|
O365 ApplicationImpersonation Role Assigned
|
O365
|
T1098.002
|
TTP
|
Office 365 Persistence Mechanisms, NOBELIUM Group, Office 365 Collection Techniques
|
2026-05-13
|
|
O365 Privileged Role Assigned To Service Principal
|
Office 365 Universal Audit Log
|
T1098.003
|
TTP
|
Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Azure AD Admin Consent Bypassed by Service Principal
|
Azure Active Directory Add app role assignment to service principal
|
T1098.003
|
TTP
|
NOBELIUM Group, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Okta Non-Standard VPN Usage
|
Okta
|
T1078
T1090
T1572
|
TTP
|
Remote Employment Fraud, Suspicious Okta Activity
|
2026-05-13
|
|
O365 Mailbox Read Access Granted to Application
|
O365 Update application.
|
T1098.003
T1114.002
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
Azure AD Service Principal Authentication
|
Azure Active Directory Sign-in activity
|
T1078.004
|
TTP
|
NOBELIUM Group, Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure Runbook Webhook Created
|
Azure Audit Create or Update an Azure Automation webhook
|
T1078.004
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Azure AD Service Principal Owner Added
|
Azure Active Directory Add owner to application
|
T1098
|
TTP
|
NOBELIUM Group, Azure Active Directory Persistence, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Azure AD Privileged Role Assigned
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters, NOBELIUM Group, Storm-0501 Ransomware
|
2026-05-13
|
|
Azure AD Application Administrator Role Assigned
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
O365 Service Principal Privilege Escalation
|
O365 Add app role assignment grant to user.
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation, Office 365 Account Takeover
|
2026-05-13
|
|
AWS IAM Successful Group Deletion
|
AWS CloudTrail DeleteGroup
|
T1069.003
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
ASL AWS IAM Failure Group Deletion
|
ASL AWS CloudTrail
|
T1098
|
Anomaly
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
ASL AWS Create Policy Version to allow all resources
|
ASL AWS CloudTrail
|
T1078.004
|
TTP
|
AWS IAM Privilege Escalation, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 Privileged Role Assigned
|
Office 365 Universal Audit Log
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 FullAccessAsApp Permission Assigned
|
O365 Update application.
|
T1098.002
T1098.003
|
TTP
|
Office 365 Persistence Mechanisms, NOBELIUM Group
|
2026-05-13
|
|
AWS IAM Failure Group Deletion
|
AWS CloudTrail DeleteGroup
|
T1098
|
Anomaly
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD User ImmutableId Attribute Updated
|
Azure Active Directory Update user
|
T1098
|
TTP
|
Azure Active Directory Persistence, Hellcat Ransomware
|
2026-05-13
|
|
O365 Application Registration Owner Added
|
O365 Add owner to application.
|
T1098
|
TTP
|
Office 365 Persistence Mechanisms, NOBELIUM Group
|
2026-05-13
|
|
AWS Create Policy Version to allow all resources
|
AWS CloudTrail CreatePolicyVersion
|
T1078.004
|
TTP
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD Successful PowerShell Authentication
|
Azure Active Directory
|
T1078.004
T1586.003
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD Multiple AppIDs and UserAgents Authentication Spike
|
Azure Active Directory Sign-in activity
|
T1078
|
Anomaly
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD Service Principal Privilege Escalation
|
Azure Active Directory Add app role assignment to service principal
|
T1098.003
|
TTP
|
Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
O365 Cross-Tenant Access Change
|
Office 365 Universal Audit Log
|
T1484.002
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
GCP Authentication Failed During MFA Challenge
|
Google Workspace login_failure
|
T1078.004
T1586.003
T1621
|
TTP
|
GCP Account Takeover, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD Authentication Failed During MFA Challenge
|
Azure Active Directory
|
T1078.004
T1586.003
T1621
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD Tenant Wide Admin Consent Granted
|
Azure Active Directory Consent to application
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, NOBELIUM Group
|
2026-05-13
|
|
O365 Tenant Wide Admin Consent Granted
|
O365 Consent to application.
|
T1098.003
|
TTP
|
Office 365 Persistence Mechanisms, NOBELIUM Group
|
2026-05-13
|
|
O365 Security And Compliance Alert Triggered
|
|
T1078.004
|
TTP
|
Office 365 Account Takeover
|
2026-05-13
|
|
Azure AD PIM Role Assignment Activated
|
Azure Active Directory
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
O365 Elevated Mailbox Permission Assigned
|
O365 Add-MailboxPermission
|
T1098.002
|
TTP
|
Office 365 Collection Techniques
|
2026-05-13
|
|
Azure AD User Enabled And Password Reset
|
Azure Active Directory Enable account, Azure Active Directory Update user, Azure Active Directory Reset password (by admin)
|
T1098
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Azure AD New Federated Domain Added
|
Azure Active Directory Set domain authentication
|
T1484.002
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters, Storm-0501 Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
ASL AWS IAM Successful Group Deletion
|
ASL AWS CloudTrail
|
T1069.003
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
AWS IAM Delete Policy
|
AWS CloudTrail DeletePolicy
|
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD New MFA Method Registered
|
Azure Active Directory Update user
|
T1098.005
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
O365 High Privilege Role Granted
|
O365 Add member to role.
|
T1098.003
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
O365 Application Available To Other Tenants
|
Office 365 Universal Audit Log
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Data Exfiltration, Azure Active Directory Account Takeover
|
2026-05-13
|
|
AWS SAML Update identity provider
|
AWS CloudTrail UpdateSAMLProvider
|
T1078
|
TTP
|
Cloud Federated Credential Abuse
|
2026-05-13
|
|
GCP Multiple Failed MFA Requests For User
|
Google Workspace
|
T1078.004
T1586.003
T1621
|
TTP
|
GCP Account Takeover, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
ASL AWS SAML Update identity provider
|
ASL AWS CloudTrail
|
T1078
|
TTP
|
Cloud Federated Credential Abuse
|
2026-05-13
|
|
Azure AD FullAccessAsApp Permission Assigned
|
Azure Active Directory Update application
|
T1098.002
T1098.003
|
TTP
|
Azure Active Directory Persistence, NOBELIUM Group
|
2026-05-13
|
|
Azure AD New Custom Domain Added
|
Azure Active Directory Add unverified domain
|
T1484.002
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
O365 New MFA Method Registered
|
O365 Update user.
|
T1098.005
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
ASL AWS IAM Delete Policy
|
ASL AWS CloudTrail
|
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
GCP Successful Single-Factor Authentication
|
Google Workspace
|
T1078.004
T1586.003
|
TTP
|
GCP Account Takeover, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Geographic Improbable Location
|
Okta
|
T1078
|
Anomaly
|
Remote Employment Fraud
|
2026-05-13
|
|
AWS SetDefaultPolicyVersion
|
AWS CloudTrail SetDefaultPolicyVersion
|
T1078.004
|
TTP
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Azure AD Successful Single-Factor Authentication
|
Azure Active Directory
|
T1078.004
T1586.003
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
O365 Admin Consent Bypassed by Service Principal
|
O365 Add app role assignment to service principal.
