high
threat
SUNBURST Command and Control Activity Detected
2 rules 2 TTPsThis rule detects post-exploitation command and control activity related to the SUNBURST backdoor, which targets SolarWind's Orion software, mimicking the Orion Improvement Program (OIP) protocol for covert communication.
SolarWinds Orion Platform
APT29
+5
solarwinds
sunburst
supply-chain
command-and-control
2r
2t
high
threat
Potential Vcruntime140 DLL Sideloading
2 rules 3 TTPsDetects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library, often used by threat actors like APT29 (via WinELOADER) to load malicious payloads under the guise of legitimate applications, leading to defense evasion, persistence, and privilege escalation.
Visual C++ Redistributable
APT29
+5
dll-sideloading
vcruntime140.dll
wineloader
defense-evasion
persistence
privilege-escalation
2r
3t
high
threat
Okta Multiple Failed MFA Requests Indicate Potential MFA Bypass Attempt
2 rules 1 TTPAn adversary may attempt to bypass MFA by bombarding a user with repeated authentication requests, potentially leading to unauthorized access and system compromise.
Okta
Lapsus$
+6
mfa
credential-access
mfa-bypass
2r
1t