Skip to content
Threat Feed

January 2024 (30)

high advisory

Control Panel Abuse for Defense Evasion and Execution

Adversaries may abuse the legitimate Windows Control Panel (control.exe) to proxy the execution of malicious code by using unusual arguments such as image file extensions, suspicious paths, or relative path traversal patterns for defense evasion.

Windows defense-evasion execution
3r 2t
high advisory

CVE-2026-27922 Windows WinSock Use-After-Free Privilege Escalation

CVE-2026-27922 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to elevate privileges locally.

Windows privilege-escalation use-after-free
2r 1t 1c 1i
medium advisory

Suspicious PowerShell TabExpansion Direct Call

This detection identifies PowerShell scripts that directly call the TabExpansion internal function, which is uncommon and may indicate malicious activity, such as TabShell, potentially bypassing sandboxes by loading PowerShell functions via directory traversal.

Splunk Enterprise +2 powershell tabexpansion bypass endpoint
2r 2t
low advisory

Windows Account Discovery of Administrator Accounts

Adversaries may execute the `net.exe` or `wmic.exe` commands to enumerate administrator accounts or groups, both locally and within the domain, to gather information for follow-on actions.

M365 Defender +2 discovery account-discovery windows
2r 4t
high advisory

Long Base64 Encoded Command via Scripting Interpreter

Detection of oversized command lines used by Python, PowerShell, Node.js, or Deno interpreters containing base64 decoding or encoded-command patterns, indicating potential evasion and malicious execution.

Elastic Endpoint defense-evasion execution scripting-interpreter base64 command-line
2r 5t
high advisory

Mimikatz MemSSP Log File Detection

This rule detects the creation of the default Mimikatz MemSSP credential log file, mimilsa.log, which is created after the misc::memssp module injects a malicious Security Support Provider into LSASS, potentially capturing credentials from subsequent logons.

Elastic Defend +3 credential-access mimikatz memssp windows
2r 1t 1i
medium advisory

Network Connection via Compiled HTML File

This rule detects network connections initiated by hh.exe, the HTML Help executable, which may indicate the execution of malicious code embedded in compiled HTML files (.chm) to deliver malicious payloads, bypass security controls, and gain initial access via social engineering.

HTML Help execution defense-evasion command-and-control malicious-file html-help
2r 3t
critical advisory

VM2 Sandbox Breakout via neutralizeArraySpeciesBatch Method

A sandbox breakout vulnerability in vm2 allows attackers to execute arbitrary commands on the host system by exploiting the `neutralizeArraySpeciesBatch` method to access host objects and the Function object.

vm2 sandbox-escape rce javascript
2r 2t
high advisory

Detecting Remcos RAT Activity Through File and Registry Traces

This brief provides detection strategies for Remcos RAT, focusing on file and registry artifacts indicative of its presence, persistence, and potential cleanup activities on Windows systems, allowing for the identification and remediation of compromised hosts.

Windows remcos rat trojan
3r 3t 6i
critical advisory

Gotenberg Unauthenticated RCE via ExifTool Metadata Key Injection

Gotenberg version 8.29.1 is vulnerable to unauthenticated remote code execution (RCE) due to newline injection in metadata keys passed to ExifTool, allowing arbitrary command execution via the `-if` flag.

Gotenberg 8.29.1 gotenberg rce exiftool newline-injection cwe-78
3r 1t
high advisory

Linux Kernel Module Load from Unusual Location

This rule detects the loading of a kernel module from an unusual location, which could indicate a rootkit attempting to maintain persistence on the system by hiding processes, files, or network activity.

Linux Kernel persistence defense-evasion rootkit linux
3r 2t
medium advisory

AWS IAM OIDC Provider Created by Rare User

An uncommon user or role creating an OpenID Connect (OIDC) Identity Provider in AWS IAM can indicate an attacker establishing persistent, federated access by creating rogue OIDC providers to assume roles using attacker-controlled IdP tokens.

IAM aws oidc persistence cloud
2r 3t
high advisory

CyberArk Privileged Access Security Error Audit Event Promotion

This rule identifies CyberArk Privileged Access Security (PAS) error level audit events, which are considered alertable events by the vendor and may indicate privilege escalation or initial access attempts.

CyberArk Privileged Access Security cyberarkpas privilege-escalation initial-access
2r 2t
high advisory

LiquidJS Memory Limit Bypass Leads to Denial of Service

A vulnerability in LiquidJS versions 10.24.0 and earlier allows a threat actor with control over template content to bypass the `memoryLimit` protection mechanism, leading to a denial of service by using reverse range expressions to allocate unlimited memory and a string flattening operation to cause a V8 Fatal error that crashes the Node.js process.

LiquidJS denial-of-service template-injection nodejs
2r 2t
medium advisory

Windows Subsystem for Linux Distribution Installed via Registry Modification

This rule detects registry modifications indicative of a new Windows Subsystem for Linux (WSL) distribution installation, a technique adversaries may leverage to evade detection by utilizing Linux environments within Windows.

