Application DLL Side Loading
|
Sysmon EventID 11
|
T1574.001
|
TTP
|
Ransomware, Revil Ransomware
|
2026-05-13
|
|
CMD Carry Out String Command Parameter
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
|
Hunting
|
Qakbot, RedLine Stealer, Warzone RAT, DarkCrystal RAT, Quasar RAT, WhisperGate, Gh0st RAT, Log4Shell CVE-2021-44228, Winter Vivern, PlugX, ProxyNotShell, AsyncRAT, Hermetic Wiper, Interlock Rat, Azorult, CISA AA23-347A, DarkGate Malware, Chaos Ransomware, Rhysida Ransomware, Crypto Stealer, StealC Stealer, Living Off The Land, 0bj3ctivity Stealer, IcedID, NjRAT, Malicious Inno Setup Loader, Data Destruction
|
2026-05-13
|
|
Windows DLL Search Order Hijacking with iscsicpl
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574.001
|
TTP
|
Living Off The Land, Compromised Windows Host, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Command Shell DCRat ForkBomb Payload
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.003
|
TTP
|
Compromised Windows Host, DarkCrystal RAT
|
2026-05-13
|
|
Socat Remote TCP Connection with Local Echo Disabled
|
Sysmon for Linux EventID 1, Osquery Results
|
T1059
T1572
|
Anomaly
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Revil Common Exec Parameter
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204
|
TTP
|
Ransomware, Revil Ransomware
|
2026-05-13
|
|
Windows PowerShell Process With Malicious String
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Linux Possible Append Command To At Allow Config File
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Socat Network Listener Binding an Executable
|
Sysmon for Linux EventID 1, Osquery Results
|
T1059
T1572
|
TTP
|
MacOS Post-Exploitation
|
2026-08-27
|
|
Process Execution via WMI
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Windows PowerShell Module File Created
|
Sysmon EventID 11
|
T1059.001
T1129
T1574
|
Anomaly
|
Windows Persistence Techniques, Malicious PowerShell
|
2026-05-13
|
|
Windows Phantom DLL Created on Disk
|
Sysmon EventID 11
|
T1068
T1574.001
|
TTP
|
Windows Privilege Escalation, RoguePlanet, Windows Defense Evasion Tactics
|
2026-08-20
|
|
Windows Rundll32 Execution With Log.DLL
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574
|
Anomaly
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Windows TeamCity Plugin Installed
|
Sysmon EventID 11
|
T1059
T1190
T1505.003
|
Anomaly
|
JetBrains TeamCity Vulnerabilities, JetBrains TeamCity Unauthenticated RCE
|
2026-05-13
|
|
Windows Masquerading Explorer As Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574.001
|
TTP
|
Compromised Windows Host, Qakbot, Water Gamayun
|
2026-05-13
|
|
Linux Possible Privilege Escalation via PYTHONPATH
|
Sysmon for Linux EventID 11
|
T1068
T1574.007
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Linux Ghostscript Exploitation
|
Sysmon for Linux EventID 1
|
T1059
T1068
T1204.002
T1566
|
TTP
|
Unusual Processes, Linux Living Off The Land, Linux Post-Exploitation, Suspicious Command-Line Executions
|
2026-09-01
|
|
CMD Echo Pipe - Escalation
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
Suspicious microsoft workflow compiler usage
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1127
|
TTP
|
Living Off The Land, Trusted Developer Utilities Proxy Execution
|
2026-05-13
|
|
Windows SCCM Adsource DLL Was Planted In SMS Provider Directory
|
Sysmon EventID 11
|
T1574.002
|
TTP
|
Windows Privilege Escalation
|
2026-08-20
|
|
GitHub Workflow File Creation or Modification
|
Sysmon for Linux EventID 11, Sysmon EventID 11
|
T1195
T1554
T1574.006
|
Hunting
|
NPM Supply Chain Compromise
|
2026-05-13
|
|
Detection of tools built by NirSoft
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1072
|
Anomaly
|
Emotet Malware DHS Report TA18-201A
|
2026-05-13
|
|
Windows Universal Data Link File Creation
|
Sysmon EventID 11
|
T1204.002
T1566.001
|
Anomaly
|
Spearphishing Attachments
|
2026-05-13
|
|
Detect Rare Executables
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204
|
Anomaly
|
Unusual Processes, Rhysida Ransomware, SnappyBee, Crypto Stealer, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Wmiprvse LOLBAS Execution Process Spawn
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
TTP
|
Active Directory Lateral Movement
|
2026-05-13
|
|
Windows Mock Trusted Directory MSC File Creation
|
Sysmon EventID 11
|
T1218.014
T1548.002
T1574
|
TTP
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-05-13
|
|
PowerShell Start-BitsTransfer
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1197
|
TTP
|
Gozi Malware, BITS Jobs
|
2026-05-13
|
|
Detect Use of cmd exe to Launch Script Interpreters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
|
Anomaly
|
Azorult, Emotet Malware DHS Report TA18-201A, Suspicious Command-Line Executions
|
2026-05-13
|
|
Linux Decode Base64 to Shell
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1027
T1059.004
|
TTP
|
Cisco Isovalent Suspicious Activity, Linux Living Off The Land
|
2026-05-13
|
|
Detect Renamed PSExec
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1569.002
|
Hunting
|
