January 2024 (30)
Azure AD Successful Single-Factor Authentication
2 rules 2 TTPsSuccessful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.
Azure AD Tenant Wide Admin Consent Granted
2 rules 1 TTPDetection of admin consent granted to an application within an Azure AD tenant which could lead to data exfiltration and persistence.
Azure AD User Added to Administrator Role
2 rules 4 TTPsAn adversary adds a user to an Azure Active Directory administrative role to gain initial access, persist in the environment, escalate privileges, and potentially operate stealthily.
Azure AD User Consent Blocked for Risky Application
2 rules 1 TTPAzure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.
Azure AD User ImmutableId Attribute Modification for Persistence
2 rules 1 TTPAttackers modify the ImmutableID attribute of an Azure AD user to establish a federation backdoor, bypassing MFA and enabling persistent access.
Azure Automation Account Creation
2 rules 1 TTPDetect the creation of new Azure Automation accounts, which can be used by attackers for persistence, privilege escalation, and malicious runbook execution within Azure environments.
Azure Automation Runbook Creation for Persistence
2 rules 1 TTPThis analytic detects the creation of a new Azure Automation Runbook within an Azure tenant using Azure Audit events, which adversaries with privileged access can abuse to maintain persistence, escalate privileges, or execute malicious code, potentially leading to unauthorized actions and compromise of the Azure environment.
Azure Compute Restore Point Collection Deleted by Unusual User
2 rules 1 TTPThe deletion of Azure Restore Point Collections, which contain recovery points for virtual machines, by a user who has not previously performed this activity, indicates a potential attempt to prevent recovery during ransomware attacks or cover tracks during malicious operations.
Azure Event Hub Authorization Rule Created or Updated
2 rules 2 TTPsCreation or modification of Azure Event Hub authorization rules can indicate unauthorized access or privilege escalation by adversaries using cryptographic keys to manage access to event hubs.
Azure Key Vault Modified by Unusual User
2 rules 2 TTPsThis rule identifies modifications to Azure Key Vaults by unusual users, potentially leading to data breaches or service disruptions through defense evasion or impact operations.
Azure Key Vault Unusual Secret Key Usage
2 rules 1 TTPDetects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.
Azure Kubernetes Services (AKS) Kubernetes Events Deleted
2 rules 2 TTPsAdversaries may delete Kubernetes events in Azure Kubernetes Services (AKS) to evade detection by removing logs of state changes, container creations, image pulls, and pod scheduling.
Azure Owner Removed from Application or Service Principal
2 rules 1 TTPAn adversary may remove an owner from an Azure application or service principal to weaken access controls, persist in the environment, or escalate privileges.
Azure RBAC Built-In Administrator Role Assignment
2 rules 2 TTPsDetection of a user being assigned a built-in administrator role in Azure RBAC, which can be abused for privilege escalation, lateral movement, or persistence.
Azure Runbook Webhook Creation Detected
2 rules 1 TTPDetection of a new Azure Automation Runbook Webhook creation, potentially leading to unauthorized access and control over Azure resources by enabling unauthenticated URL triggers.
Azure Storage Account Blob Public Access Enabled
2 rules 1 TTPDetection of Azure Storage Account Blob public access being enabled, potentially allowing external access to blob containers for data exfiltration, as abused by threat actors modifying storage account settings.
Azure Subscription Permission Elevation via Activity Logs
2 rules 1 TTPAn attacker elevates their Azure subscription permissions to manage all subscriptions, potentially leading to unauthorized access and control over the environment.
Azure VNet Firewall Policy Deletion for Defense Evasion
2 rules 1 TTPAn adversary may delete a firewall policy in Azure in an attempt to evade defenses, which can be detected by monitoring Azure activity logs for successful deletion operations of firewall policies.
BCDEdit Failure Recovery Modification
2 rules 1 TTPDetection of modifications to Windows error recovery boot configurations using bcdedit.exe, a technique commonly used by ransomware to disable system restoration options.
Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
2 rules 1 TTP 1 CVEBeghelli Sicuro24 SicuroWeb is vulnerable to arbitrary JavaScript execution due to embedding an end-of-life AngularJS 1.5.2 component with known sandbox escape primitives combined with template injection, enabling attackers to compromise operator browser sessions via MITM attacks.
Betheme WordPress Theme Arbitrary File Upload Vulnerability
2 rules 1 TTP 1 CVEThe Betheme theme for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level privileges or higher to upload arbitrary files, including PHP, leading to remote code execution.
BITS Job Notify Command Persistence
2 rules 1 TTPAdversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.
blueprintUE Password Reset Token Vulnerability (CVE-2026-40585)
2 rules 1 TTP 1 CVEblueprintUE versions before 4.2.0 generate password reset tokens that remain valid indefinitely due to the absence of a timestamp validation, allowing attackers to potentially gain unauthorized access via token reuse.
Budibase Authentication Bypass via Unanchored Regex
2 rules 1 TTP 2 IOCsBudibase versions 3.35.3 and earlier are vulnerable to an authentication bypass due to unanchored regular expressions in the public endpoint matcher, allowing unauthenticated attackers to access protected endpoints by manipulating the query string.
Certreq HTTP POST Abuse for File Transfer
2 rules 4 TTPsAdversaries may abuse the Windows Certreq utility to download files or upload data to a remote URL by making an HTTP POST request, potentially for command and control, defense evasion, or exfiltration.
CF Image Hosting Script 1.6.5 Unauthenticated Database Download and Remote Image Deletion
2 rules 2 TTPs 1 CVECF Image Hosting Script 1.6.5 allows unauthenticated attackers to download the application database, extract delete IDs, and delete all pictures via the `d` parameter.
changedetection.io Arbitrary Local File Read via Crafted Backup Restore
2 rules 1 TTPchangedetection.io is vulnerable to arbitrary local file read due to insufficient validation of snapshot paths restored from backup files, allowing attackers to read sensitive files by crafting a malicious backup archive containing a manipulated `history.txt` file.
changedetection.io Authentication Bypass via Flask Decorator Misordering
2 rules 4 TTPs 1 IOCchangedetection.io is vulnerable to authentication bypass due to incorrect decorator ordering in Flask routes, allowing unauthenticated access to backup functionalities and potentially leading to data exfiltration of sensitive information.
charm.land/wish SCP Path Traversal Vulnerability
2 rules 1 TTPThe charm.land/wish/v2 and github.com/charmbracelet/wish libraries are vulnerable to path traversal attacks via the SCP protocol, allowing malicious clients to read or write arbitrary files, create directories outside the configured root, and enumerate files, potentially leading to remote code execution or data exfiltration.
ChatGPTNextWeb NextChat Improper Authorization Vulnerability (CVE-2026-7644)
1 rule 1 TTP 1 CVECVE-2026-7644 is an improper authorization vulnerability in the addMcpServer function of ChatGPTNextWeb NextChat version 2.16.1 and earlier, allowing for potential remote exploitation following public disclosure of the exploit.