Skip to content
Threat Feed

January 2024 (30)

medium advisory

Attrib.exe Used to Hide Files and Directories

Detection of attrib.exe being used with the +h flag to hide files and directories on Windows systems, a technique used by attackers for defense evasion and persistence.

Splunk Enterprise +2 defense-evasion persistence windows
2r 1t
high advisory

AWS CloudTrail Stop Logging Detection

Detection of adversaries stopping CloudTrail logging to evade detection and operate stealthily within a compromised AWS environment.

AWS CloudTrail aws cloudtrail defense-evasion
2r 1t
medium advisory

AWS Console Login from New Country

Detects AWS console logins by a user from a previously unseen country, potentially indicating compromised credentials.

AWS Console aws cloud credential-access initial-access
2r 3t
high advisory

AWS Data Exfiltration via DataSync Task Creation

An attacker may create an AWS DataSync task to exfiltrate data from a private AWS location to a public one, leading to data compromise, detected by monitoring AWS CloudTrail logs for the `CreateTask` event from the DataSync service.

AWS DataSync aws datasync data-exfiltration cloudtrail
2r 1t
low advisory

AWS DynamoDB Table Export to S3 Detection

Detects the initial export of an AWS DynamoDB table to S3, potentially indicating reconnaissance or exfiltration by a compromised account or insider threat.

AWS DynamoDB +2 aws dynamodb exfiltration
2r 2t
medium advisory

AWS GuardDuty Member Account Manipulation

Adversaries may attempt to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization to break centralized visibility, allowing them to operate undetected in member accounts.

GuardDuty aws defense_evasion
2r 1t
medium advisory

AWS IAM SAML Provider Updated Detection

Detection of unauthorized updates to AWS IAM SAML providers, potentially leading to privilege escalation and persistent access via trust manipulation.

AWS IAM aws iam saml privilege-escalation defense-evasion
2r 2t
medium advisory

AWS KMS Customer Managed Key Disabled or Scheduled for Deletion

An adversary may disable or schedule the deletion of an AWS customer-managed KMS Key to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity.

AWS Key Management Service cloud aws kms datadestruction
2r 1t
high advisory

AWS Lateral Movement from Kubernetes Service Account via AssumeRoleWithWebIdentity

This rule detects lateral movement in AWS environments originating from Kubernetes service accounts by identifying instances where credentials obtained for a service account are used for multiple distinct AWS control-plane actions, potentially indicating unauthorized access.

AWS CloudTrail +1 cloud aws kubernetes lateral-movement credential-access discovery
2r 4t
low advisory

AWS S3 Bucket Configuration Deletion

Detection of Amazon S3 bucket configuration deletions, such as bucket policies or encryption settings, indicating potential defense evasion or impact attempts by adversaries who may delete logging or policy configurations to disrupt forensic visibility and inhibit recovery.

Amazon S3 aws s3 defense_evasion impact
2r 5t
high advisory

AWS S3 Bucket Replication for Data Exfiltration

An attacker enables S3 bucket replication to exfiltrate data to an external AWS account by creating a bucket replication rule.

S3 aws exfiltration bucket-replication
2r 1t
medium advisory

AWS SES Identity Deletion

Detection of an AWS Simple Email Service (SES) identity deletion event, potentially indicating an adversary attempting to cover their tracks after malicious activity.

Simple Email Service attack.stealth attack.t1070 cloud
2r 1t
medium advisory

AWS STS Role Assumption by Service for Privilege Escalation

Detection of AWS services assuming roles within AWS Security Token Service (STS) to gain temporary credentials and potentially escalate privileges or move laterally within the AWS environment.

AWS Security Token Service aws sts privilege-escalation lateral-movement
2r 2t
medium advisory

AWS User Login Profile Update by Different User

A user updating the login profile of another user in AWS CloudTrail logs may indicate privilege escalation attempts.

AWS Identity and Access Management aws cloudtrail iam privilege-escalation
2r 1t
medium advisory

Azure AD Guest to Member User Type Conversion

An adversary may convert a guest user account to a member account in Azure Active Directory to elevate privileges and gain persistent access to resources.

Azure Active Directory privilege-escalation azure entra guest-account
2r 1t
medium advisory

Azure AD User Password Reset Detection

Detects when a user successfully resets their own password in Azure Active Directory, which may indicate malicious activity or account compromise.

