Skip to content
Threat Feed

January 2024 (30)

low advisory

AWS CloudShell Environment Creation Detection

Detection of AWS CloudShell environment creation can indicate unauthorized command execution within AWS by an adversary leveraging a compromised console session to interact with AWS services.

AWS CloudShell aws cloudshell execution initial-access
2r 2t
medium advisory

AWS CloudTrail Trail Deletion Detected

Detection of AWS CloudTrail trail deletion via the DeleteTrail API indicates potential defense evasion and destruction of audit logging.

AWS CloudTrail cloudtrail aws defense-evasion
2r 2t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
medium advisory

Cisco ASA - New Local User Account Creation

Detection of new user account creations on Cisco ASA devices, potentially indicating unauthorized access or persistence attempts by adversaries.

Cisco ASA cisco-asa account-creation persistence
2r 2t
medium advisory

DCOM Lateral Movement via ShellWindows/ShellBrowserWindow

This analytic identifies the use of Distributed Component Object Model (DCOM) to execute commands on a remote host, specifically when launched via ShellBrowserWindow or ShellWindows Application COM objects, indicating potential lateral movement by an attacker.

Windows lateral-movement dcom
2r 2t
medium advisory

Detection of Command and Control Activity via Commonly Abused Web Services

This rule detects command and control activity using common web services by identifying Windows hosts making DNS requests to a list of commonly abused web services from processes outside of known program locations, potentially indicating adversaries attempting to blend malicious traffic with legitimate network activity.

OneDrive +7 command-and-control windows threat-detection
2r 2t
high advisory

Entra ID: Global Administrator Role Assigned to PIM User

An adversary may add an account to the Global Administrator role within Azure AD Privileged Identity Management (PIM) to establish persistence and gain privileged access.

Azure Active Directory +1 azure entra_id persistence privilege_escalation
2r 2t
medium advisory

GCP Service Account Disabled

Detection of a Google Cloud Platform (GCP) service account being disabled, potentially indicating malicious activity aimed at disrupting business operations by an adversary.

Google Cloud Platform gcp cloud iam impact
2r 1t
medium advisory

GCP Virtual Private Cloud Network Deletion

Detection of Virtual Private Cloud (VPC) network deletion in Google Cloud Platform (GCP), which can be used by an adversary to disrupt a target's network and business operations.

Virtual Private Cloud cloud gcp defense-evasion impact
2r 2t
medium advisory

GitHub Enterprise Audit Log Streaming Paused

Detection of a user pausing audit log event streaming in GitHub Enterprise, potentially indicating an attempt to evade detection by disabling the audit trail.

GitHub Enterprise +3 github audit-log defense-evasion
2r 2t
low advisory

GitHub Private Repository Visibility Changed to Public

An adversary may change a private GitHub repository to public visibility to exfiltrate sensitive code or data, potentially indicating a compromise or unauthorized access, and immediately fork or mirror the repo to an external account to retain access and harvest embedded secrets.

GitHub exfiltration repository
2r 2t
medium advisory

Kubernetes Sensitive Role Creation or Modification

Detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs, potentially leading to privilege escalation or unauthorized access within the cluster.

Kubernetes rbac privilege-escalation persistence
2r 2t
low advisory

Linux Kernel Instrumentation Discovery via Kprobes and Tracefs

Adversaries may attempt to discover kernel instrumentation tools like Kprobes and Tracefs on Linux systems to understand the security landscape and potential detection mechanisms.

Linux Kernel kernel discovery linux tracefs kprobes
2r 1t
medium advisory

Persistence via Malicious Microsoft Outlook VBA Template

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file, detected by monitoring for unauthorized file modifications.

Outlook persistence vba windows
2r 1t
medium advisory

Disable Windows Event and Security Logs Using Built-in Tools

Attackers attempt to disable Windows Event and Security Logs using logman, PowerShell, or auditpol to evade detection and cover their tracks.

Microsoft Defender XDR +2 defense-evasion windows eventlog
3r 3t
medium advisory

Executable File Creation with Multiple Extensions

This rule detects the creation of executable files with multiple extensions, a masquerading technique used to evade defenses by disguising malicious executables as benign files to trick users into executing them.