|
T1098.003
|
TTP
|
Office 365 Persistence Mechanisms
|
2026-05-13
|
|
O365 Mailbox Folder Read Permission Assigned
|
O365 ModifyFolderPermissions
|
T1098.002
|
TTP
|
Office 365 Collection Techniques
|
2026-05-13
|
|
AWS Successful Single-Factor Authentication
|
AWS CloudTrail ConsoleLogin
|
T1078.004
T1586.003
|
TTP
|
AWS Identity and Access Management Account Takeover
|
2026-05-13
|
|
GCP Detect gcploit framework
|
|
T1078
|
TTP
|
GCP Cross Account Activity
|
2026-05-13
|
|
O365 Service Principal New Client Credentials
|
O365
|
T1098.001
|
TTP
|
Office 365 Persistence Mechanisms, NOBELIUM Group
|
2026-05-13
|
|
Azure AD Global Administrator Role Assigned
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
O365 Mailbox Folder Read Permission Granted
|
O365 ModifyFolderPermissions
|
T1098.002
|
TTP
|
Office 365 Collection Techniques
|
2026-05-13
|
|
Azure AD Multiple Failed MFA Requests For User
|
Azure Active Directory Sign-in activity
|
T1078.004
T1586.003
T1621
|
TTP
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Azure AD PIM Role Assigned
|
Azure Active Directory
|
T1098.003
|
TTP
|
Azure Active Directory Persistence, Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Azure AD Service Principal New Client Credentials
|
Azure Active Directory
|
T1098.001
|
TTP
|
NOBELIUM Group, Azure Active Directory Persistence, Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
Azure AD Privileged Role Assigned to Service Principal
|
Azure Active Directory Add member to role
|
T1098.003
|
TTP
|
NOBELIUM Group, Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation
|
2026-05-13
|
|
AWS Bedrock Invoke Model Access Denied
|
AWS CloudTrail
|
T1078
T1550
|
TTP
|
AWS Bedrock Security
|
2026-05-13
|
|
O365 Multiple AppIDs and UserAgents Authentication Spike
|
O365 UserLoginFailed, O365 UserLoggedIn
|
T1078
|
Anomaly
|
Office 365 Account Takeover
|
2026-05-13
|
|
Microsoft Intune DeviceManagementConfigurationPolicies
|
Azure Monitor Activity
|
T1021.007
T1072
T1484
T1685
T1686
|
Hunting
|
Azure Active Directory Account Takeover
|
2026-05-13
|
|
Kubernetes Cron Job Creation
|
Kubernetes Audit
|
T1053.007
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Windows Cloud Files Filter Log Created by Non-System Process
|
Sysmon EventID 11
|
T1068
|
TTP
|
Windows Privilege Escalation, RedSun
|
2026-05-01
|
|
Windows Scheduled Task with Suspicious Name
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Ryuk Ransomware, 0bj3ctivity Stealer, Ransomware, Castle RAT, Scheduled Tasks, Windows Persistence Techniques, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Schedule Task with Rundll32 Command Trigger
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Living Off The Land, Compromised Windows Host, Trickbot, IcedID, Castle RAT, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows AD DCShadow Privileges ACL Addition
|
Windows Event Log Security 5136
|
T1207
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Large Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
T1135
|
Anomaly
|
Active Directory Lateral Movement, Active Directory Privilege Escalation
|
2026-07-05
|
|
Windows PowerShell ScheduleTask
|
Powershell Script Block Logging 4104
|
T1053.005
T1059.001
|
Anomaly
|
Scattered Spider, Scheduled Tasks, Starland RAT Campaign
|
2026-07-20
|
|
Windows AD add Self to Group
|
Windows Event Log Security 4728
|
T1098
|
TTP
|
Active Directory Privilege Escalation, Medusa Ransomware, Sneaky Active Directory Persistence Tricks
|
2026-06-01
|
|
Linux Auditd Nopasswd Entry In Sudoers File
|
Linux Auditd Proctitle
|
T1548.003
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows AD Short Lived Domain Account ServicePrincipalName
|
Windows Event Log Security 5136
|
T1098
|
TTP
|
Interlock Ransomware, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Cisco Isovalent - Late Process Execution
|
Cisco Isovalent Process Exec
|
T1543
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows AD Same Domain SID History Addition
|
Windows Event Log Security 4742, Windows Event Log Security 4738
|
T1134.005
|
TTP
|
Compromised Windows Host, Windows Persistence Techniques, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Uncommon Remote Thread Creation In Browser Process
|
Sysmon EventID 8
|
T1055.001
|
Anomaly
|
Living Off The Land, IcedID, Qakbot
|
2026-06-29
|
|
Windows AD GPO Disabled
|
Windows Event Log Security 5136
|
T1484.001
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Python Site Hooks Creation During Package Installation
|
Sysmon EventID 1, Sysmon EventID 11
|
T1195.002
T1546
|
TTP
|
Malicious Python Package Installation, Compromised Windows Host, Windows Persistence Techniques
|
2026-08-21
|
|
Windows Suspicious Driver Loaded Path
|
Sysmon EventID 6
|
T1543.003
|
TTP
|
Snake Keylogger, BlackByte Ransomware, XMRig, Interlock Ransomware, CISA AA22-320A, AgentTesla, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Powershell Fileless Process Injection via GetProcAddress
|
Powershell Script Block Logging 4104
|
T1055
T1059.001
|
TTP
|
Data Destruction, Hermetic Wiper, Malicious PowerShell, Hellcat Ransomware
|
2026-05-13
|
|
Windows Vulnerable Driver Installed
|
Windows Event Log System 7045
|
T1543.003
|
TTP
|
Windows Drivers, Void Manticore
|
2026-09-08
|
|
Windows AD Dangerous User ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Powershell Execute COM Object
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Ransomware, Hermetic Wiper, Malicious PowerShell, Data Destruction
|
2026-05-13
|
|
Detect Baron Samedit CVE-2021-3156 Segfault
|
|
T1068
|
TTP
|
Baron Samedit CVE-2021-3156
|
2026-05-13
|
|
Linux Auditd Setuid Using Setcap Utility
|
Linux Auditd Execve
|
T1548.001
|
TTP
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Defender Threat Detected on Kernel Object Path
|
Windows Event Log Defender 1117, Windows Event Log Defender 1116
|
T1068
T1211
|
TTP
|
RoguePlanet
|
2026-08-18
|
|
Rundll32 Create Remote Thread To A Process
|
Sysmon EventID 8
|
T1055
|
TTP
|
Living Off The Land, IcedID
|
2026-06-29
|
|
Cisco Isovalent - Shell Execution
|
Cisco Isovalent Process Exec
|
T1543
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows MsMpEng Writing to System32
|
Sysmon EventID 15, Sysmon EventID 11
|
T1068
T1543.003
|
TTP
|
Windows Privilege Escalation, Windows Drivers, BlueHammer, RedSun
|
2026-04-27
|
|
Windows Admon Default Group Policy Object Modified
|
Windows Active Directory Admon
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Non-System Process Querying Definition Update
|
Sysmon EventID 22
|
T1068
T1071.001
|
Anomaly
|
Windows Privilege Escalation, BlueHammer, RedSun
|
2026-04-27
|
|
Windows Bluetooth Service Installed From Uncommon Location
|
Windows Event Log System 7045
|
T1036
T1543.003
|
Anomaly
|
Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Linux Auditd Setuid Using Chmod Utility
|
Linux Auditd Proctitle
|
T1548.001
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Auditd Doas Conf File Creation
|
Linux Auditd Path, Linux Auditd Cwd
|
T1548.003
|
TTP
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Scheduled Task DLL Module Loaded
|
Sysmon EventID 7
|
T1053
|
TTP
|
ValleyRAT
|
2026-05-13
|
|
WinEvent Scheduled Task Created to Spawn Shell
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Compromised Windows Host, Ryuk Ransomware, 0bj3ctivity Stealer, Medusa Ransomware, Windows Error Reporting Service Elevation of Privilege Vulnerability, Ransomware, Winter Vivern, Castle RAT, SystemBC, Scheduled Tasks, Windows Persistence Techniques, CISA AA22-257A, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Hidden Schedule Task Settings
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Compromised Windows Host, Hellcat Ransomware, Malicious Inno Setup Loader, Scheduled Tasks, CISA AA22-257A, Active Directory Discovery, Cactus Ransomware, Data Destruction, Industroyer2
|
2026-05-13
|
|
Windows Service Create RemComSvc
|
Windows Event Log System 7045
|
T1543.003
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows AD Cross Domain SID History Addition
|
Windows Event Log Security 4742, Windows Event Log Security 4738
|
T1134.005
|
TTP
|
Compromised Windows Host, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Suspicious C2 Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
TTP
|
Brute Ratel C4, Graceful Wipe Out Attack, BlackByte Ransomware, DarkSide Ransomware, Hellcat Ransomware, Remote Monitoring and Management Software, Storm-0501 Ransomware, Gozi Malware, Meterpreter, Trickbot, Tuoni, Cobalt Strike, LockBit Ransomware, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Linux Auditd Sudo Or Su Execution
|
Linux Auditd Proctitle
|
T1548.003
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Azure PowerShell Module Installation Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1021.007
T1069.003
T1078
T1098
T1136.003
|
Anomaly
|
Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Azure Active Directory Account Takeover
|
2026-05-13
|
|
Create Remote Thread In Shell Application
|
Sysmon EventID 8
|
T1055
|
TTP
|
IcedID, Warzone RAT, Qakbot
|
2026-06-29
|
|
Windows Multiple Accounts Disabled
|
Windows Event Log Security 4725
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Linux Auditd Edit Cron Table Parameter
|
Linux Auditd Syscall
|
T1053.003
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land
|
2026-05-13
|
|
Windows Suspicious Defender Update Activity in INetCache
|
Sysmon EventID 23, Sysmon EventID 11
|
T1068
T1105
|
Anomaly
|
Windows Persistence Techniques, BlueHammer
|
2026-07-20
|
|
Windows AD Dangerous Group ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Linux Auditd Unload Module Via Modprobe
|
Linux Auditd Execve
|
T1547.006
|
TTP
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Auditd Unix Shell Configuration Modification
|
Linux Auditd Path, Linux Auditd Cwd
|
