Skip to content
Threat Feed

January 2024 (30)

low advisory

Adding Hidden File Attribute via Attrib.exe

Adversaries can use attrib.exe to add the 'hidden' attribute to files to hide them from users and evade detection, which can be detected by monitoring process executions related to attrib.exe.

M365 Defender +4 defense-evasion persistence windows attrib.exe
2r 2t
high advisory

AWS High Number of Failed Console Login Attempts

An IP address exhibiting more than 20 failed AWS console login attempts within a 5-minute window, indicative of potential brute-force or password spraying attacks against AWS accounts.

AWS cloudtrail brute-force password-spraying credential-access
2r 2t
low advisory

AWS IAM Group Creation for Persistence

An adversary with compromised IAM write privileges creates a new group in AWS IAM and grants it excessive permissions to establish a persistence mechanism.

AWS Identity and Access Management aws iam persistence cloud
2r 1t
high advisory

AWS MFA Bombing Attack Attempt

An attacker attempts to bypass MFA by flooding a user with authentication requests on the AWS console, as detected through AWS CloudTrail logs showing multiple failed MFA attempts within a short timeframe.

AWS mfa credential-access defense-evasion
2r 2t
high advisory

AWS Network ACL Created with All Ports Open

The analytic detects the creation or replacement of AWS Network Access Control Lists (ACLs) with rules that allow all traffic from a specified CIDR block, potentially exposing the network to unauthorized access and increasing the risk of data breaches.

CloudTrail +5 aws network-acl misconfiguration cloud security-group
2r
high advisory

AWS RDS Master User Password Reset Detection

Detection of unauthorized master user password resets for Amazon RDS DB instances via AWS CloudTrail logs, potentially leading to sensitive data access and data breaches.

Amazon RDS cloud aws credential-access rds
2r 2t
high advisory

AWS S3 Bucket Lifecycle Rule Abuse for Log Deletion

Attackers may abuse the AWS S3 PutBucketLifecycle API to rapidly delete CloudTrail logs by setting short expiration periods on S3 buckets, hindering incident response and forensic investigations.

CloudTrail +3 aws defense-evasion
2r 1t
high advisory

AWS S3 Bucket Versioning Disabled

An adversary disables AWS S3 bucket versioning, preventing recovery of deleted or modified data as a potential precursor to data exfiltration or ransomware activity.

S3 aws bucket_versioning data_protection ransomware
2r 1t
medium advisory

AWS Suspicious User Agent Detected in CloudTrail

Successful AWS API calls with CloudTrail user agents indicating offensive tooling (Kali Linux) or credential verification (TruffleHog) can indicate compromised credentials or unauthorized access.

AWS cloudtrail initial-access credential-access
2r 2t
high advisory

Azure AD Account Authentication from Multiple IPs

An Azure AD account successfully authenticating from multiple unique IP addresses within a 30-minute window, detected using Azure AD SignInLogs, which may indicate compromised credentials and unauthorized access to corporate resources.

Azure Active Directory azure credential-access compromised-account
1r 3t
medium threat

Azure AD External Guest User Invitation

Detection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.

exploited Azure Active Directory azuread cloud persistence
2r 1t
critical advisory

Azure AD Global Administrator Role Assigned

Detection of Azure AD Global Administrator role assignment to a user, potentially leading to privilege escalation and control over Azure resources.

Azure Active Directory azuread privilege-escalation persistence
2r 2t
high advisory

Azure AD PowerShell Authentication Abuse

Adversaries may compromise accounts and leverage successful PowerShell authentication in Azure AD to enumerate cloud resources, escalate privileges, and further exploit the Azure environment.

Azure Active Directory +1 azuread powershell authentication cloud
2r 2t
medium advisory

Azure AD User Consent Denied for OAuth Application

This analytic identifies instances where a user has denied consent to an OAuth application seeking permissions within the Azure AD environment, potentially indicating malicious OAuth application activity.

Azure AD azure oauth consent-phishing credential-access
2r 1t
high threat

Braodo Stealer Screen Capture in TEMP Directory

This analytic detects the creation of screen capture files in the TEMP directory, specifically targeting activity associated with the Braodo stealer malware, which captures screenshots of the victim's desktop as part of its data theft activities.

Splunk Enterprise +2 Braodo Stealer stealc-stealer crypto-stealer braodo-stealer apt37 hellcat-ransomware vip-keylogger screen-capture malware
2r 1t
high advisory

Cisco ASA Device File Copy to Remote Location

The analytic detects file copy operations from Cisco ASA devices to remote locations using protocols like TFTP, FTP, HTTP, HTTPS, SMB, or SCP, potentially indicating data exfiltration by threat actors targeting network devices.