Active Directory Lateral Movement, HAFNIUM Group, BlackByte Ransomware, DarkSide Ransomware, Medusa Ransomware, Sandworm Tools, DarkGate Malware, China-Nexus Threat Activity, Rhysida Ransomware, SamSam Ransomware, VanHelsing Ransomware, CISA AA22-320A, Salt Typhoon, DHS Report TA18-074A, Cactus Ransomware
|
2026-05-13
|
|
Windows Powershell RemoteSigned File
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
|
Anomaly
|
Amadey
|
2026-05-13
|
|
MSBuild Suspicious Spawned By Script Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1127.001
|
TTP
|
Storm-2460 CLFS Zero Day Exploitation, Trusted Developer Utilities Proxy Execution MSBuild
|
2026-05-13
|
|
Windows Account Access Removal via Logoff Exec
|
Sysmon EventID 1
|
T1059.001
T1531
|
Anomaly
|
Crypto Stealer
|
2026-05-13
|
|
Windows Shell Process from CrushFTP
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.001
T1059.003
T1190
T1505
|
TTP
|
CrushFTP Vulnerabilities
|
2026-05-13
|
|
Suspicious Scheduled Task from Public Directory
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
Anomaly
|
Medusa Ransomware, DarkCrystal RAT, Quasar RAT, Windows Persistence Techniques, Salt Typhoon, China-Nexus Threat Activity, Ransomware, Scheduled Tasks, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Azorult, CISA AA23-347A, Ryuk Ransomware, Crypto Stealer, Lokibot, APT37 Rustonotto and FadeStealer, Living Off The Land, MoonPeak, Scattered Spider, NetSupport RMM Tool Abuse, Malicious Inno Setup Loader, XWorm
|
2026-05-13
|
|
Windows Outlook Macro Created by Suspicious Process
|
Sysmon EventID 11
|
T1059.005
T1137
|
TTP
|
NotDoor Malware
|
2026-05-13
|
|
Windows Get-Variable.EXE Execution from WindowsApps Folder
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1574.008
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Linux Unix Shell Enable All SysRq Functions
|
Sysmon for Linux EventID 1
|
T1059.004
|
Anomaly
|
Data Destruction, AwfulShred
|
2026-05-13
|
|
Linux Preload Hijack Library Calls
|
Sysmon for Linux EventID 1
|
T1574.006
|
TTP
|
Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Schtasks used for forcing a reboot
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
Ransomware, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows Cmdline Tool Execution From Non-Shell Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.007
|
Anomaly
|
SolarWinds WHD RCE Post Exploitation, CISA AA23-347A, Qakbot, Medusa Ransomware, Gh0st RAT, CISA AA22-277A, Gozi Malware, Tuoni, DarkGate Malware, Rhysida Ransomware, BlankGrabber Stealer, Volt Typhoon, FIN7, Water Gamayun
|
2026-05-13
|
|
Process Writing DynamicWrapperX
|
Sysmon EventID 11
|
T1059
T1559.001
|
Hunting
|
Remcos
|
2026-05-13
|
|
Linux Suspicious React or Next.js Child Process
|
Sysmon for Linux EventID 1
|
T1059.004
T1190
|
TTP
|
React2Shell
|
2026-05-13
|
|
Impacket Lateral Movement WMIExec Commandline Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Active Directory Lateral Movement, Compromised Windows Host, CISA AA22-277A, Storm-0501 Ransomware, Gozi Malware, Prestige Ransomware, WhisperGate, Volt Typhoon, Data Destruction, Industroyer2
|
2026-05-13
|
|
Single Letter Process On Endpoint
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204.002
|
TTP
|
DHS Report TA18-074A, Compromised Windows Host
|
2026-05-13
|
|
Svchost LOLBAS Execution Process Spawn
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1053.005
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, Scheduled Tasks, Hellcat Ransomware
|
2026-07-27
|
|
Shai-Hulud Workflow File Creation or Modification
|
Sysmon for Linux EventID 11, Sysmon EventID 11
|
T1195
T1554
T1574.006
|
TTP
|
NPM Supply Chain Compromise
|
2026-05-13
|
|
Script Execution via WMI
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1047
|
TTP
|
Scattered Spider, Suspicious WMI Use
|
2026-05-13
|
|
Windows EFI Volume Mount Attempt Via Mountvol
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204.002
T1542
T1688
|
Anomaly
|
Compromised Windows Host
|
2026-05-13
|
|
Windows Service Execution RemCom
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1569.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows PowGoop Beacon Decoding
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1001
T1059.001
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Windows For Loop Usage Within Cmd.exe To Execute Commands
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1059.003
|
Anomaly
|
Living Off The Land, Compromised Windows Host, Suspicious Command-Line Executions, Fake CAPTCHA Campaigns, Windows Post-Exploitation
|
2026-09-16
|
|
Detect Outbound LDAP Traffic
|
Cisco Secure Access Firewall, Palo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection Event
|
T1059
T1190
|
Hunting
|
Cisco Secure Firewall Threat Defense Analytics, Cisco Secure Access Analytics, Log4Shell CVE-2021-44228
|
2026-05-13
|
|
Detect Windows DNS SIGRed via Zeek
|
|
T1203
|
TTP
|
Windows DNS SIGRed CVE-2020-1350
|
2026-05-13
|
|
Linux Adding Crontab Using List Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Cisco Isovalent Suspicious Activity, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction, Industroyer2
|
2026-09-03
|