T1546.004
|
TTP
|
Compromised Linux Host, Linux Persistence Techniques, QuietVault, Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows Driver Load Non-Standard Path
|
Windows Event Log System 7045
|
T1014
T1068
|
TTP
|
BlackByte Ransomware, BlackSuit Ransomware, Windows Drivers, CISA AA22-320A, AgentTesla
|
2026-05-13
|
|
Print Spooler Failed to Load a Plug-in
|
Windows Event Log Printservice 808, Windows Event Log Printservice 4909
|
T1547.012
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Windows Process Injection into Commonly Abused Processes
|
Sysmon EventID 10
|
T1055.002
|
Anomaly
|
Earth Alux, SAP NetWeaver Exploitation, BishopFox Sliver Adversary Emulation Framework, APT37 Rustonotto and FadeStealer
|
2026-09-08
|
|
Detect Baron Samedit CVE-2021-3156
|
|
T1068
|
TTP
|
Baron Samedit CVE-2021-3156
|
2026-05-13
|
|
Windows AD Object Owner Updated
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD GPO New CSE Addition
|
Windows Event Log Security 5136
|
T1222.001
T1484.001
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Multiple Accounts Deleted
|
Windows Event Log Security 4726
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Spoolsv Writing a DLL - Sysmon
|
Sysmon EventID 11
|
T1547.012
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Cisco Isovalent - Nsenter Usage in Kubernetes Pod
|
Cisco Isovalent Process Exec
|
T1543
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Python PTH File Creation During Package Installation
|
Sysmon EventID 1, Sysmon EventID 11
|
T1195.002
T1546
|
Anomaly
|
Malicious Python Package Installation, Compromised Windows Host, Windows Persistence Techniques
|
2026-08-21
|
|
Cisco Isovalent - Potential Escape to Host
|
Cisco Isovalent Process Exec
|
T1611
|
Anomaly
|
VoidLink Cloud-Native Linux Malware, Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows Access Token Winlogon Duplicate Handle In Uncommon Path
|
Sysmon EventID 10
|
T1134.001
|
Anomaly
|
Brute Ratel C4, PathWiper
|
2026-09-08
|
|
Powershell Remote Thread To Known Windows Process
|
Sysmon EventID 8
|
T1055
|
TTP
|
Trickbot
|
2026-07-01
|
|
Windows Admon Group Policy Object Created
|
Windows Active Directory Admon
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Linux Auditd Install Kernel Module Using Modprobe Utility
|
Linux Auditd Syscall
|
T1547.006
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows DnsAdmins New Member Added
|
Windows Event Log Security 4732
|
T1098
|
TTP
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Trickbot Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1055
|
TTP
|
Hellcat Ransomware, Trickbot
|
2026-05-13
|
|
Windows Admin Password Changed by Non-Admin
|
Windows Event Log Security 4723
|
T1068
T1543.003
|
TTP
|
Windows Privilege Escalation, BlueHammer
|
2026-04-27
|
|
Windows AD Self DACL Assignment
|
Windows Event Log Security 5136
|
T1098
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Handle Duplication in Known UAC-Bypass Binaries
|
Sysmon EventID 10
|
T1134.001
|
Anomaly
|
Castle RAT
|
2026-09-08
|
|
Linux Malformed Auth Entry
|
Linux Secure
|
T1068
|
Anomaly
|
Linux Privilege Escalation
|
2026-05-06
|
|
Detect WMI Event Subscription Persistence
|
Sysmon EventID 20
|
T1546.003
|
TTP
|
Suspicious WMI Use, Hellcat Ransomware
|
2026-05-13
|
|
Windows AD Domain Replication ACL Addition
|
Windows Event Log Security 5136
|
T1484
|
TTP
|
Compromised Windows Host, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Linux Auditd Insert Kernel Module Using Insmod Utility
|
Linux Auditd Syscall
|
T1547.006
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Linux Rootkit, XorDDos
|
2026-05-13
|
|
Linux Auditd Kernel Module Using Rmmod Utility
|
Linux Auditd Syscall
|
T1547.006
|
TTP
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Windows Builtin Account Name Was Changed
|
Windows Event Log Security 4781
|
T1036.010
T1078.003
|
TTP
|
Compromised Windows Host, Windows Defense Evasion Tactics
|
2026-08-24
|
|
Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
ValleyRAT, Water Gamayun
|
2026-05-13
|
|
Windows Multiple Account Passwords Changed
|
Windows Event Log Security 4724
|
T1078
T1098
|
TTP
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Windows Potato Privilege Escalation Tool Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File
|
Linux Auditd Path, Linux Auditd Cwd
|
T1053.003
|
Hunting
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows Suspicious Defender Engine or Signature Files Created
|
Sysmon EventID 11
|
T1068
|
Anomaly
|
Windows Privilege Escalation, BlueHammer
|
2026-04-27
|
|
Windows PowerView AD Access Control List Enumeration
|
Powershell Script Block Logging 4104
|
T1069
T1078.002
|
TTP
|
Active Directory Discovery, Active Directory Privilege Escalation, Rhysida Ransomware
|
2026-05-13
|
|
Windows Unsigned MS DLL Side-Loading
|
Sysmon EventID 7
|
T1547
T1574.001
|
Anomaly
|
Earth Alux, APT29 Diplomatic Deceptions with WINELOADER, Derusbi, Salt Typhoon, China-Nexus Threat Activity, XWorm
|
2026-05-13
|
|
Cisco NVM - Suspicious Network Connection From Process With No Args
|
Cisco Network Visibility Module Flow Data
|
T1055
T1218
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Linux Auditd Possible Access Or Modification Of Sshd Config File
|
Linux Auditd Path, Linux Auditd Cwd
|
T1098.004
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Windows Event Triggered Image File Execution Options Injection
|
Windows Event Log Application 3000
|
T1546.012
|
Hunting
|
Windows Persistence Techniques
|
2026-05-13
|
|
Loading Of Dynwrapx Module
|
Sysmon EventID 7
|
T1055.001
|
TTP
|
Remcos, AsyncRAT
|
2026-05-13
|
|
Spoolsv Suspicious Process Access
|
Sysmon EventID 10
|
T1068
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Windows AD Domain Root ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
UAC Bypass MMC Load Unsigned Dll
|
Sysmon EventID 7
|
T1218.014
T1548.002
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows MSI Rollback Script Deleted By Non-Msiexec Process
|
Sysmon EventID 23, Sysmon EventID 26
|
T1068
T1218.007
|
TTP
|
Windows Privilege Escalation
|
2026-07-20
|
|
Linux Pedit Offset Out Of Bounds
|
Linux Messages Syslog
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-07-06
|
|
Windows Process Injection Remote Thread
|
Sysmon EventID 8
|
T1055.002
|
TTP
|
Graceful Wipe Out Attack, Qakbot, Earth Alux, Vidar Stealer, Warzone RAT, Phantom Stealer, Water Gamayun
|
2026-08-14
|
|
Linux Auditd At Application Execution
|
Linux Auditd Syscall
|
T1053.002
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land
|
2026-05-13
|
|
Suspicious Kerberos Service Ticket Request
|
Windows Event Log Security 4769
|
T1078.002
|
TTP
|
Active Directory Privilege Escalation, Active Directory Kerberos Attacks, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Windows Default Group Policy Object Modified
|
Windows Event Log Security 5136
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Cisco NVM - Non-Network Binary Making Network Connection
|
Cisco Network Visibility Module Flow Data
|
T1036
T1055
|
Anomaly
|
Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Detect Baron Samedit CVE-2021-3156 via OSQuery
|
|
T1068
|
TTP
|
Baron Samedit CVE-2021-3156
|
2026-05-13
|
|
Unusual Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
|
Hunting
|
Active Directory Lateral Movement, Active Directory Privilege Escalation, Scattered Lapsus$ Hunters, Active Directory Kerberos Attacks
|
2026-05-13
|
|
Linux Auditd Service Restarted
|
Linux Auditd Proctitle
|
T1053.006
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, AwfulShred, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction
|
2026-05-13
|
|
Windows Increase in User Modification Activity
|
Windows Event Log Security 4720
|
T1098
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
WinEvent Scheduled Task Created Within Public Path
|
Windows Event Log Security 4698
|
T1053.005
|
TTP
|
Medusa Ransomware, Data Destruction, Quasar RAT, Prestige Ransomware, Windows Persistence Techniques, Salt Typhoon, China-Nexus Threat Activity, ValleyRAT, Winter Vivern, Ransomware, PlugX, AsyncRAT, SystemBC, Scheduled Tasks, Compromised Windows Host, CISA AA23-347A, Ryuk Ransomware, Active Directory Lateral Movement, Remcos, Castle RAT, APT37 Rustonotto and FadeStealer, Industroyer2, 0bj3ctivity Stealer, IcedID, Malicious Inno Setup Loader, CISA AA22-257A, XWorm
|
2026-05-13
|
|
Linux Dirty Frag Kernel Privilege Escalation
|
Linux Auditd Syscall
|
T1068
T1548.001
|
TTP
|
Linux Privilege Escalation
|
2026-07-06
|
|
Schedule Task with HTTP Command Arguments
|
Windows Event Log Security 4698
|
T1053
|
TTP
|
Living Off The Land, Compromised Windows Host, Hellcat Ransomware, Winter Vivern, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows RMM Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
Anomaly
|
Cactus Ransomware, Remote Monitoring and Management Software, Ransomware, Gozi Malware, Scattered Spider, Interlock Ransomware, Scattered Lapsus$ Hunters, Command And Control, GhostRedirector IIS Module and Rungan Backdoor, Seashell Blizzard, Insider Threat, CISA AA24-241A
|
2026-05-13
|
|
Randomly Generated Scheduled Task Name
|
Windows Event Log Security 4698
|
T1053.005
|
Hunting
|
Active Directory Lateral Movement, 0bj3ctivity Stealer, Scheduled Tasks, CISA AA22-257A
|
2026-05-13
|
|
WinEvent Windows Task Scheduler Event Action Started
|
Windows Event Log TaskScheduler 200, Windows Event Log TaskScheduler 201
|
T1053.005
|
Hunting
|
Qakbot, Sandworm Tools, DarkCrystal RAT, Windows Persistence Techniques, Prestige Ransomware, ValleyRAT, BlackSuit Ransomware, Winter Vivern, PlugX, AsyncRAT, SystemBC, Scheduled Tasks, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Remcos, Industroyer2, IcedID, Malicious Inno Setup Loader, CISA AA22-257A, Amadey, Data Destruction
|
2026-05-13
|
|
