Skip to content
Threat Feed

January 2024 (30)

high advisory

Newly Observed High Severity Detection Alert in Elastic SIEM

This rule detects newly observed, low-frequency, high-severity Elastic SIEM detection alerts affecting a single agent, helping prioritize triage and response by highlighting alerts tied to specific detection rules that have not been seen previously for the host.

SIEM threat-detection higher-order-rule elastic-siem
3r
critical advisory

Nhost Account Takeover via OAuth Email Verification Bypass

Nhost is vulnerable to account takeover due to improper OAuth email verification in Discord, Bitbucket, AzureAD, and EntraID providers, allowing attackers to merge an unverified OAuth identity into a victim's account.

Nhost oauth account-takeover
2r 1t
critical advisory

NocoBase SQL Injection via Recursive Eager Loading

NocoBase versions 2.0.32 and earlier are vulnerable to SQL injection due to string concatenation in the `queryParentSQL()` function, allowing attackers with record creation permissions to inject arbitrary SQL and potentially extract sensitive information or execute commands.

NocoBase sqli cve-2026-41640 injection
2r 4t
high threat

Non-Chrome Process Accessing Chrome Login Data

This analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', an SQLite database containing sensitive information like saved passwords, potentially indicating credential theft attempts.

Chrome RedLine Stealer +1 credential-access stealer
2r 1t
high advisory

Non-Chrome Process Accessing Chrome Login Data

This analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', which is an SQLite database containing sensitive information like saved passwords, potentially leading to credential theft.

Chrome +3 credential-access password-stealing windows
2r 1t
high advisory

NorthStar C2 Agent Execution Detection

This brief details detection strategies for NorthStar C2 agent execution on Windows endpoints, an open-source command and control framework used for penetration testing and red teaming.

Splunk Enterprise +2 command-and-control red-teaming penetration-testing windows
2r 3t 2i
critical advisory

Note Mark OIDC Authentication Bypass via Hardcoded Password

A critical authentication bypass vulnerability in note-mark allows attackers to authenticate as any OIDC-registered user by submitting the password 'null' to the internal login endpoint due to a hardcoded bcrypt hash fallback, potentially leading to account takeover and persistent access.

note-mark authentication-bypass credential-access ghsa
2r 1t
medium advisory

Notepad++ Updater Querying Uncommon Domains

The Notepad++ updater, gup.exe, makes DNS queries to domains not part of the legitimate update infrastructure, potentially indicating updater mechanism exploitation or suspicious network activity.

Notepad++ supply-chain dns
2r 2t
high advisory

NTDS or SAM Database File Copied

Detects copy operations of the Active Directory Domain Database (ntds.dit) or Security Account Manager (SAM) files using command-line tools, potentially leading to credential access.

Windows +1 credential-access ntds sam
2r 2t
medium advisory

NullSessionPipe Registry Modification for Lateral Movement

Attackers modify the NullSessionPipe registry setting in Windows to enable anonymous access to named pipes, potentially facilitating lateral movement and unauthorized access to network resources.

M365 Defender +3 lateral-movement defense-evasion registry-modification
3r 2t
high advisory

O365 Add App Role Assignment Grant User

This analytic detects the addition of an application role assignment grant to a user in Office 365, which can indicate unauthorized privilege escalation or the assignment of sensitive roles, leading to unauthorized access within the Office 365 environment.

Office 365 +1 office365 azuread privilege-escalation
2r 1t
medium advisory

O365 Advanced Audit Disabled

The O365 Advanced Audit feature provides critical logging and insights into user and administrator activities, and this analytic detects instances where it is disabled for a specific user, potentially blinding security teams to malicious actions.

Microsoft 365 +1 o365 audit defense-evasion persistence
2r 1t
high advisory

O365 Application Available To Other Tenants

An Azure Active Directory Application is configured to allow authentication from external tenants or personal accounts, potentially leading to unauthorized access to data or capabilities.

Azure Active Directory +1 azuread o365 multitenant
2r 1t
medium threat

O365 Application Registration Owner Added

A new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.

Azure Active Directory +1 NOBELIUM Group azuread o365 persistence
3r 1t
critical threat

O365 ApplicationImpersonation Role Assigned

Detection of the ApplicationImpersonation role being assigned in Office 365, potentially leading to unauthorized mailbox access and impersonation.

