Skip to content
Threat Feed

January 2024 (30)

high advisory

Azure AD PowerShell Authentication Abuse

Adversaries may compromise accounts and leverage successful PowerShell authentication in Azure AD to enumerate cloud resources, escalate privileges, and further exploit the Azure environment.

Azure Active Directory +1 azuread powershell authentication cloud
2r 2t
medium advisory

Azure AD User Consent Denied for OAuth Application

This analytic identifies instances where a user has denied consent to an OAuth application seeking permissions within the Azure AD environment, potentially indicating malicious OAuth application activity.

Azure AD azure oauth consent-phishing credential-access
2r 1t
high threat

Braodo Stealer Screen Capture in TEMP Directory

This analytic detects the creation of screen capture files in the TEMP directory, specifically targeting activity associated with the Braodo stealer malware, which captures screenshots of the victim's desktop as part of its data theft activities.

Splunk Enterprise +2 Braodo Stealer stealc-stealer crypto-stealer braodo-stealer apt37 hellcat-ransomware vip-keylogger screen-capture malware
2r 1t
high advisory

Cisco ASA Device File Copy to Remote Location

The analytic detects file copy operations from Cisco ASA devices to remote locations using protocols like TFTP, FTP, HTTP, HTTPS, SMB, or SCP, potentially indicating data exfiltration by threat actors targeting network devices.

Cisco ASA cisco-asa data-exfiltration network-device
2r 3t
medium advisory

Cisco ASA User Account Deletion

Detection of user account deletion on Cisco ASA devices, potentially indicating adversary attempts to cover tracks, disrupt incident response, or deny administrator access.

Cisco ASA cisco_asa account_deletion defense_evasion
2r 2t
high advisory

Cisco ASA User Privilege Level Change Detection

Detection of unauthorized privilege level changes on Cisco ASA devices, potentially indicating privilege escalation or persistence attempts by threat actors.

Cisco ASA cisco-asa privilege-escalation persistence network
2r 2t
high advisory

Conhost Proxy Execution for Defense Evasion

Adversaries abuse the Console Window Host (conhost.exe) with the `--headless` argument to proxy command execution, evading detection by blending malicious activity with legitimate Windows software.

Windows defense-evasion proxy-execution conhost
2r 4t
high advisory

CoreDNS Transfer Plugin ACL Bypass Vulnerability

CoreDNS' transfer plugin prior to version 1.14.3 can select the wrong ACL stanza due to lexicographic comparison, leading to unauthorized zone transfers by clients intended to be denied by subzone-specific transfer policies.

CoreDNS cve-2026-33489 acl-bypass dns zone-transfer
2r 1t
critical advisory

Daptin Unauthenticated Path Traversal and Zip Slip Vulnerability

Daptin versions up to and including v0.11.3 are vulnerable to unauthenticated path traversal and zip slip attacks via the cloudstore.file.upload action, allowing arbitrary file write and potential remote code execution.

Daptin path-traversal zip-slip remote-code-execution
1r 2t
medium advisory

Detecting Remote Scheduled Task Creation for Lateral Movement

This rule identifies remote scheduled task creations on a target Windows host, potentially indicating lateral movement by adversaries, by monitoring network connections and registry modifications related to task scheduling.

Elastic Defend +2 lateral-movement execution windows scheduled-task
2r 2t
high advisory

Detection of Public AWS S3 Bucket Creation via CLI

An AWS user creates a publicly accessible S3 bucket by using the AWS CLI to set permissive ACLs, potentially leading to unauthorized data access and data breaches.

Amazon S3 +2 aws s3 cloudtrail misconfiguration data-breach
2r 1t
high threat

Detection of Taskkill Command to Terminate Browser Processes

This analytic detects the use of the taskkill command to terminate known browser processes, a technique employed by malware such as Braodo stealer to steal credentials by forcefully closing browsers like Chrome, Edge, and Firefox to unlock files containing sensitive information.

Splunk Enterprise +2 Braodo Stealer credential-theft malware windows
2r
high advisory

Detection of Unauthorized Windows Hosts File Access

This analytic detects processes attempting to access the Windows hosts file, enabling attackers to redirect traffic to malicious sites or block legitimate security websites by modifying DNS resolution.

Windows hosts-file dns-redirection
2r 1t
high advisory

Detects Kirbi File Creation

Detects the creation of .kirbi files, a suspicious Kerberos ticket artifact often produced by ticket export or dumping tools such as Rubeus or Mimikatz, indicating preparation for Kerberos ticket theft or Pass-The-Ticket (PTT) attacks.

