Skip to content
Threat Feed

January 2024 (30)

low advisory

AWS EC2 Route Table Created for Persistence or Defense Evasion

An EC2 Route Table creation event in AWS can indicate an attacker attempting to disrupt network traffic, reroute communications, or maintain persistence by creating unauthorized routes.

EC2 cloud aws persistence network-security
2r 2t
medium advisory

AWS ECR Container Upload Outside Business Hours

This analytic detects the upload of a new container image to AWS Elastic Container Registry (ECR) outside of standard business hours, indicating potential unauthorized activity and leveraging AWS CloudTrail logs to identify `PutImage` events during non-business hours.

Elastic Container Registry cloud aws ecr container
2r 1t
high advisory

Detecting External RPC Traffic for Initial Access

This brief focuses on detecting Remote Procedure Call (RPC) traffic originating from the internet, a common initial access vector, by monitoring network connections to TCP port 135 and filtering known internal IP ranges.

Elasticsearch initial-access network rpc
2r 2t
medium advisory

Web Server Potential Remote File Inclusion Activity

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths, potentially leading to information disclosure or further compromise.

Nginx +4 rfi webserver vulnerability
2r 2t
high advisory

ApostropheCMS Stored XSS Vulnerability in SEO Fields Leads to Data Exposure

A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS v4.28.0, allowing injection of arbitrary JavaScript into HTML contexts, performing authenticated API requests, and exfiltrating sensitive data, leading to a compromise of application confidentiality.

ApostropheCMS xss stored-xss data-exfiltration
2r 5t 1c 2i
high advisory

Conhost Spawned By Suspicious Parent Process

The Windows Console Host process (conhost.exe) spawned by a suspicious parent process, such as lsass.exe or explorer.exe, can indicate code injection used to bypass application allowlisting and execute malicious commands.

Windows execution defense-evasion privilege-escalation process-injection
2r 3t
high advisory

Entra ID Protection Detects User Risk

Entra ID Protection detects user risk activity such as anonymized IP addresses, unlikely travel, password spray, and other suspicious behaviors indicating potential initial access attempts and compromised accounts within cloud environments.

Entra ID azure entra-id risk-detection initial-access
3r 4t
medium advisory

ESXi System Information Discovery via ESXCLI

Adversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.

ESXi reconnaissance vmware
2r 1t
medium advisory

Netsh Used to Enable Remote Desktop Protocol (RDP) in Windows Firewall

Adversaries use the `netsh.exe` utility to enable inbound Remote Desktop Protocol (RDP) connections through the Windows Firewall, potentially for unauthorized remote access and lateral movement.

Windows +1 defense-evasion lateral-movement rdp
2r 2t
high advisory

Windows Event Log Cleared

Detection of Windows event log clearing using Event IDs 1102 (Security) or 104 (System) which may indicate an attempt to hide malicious activity and impede forensic investigation.

Windows defense-evasion event-logs
2r 1t
medium advisory

Windows Subsystem for Linux Distribution Installation via Registry Modification

Detects the installation of a new Windows Subsystem for Linux (WSL) distribution through registry modifications, which can be leveraged by attackers to evade security measures and execute malicious activities on Windows systems.

Windows Subsystem for Linux defense-evasion execution windows wsl
2r 3t
medium advisory

Azure Storage Account Deletion Detection

This brief detects the deletion of Azure Storage Accounts which can indicate malicious activity like data destruction, denial of service, or covering tracks after data exfiltration by adversaries.

Azure Storage Account azure storage deletion impact
2r 2t
medium advisory

macOS Mojave Beta Webcam and Microphone Access Bypass

macOS Mojave beta's new privacy controls can be bypassed by exploiting the entitlements of trusted applications like QuickTime Player via AppleScript to access the webcam and microphone without user consent.

macOS Mojave +2 macos webcam microphone applescript tcc
2r 1t
high advisory

ApostropheCMS Stored XSS Vulnerability in SEO Fields (CVE-2026-35569)

A stored XSS vulnerability in ApostropheCMS versions 4.28.0 and prior allows attackers to inject arbitrary JavaScript into SEO-related fields, leading to potential data exfiltration and unauthorized actions.

ApostropheCMS xss cve-2026-35569 web-application
2r 2t 1c
medium advisory

BloodHound Suite User-Agent Detected in Entra ID Sign-ins

Detection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.

Microsoft Azure +2 azuread bloodhound enumeration discovery
3r 6t
medium advisory

Entra ID OAuth PRT Issuance to Non-Managed Device Detected

Detection of Entra ID OAuth Primary Refresh Token (PRT) issuance to a non-managed device following a refresh token sign-in via Microsoft Authentication Broker (MAB), potentially indicating device registration abuse (ROADtx) for persistent access.

