January 2024 (30)
Newly Observed High Severity Detection Alert in Elastic SIEM
3 rulesThis rule detects newly observed, low-frequency, high-severity Elastic SIEM detection alerts affecting a single agent, helping prioritize triage and response by highlighting alerts tied to specific detection rules that have not been seen previously for the host.
Nhost Account Takeover via OAuth Email Verification Bypass
2 rules 1 TTPNhost is vulnerable to account takeover due to improper OAuth email verification in Discord, Bitbucket, AzureAD, and EntraID providers, allowing attackers to merge an unverified OAuth identity into a victim's account.
NocoBase SQL Injection via Recursive Eager Loading
2 rules 4 TTPsNocoBase versions 2.0.32 and earlier are vulnerable to SQL injection due to string concatenation in the `queryParentSQL()` function, allowing attackers with record creation permissions to inject arbitrary SQL and potentially extract sensitive information or execute commands.
Non-Chrome Process Accessing Chrome Login Data
2 rules 1 TTPThis analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', an SQLite database containing sensitive information like saved passwords, potentially indicating credential theft attempts.
Non-Chrome Process Accessing Chrome Login Data
2 rules 1 TTPThis analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', which is an SQLite database containing sensitive information like saved passwords, potentially leading to credential theft.
NorthStar C2 Agent Execution Detection
2 rules 3 TTPs 2 IOCsThis brief details detection strategies for NorthStar C2 agent execution on Windows endpoints, an open-source command and control framework used for penetration testing and red teaming.
Note Mark OIDC Authentication Bypass via Hardcoded Password
2 rules 1 TTPA critical authentication bypass vulnerability in note-mark allows attackers to authenticate as any OIDC-registered user by submitting the password 'null' to the internal login endpoint due to a hardcoded bcrypt hash fallback, potentially leading to account takeover and persistent access.
Notepad++ Updater Querying Uncommon Domains
2 rules 2 TTPsThe Notepad++ updater, gup.exe, makes DNS queries to domains not part of the legitimate update infrastructure, potentially indicating updater mechanism exploitation or suspicious network activity.
NTDS or SAM Database File Copied
2 rules 2 TTPsDetects copy operations of the Active Directory Domain Database (ntds.dit) or Security Account Manager (SAM) files using command-line tools, potentially leading to credential access.
NullSessionPipe Registry Modification for Lateral Movement
3 rules 2 TTPsAttackers modify the NullSessionPipe registry setting in Windows to enable anonymous access to named pipes, potentially facilitating lateral movement and unauthorized access to network resources.
O365 Add App Role Assignment Grant User
2 rules 1 TTPThis analytic detects the addition of an application role assignment grant to a user in Office 365, which can indicate unauthorized privilege escalation or the assignment of sensitive roles, leading to unauthorized access within the Office 365 environment.
O365 Advanced Audit Disabled
2 rules 1 TTPThe O365 Advanced Audit feature provides critical logging and insights into user and administrator activities, and this analytic detects instances where it is disabled for a specific user, potentially blinding security teams to malicious actions.
O365 Application Available To Other Tenants
2 rules 1 TTPAn Azure Active Directory Application is configured to allow authentication from external tenants or personal accounts, potentially leading to unauthorized access to data or capabilities.
O365 Application Registration Owner Added
3 rules 1 TTPA new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.
O365 ApplicationImpersonation Role Assigned
2 rules 2 TTPsDetection of the ApplicationImpersonation role being assigned in Office 365, potentially leading to unauthorized mailbox access and impersonation.
O365 BEC Email Hiding Rule Creation
2 rules 2 TTPsThis analytic detects suspicious Office 365 mailbox rule creation, a common technique used in Business Email Compromise (BEC), by scoring rule attributes like short names, marking emails as read, and moving emails to specific folders.
O365 Compliance Content Search Activity Detected
2 rules 1 TTPDetection of content search initiation within the Office 365 Security and Compliance Center using the SearchCreated operation, which may signal unauthorized access to sensitive organizational data such as emails and documents, potentially leading to data exfiltration and compliance breaches.
O365 Compliance Content Search Exported
2 rules 1 TTPAn adversary exports the results of an Office 365 Security and Compliance Center content search, potentially leading to data exfiltration of sensitive information.
O365 Data Loss Prevention Rule Triggered
2 rules 2 TTPsDetection of triggered Microsoft Office 365 Data Loss Prevention (DLP) rules, which can indicate potential data exfiltration or policy violations, dependent on upstream DLP configuration.
O365 Elevated Mailbox Permission Assignment
2 rules 1 TTPDetection of elevated mailbox permissions (FullAccess, ChangePermission, ChangeOwner) being assigned in Office 365, potentially leading to unauthorized access, data exfiltration, or privilege escalation.
O365 Email Access By Security Administrator
2 rules 2 TTPsAtypical access to O365 mailboxes is detected when a security administrator uses Threat Explorer features to directly view email, potentially indicating reconnaissance or data exfiltration by a compromised or malicious insider.
O365 Email Receive and Hard Delete Takeover Behavior
2 rules 3 TTPsCompromised Office 365 accounts may receive and then hard delete emails related to password resets or banking/payroll changes, potentially indicating an attempt to redirect victim payroll to an attacker-controlled bank account.
O365 Email Reported by User Found Malicious
2 rules 2 TTPsDetection of emails reported by users as malicious via the Outlook 'Report Message' feature, subsequently confirmed as Phish or Malware by Microsoft's analysis, indicating successful initial access.
O365 Risk-Based Consent Disabled
2 rules 1 TTPThe disabling of the 'risk-based step-up consent' security setting in Microsoft 365 allows users to grant consent to potentially malicious applications, increasing the risk of OAuth phishing and unauthorized access to sensitive data.
O365 Security Feature Modification
2 rules 1 TTPAttackers modify or disable Office 365 advanced security settings, such as AntiPhish, SafeLink, SafeAttachment, or Malware policies, to evade detection and operate with reduced risk within the target tenant.
O365 Service Principal Creation Detection
2 rules 1 TTPDetection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.
Office 365 Concurrent Sessions Indicate Adversary-in-the-Middle (AiTM) Attack
2 rules 1 TTPAn adversary may compromise user credentials and conduct an Adversary-in-the-Middle (AiTM) attack, granting them unauthorized access to an Office 365 account from multiple IP addresses simultaneously, potentially leading to data theft, account takeover, and internal phishing campaigns.
Office 365 MFA Bypass via Trusted IP Modification
2 rules 1 TTPAn adversary modifies the trusted IP list in Office 365 to bypass multi-factor authentication (MFA) and gain unauthorized access to accounts.
Office 365 MFA Notification Email Deletion for Defense Evasion
2 rules 1 TTPAttackers may delete multi-factor authentication (MFA) notification emails in Office 365 to evade detection and maintain unauthorized access after compromising an account.
Office Application Autorun Registry Key Modification
2 rules 1 TTPAdversaries modify Office application autostart extensibility point (ASEP) registry keys to achieve persistence and execute malicious code when Office applications are launched.