Windows Scheduled Task Created in a Group Policy Object
|
Windows Event Log Security 5145
|
T1053.005
T1484.001
|
TTP
|
Living Off The Land, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Windows AD ServicePrincipalName Added To Domain Account
|
Windows Event Log Security 5136
|
T1098
|
TTP
|
Interlock Ransomware, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Increase in Group or Object Modification Activity
|
Windows Event Log Security 4663
|
T1098
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Powershell COM Hijacking InprocServer32 Modification
|
Powershell Script Block Logging 4104
|
T1059.001
T1546.015
|
TTP
|
Malicious PowerShell
|
2026-05-13
|
|
Linux Auditd Copy Fail Privilege Escalation
|
Linux Auditd Syscall
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-05-13
|
|
Windows Remote Image Load
|
Sysmon EventID 7
|
T1059
T1068
T1129
T1203
|
Anomaly
|
Ransomware, LockBit Ransomware, BlackByte Ransomware
|
2026-05-13
|
|
Windows KrbRelayUp Service Creation
|
Windows Event Log System 7045
|
T1543.003
|
TTP
|
Compromised Windows Host, Local Privilege Escalation With KrbRelayUp
|
2026-05-13
|
|
Suspicious Computer Account Name Change
|
Windows Event Log Security 4781
|
T1078.002
|
TTP
|
Compromised Windows Host, Active Directory Privilege Escalation, Scattered Lapsus$ Hunters, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Windows Suspicious Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
TTP
|
Brute Ratel C4, Graceful Wipe Out Attack, BlackByte Ransomware, Hellcat Ransomware, APT37 Rustonotto and FadeStealer, Remote Monitoring and Management Software, Trickbot, Gozi Malware, Meterpreter, Tuoni, Cobalt Strike, LockBit Ransomware, DarkSide Ransomware
|
2026-05-13
|
|
Windows Scheduled Task with Suspicious Command
|
Windows Event Log Security 4702, Windows Event Log Security 4700, Windows Event Log Security 4698
|
T1053.005
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Ryuk Ransomware, Ransomware, Quasar RAT, Scheduled Tasks, Windows Persistence Techniques, Seashell Blizzard, APT37 Rustonotto and FadeStealer
|
2026-05-13
|
|
Windows AD SID History Attribute Modified
|
Windows Event Log Security 5136
|
T1134.005
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows Cloud Files Filter Loaded by Uncommon Process
|
Sysmon EventID 7
|
T1543.003
|
Anomaly
|
BlueHammer, RedSun
|
2026-05-18
|
|
Windows Access Token Manipulation Winlogon Duplicate Token Handle
|
Sysmon EventID 10
|
T1134.001
|
Hunting
|
Brute Ratel C4
|
2026-09-08
|
|
Linux Binary Launched Process with Null Argv
|
Linux Messages Syslog
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-07-17
|
|
Unusual Number of Remote Endpoint Authentication Events
|
Windows Event Log Security 4624
|
T1078
|
Hunting
|
Active Directory Lateral Movement, Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Vulnerable Driver Loaded
|
Sysmon EventID 6
|
T1543.003
|
Hunting
|
Windows Drivers, Void Manticore, BlackByte Ransomware
|
2026-05-13
|
|
Clop Ransomware Known Service Name
|
Windows Event Log System 7045
|
T1543
|
TTP
|
Compromised Windows Host, Clop Ransomware
|
2026-05-13
|
|
Windows AD Dangerous Deny ACL Modification
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Suspicious PlistBuddy Usage via OSquery
|
Osquery Results
|
T1543.001
|
TTP
|
Silver Sparrow
|
2026-05-13
|
|
Windows Driver Inventory
|
|
T1068
|
Hunting
|
Windows Drivers
|
2026-05-13
|
|
Windows AD GPO Deleted
|
Windows Event Log Security 5136
|
T1484.001
T1685
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Short Lived Scheduled Task
|
Windows Event Log Security 4698, Windows Event Log Security 4699
|
T1053.005
|
Anomaly
|
Active Directory Lateral Movement, CISA AA23-347A, Compromised Windows Host, Scheduled Tasks, CISA AA22-257A
|
2026-07-07
|
|
Windows Level RMM Watchdog Task Created
|
Windows Event Log Security 4698
|
T1053
T1219
|
Anomaly
|
Remote Monitoring and Management Software
|
2026-05-13
|
|
Randomly Generated Windows Service Name
|
Windows Event Log System 7045
|
T1543.003
|
Hunting
|
BlackSuit Ransomware, Active Directory Lateral Movement
|
2026-05-13
|
|
Windows VSSVC Process Accessing Defender Engine
|
Sysmon EventID 10
|
T1068
|
TTP
|
Windows Privilege Escalation, RedSun
|
2026-05-01
|
|
Windows Group Policy Object Created
|
Windows Event Log Security 5137, Windows Event Log Security 5136
|
T1078.002
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD Privileged Group Modification
|
Windows Event Log Security 4728
|
T1098
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Cisco Isovalent - Kprobe Spike
|
Cisco Isovalent Process Kprobe
|
T1068
|
Hunting
|
VoidLink Cloud-Native Linux Malware, Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows PowerShell MSIX Package Installation
|
Powershell Script Block Logging 4104
|
T1059.001
T1547.001
|
TTP
|
MSIX Package Abuse, Malicious PowerShell
|
2026-05-13
|
|
PowerShell PInvoke Process Injection API Chain
|
Powershell Script Block Logging 4104
|
T1055.001
T1055.003
T1055.004
T1055.012
T1055.013
T1059.001
T1620
|
TTP
|
VIP Keylogger, Phantom Stealer
|
2026-06-25
|
|
Windows Drivers Loaded by Signature
|
Sysmon EventID 6
|
T1014
T1068
|
Hunting
|
Windows Drivers, BlackByte Ransomware, CISA AA22-320A, AgentTesla
|
2026-05-13
|
|
Windows Suspicious Burst of Password Changes
|
Windows Event Log Security 4723, Windows Event Log Security 4724
|
T1068
|
TTP
|
Windows Privilege Escalation, BlueHammer
|
2026-04-29
|
|
Linux Auditd Possible Setuid Execve Privesc
|
Linux Auditd Execve
|
T1068
|
Anomaly
|
Linux Privilege Escalation
|
2026-07-06
|
|
Suspicious Ticket Granting Ticket Request
|
Windows Event Log Security 4781, Windows Event Log Security 4768
|
T1078.002
|
Hunting
|
Active Directory Privilege Escalation, Active Directory Kerberos Attacks, sAMAccountName Spoofing and Domain Controller Impersonation
|
2026-05-13
|
|
Linux PF_ALG Registration Outside of Boot Window
|
Linux Messages Syslog
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-07-17
|
|
Linux Auditd Possible Access To Sudoers File
|
Linux Auditd Path, Linux Auditd Cwd
|
T1548.003
|
Anomaly
|
Compromised Linux Host, Linux Persistence Techniques, Linux Privilege Escalation, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows AD Hidden OU Creation
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
WMI Permanent Event Subscription - Sysmon
|
Sysmon EventID 21
|
T1546.003
|
TTP
|
Suspicious WMI Use
|
2026-05-13
|
|
Linux Suspicious Namespace Creation
|
Linux Auditd Syscall, Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-05-12
|
|
Windows AD AdminSDHolder ACL Modified
|
Windows Event Log Security 5136
|
T1546
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AD Domain Root ACL Deletion
|
Windows Event Log Security 5136
|
T1222.001
T1484
|
TTP
|
Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Cisco Isovalent - Cron Job Creation
|
Cisco Isovalent Process Exec
|
T1053.003
T1053.007
|
Anomaly
|
Cisco Isovalent Suspicious Activity
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Azure Active Directory Account Takeover
|
2026-05-13
|
|
Spoolsv Suspicious Loaded Modules
|
Sysmon EventID 7
|
T1547.012
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Windows Privilege Escalation System Process Without System Parent
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, BlackSuit Ransomware
|
2026-05-13
|
|
Windows AD Privileged Account SID History Addition
|
Windows Event Log Security 4742, Windows Event Log Security 4738
|
T1134.005
|
TTP
|
Compromised Windows Host, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows PUA Named Pipe
|
Sysmon EventID 18, Sysmon EventID 17
|
T1021.002
T1055
T1559
|
Anomaly
|
Active Directory Lateral Movement, HAFNIUM Group, BlackByte Ransomware, DarkSide Ransomware, Medusa Ransomware, Sandworm Tools, IcedID, DarkGate Malware, Rhysida Ransomware, SamSam Ransomware, VanHelsing Ransomware, CISA AA22-320A, Volt Typhoon, Seashell Blizzard, DHS Report TA18-074A, Cactus Ransomware
|
2026-05-13
|
|
Linux Auditd Doas Tool Execution
|
Linux Auditd Syscall
|
T1548.003
|
Anomaly
|
Compromised Linux Host, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Access Token Manipulation SeDebugPrivilege
|
Windows Event Log Security 4703
|
T1134.002
|
Anomaly
|
Tuoni, Meduza Stealer, Scattered Lapsus$ Hunters, Salt Typhoon, China-Nexus Threat Activity, Gh0st RAT, ValleyRAT, Vidar Stealer, PlugX, AsyncRAT, GhostRedirector IIS Module and Rungan Backdoor, Brute Ratel C4, CISA AA23-347A, Derusbi, WinDealer RAT, DarkGate Malware, Lokibot, PathWiper, Salat Stealer, SnappyBee
|
2026-08-14
|
|
Windows Error Report Created in ReportQueue Manually
|
Sysmon EventID 11
|
T1053.005
T1068
|
Anomaly
|
Windows Privilege Escalation, RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-08-18
|
|
Print Spooler Adding A Printer Driver
|
Windows Event Log Printservice 316
|
T1547.012
|
TTP
|
Black Basta Ransomware, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Windows Snake Malware Service Create
|
Windows Event Log System 7045
|
T1547.006
T1569.002
|
TTP
|
Compromised Windows Host, Snake Malware
|
2026-05-13
|
|
Cisco Secure Firewall - Wget or Curl Download
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1053.003
T1059
T1071.001
T1105
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Communication Over Suspicious Ports
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1021
T1055
T1059.001
T1105
T1219
T1571
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - High Priority Intrusion Classification
|
Cisco Secure Firewall Threat Defense Intrusion Event
|
T1003
T1071
T1078
T1190
T1203
|
TTP
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco IOS XE WebUI Login From IOSd Local Port
|
Cisco IOS Logs
|
T1078
T1190
|
TTP
|
Salt Typhoon
|
2026-05-19
|
|
AWS Bedrock Claude Unusually Large Prompts
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-08
|
|