Microsoft 365 +1 NOBELIUM Group cloud o365 applicationimpersonation persistence
2r 2t
high advisory

O365 BEC Email Hiding Rule Creation

This analytic detects suspicious Office 365 mailbox rule creation, a common technique used in Business Email Compromise (BEC), by scoring rule attributes like short names, marking emails as read, and moving emails to specific folders.

Office 365 +1 bec office365 email
2r 2t
medium advisory

O365 Compliance Content Search Activity Detected

Detection of content search initiation within the Office 365 Security and Compliance Center using the SearchCreated operation, which may signal unauthorized access to sensitive organizational data such as emails and documents, potentially leading to data exfiltration and compliance breaches.

Microsoft 365 +1 o365 compliance content search data exfiltration
2r 1t
high advisory

O365 Compliance Content Search Exported

An adversary exports the results of an Office 365 Security and Compliance Center content search, potentially leading to data exfiltration of sensitive information.

Microsoft 365 +1 o365 data-exfiltration compliance
2r 1t
medium advisory

O365 Data Loss Prevention Rule Triggered

Detection of triggered Microsoft Office 365 Data Loss Prevention (DLP) rules, which can indicate potential data exfiltration or policy violations, dependent on upstream DLP configuration.

Office 365 Data Loss Prevention data-exfiltration o365 dlp
2r 2t
high advisory

O365 Elevated Mailbox Permission Assignment

Detection of elevated mailbox permissions (FullAccess, ChangePermission, ChangeOwner) being assigned in Office 365, potentially leading to unauthorized access, data exfiltration, or privilege escalation.

Office 365 +1 o365 mailbox-permissions privilege-escalation
2r 1t
medium advisory

O365 Email Access By Security Administrator

Atypical access to O365 mailboxes is detected when a security administrator uses Threat Explorer features to directly view email, potentially indicating reconnaissance or data exfiltration by a compromised or malicious insider.

Office 365 cloud o365 data exfiltration azure ad
2r 2t
high advisory

O365 Email Receive and Hard Delete Takeover Behavior

Compromised Office 365 accounts may receive and then hard delete emails related to password resets or banking/payroll changes, potentially indicating an attempt to redirect victim payroll to an attacker-controlled bank account.

Office 365 office365 account-takeover email data-destruction
2r 3t
high advisory

O365 Email Reported by User Found Malicious

Detection of emails reported by users as malicious via the Outlook 'Report Message' feature, subsequently confirmed as Phish or Malware by Microsoft's analysis, indicating successful initial access.

Microsoft 365 +2 o365 phishing malware email
2r 2t
high advisory

O365 Risk-Based Consent Disabled

The disabling of the 'risk-based step-up consent' security setting in Microsoft 365 allows users to grant consent to potentially malicious applications, increasing the risk of OAuth phishing and unauthorized access to sensitive data.

Microsoft 365 +1 o365 azuread oauth consent-phishing defense-evasion
2r 1t
high advisory

O365 Security Feature Modification

Attackers modify or disable Office 365 advanced security settings, such as AntiPhish, SafeLink, SafeAttachment, or Malware policies, to evade detection and operate with reduced risk within the target tenant.

Office 365 +3 o365 email_security defense_evasion persistence
2r 1t
high threat

O365 Service Principal Creation Detection

Detection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.

Office 365 +5 NOBELIUM Group cloud o365 service_principal persistence azuread
2r 1t
high advisory

Office 365 Concurrent Sessions Indicate Adversary-in-the-Middle (AiTM) Attack

An adversary may compromise user credentials and conduct an Adversary-in-the-Middle (AiTM) attack, granting them unauthorized access to an Office 365 account from multiple IP addresses simultaneously, potentially leading to data theft, account takeover, and internal phishing campaigns.

Office 365 o365 aitm phishing credential-access
2r 1t
high advisory

Office 365 MFA Bypass via Trusted IP Modification

An adversary modifies the trusted IP list in Office 365 to bypass multi-factor authentication (MFA) and gain unauthorized access to accounts.

Office 365 azure o365 mfa bypass defense-evasion
2r 1t
medium advisory

Office 365 MFA Notification Email Deletion for Defense Evasion

Attackers may delete multi-factor authentication (MFA) notification emails in Office 365 to evade detection and maintain unauthorized access after compromising an account.

Office 365 o365 mfa defense_evasion email
2r 1t
medium advisory

Office Application Autorun Registry Key Modification

Adversaries modify Office application autostart extensibility point (ASEP) registry keys to achieve persistence and execute malicious code when Office applications are launched.

Microsoft Office attack.privilege-escalation attack.persistence attack.t1547.001
2r 1t