Cisco ASA cisco-asa data-exfiltration network-device
2r 3t
medium advisory

macOS File Monitoring via Endpoint Security Framework

Objective-See details how to create a file monitor for macOS 10.15 using Apple's Endpoint Security Framework to capture file I/O events and process information.

macOS +6 file-monitoring endpoint-security
2r 1t
high advisory

free5GC NEF Denial-of-Service via Unreachable notifyUri

free5GC's NEF component is vulnerable to a denial-of-service attack where an attacker can create a PFD subscription with an attacker-controlled `notifyUri`, and when a PFD change is triggered, NEF attempts to deliver a notification to the specified URI, and if the URI is unreachable, NEF terminates the entire process, causing a service outage, and this can be triggered without authentication in version 4.2.1, making it easily exploitable.

nef +1 dos vulnerability free5gc
2r 1t 1i
high advisory

free5GC NEF Unauthenticated Callback Vulnerability

free5GC NEF v4.2.1 exposes an unauthenticated callback route group, enabling attackers to forge SMF callbacks and potentially corrupt AF traffic-influence or PFD-management subscription views, leading to unauthorized policy changes.

nef:v4.2.1 +1 5G NEF Authentication Bypass CWE-306 CWE-862
2r 1t
medium advisory

Suspicious SUID Binary Execution Sequence on Linux

This rule detects suspicious sequences where a non-root user launches a high-risk parent process and then executes a common privilege elevation helper gaining an effective UID of 0 while the real UID remains non-root, potentially indicating misuse of SUID/SGID helpers or privilege escalation attempts.

auditbeat-* +1 privilege-escalation linux suid
2r 2t
high advisory

AWS Console Login Password Spraying

A single source IP failing to authenticate into the AWS Console with multiple valid users, potentially indicating a password spraying attack against cloud resources.

AWS Console aws cloudtrail password-spraying
2r 3t
low advisory

Adobe Acrobat Reader Hijack for Persistence

Attackers can maintain persistence by replacing the legitimate RdrCEF.exe file, used by Adobe Acrobat Reader, with a malicious executable that will be launched upon execution of Adobe Acrobat Reader.

Adobe Acrobat Reader persistence adobe file-replacement
2r 2t
high advisory

O365 MFA Disabled by User

Detection of Multi-Factor Authentication (MFA) being disabled for a user account in Office 365, potentially indicating malicious activity or an insider threat.

Office 365 o365 mfa persistence
2r 1t
high advisory

Azure Identity Protection Atypical Travel Anomaly

The Atypical Travel detection in Azure Identity Protection identifies potentially compromised user accounts by detecting geographically improbable sign-in activity, indicative of account compromise or misuse.

Azure Active Directory +1 azure identity-protection atypical-travel account-compromise credential-theft
2r 1t
low advisory

Direct Interactive Kubernetes API Request by Unusual Utilities

This rule detects interactive commands executed inside containers using atypical utilities to interact with the Kubernetes API, paired with near-simultaneous API activity on sensitive resources, potentially indicating lateral movement and discovery by an attacker from within a container.

Kubernetes container execution discovery
2r 5t
high advisory

Credential Acquisition via Registry Hive Dumping

Attackers may dump the SECURITY and/or SAM hives to obtain credentials stored in the host by using the Windows reg.exe tool.

Windows credential-access registry-dump
2r 2t
medium advisory

Entra ID User Sign-in with Unusual Authentication Type

Detects rare authentication requirements for Azure Entra ID principal users, potentially indicating an adversary attempting to bypass conditional access policies and MFA using stolen credentials.

Azure Entra ID azure entra_id initial_access credential_access
2r 4t
critical advisory

OpenLearnX Remote Code Execution via Python Sandbox Escape

A critical RCE vulnerability in OpenLearnX allows for sandbox escape and arbitrary command execution in versions prior to 2.0.3.

openlearnx rce sandbox escape code injection
2r 1t
high advisory

PowerShell PSReflect Script Detection

This rule detects PowerShell script block content containing PSReflect-style helper indicators, such as Add-Win32Type, New-InMemoryModule, or DllImport patterns, that may support dynamic Win32 API invocation from PowerShell.

PowerShell +1 psreflect windows execution
2r 1t
medium advisory

Remote File Download via Script Interpreter

The rule identifies built-in Windows script interpreters, specifically cscript.exe or wscript.exe, being used to download an executable file from a remote destination, often employed by attackers for initial access or to deploy secondary payloads.

Windows command_and_control execution
2r 2t