Windows defense-evasion masquerading file-extension
2r 2t
medium advisory

Incoming Execution via PowerShell Remoting

This rule identifies remote execution via Windows PowerShell remoting, which allows a user to run any Windows PowerShell command on one or more remote computers, potentially indicating lateral movement.

Elastic Defend +2 lateral-movement powershell remoting
2r 2t
medium advisory

Suspicious Container Runtime CLI Execution

The rule detects execution of container runtime CLI tools (ctr, crictl, nerdctl) with arguments indicating container creation, command execution inside existing containers, image manipulation, or host filesystem mounting, potentially leading to container escape and privilege escalation.

Elastic Defend for Containers container execution privilege_escalation linux
3r 2t
low advisory

Unusual Time or Day for an RDP Session Detected by Machine Learning

A machine learning job detected an RDP session initiated at an unusual time or day, potentially indicating lateral movement activity within a network.

Windows lateral-movement threat-detection
2r 2t
critical advisory

D-Link DIR-513 v1.10 Remote Buffer Overflow Vulnerability (CVE-2026-6013)

A remote buffer overflow vulnerability exists in the formSetRoute function of the D-Link DIR-513 v1.10 router's web interface, triggered by manipulating the 'curTime' argument in a POST request, potentially allowing unauthenticated attackers to execute arbitrary code; this vulnerability affects an end-of-life product with a public exploit.

DIR-513 CVE-2026-6013 buffer-overflow dlink router
2r 3t 1c
high advisory

Azure PIM Account Stale Sign-in Alert

Detection of stale accounts in Azure Privileged Identity Management (PIM) through the 'staleSignInAlertIncident' event, indicating potential compromised or unused privileged accounts.

Azure Privileged Identity Management azure pim stale_account
2r 1t
medium advisory

Okta Session Hijacking via Multiple Device Token Hashes

Detection of multiple device token hashes and source IPs for a single Okta session, indicating potential session hijacking and unauthorized access to Okta resources.

Okta session-hijacking credential-access
2r 2t
medium advisory

Azure Firewall Modification or Deletion Detected

An Azure firewall was created, modified, or deleted, potentially indicating malicious activity aimed at impairing network defenses.

Azure firewall defense-evasion
2r 1t
medium advisory

Linux Clipboard Activity Monitoring

This brief provides detection strategies for monitoring clipboard activity on Linux systems, potentially identifying malicious data exfiltration or command execution attempts.

Linux clipboard data exfiltration collection
3r 1t
low advisory

Suspicious Whoami Process Activity

The `whoami` command is being used by an attacker to enumerate user, group, and privilege information on a Windows system, potentially indicating post-exploitation discovery activity after initial compromise or privilege escalation.

Windows discovery
3r 2t
medium advisory

Azure AD Bitlocker Key Retrieval

An adversary with sufficient privileges in Azure Active Directory may attempt to retrieve BitLocker keys to decrypt drives for lateral movement or data exfiltration.

Azure Active Directory azure bitlocker key-retrieval persistence privilege-escalation
2r 3t
critical advisory

ChilliCream GraphQL Platform Stack Overflow via Deeply Nested GraphQL Documents

ChilliCream GraphQL Platform is vulnerable to a stack overflow exception due to unbounded recursion depth in the Utf8GraphQLParser; a crafted GraphQL document with deeply nested elements can trigger a StackOverflowException, terminating the worker process.

Hot Chocolate graphql stack-overflow denial-of-service hotchocolate
3r 3t
high advisory

Elastic Defend and Email Alerts Correlation

This rule correlates Elastic Defend alerts with email security alerts by target username, potentially indicating a successful phishing attack and subsequent endpoint compromise.

Check Point Harmony Email & Collaboration threat-detection phishing endpoint email
2r 1t
high advisory

Azure AD User Added to Global or Device Admin Role

An attacker may attempt to add a user to a high-privilege Azure AD role, such as Global Administrator or Device Administrator, to establish persistence, gain initial access, escalate privileges, or operate stealthily within the compromised environment.

Azure Active Directory azuread role-assignment privilege-escalation persistence
2r 3t
high advisory

Azure PIM Elevation Approved or Denied

Detection of Azure Privileged Identity Management (PIM) elevation approvals or denials, which, if unexpected, may indicate unauthorized privilege escalation or malicious activity within an Azure environment.

Azure pim privilege-escalation persistence
2r 3t