AWS Bedrock Claude High Risk Filesystem and Exec Tool Invocation
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
Cisco ASA - User Privilege Level Change
|
Cisco ASA Logs
|
T1078.003
T1098
|
Anomaly
|
Suspicious Cisco Adaptive Security Appliance Activity, ArcaneDoor
|
2026-05-13
|
|
Splunk User Enumeration Attempt
|
Splunk
|
T1078
|
TTP
|
Splunk Vulnerabilities
|
2026-05-14
|
|
ESXi Account Modified
|
VMWare ESXi Syslog
|
T1078
T1098
T1136.001
|
Anomaly
|
Black Basta Ransomware, ESXi Post Compromise
|
2026-05-13
|
|
PingID Mismatch Auth Source and Verification Response
|
PingID
|
T1098.005
T1556.006
T1621
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
ESXi User Granted Admin Role
|
VMWare ESXi Syslog
|
T1078
T1098
|
TTP
|
Black Basta Ransomware, ESXi Post Compromise
|
2026-05-13
|
|
Okta Successful Single Factor Authentication
|
Okta
|
T1078.004
T1586.003
T1621
|
Anomaly
|
Okta Account Takeover
|
2026-05-13
|
|
AWS Bedrock Claude Hostile Prompt Sentiment
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
M365 Copilot Application Usage Pattern Anomalies
|
M365 Copilot Graph API
|
T1078
|
Anomaly
|
Suspicious Microsoft 365 Copilot Activities
|
2026-05-13
|
|
AWS Bedrock Claude Possible Prompt Injection
|
AWS Bedrock Claude
|
T1055
|
Hunting
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
PingID New MFA Method Registered For User
|
PingID
|
T1098.005
T1556.006
T1621
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
Cisco IOS XE Guestshell Activation and Destroy
|
Cisco IOS Logs
|
T1059
T1611
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
PingID New MFA Method After Credential Reset
|
PingID
|
T1098.005
T1556.006
T1621
|
TTP
|
Scattered Lapsus$ Hunters, Compromised User Account
|
2026-05-13
|
|
AWS Bedrock Claude Sensitive Data in Prompts
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
Zoom High Video Latency
|
|
T1078
|
Anomaly
|
Remote Employment Fraud
|
2026-05-13
|
|
Cisco ASA - New Local User Account Created
|
Cisco ASA Logs
|
T1078.003
T1136.001
|
Anomaly
|
Suspicious Cisco Adaptive Security Appliance Activity
|
2026-05-13
|
|
Okta Phishing Detection with FastPass Origin Check
|
Okta
|
T1078.001
T1556
|
TTP
|
Okta Account Takeover
|
2026-05-13
|
|
Cisco IOS XE WebUI Programmatic Configuration
|
Cisco IOS Logs
|
T1078
T1190
|
Anomaly
|
Salt Typhoon
|
2026-09-08
|
|
ESXi Shared or Stolen Root Account
|
VMWare ESXi Syslog
|
T1078
|
Anomaly
|
Black Basta Ransomware, ESXi Post Compromise
|
2026-05-13
|
|
Okta ThreatInsight Threat Detected
|
Okta
|
T1078.004
|
Anomaly
|
Okta Account Takeover
|
2026-05-13
|
|
ESXi External Root Login Activity
|
VMWare ESXi Syslog
|
T1078
|
Anomaly
|
Black Basta Ransomware, ESXi Post Compromise
|
2026-05-13
|
|
M365 Copilot Session Origin Anomalies
|
M365 Copilot Graph API
|
T1078
|
Anomaly
|
Suspicious Microsoft 365 Copilot Activities
|
2026-05-13
|
|
AWS Bedrock Claude excessive use of tokens
|
AWS Bedrock Claude
|
T1055
|
Anomaly
|
Suspicious AWS Bedrock Claude Activities
|
2026-07-06
|
|
PingID Multiple Failed MFA Requests For User
|
PingID
|
T1078
T1110
T1621
|
TTP
|
Compromised User Account
|
2026-05-13
|
|
Okta Suspicious Activity Reported
|
Okta
|
T1078.001
|
TTP
|
Okta Account Takeover
|
2026-05-13
|
|
VMWare Aria Operations Exploit Attempt
|
Palo Alto Network Threat
|
T1068
T1133
T1190
T1210
|
TTP
|
VMware Aria Operations vRealize CVE-2023-20887
|
2026-05-13
|
|
Microsoft SharePoint Server Elevation of Privilege
|
Suricata
|
T1068
|
Anomaly
|
Microsoft SharePoint Server Elevation of Privilege CVE-2023-29357
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen IP Address
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen Country
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Cloud Instance Modified By Previously Unseen User
|
AWS CloudTrail
|
T1078.004
|
Anomaly
|
Suspicious Cloud Instance Activities
|
2026-05-13
|
|
Cloud Compute Instance Created By Previously Unseen User
|
AWS CloudTrail
|
T1078.004
|
Anomaly
|
Cloud Cryptomining
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen City
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Cloud API Calls From Previously Unseen User Roles
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud User Activities
|
2026-05-13
|
|
Cloud Provisioning Activity From Previously Unseen Region
|
AWS CloudTrail
|
T1078
|
Anomaly
|
Suspicious Cloud Provisioning Activities
|
2026-05-13
|
|
Monitor Registry Keys for Print Monitors
|
Sysmon EventID 13
|
T1547.010
|
TTP
|
Windows Registry Abuse, Windows Persistence Techniques, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Windows Bypass UAC via Pkgmgr Tool
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1548.002
|
Anomaly
|
Warzone RAT
|
2026-05-13
|
|
Linux Insert Kernel Module Using Insmod Utility
|
Sysmon for Linux EventID 1
|
T1547.006
|
Anomaly
|
Linux Rootkit, Linux Privilege Escalation, Linux Persistence Techniques, XorDDos
|
2026-05-13
|
|
Linux c89 Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Usermod Root UID Set
|
Sysmon for Linux EventID 1
|
T1078
T1098
T1548.001
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Remote Assistance Spawning Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
Unusual Processes, Compromised Windows Host
|
2026-05-13
|
|
Windows Audit Policy Auditing Option Modified - Registry
|
Sysmon EventID 13
|
T1547.014
|
Anomaly
|
Windows Audit Policy Tampering
|
2026-05-13
|
|
Windows COM Hijacking InprocServer32 Modification
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1546.015
|
TTP
|
Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Linux Doas Tool Execution
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Scheduled Task with Highest Privileges
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Compromised Windows Host, CISA AA23-347A, RedLine Stealer, NetSupport RMM Tool Abuse, AsyncRAT, Castle RAT, Quasar RAT, Scheduled Tasks, XWorm
|
2026-05-13
|
|
FodHelper UAC Bypass
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1112
T1548.002
|
TTP
|
Compromised Windows Host, Windows Defense Evasion Tactics, ValleyRAT, IcedID, BlankGrabber Stealer
|
2026-05-13
|
|
Linux File Creation In Profile Directory
|
Sysmon for Linux EventID 11
|
T1546.004
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Linux Possible Access Or Modification Of sshd Config File
|
Sysmon for Linux EventID 1
|
T1098.004
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Possible Nimbuspwn Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Linux GDB Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows Service Initiation on Remote Endpoint
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543.003
|
TTP
|
Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Linux OpenVPN Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows New Default File Association Value Set
|
Sysmon EventID 13
|
T1546.001
|
Hunting
|
Windows Privilege Escalation, Hermetic Wiper, Prestige Ransomware, Windows Persistence Techniques, Windows Registry Abuse, Data Destruction
|
2026-05-13
|
|
Linux Suspicious GCC Invocation Building Init Shared Object
|
Sysmon for Linux EventID 1
|
T1027.004
T1068
T1129
T1608
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows Local LLM Framework Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-07-15
|
|
Linux Gem Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows Entra User Management Via Azure CLI
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1078.004
T1098
T1136
|
Anomaly
|
Azure Active Directory Persistence
|
2026-05-13
|
|
Screensaver Event Trigger Execution
|
Sysmon EventID 13
|
T1546.002
|
TTP
|
Windows Privilege Escalation, Hermetic Wiper, Windows Persistence Techniques, Windows Registry Abuse, Data Destruction
|
2026-05-13
|
|
Windows Rasautou DLL Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055.001
T1218
|
TTP
|
Compromised Windows Host, Windows Defense Evasion Tactics, Hellcat Ransomware
|
2026-05-13
|
|
Windows Process With NamedPipe CommandLine
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
Anomaly
|
Windows Defense Evasion Tactics
|
2026-07-08
|
|
DLLHost with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Earth Alux, Cactus Ransomware, BlackByte Ransomware, Cobalt Strike, Storm-2460 CLFS Zero Day Exploitation
|
2026-05-13
|
|
SLUI Spawning a Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host, DarkSide Ransomware
|
2026-05-13
|
|
NET Profiler UAC bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Compatibility Telemetry Tampering Through Registry
|
Sysmon EventID 13
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Guest Account Enabled Via Net.EXE
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1078.001
|
Anomaly
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Service Create with Tscon
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543.003
T1563.002
|
TTP
|
Active Directory Lateral Movement, Windows RDP Artifacts and Defense Evasion, Compromised Windows Host
|
2026-05-13
|
|
Services Escalate Exe
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1548
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, CISA AA23-347A, BlackByte Ransomware, Cobalt Strike
|
2026-05-13
|
|
Windows Defender MpClient.dll Loaded by Non-Defender Process
|
Sysmon EventID 7
|
T1068
|
Anomaly
|
RoguePlanet
|
2026-08-19
|
|
Scheduled Task Creation on Remote Endpoint using At
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.002
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, 0bj3ctivity Stealer, Scheduled Tasks
|
2026-05-13
|
|
Windows Change File Association Command To Notepad
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1546.001
|
TTP
|
Compromised Windows Host, Prestige Ransomware
|
2026-05-13
|
|
Schtasks Run Task On Demand
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053
|
Anomaly
|
Qakbot, Medusa Ransomware, XMRig, Scheduled Tasks, CISA AA22-257A, Data Destruction, Industroyer2