Microsoft Defender XDR +2 credential-access kerberos pass-the-ticket mimikatz rubeus
2r 1t
high advisory

Directus File Overwrite Vulnerability (CVE-2026-39942)

A file overwrite vulnerability (CVE-2026-39942) exists in Directus versions prior to 11.17.0, where an attacker can overwrite another user's files by manipulating the filename_disk parameter in the PATCH /files/{id} endpoint, potentially leading to data corruption or privilege escalation.

Directus file-overwrite privilege-escalation CVE-2026-39942
2r 2t 1c
high advisory

Disabling CMD Application via Registry Modification

Attackers modify the Windows registry to disable the command prompt (cmd.exe), hindering incident response and potentially maintaining persistence.

Splunk Enterprise +2 registry-modification defense-evasion windows
2r 1t
high advisory

Disabling LSA Protection via Registry Modification

Attackers may disable LSA protection by modifying the RunAsPPL registry value in order to access LSASS memory and dump credentials, potentially leading to credential compromise and further lateral movement.

Windows defense-evasion credential-access registry-modification
2r 3t
high advisory

Download Monitor WordPress Plugin Insecure Direct Object Reference

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) allowing unauthenticated attackers to steal paid digital goods by manipulating PayPal transaction tokens to complete arbitrary orders.

Download Monitor plugin wordpress plugin idor download-monitor cve-2026-3124
2r 1t
medium advisory

Entra ID Application Credential Modification

An adversary may add unauthorized credentials to an Azure application, enabling persistent access, evading defenses, and escalating privileges by modifying certificates or secrets.

Azure +1 persistence entra_id account_manipulation
3r 2t
high advisory

Entra ID High Risk Sign-in Detected

This rule detects high-risk sign-ins in Microsoft Entra ID, as identified by Identity Protection, where the sign-in is flagged with a risk level of `high` during the authentication process, indicating a strong likelihood of account compromise.

Microsoft Entra ID azure entra_id initial_access high_risk_signin
2r 1t
high advisory

ESXi Account Modification Detection

Detection of local user account creation, deletion, or modification on an ESXi host, potentially indicating unauthorized access, persistence attempts, or defense evasion.

ESXi vmware account-management persistence privilege-escalation
2r 7t
high advisory

ESXi Loghost Configuration Tampering

Attackers modify the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response efforts after a compromise.

ESXi vmware syslog defense-evasion t1562
2r 1t
high advisory

Executable or Script Creation in Suspicious Paths

This analytic identifies the creation of executables or scripts in suspicious file paths on Windows systems, where adversaries often use these paths to evade detection and maintain persistence, potentially leading to unauthorized code execution, privilege escalation, or persistence within the environment.

Windows defense-evasion persistence privilege-escalation execution
2r 1t
critical advisory

Fortinet Appliance Authentication Bypass Vulnerability (CVE-2022-40684) Exploitation

Exploitation of CVE-2022-40684, a Fortinet appliance authentication bypass vulnerability, allows unauthorized REST API access to modify system configurations, potentially leading to complete system compromise.

FortiOS +2 cve-2022-40684 fortinet authentication-bypass network-appliance initial-access
2r 2t
critical threat

Fortinet FortiNAC CVE-2022-39952 Exploitation Attempt

An attacker attempts to exploit the Fortinet FortiNAC CVE-2022-39952 vulnerability by sending a malicious HTTP POST request to upload a payload, potentially leading to remote code execution.

FortiNAC fortinet cve-2022-39952 rce web-exploit
2r 2t
medium advisory

Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.10.0, allowing unauthenticated attackers to inject arbitrary web scripts via form submissions that execute when an administrator views the entry detail page.

Gravity Forms plugin xss wordpress gravityforms
2r 1c
critical threat

Ivanti EPMM Unauthenticated API Access via CVE-2023-35078

Exploitation of CVE-2023-35078 in Ivanti EPMM allows unauthenticated remote API access, potentially leading to data theft, unauthorized modifications, or further system compromise.

Endpoint Manager Mobile ivanti epmm cve-2023-35078 unauthenticated-access
2r 2t
high advisory

Katana Mirai Variant Targeting Android TV Devices

Katana is a Mirai botnet variant that infects Android TV set-top boxes and compiles its own rootkit for persistence and control.

Android TV mirai botnet android rootkit
2r 7t
medium advisory

Kubernetes Scanning by Unauthenticated IP Address

Detects potential scanning activities within a Kubernetes environment by identifying multiple unauthorized access attempts (HTTP 403 responses) from unauthenticated IP addresses in Kubernetes audit logs, potentially indicating vulnerability probing or exploitation attempts.

Kubernetes scanning cloud
2r 1t
high advisory

Linux Auditd Detects Firewall Modification or Disabling

The analytic detects suspicious disabling or modification of the system firewall on Linux systems, which can indicate unauthorized access or attempts to maintain control over a system by disabling host protections.

Splunk Enterprise +3 defense-evasion persistence privilege-escalation firewall
3r 1t