Windows Subsystem for Linux +4 wsl defense-evasion windows
2r 3t
medium advisory

Azure AD Authentication to Important Apps Using Single-Factor Authentication

Detection of successful Azure AD authentications to critical applications that only required single-factor authentication, potentially indicating a security lapse or policy violation leading to unauthorized access.

Azure Active Directory attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078
2r 3t
high advisory

Azure AD Temporary Access Pass Added to Account

Detection of a temporary access pass (TAP) being added to an Azure AD account, which could indicate potential privilege escalation, initial access, persistence, or stealth activity.

Azure Active Directory azuread temporary-access-pass privilege-escalation initial-access persistence
2r 4t
medium advisory

Detection of Bcdedit Boot Configuration Modification

This rule identifies the use of bcdedit.exe to modify boot configuration data, which may be indicative of a destructive attack or ransomware activity aimed at inhibiting system recovery by disabling error recovery or ignoring boot failures.

Microsoft Defender XDR +2 boot-configuration bcdedit impact windows
2r 1t
high advisory

Detection of Invoke-Obfuscation via Standard Input

This brief outlines detection strategies for adversaries leveraging Invoke-Obfuscation techniques within PowerShell scripts executed via standard input, a method commonly used to evade traditional detection mechanisms.

Windows defense-evasion obfuscation powershell
2r 2t
low advisory

High Command Line Entropy Detected for Privileged Commands on Linux

A machine learning job has identified an unusually high median command line entropy for privileged commands executed by a user on Linux systems, suggesting possible privileged access activity through command lines, indicating potential obfuscation or unauthorized use of privileged access.

privileged-access-detection machine-learning linux
2r 2t
high advisory

Kubernetes Security Scanner Image Pulling Detected

Detection of Kubernetes security scanner images such as kube-hunter, kube-bench, and kube-recon being pulled, indicating potential vulnerability assessment and reconnaissance activity within the Kubernetes environment.

Kubernetes container vulnerability-scan
2r 1t
high threat

Lazarus Group's AppleJeus macOS Backdoor via JMT Trader

The Lazarus APT group is distributing a macOS backdoor named AppleJeus via a fake cryptocurrency trading application called JMT Trader, persisting through a launch daemon and communicating with the C&C server beastgoc.com.

macOS Lazarus Group +4 applejeus backdoor cryptocurrency
2r 2t 3i
medium advisory

Malicious Azure Kubernetes Admission Controller Configuration

An adversary can exploit Kubernetes Admission Controllers in Azure to achieve persistence, privilege escalation, or credential access by manipulating webhook configurations.

Azure Kubernetes Service +1 azure kubernetes admission-controller persistence privilege-escalation credential-access
2r 4t
medium advisory

MSBuild запускает необычные процессы

Adversaries may exploit MSBuild to execute malicious scripts or compile code, bypassing security controls; this rule detects unusual processes initiated by MSBuild, such as PowerShell or C# compiler, signaling potential misuse for executing unauthorized or harmful actions.

MSBuild +3 defense-evasion execution
2r 3t
medium advisory

Multiple Logon Failures from Single Source Indicate Brute Force Attempt

Detection of multiple consecutive logon failures from a single source IP within a short time interval indicates a potential brute force or password guessing attack targeting Windows systems.

Windows credential-access brute-force
2r 2t
medium advisory

OpenSSL Data Encryption Detection

This brief documents detection of OpenSSL being used to encrypt data using command-line arguments specifying input and output files, potentially indicating data exfiltration preparation or ransomware activity by threat actors.

OpenSSL defense-evasion collection data-encryption
2r 2t
medium advisory

Potential Data Exfiltration via Rclone

The rule detects the abuse of rclone, a legitimate file synchronization tool, potentially renamed to evade detection, to exfiltrate data to cloud storage or remote endpoints, using copy/sync commands and specific file filters.

rclone exfiltration cloud storage windows
3r 1t
low advisory

Spike in Bytes Sent to an External Device via Airdrop

A machine learning job has detected a spike in bytes of data written to an external device via Airdrop, potentially indicating illicit data copying or transfer activities.

Airdrop +1 data-exfiltration macos
2r 1t
medium advisory

Windows Hosts Querying Abused Web Services

Adversaries may use abused web services such as paste sites, VoIP, and file hosting to host malicious payloads or facilitate command and control, detected via DNS queries from Windows hosts to these services.

githubusercontent.com +34 abused-web-service command-and-control initial-access windows
2r 1t 34i
medium advisory

Zoom High Video Latency Potentially Indicating Remote Employment Fraud

This analytic identifies Zoom users exhibiting high video latency, a potential indicator of Remote Employment Fraud (REF), by analyzing Zoom logs for average and overall latency and highlighting users with latency exceeding 300ms.

Zoom remote-employment-fraud identity
2r 1t 1i