|
2026-05-13
|
|
Spoolsv Writing a DLL
|
Sysmon EventID 1, Sysmon EventID 11, Windows Event Log Security 4688
|
T1547.012
|
TTP
|
Black Basta Ransomware, Compromised Windows Host, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Windows Enable Win32 ScheduledJob via Registry
|
Sysmon EventID 13
|
T1053.005
|
Anomaly
|
Active Directory Lateral Movement, Scheduled Tasks
|
2026-05-13
|
|
Windows Privilege Escalation User Process Spawn System Process
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, Compromised Windows Host, BlackSuit Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Linux Apparmor Bypass Via Aaexec
|
Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Privilege Escalation
|
2026-06-30
|
|
Scheduled Task Initiation on Remote Endpoint
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, Medusa Ransomware, Scheduled Tasks, Seashell Blizzard
|
2026-05-13
|
|
Windows Suspicious Child Process of Consent.EXE
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059
T1068
T1548.002
|
Anomaly
|
Windows Privilege Escalation, Unusual Processes
|
2026-07-30
|
|
Suspicious DLLHost no Command Line Arguments
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Cactus Ransomware, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
Scheduled Task Deleted Or Created via CMD
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
Anomaly
|
Qakbot, Sandworm Tools, Trickbot, Medusa Ransomware, RedLine Stealer, DarkCrystal RAT, Quasar RAT, Prestige Ransomware, Windows Persistence Techniques, Salt Typhoon, China-Nexus Threat Activity, NOBELIUM Group, ShrinkLocker, ValleyRAT, Winter Vivern, PlugX, AsyncRAT, Scheduled Tasks, Amadey, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Azorult, CISA AA23-347A, Remcos, Rhysida Ransomware, Phemedrone Stealer, Lokibot, APT37 Rustonotto and FadeStealer, Living Off The Land, 0bj3ctivity Stealer, MoonPeak, NjRAT, Scattered Spider, NetSupport RMM Tool Abuse, CISA AA22-257A, AgentTesla, DHS Report TA18-074A, XWorm
|
2026-05-13
|
|
Linux pkexec Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1068
|
TTP
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Shim Database File Creation
|
Sysmon EventID 11
|
T1546.011
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Suspicious PlistBuddy Usage
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543.001
|
TTP
|
Silver Sparrow
|
2026-05-13
|
|
MacOS LoginHook Persistence
|
Osquery Results
|
T1037.002
|
TTP
|
MacOS Post-Exploitation
|
2026-05-13
|
|
SearchProtocolHost with no Command Line with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, BlackByte Ransomware, Cactus Ransomware, Hellcat Ransomware, Cobalt Strike
|
2026-05-13
|
|
SilentCleanup UAC Bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics, MoonPeak
|
2026-05-13
|
|
Windows Privilege Escalation Suspicious Process Elevation
|
Sysmon EventID 1
|
T1068
T1134
T1548
|
TTP
|
Windows Privilege Escalation, BlackSuit Ransomware, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Linux Service Started Or Enabled
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, Gomir
|
2026-05-13
|
|
Windows Process Injection In Non-Service SearchIndexer
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
Qakbot
|
2026-05-13
|
|
Wscript Or Cscript Suspicious Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
T1134.004
T1543
|
Anomaly
|
ShrinkLocker, FIN7, 0bj3ctivity Stealer, Data Destruction, NjRAT, Remcos, Axios Supply Chain Post Compromise, VIP Keylogger, MuddyWater, Starland RAT Campaign, Unusual Processes, WhisperGate, XWorm
|
2026-07-20
|
|
Linux Service Restarted
|
Sysmon for Linux EventID 1
|
T1053.006
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation, AwfulShred, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction
|
2026-05-13
|
|
Linux UDEV Rule Created
|
Sysmon for Linux EventID 11
|
T1037
T1547
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Windows SCCM Smsexec Spawned a Suspicious Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
T1574.001
|
Anomaly
|
Windows Privilege Escalation
|
2026-08-24
|
|
Linux Add Files In Known Crontab Directories
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows Scheduled Task Created Via XML
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
Anomaly
|
CISA AA23-347A, MoonPeak, Winter Vivern, Malicious Inno Setup Loader, Lokibot, Scheduled Tasks
|
2026-05-13
|
|
Windows ComputerDefaults Spawning a Process
|
Sysmon EventID 1
|
T1548.002
|
TTP
|
BlankGrabber Stealer, Castle RAT
|
2026-05-13
|
|
Linux Possible Cronjob Modification With Editor
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows UAC Bypass Suspicious Escalation Behavior
|
Sysmon EventID 1
|
T1548.002
|
TTP
|
Living Off The Land, Compromised Windows Host, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Runas Execution in CommandLine
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1134.001
|
Hunting
|
Windows Privilege Escalation, Hermetic Wiper, Data Destruction, Quasar RAT
|
2026-05-13
|
|
Linux At Allow Config File Creation
|
Sysmon for Linux EventID 11
|
T1053.003
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Emacs Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Possible Lateral Movement PowerShell Spawn
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1021.003
T1021.006
T1047
T1053.005
T1059.001
T1218.014
T1543.003
|
Anomaly
|
Active Directory Lateral Movement, Malicious PowerShell, Scheduled Tasks, Hermetic Wiper, Microsoft WSUS CVE-2025-59287, CISA AA24-241A, Data Destruction
|
2026-05-13
|
|
Linux Telnet Authentication Bypass
|
Sysmon for Linux EventID 1
|
T1548
|
TTP
|
Telnetd CVE-2026-24061
|
2026-05-13
|
|
Registry Keys Used For Privilege Escalation
|
Sysmon EventID 13
|
T1546.012
|
TTP
|
Cloud Federated Credential Abuse, Suspicious Windows Registry Activities, Windows Privilege Escalation, Hermetic Wiper, Windows Registry Abuse, Data Destruction
|
2026-05-13
|
|
Active Directory Privilege Escalation Identified
|
|
T1484
|
Correlation
|
Active Directory Privilege Escalation
|
2026-05-13
|
|
Sdclt UAC Bypass
|
Sysmon EventID 12, Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Registry Abuse, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Suspicious XDG Autostart
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Winhlp32 Spawning a Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
Compromised Windows Host, Remcos
|
2026-05-13
|
|
Linux Docker Root Directory Mount
|
Sysmon for Linux EventID 1
|
T1611
|
TTP
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows Schtasks Create Run As System
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
SolarWinds WHD RCE Post Exploitation, Qakbot, Medusa Ransomware, Castle RAT, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
GPUpdate with no Command Line Arguments with Network
|
Sysmon EventID 1, Sysmon EventID 3
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, BlackByte Ransomware, Hellcat Ransomware, Cobalt Strike
|
2026-05-13
|
|
Linux Visudo Utility Execution
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Default Group Policy Object Modified with GPME
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1484.001
|
TTP
|
Active Directory Privilege Escalation, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Linux Find Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Csvtool Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows List ENV Variables Via SET Command From Uncommon Parent
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
Windows MOF Event Triggered Execution via WMI
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1546.003
|
TTP
|
Living Off The Land, Compromised Windows Host
|
2026-05-13
|
|
Notepad with no Command Line Arguments
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
BishopFox Sliver Adversary Emulation Framework
|
2026-05-13
|
|
Windows AppCertDLL Modification Via Command Line
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1546.009
|
Anomaly
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-07-27
|
|
Linux File Creation In System Generator Directory
|
Sysmon for Linux EventID 11
|
T1037.005
T1547
|
Anomaly
|
Linux Persistence Techniques
|
2026-07-08
|
|
Windows Suspicious Process File Path
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.005
T1543
|
TTP
|
Graceful Wipe Out Attack, Swift Slicer, Qakbot, Earth Alux, Trickbot, RedLine Stealer, XWorm, Warzone RAT, DarkCrystal RAT, Quasar RAT, Meduza Stealer, Prestige Ransomware, WhisperGate, Phantom Stealer, Salt Typhoon, Handala Wiper, RoguePlanet, China-Nexus Threat Activity, Double Zero Destructor, Void Manticore, ValleyRAT, XMRig, Vidar Stealer, PlugX, Axios Supply Chain Post Compromise, AsyncRAT, VIP Keylogger, Interlock Ransomware, SystemBC, Hermetic Wiper, Interlock Rat, Volt Typhoon, GhostRedirector IIS Module and Rungan Backdoor, LockBit Ransomware, SesameOp, Brute Ratel C4, Azorult, CISA AA23-347A, Remcos, DarkGate Malware, Chaos Ransomware, Castle RAT, Rhysida Ransomware, Phemedrone Stealer, Lokibot, Industroyer2, StealC Stealer, Water Gamayun, PromptLock, BlackByte Ransomware, MoonPeak, IcedID, Malicious Inno Setup Loader, Starland RAT Campaign, NailaoLocker Ransomware, SnappyBee, AgentTesla, Amadey, Data Destruction
|
2026-09-01
|
|
Windows Process Execution in Temp Dir
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1036.005
T1543
|
Anomaly
|
PathWiper, Ryuk Ransomware, Qakbot, Gh0st RAT, Trickbot, Ransomware, NjRAT, Remcos, Axios Supply Chain Post Compromise, Salat Stealer, SesameOp, Lokibot, AgentTesla, RoguePlanet, XWorm, PromptLock
|
2026-09-01
|
|
Linux File Created In Kernel Driver Directory
|
Sysmon for Linux EventID 11
|
T1547.006
|
Anomaly
|
Linux Rootkit, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Schtasks scheduling job on remote system