Entra ID +1 cloud entra_id persistence initial_access credential_access defense_evasion
2r 4t
medium advisory

Entra ID Service Principal Federated Credential Authentication by Unusual Client

Detection of initial Entra ID service principal authentication using a federated identity credential, potentially indicating a rogue identity provider abusing compromised applications.

Entra ID entra-id federated-credentials byoidp initial-access
2r 3t
high advisory

gitoxide Arbitrary Command Execution via .gitmodules Bypass

A vulnerability in gitoxide's `gix_submodule::File::update()` allows arbitrary command execution via a crafted `.gitmodules` file by incorrectly validating the source of the `update` command, enabling an attacker to inject malicious commands after a submodule has been initialized.

gix code-vulnerability remote-code-execution gitoxide
2r 1t 1c
medium advisory

GoBGP Remote Denial of Service via Malformed BGP Update Message

GoBGP version 4.4.0 is vulnerable to a remote denial-of-service attack where a malformed BGP UPDATE message triggers a nil pointer dereference, crashing the GoBGP process.

gobgp/v4 bgp denial-of-service networking
2r 1t
medium advisory

Microsoft Graph API Email Access by Unusual Client and User

Detects anomalous access to email resources via Microsoft Graph API, potentially indicating a compromised OAuth refresh token or Primary Refresh Token (PRT) being used by an attacker.

Microsoft 365 +1 azure graphapi email oauth credentialtheft
2r 1t
medium advisory

Twisted DNS Server Denial of Service via Crafted Compression Pointers

A denial-of-service vulnerability exists in the twisted.names module, where an unauthenticated attacker can send a crafted TCP DNS packet with deeply chained compression pointers, causing the Twisted reactor to hang while processing recursive lookups and effectively freezing the server.

Twisted denial-of-service dns
2r 1t
low advisory

Rapid Enumeration of AWS S3 Buckets via API Calls

An AWS principal from a single source IP rapidly invokes read-only S3 control-plane APIs, revealing bucket posture across many buckets in a short time, potentially indicating automated reconnaissance or post-compromise enumeration.

Amazon S3 aws cloudtrail s3 reconnaissance
2r 4t
medium advisory

M365 Copilot Impersonation Jailbreak Attack

This detection identifies attempts to jailbreak M365 Copilot by impersonating roles, adopting unrestricted personas, or mimicking malicious AI systems to bypass safety controls, searching exported eDiscovery prompt logs for roleplay keywords and categorizing prompts into impersonation types to detect persona injection attacks.

M365 Copilot ai_jailbreak prompt_injection m365_copilot
3r
high threat

AMOS Stealer macOS VM Detection

This brief describes detection of AMOS Stealer checking for virtual machine environments on macOS via osascript and system_profiler, potentially leading to information theft and further malicious activity.

macOS AMOS Stealer amos-stealer hellcat-ransomware vm-detection
2r 2t
high advisory

Potential Antimalware Scan Interface Bypass via PowerShell

This rule detects PowerShell scripts that attempt to bypass the Antimalware Scan Interface (AMSI) in order to disable scanning and execute malicious PowerShell code undetected.

defense-evasion amsi powershell windows
3r 1t
medium advisory

CustomLoadImage .NET Assembly Loading Technique

CustomLoadImage enables stealthy reflective loading of .NET assemblies by directly calling AssemblyNative::LoadFromBuffer, bypassing hooks on RuntimeAssembly.nLoadImage for defense evasion.

.NET Framework defense-evasion .net reflective-loading
2r 1t 1i
high advisory

spdystream SPDY/3 Frame Parser Denial of Service

The SPDY/3 frame parser in spdystream before v0.5.1 improperly validates attacker-controlled counts and lengths, allowing a remote attacker to trigger excessive memory allocation and cause a denial-of-service condition.

spdystream spdy denial-of-service memory-allocation
2r 1t
critical advisory

Unauthenticated Remote File Read Vulnerability in Sonarr (CVE-2026-30976)

CVE-2026-30976 allows an unauthenticated remote attacker to read arbitrary files readable by the Sonarr process on Windows systems running vulnerable versions prior to 4.0.17.2950, potentially exposing sensitive data.

Sonarr CVE-2026-30976 file-read windows
2r 1t
medium threat

Unusual Azure Storage Account Key Access by Privileged User

Detects unusual access to Azure Storage Account keys by users with Owner, Contributor, Storage Account Contributor, or User Access Administrator roles, potentially indicating compromised identities as seen in STORM-0501 ransomware campaigns.

Microsoft Azure +1 Storm-0501 azure storage account credential access ransomware
2r 2t
low advisory

Windows User Account Creation via net.exe

Attackers may create new accounts on Windows systems using `net.exe` to maintain access and establish persistence, which this detection identifies.

Windows persistence account-creation
3r 2t