July 2024 (12)
AWS RDS DB Instance Made Public
2 rules 3 TTPsAn attacker with compromised AWS credentials may modify an Amazon RDS DB instance or cluster to be publicly accessible for persistence, data exfiltration, or to bypass network restrictions.
AWS RDS Snapshot Deletion Detected
3 rules 2 TTPsThe deletion of AWS RDS DB snapshots or disabling backups via configuration changes can inhibit recovery, destroy forensic evidence, and prepare for destructive actions by adversaries.
bitcoinj ScriptExecution P2PKH/P2WPKH Verification Bypass
2 rulesA vulnerability in bitcoinj's ScriptExecution.correctlySpends() allows attackers to bypass signature verification for P2PKH and P2WPKH spends, potentially leading to unauthorized transaction validation.
AWS RDS DB Instance or Cluster Password Modification
2 rules 3 TTPsThe modification of the master password for an AWS RDS DB instance or cluster can indicate malicious activity used for persistence, privilege escalation, or defense evasion.
DNS Global Query Block List Modified or Disabled
2 rules 3 TTPsAttackers with DNSAdmin privileges can modify or disable the DNS Global Query Block List (GQBL) in Windows, allowing exploitation of hosts running WPAD with default settings for privilege escalation and lateral movement.
Grafana Vulnerability Allows Remote Code Execution
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Grafana to execute arbitrary code, potentially leading to system compromise and data exfiltration.
Ivanti VTM Administrator Account Creation via CVE-2024-7593
2 rules 2 TTPs 1 CVEUnauthenticated remote attackers are exploiting CVE-2024-7593 in Ivanti Virtual Traffic Manager (vTM) to bypass authentication and create new administrator accounts, potentially leading to full system compromise.
Microsoft Management Console File Execution from Unusual Path
2 rules 4 TTPsAdversaries may use Microsoft Management Console (MMC) files from untrusted paths to bypass security controls for initial access and execution on Windows systems.
NTDS Dump via Wbadmin
2 rules 2 TTPsAttackers with Backup Operator privileges may abuse wbadmin.exe to access the NTDS.dit file, enabling credential dumping and domain compromise.
Potential Windows Session Hijacking via CcmExec
2 rules 1 TTPAdversaries may exploit Microsoft's System Center Configuration Manager by loading malicious DLLs into SCNotification.exe, a process associated with user notifications, potentially leading to Windows session hijacking.
First Time Python Spawned a Shell on macOS Host
2 rules 1 TTPThis rule detects the first time a Python process spawns a shell on a given macOS host using the `-c` flag, indicating potential malicious activity stemming from compromised Python environments.
Suspicious Registry Hive Access via RegBack
2 rules 1 TTPThis rule detects attempts to access registry backup hives (SAM, SECURITY, SYSTEM) via RegBack on Windows systems, which can contain or enable access to credential material.
June 2024 (14)
VMware Tanzu Spring Framework Vulnerability Allows File Manipulation
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in VMware Tanzu Spring Framework to manipulate files or disclose information.
Apache Tomcat Vulnerability Allows Remote Code Execution
2 rules 1 TTPAn anonymous, remote attacker can exploit an unspecified vulnerability in Apache Tomcat to achieve arbitrary code execution.
SimpleHelp Missing Authorization Vulnerability Leads to Privilege Escalation
2 rules 1 TTP 1 CVEA missing authorization vulnerability in SimpleHelp (CVE-2024-57726) allows low-privileged technicians to create API keys with excessive permissions, potentially escalating privileges to the server admin role.
Oracle Fusion Middleware Multiple Vulnerabilities
2 rules 1 TTPAn unauthenticated or authenticated remote attacker can exploit multiple vulnerabilities in Oracle Fusion Middleware to compromise confidentiality, integrity, and availability.
SimpleHelp Path Traversal Vulnerability (CVE-2024-57728)
2 rules 3 TTPs 1 CVECVE-2024-57728 is a path traversal vulnerability in SimpleHelp that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file, potentially leading to arbitrary code execution.
Otter Blocks Plugin Purchase Verification Bypass Vulnerability (CVE-2026-2892)
3 rules 1 TTP 1 CVECVE-2026-2892 is a purchase verification bypass vulnerability in the Otter Blocks plugin for WordPress, affecting versions up to 3.1.4, that allows unauthenticated attackers to access restricted content by forging a cookie used for purchase validation.
Docker Privilege Escalation Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Docker to escalate privileges on a Linux host.
Phoenix Contact FL MGUARD Multiple Vulnerabilities
2 rules 3 TTPsA remote attacker can exploit multiple vulnerabilities in Phoenix Contact FL MGUARD to escalate privileges, disclose sensitive information, or cause a denial-of-service condition.
Red Hat Enterprise Linux File Manipulation Vulnerability
2 rules 2 TTPsAn authenticated remote attacker can exploit a vulnerability in Red Hat Enterprise Linux (CPython) to manipulate files.
Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.
Juniper Junos OS SRX Series ICMPv6 Denial-of-Service Vulnerability (CVE-2026-33790)
2 rules 1 TTP 1 CVEA specific, malformed ICMPv6 packet sent to a Juniper Networks Junos OS SRX Series device can trigger a crash and restart of the srxpfe process, leading to a sustained Denial of Service.
Samsung MagicINFO 9 Server Path Traversal Vulnerability (CVE-2024-7399)
2 rules 1 TTP 1 CVEA path traversal vulnerability in Samsung MagicINFO 9 Server could allow an attacker to write arbitrary files with system privileges, potentially leading to code execution or system compromise.
AWS IAM AdministratorAccess Policy Attached to Role
2 rules 2 TTPsAn adversary with compromised AWS credentials may escalate privileges or persist in the environment by attaching the AdministratorAccess AWS managed policy to an existing IAM role.
NetScaler ADC and Gateway Vulnerabilities Lead to Session Mixup
2 rules 1 TTPA race condition vulnerability in NetScaler ADC and Gateway (CVE-2026-3055 and CVE-2026-4368) could lead to user session mixup, potentially allowing unauthorized access to sensitive information.
May 2024 (4)
Unauthorized Modification of Azure Conditional Access Policy
2 rules 2 TTPsAn unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.
zyx0814 FilePress SQL Injection Vulnerability (CVE-2026-8133)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-8133) exists in zyx0814 FilePress up to version 2.2.0 via the Shares Filelist API by manipulating the argument order, potentially leading to unauthorized data access or modification.
Suspicious DNS-Named Record Creation in Active Directory Integrated DNS
2 rules 1 TTPDetection of DNS record creation by non-system accounts within Active Directory Integrated DNS (ADIDNS), which attackers can abuse to perform Dynamic Spoofing attacks, potentially targeting services like WPAD for credential access.
OpenStack Keystone LDAP Authentication Bypass Vulnerability (CVE-2026-40683)
2 rules 3 TTPs 1 CVEOpenStack Keystone before 28.0.1 is vulnerable to an authentication bypass due to improper handling of the user enabled attribute in the LDAP identity backend when the user_enabled_invert configuration option is False, leading to disabled users being treated as enabled.