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, NOBELIUM Group, Compromised Windows Host, RedLine Stealer, Quasar RAT, Phemedrone Stealer, Scheduled Tasks, Prestige Ransomware
|
2026-05-13
|
|
Impacket Lateral Movement Commandline Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Active Directory Lateral Movement, Compromised Windows Host, CISA AA22-277A, Storm-0501 Ransomware, Gozi Malware, Prestige Ransomware, WhisperGate, Volt Typhoon, Data Destruction, Industroyer2
|
2026-05-13
|
|
Windows Privilege Escalation Attempt Via MSI Rollback
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
|
TTP
|
Windows Privilege Escalation
|
2026-05-13
|
|
Windows Scheduled Task Service Spawned Shell
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1053.005
T1059
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Allow Operation with Consent Admin
|
Sysmon EventID 13
|
T1548
|
TTP
|
Azorult, Ransomware, Windows Registry Abuse, MoonPeak
|
2026-05-13
|
|
Linux APT Privilege Escalation
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux MySQL Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Possible Append Cronjob Entry on Existing Cronjob File
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, XorDDos, Linux Living Off The Land
|
2026-05-13
|
|
Windows Wermgr Spawning System Integrity Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
T1134.001
|
TTP
|
Windows Privilege Escalation, RoguePlanet, Windows Error Reporting Service Elevation of Privilege Vulnerability
|
2026-08-18
|
|
Windows Process Injection Wermgr Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
Anomaly
|
Windows Error Reporting Service Elevation of Privilege Vulnerability, RoguePlanet, Qakbot
|
2026-08-18
|
|
Potential password in username
|
Linux Secure
|
T1078.003
T1552.001
|
Hunting
|
Insider Threat, Credential Dumping
|
2026-05-13
|
|
Overwriting Accessibility Binaries
|
Sysmon EventID 11
|
T1546.008
|
TTP
|
Windows Privilege Escalation, Flax Typhoon, Hermetic Wiper, Data Destruction
|
2026-05-13
|
|
Detect Excessive Account Lockouts From Endpoint
|
|
T1078.002
|
Anomaly
|
Active Directory Password Spraying
|
2026-05-13
|
|
Linux Persistence and Privilege Escalation Risk Behavior
|
|
T1548
|
Correlation
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
WSReset UAC Bypass
|
Sysmon EventID 12, Sysmon EventID 13
|
T1548.002
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, Windows Registry Abuse, MoonPeak
|
2026-05-13
|
|
Linux Crontab Enumeration
|
Cisco Isovalent Process Exec, Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Cisco Isovalent Suspicious Activity, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction, Industroyer2
|
2026-09-03
|
|
Linux Busybox Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Service File Created In Systemd Directory
|
Sysmon for Linux EventID 11
|
T1053.006
|
Anomaly
|
Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land, China-Nexus Threat Activity, Gomir
|
2026-05-13
|
|
Windows NorthStar C2 Agent Execution
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1204.002
T1547.001
T1608
|
TTP
|
Compromised Windows Host
|
2026-05-13
|
|
Linux Cpulimit Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux At Application Execution
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Cisco Isovalent Suspicious Activity, Linux Persistence Techniques, Linux Privilege Escalation, Scheduled Tasks, Linux Living Off The Land
|
2026-05-13
|
|
Linux Octave Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Node Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Possible Access To Sudoers File
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Salt Typhoon, Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques
|
2026-05-13
|
|
Active Setup Registry Autostart
|
Sysmon EventID 13
|
T1547.014
|
TTP
|
Windows Privilege Escalation, Hermetic Wiper, Data Destruction, Windows Persistence Techniques
|
2026-05-13
|
|
Windows Compatibility Telemetry Suspicious Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
T1546
|
TTP
|
Windows Persistence Techniques
|
2026-05-13
|
|
Windows Registry BootExecute Modification
|
Sysmon EventID 13
|
T1542
T1547.001
|
TTP
|
Windows BootKits
|
2026-05-13
|
|
Windows Boot or Logon Autostart Execution In Startup Folder
|
Sysmon EventID 11
|
T1547.001
|
Anomaly
|
PromptFlux, RedLine Stealer, NjRAT, Gozi Malware, Chaos Ransomware, Quasar RAT, Starland RAT Campaign, Interlock Ransomware, Crypto Stealer, BlankGrabber Stealer, Phantom Stealer, APT37 Rustonotto and FadeStealer, XWorm
|
2026-07-20
|
|
Windows Registry Delete Task SD
|
Sysmon EventID 12
|
T1053.005
T1685
|
Anomaly
|
Windows Registry Abuse, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
Linux MOTD Script Added
|
Sysmon for Linux EventID 11
|
T1037
T1059.004
T1547
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Registry Keys for Creating SHIM Databases
|
Sysmon EventID 13
|
T1546.011
|
TTP
|
Windows Registry Abuse, Windows Persistence Techniques, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Linux GNU Awk Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Setuid Using Setcap Utility
|
Sysmon for Linux EventID 1
|
T1548.001
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows DISM Install PowerShell Web Access
|
Sysmon EventID 1, Windows Event Log Security 4688
|
T1548.002
|
TTP
|
CISA AA24-241A
|
2026-05-13
|
|
Short Lived Windows Accounts
|
Windows Event Log System 4720, Windows Event Log System 4726
|
T1078.003
T1136.001
|
TTP
|
Active Directory Lateral Movement, GhostRedirector IIS Module and Rungan Backdoor
|
2026-05-13
|
|
Linux File Creation In Init Boot Directory
|
Sysmon for Linux EventID 11
|
T1037.004
|
Anomaly
|
Linux Persistence Techniques, Backdoor Pingpong, Linux Privilege Escalation, XorDDos, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Parent PID Spoofing with Explorer
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1134.004
|
TTP
|
Compromised Windows Host, Windows Defense Evasion Tactics
|
2026-05-13
|
|
Linux Sqlite3 Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows Remote Create Service
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543.003
|
Anomaly
|
BlackSuit Ransomware, Active Directory Lateral Movement, CISA AA23-347A
|
2026-05-13
|
|
Linux Edit Cron Table Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Sudo OR Su Execution
|
Sysmon for Linux EventID 1
|
T1548.003
|
Hunting
|
VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Windows Service Creation on Remote Endpoint
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543.003
|
TTP
|
Active Directory Lateral Movement, CISA AA23-347A, SnappyBee, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Snake Malware Kernel Driver Comadmin
|
Sysmon EventID 11
|
T1547.006
|
TTP
|
Snake Malware
|
2026-05-13
|
|
Linux Possible GSM Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1068
|
Anomaly
|
Linux Privilege Escalation
|
2026-07-08
|
|
Suspicious GPUpdate no Command Line Arguments
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
Graceful Wipe Out Attack, Cobalt Strike, BlackByte Ransomware, Hellcat Ransomware
|
2026-05-13
|
|
Windows Suspicious Child Process of TieringEngineService.exe
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
|
TTP
|
Windows Privilege Escalation, RedSun
|
2026-05-01
|
|
Linux Make Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Impacket Lateral Movement smbexec CommandLine Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Active Directory Lateral Movement, Compromised Windows Host, CISA AA22-277A, Prestige Ransomware, WhisperGate, Volt Typhoon, Data Destruction, Industroyer2
|
2026-05-13
|
|
Spoolsv Spawning Rundll32
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1547.012
|
TTP
|
Black Basta Ransomware, Compromised Windows Host, PrintNightmare CVE-2021-34527
|
2026-05-13
|
|
Windows AD DSRM Account Changes
|
Sysmon EventID 13
|
T1098
|
TTP
|
Windows Registry Abuse, Scattered Lapsus$ Hunters, Windows Persistence Techniques, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Linux SSH Authorized Keys Modification
|
Sysmon for Linux EventID 1
|
T1098.004
|
Anomaly
|
VoidLink Cloud-Native Linux Malware, Hellcat Ransomware, Linux Living Off The Land
|
2026-05-13
|
|
Linux Possible Append Command To At Allow Config File
|
Sysmon for Linux EventID 1
|
T1053.002
|
Anomaly
|
Scheduled Tasks, Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Services LOLBAS Execution Process Spawn
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1543.003
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, Qakbot, CISA AA23-347A, Hellcat Ransomware
|
2026-05-13
|
|
Disabling Remote User Account Control
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Azorult, Windows Defense Evasion Tactics, Remcos, Suspicious Windows Registry Activities, AgentTesla, Windows Registry Abuse
|
2026-05-13
|
|
Time Provider Persistence Registry
|
Sysmon EventID 13
|
T1547.003
|
TTP
|
Windows Privilege Escalation, Hermetic Wiper, Windows Persistence Techniques, Windows Registry Abuse, Data Destruction
|
2026-07-08
|
|
Linux PHP Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows Phantom DLL Created on Disk
|
Sysmon EventID 11
|
T1068
T1574.001
|
TTP
|
Windows Privilege Escalation, RoguePlanet, Windows Defense Evasion Tactics
|
2026-08-20
|
|
Linux Composer Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
LLM Model File Creation
|
Sysmon EventID 11
|
T1543
|
Hunting
|
Suspicious Local LLM Frameworks
|
2026-07-15
|
|
Detect Excessive User Account Lockouts
|
|
T1078.003
|
Anomaly
|
Active Directory Password Spraying, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Suspicious SearchProtocolHost no Command Line Arguments
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1055
|
TTP
|
Graceful Wipe Out Attack, BlackByte Ransomware, Hellcat Ransomware, Cobalt Strike, Cactus Ransomware
|
2026-05-13
|
|
Linux Possible Privilege Escalation via PYTHONPATH
|
Sysmon for Linux EventID 11