Azure Active Directory azure password-reset privilege-escalation initial-access persistence credential-access stealth
2r 1t
medium advisory

Azure Key Vault Excessive Secret or Key Retrieval

Detects excessive secret or key retrieval operations from Azure Key Vault, indicating potential unauthorized access attempts or credential harvesting.

Azure Key Vault azure keyvault credential-access threat-detection
2r 2t
medium advisory

Azure Network Watcher Deletion for Defense Evasion

An adversary may delete an Azure Network Watcher to impair defenses by disabling network monitoring and logging capabilities, as detected by monitoring Azure activity logs for Network Watcher deletion events.

Azure Network Watcher cloud azure defense-evasion
2r 2t
medium advisory

Bandit WebSocket Memory Exhaustion Vulnerability

An unauthenticated attacker can exhaust server memory by sending unbounded WebSocket continuation frames in Bandit-fronted applications, leading to a denial of service.

Phoenix Channels +1 denial-of-service websocket memory-exhaustion
2r 2t
high advisory

Conhost Proxy Execution for Defense Evasion

Adversaries abuse the Console Window Host (conhost.exe) with the `--headless` argument to proxy execution of malicious commands, evading detection by blending in with legitimate Windows software.

Elastic Defend +2 defense-evasion proxy-execution windows
3r 1t
medium advisory

Detect Windows Entra User Management Via Azure CLI

This analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.

Azure CLI +3 azure entra-id user-management persistence windows
2r 3t
high advisory

Detection of Azure Subscription Permission Elevation

Detection of a user being assigned the 'User Access Administrator' role, which grants the ability to manage all Azure Subscriptions, potentially leading to privilege escalation and unauthorized access.

Azure attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078
2r 1t
low advisory

Detection of Command and Control Activity via Common Web Services

This rule detects command and control (C2) communications that use common web services to hide malicious activity on Windows hosts by identifying network connections to commonly abused web services from processes outside of known legitimate program locations, indicating potential exfiltration or C2 activity blended with legitimate traffic.

Elastic Defend +10 command-and-control webservice windows
2r 1t
critical advisory

Detection of ConvertTo-AADIntBackdoor Execution via PowerShell

This brief outlines the detection of the ConvertTo-AADIntBackdoor command execution via PowerShell Script Block Logging, a technique used to create a backdoor in federated Azure AD domains by modifying federation settings and allowing attackers to control the authentication process.

Azure Active Directory azure-ad backdoor powershell persistence privilege-escalation
2r 4t
high advisory

Detection of Malicious Office 365 Inbox Rule Creation

This brief outlines the detection of malicious Office 365 inbox rule creation, where attackers leverage 'New-InboxRule' and 'Set-InboxRule' operations to forward, delete, or obfuscate emails, potentially leading to data exfiltration or business email compromise.

Office 365 o365 inbox-rule email data-exfiltration business-email-compromise
3r 2t
medium advisory

Entra ID User Sign-in with Unusual Client Application

Adversaries with stolen credentials or OAuth tokens may abuse Entra ID-managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic and evading detection by using a rare application ID for principal authentication.

Entra ID +1 azure entra-id initial-access oauth
2r 3t
high advisory

ESXi Audit Tampering via esxcli

Attackers use esxcli system auditrecords commands on ESXi hosts to tamper with logging, hindering forensic analysis and detection efforts, potentially leading to prolonged compromise and data breaches.

ESXi audit-tampering defense-evasion vmware
3r 2t
high advisory

ESXi Host Reverse Shell Detection

This detection identifies reverse shell string patterns on an ESXi host via syslog, potentially indicating a threat actor attempting to establish remote control over the system, which may lead to further compromise such as ransomware deployment.

ESXi reverse-shell vmware syslog ransomware
3r 1t
medium advisory

Execution of Persistent Suspicious Programs via Run Keys

This analytic identifies suspicious programs such as script interpreters, rundll32, or MSBuild being executed shortly after user logon, indicating potential persistence mechanisms abusing the registry run keys.

Elastic Defend persistence windows threat-detection
2r 8t
medium advisory

Generic Ransomware Detection on macOS

This brief outlines a method for generically detecting ransomware on macOS by monitoring file I/O events and identifying the rapid creation of encrypted files by untrusted processes, as proposed by Objective-See.

Transmission +1 ransomware malware macos
2r 1t