|
T1068
T1574.007
|
TTP
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Post-Exploitation
|
2026-07-08
|
|
Linux Common Process For Elevation Control
|
Sysmon for Linux EventID 1
|
T1548.001
|
Hunting
|
Linux Persistence Techniques, Axios Supply Chain Post Compromise, Linux Privilege Escalation, Linux Living Off The Land, Salt Typhoon, China-Nexus Threat Activity
|
2026-05-13
|
|
Windows Service Create Kernel Mode Driver
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
T1543.003
|
TTP
|
Windows Drivers, CISA AA22-320A
|
2026-05-13
|
|
Linux Setuid Using Chmod Utility
|
Sysmon for Linux EventID 1
|
T1548.001
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Linux Ghostscript Exploitation
|
Sysmon for Linux EventID 1
|
T1059
T1068
T1204.002
T1566
|
TTP
|
Unusual Processes, Linux Living Off The Land, Linux Post-Exploitation, Suspicious Command-Line Executions
|
2026-09-01
|
|
CMD Echo Pipe - Escalation
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1059.003
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Compromised Windows Host, Cobalt Strike, BlackByte Ransomware
|
2026-05-13
|
|
Linux Ruby Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Registry Keys Used For Persistence
|
Sysmon EventID 13
|
T1547.001
|
TTP
|
Qakbot, RedLine Stealer, Warzone RAT, DarkCrystal RAT, Quasar RAT, Windows Persistence Techniques, Suspicious MSHTA Activity, Phantom Stealer, Salt Typhoon, Cactus Ransomware, China-Nexus Threat Activity, Gh0st RAT, ValleyRAT, Sneaky Active Directory Persistence Tricks, BlackSuit Ransomware, Ransomware, Axios Supply Chain Post Compromise, AsyncRAT, Interlock Ransomware, SystemBC, Emotet Malware DHS Report TA18-201A, Amadey, Azorult, Snake Keylogger, CISA AA23-347A, Derusbi, WinDealer RAT, Remcos, DarkGate Malware, Chaos Ransomware, Suspicious Windows Registry Activities, Castle RAT, MuddyWater, Lokibot, Windows Registry Abuse, APT37 Rustonotto and FadeStealer, 0bj3ctivity Stealer, BlackByte Ransomware, MoonPeak, IcedID, NjRAT, NetSupport RMM Tool Abuse, Salat Stealer, Braodo Stealer, SnappyBee, Starland RAT Campaign, Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns, DHS Report TA18-074A, XWorm
|
2026-07-20
|
|
Linux Install Kernel Module Using Modprobe Utility
|
Sysmon for Linux EventID 1
|
T1547.006
|
Anomaly
|
Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Linux Rootkit, China-Nexus Threat Activity
|
2026-05-13
|
|
Child Processes of Spoolsv exe
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
|
TTP
|
Windows Privilege Escalation, Hermetic Wiper, Data Destruction
|
2026-05-13
|
|
Windows Mock Trusted Directory MSC File Creation
|
Sysmon EventID 11
|
T1218.014
T1548.002
T1574
|
TTP
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-05-13
|
|
Windows System File on Disk
|
Sysmon EventID 11
|
T1068
|
Hunting
|
Crypto Stealer, Windows Drivers, CISA AA22-264A
|
2026-05-13
|
|
Linux NOPASSWD Entry In Sudoers File
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Salt Typhoon, Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques
|
2026-05-13
|
|
Linux AWK Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux c99 Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Windows AD DSRM Password Reset
|
Windows Event Log Security 4794
|
T1098
|
TTP
|
Scattered Lapsus$ Hunters, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Windows AppCertDLL Modification Via Registry
|
Sysmon EventID 13
|
T1546.009
|
Anomaly
|
Windows Privilege Escalation, Windows Persistence Techniques
|
2026-07-27
|
|
Linux Puppet Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Linux Possible Ssh Key File Creation
|
Sysmon for Linux EventID 11
|
T1098.004
|
Anomaly
|
Hellcat Ransomware, Linux Privilege Escalation, Linux Persistence Techniques, Linux Living Off The Land
|
2026-05-13
|
|
Windows UAC Bypass Suspicious Child Process
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1548.002
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, Castle RAT
|
2026-05-13
|
|
Shim Database Installation With Suspicious Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1546.011
|
TTP
|
Compromised Windows Host, Windows Persistence Techniques
|
2026-05-13
|
|
Suspicious Scheduled Task from Public Directory
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
Anomaly
|
Medusa Ransomware, DarkCrystal RAT, Quasar RAT, Windows Persistence Techniques, Salt Typhoon, China-Nexus Threat Activity, Ransomware, Scheduled Tasks, CISA AA24-241A, SolarWinds WHD RCE Post Exploitation, Azorult, CISA AA23-347A, Ryuk Ransomware, Crypto Stealer, Lokibot, APT37 Rustonotto and FadeStealer, Living Off The Land, MoonPeak, Scattered Spider, NetSupport RMM Tool Abuse, Malicious Inno Setup Loader, XWorm
|
2026-05-13
|
|
Linux Doas Conf File Creation
|
Sysmon for Linux EventID 11
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-05-13
|
|
Disable UAC Remote Restriction
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Windows Registry Abuse, CISA AA23-347A, Windows Defense Evasion Tactics, Suspicious Windows Registry Activities
|
2026-05-13
|
|
Linux Sudoers Tmp File Creation
|
Sysmon for Linux EventID 11
|
T1548.003
|
Anomaly
|
Salt Typhoon, Linux Privilege Escalation, China-Nexus Threat Activity, Linux Persistence Techniques
|
2026-05-13
|
|
Schtasks used for forcing a reboot
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1053.005
|
TTP
|
Ransomware, Scheduled Tasks, Windows Persistence Techniques
|
2026-05-13
|
|
MacOS Kextload Usage
|
Osquery Results
|
T1543
|
TTP
|
MacOS Privilege Escalation, MacOS Persistence Techniques
|
2026-05-13
|
|
Windows Autostart Execution LSASS Driver Registry Modification
|
Sysmon EventID 13
|
T1547.008
|
TTP
|
Windows Registry Abuse
|
2026-05-13
|
|
Linux RPM Privilege Escalation
|
Sysmon for Linux EventID 1
|
T1548.003
|
Anomaly
|
Linux Privilege Escalation, Linux Living Off The Land
|
2026-05-13
|
|
Eventvwr UAC Bypass
|
Sysmon EventID 13
|
T1548.002
|
TTP
|
Living Off The Land, Windows Defense Evasion Tactics, ValleyRAT, IcedID, Windows Registry Abuse
|
2026-05-13
|
|
Windows Registry Modification for Safe Mode Persistence
|
Sysmon EventID 13
|
T1547.001
|
TTP
|
Ransomware, Windows Drivers, Windows Registry Abuse
|
2026-05-13
|
|
Impacket Lateral Movement WMIExec Commandline Parameters
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1021.002
T1021.003
T1047
T1543.003
|
TTP
|
Graceful Wipe Out Attack, Active Directory Lateral Movement, Compromised Windows Host, CISA AA22-277A, Storm-0501 Ransomware, Gozi Malware, Prestige Ransomware, WhisperGate, Volt Typhoon, Data Destruction, Industroyer2
|
2026-05-13
|
|
Linux Possible Append Command To Profile Config File
|
Sysmon for Linux EventID 1
|
T1546.004
|
Anomaly
|
Linux Privilege Escalation, Linux Persistence Techniques
|
2026-08-12
|
|
Svchost LOLBAS Execution Process Spawn
|
CrowdStrike ProcessRollup2, Sysmon EventID 1
|
T1053.005
|
TTP
|
Living Off The Land, Active Directory Lateral Movement, Scheduled Tasks, Hellcat Ransomware
|
2026-07-27
|
|
SLUI RunAs Elevated
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1548.002
|
TTP
|
Windows Defense Evasion Tactics, Compromised Windows Host, DarkSide Ransomware
|
2026-05-13
|
|
Windows Security Support Provider Reg Query
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1547.005
|
Anomaly
|
Windows Post-Exploitation, Prestige Ransomware, Sneaky Active Directory Persistence Tricks
|
2026-05-13
|
|
Print Processor Registry Autostart
|
Sysmon EventID 13
|
T1547.012
|
TTP
|
Windows Privilege Escalation, Hermetic Wiper, Data Destruction, Windows Persistence Techniques
|
2026-05-13
|
|
Logon Script Event Trigger Execution
|
Sysmon EventID 13
|
T1037.001
|
TTP
|
VIP Keylogger, Windows Privilege Escalation, Hermetic Wiper, Windows Persistence Techniques, Data Destruction
|
2026-05-13
|
|
Cisco IOS Suspicious Privileged Account Creation
|
Cisco IOS Logs
|
T1078
T1136
|
Anomaly
|
Cisco Smart Install Remote Code Execution CVE-2018-0171
|
2026-05-13
|
|
Cisco Privileged Account Creation with Suspicious SSH Activity
|
|
T1021.004
T1078
T1136
|
Correlation
|
Cisco Secure Firewall Threat Defense Analytics, Salt Typhoon
|
2026-05-13
|
|
Cisco Privileged Account Creation with HTTP Command Execution
|
|
T1021.004
T1078
T1136
|
Correlation
|
Cisco Secure Firewall Threat Defense Analytics, Salt Typhoon
|
2026-05-13
|
|
Cisco Configuration Archive Logging Analysis
|
Cisco IOS Logs
|
T1098
T1505.003
T1685
|
Hunting
|
Cisco Smart Install Remote Code Execution CVE-2018-0171
|
2026-05-13
|
|
Okta New API Token Created
|
Okta
|
T1078.001
|
TTP
|
Scattered Lapsus$ Hunters, Okta Account Takeover
|
2026-05-13
|
|
Okta New Device Enrolled on Account
|
Okta
|
T1098.005
|
TTP
|
Scattered Lapsus$ Hunters, Okta Account Takeover
|
2026-05-13
|
|
Okta Risk Threshold Exceeded
|
Okta
|
T1078
T1110
|
Correlation
|
Okta MFA Exhaustion, Okta Account Takeover, Suspicious Okta Activity
|
2026-05-13
|
|
Okta Authentication Failed During MFA Challenge
|
Okta
|
T1078.004
T1586.003
T1621
|
TTP
|
Scattered Lapsus$ Hunters, Okta Account Takeover
|
2026-05-13
|
|
XMRIG Driver Loaded
|
Sysmon EventID 6
|
T1543.003
|
TTP
|
Crypto Stealer, CISA AA22-320A, XMRig
|
2026-09-08
|
|
Windows Process Injection into Notepad
|
Sysmon EventID 10
|
T1055.002
|
Anomaly
|
Earth Alux, BishopFox Sliver Adversary Emulation Framework, APT37 Rustonotto and FadeStealer
|
2026-09-21
|
|
First Time Seen Child Process of Zoom
|
CrowdStrike ProcessRollup2, Windows Event Log Security 4688, Sysmon EventID 1
|
T1068
|
Anomaly
|
Suspicious Zoom Child Processes
|
2026-05-13
|
|
Linux Adding Crontab Using List Parameter
|
Sysmon for Linux EventID 1
|
T1053.003
|
Hunting
|
Cisco Isovalent Suspicious Activity, Linux Persistence Techniques, VoidLink Cloud-Native Linux Malware, Linux Privilege Escalation, Gomir, Scheduled Tasks, Linux Living Off The Land, Data Destruction, Industroyer2
|
2026-09-03
|