Skip to content
Threat Feed

January 2024 (30)

medium advisory

Unauthorized Guest User Invitations in Azure AD

Detection of unauthorized guest user invitations within an Azure Active Directory tenant, indicating potential privilege escalation, persistence, or initial access attempts.

azure azuread guest-user privilege-escalation persistence initial-access
2r 3t
high advisory

Unusual Child Process from System Virtual Process Indicates Process Injection

The rule detects suspicious child processes of the Windows System process (PID 4), excluding legitimate processes, potentially indicating code injection used for defense evasion.

Windows defense-evasion process-injection
2r 1t
high advisory

Unusual Executable File Creation by System Critical Process

This rule detects the creation or modification of executable files by Windows system-critical processes, potentially indicating remote code execution or other forms of exploitation for defense evasion, execution, or privilege escalation.

Windows defense-evasion execution privilege-escalation
2r 3t
high advisory

Unusual File Creation via Alternate Data Streams

Detection of suspicious creation of Alternate Data Streams (ADS) on targeted files using command interpreters indicates potential malware hiding or defense evasion.

Windows defense-evasion alternate-data-stream
2r 1t
medium advisory

Unusual Parent Process for cmd.exe

Atypical parent processes spawning cmd.exe indicate potential malicious command execution on Windows systems, where adversaries leverage cmd.exe from unusual parent processes to execute malicious commands stealthily.

Windows execution process-tree
1r 1t
medium advisory

Unusual Process Execution via Alternate Data Streams

Adversaries may use Alternate Data Streams (ADS) to hide malicious executables and execute them, evading traditional detection methods by concealing the file's true nature.

Windows defense-evasion malware
2r 1t
low advisory

Unusual Process Writing Data to an External Device via Machine Learning

A machine learning job detects a rare process writing data to an external device, potentially indicating data exfiltration masked by benign-looking processes.

data-exfiltration machine-learning elastic-defend
2r 1t
medium advisory

Unusual Service Host Child Process - Childless Service

The rule identifies unusual child processes of Service Host (svchost.exe) instances hosting services that do not traditionally spawn child processes, potentially indicating code injection or exploitation leading to privilege escalation and defense evasion.

Windows process-injection privilege-escalation defense-evasion
2r 2t
medium advisory

User Account ServicePrincipalName Attribute Modified

Detection of modifications to the servicePrincipalName attribute on user accounts, potentially exposing them to Kerberoasting attacks by allowing attackers to request Kerberos tickets for the account.

Active Directory kerberoasting credential-access windows spn
2r 2t
critical advisory

UTT HiPER 1250GW strcpy Buffer Overflow Vulnerability (CVE-2026-4862)

A buffer overflow vulnerability exists in UTT HiPER 1250GW devices, allowing remote attackers to execute arbitrary code by exploiting the strcpy function in the /goform/formConfigDnsFilterGlobal component through manipulation of the GroupName argument.

HiPER 1250GW cve-2026-4862 buffer-overflow utt-hiper webserver
2r 1t
critical advisory

V2Board and Xboard Authentication Bypass via Exposed Tokens

V2Board and Xboard are vulnerable to authentication bypass due to exposing authentication tokens in HTTP response bodies, allowing unauthenticated attackers to gain complete account access.

V2Board +1 CVE-2026-39912 xboard authentication-bypass webserver
2r 1t 1c
high advisory

Vikunja Link Share Hash Disclosure Leads to Privilege Escalation

The Vikunja application is vulnerable to privilege escalation, where the LinkSharing.ReadAll() method permits authenticated users to list all link shares, including secret hashes, without proper authorization checks, allowing an attacker with a read-only link share to escalate to full admin access.

Vikunja privilege-escalation credential-access
2r 2t
critical advisory

Vvveb CMS v1.0.8 Remote Code Execution via File Rename

Vvveb CMS v1.0.8 is vulnerable to remote code execution due to a missing return statement in the file rename handler, allowing authenticated attackers to bypass extension restrictions and execute arbitrary code by manipulating .htaccess and .php files.

Vvveb CMS rce web-application vvveb-cms
3r 1t 1c
critical advisory

Wasmtime Cranelift AArch64 Sandbox Escape Vulnerability

A critical sandbox escape vulnerability exists in Wasmtime's Cranelift compilation backend on aarch64, allowing guest WebAssembly modules to bypass bounds checks and achieve arbitrary read/write access to host memory under specific configuration conditions.

Wasmtime cranelift aarch64 sandbox-escape memory-corruption
2r 2t
medium advisory

Wbadmin Backup Catalog Deletion

Adversaries may delete Windows backup catalogs using wbadmin.exe to inhibit system recovery, often as part of ransomware or other destructive attacks.

Windows impact backup-deletion ransomware
2r 2t
low advisory

Web Server Discovery or Fuzzing Activity

Detection of potential web server discovery or fuzzing activity characterized by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, indicating attackers are probing for hidden resources.

Nginx +4 reconnaissance web-server fuzzing
2r 2t
low advisory

Web Server Discovery or Fuzzing Activity Detected

Detection of web server discovery or fuzzing activity indicated by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, suggesting attempts to discover hidden resources.

Nginx +4 web-server fuzzing reconnaissance web-application
2r 2t
medium advisory

Web Server Local File Inclusion Activity

This rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.

Nginx +4 lfi web-server directory-traversal information-disclosure
2r 1t
high advisory

WeKan SSRF Vulnerability in Webhook Integration

WeKan before 8.35 is vulnerable to server-side request forgery (SSRF), allowing attackers with integration modification privileges to set webhook URLs to internal network addresses, leading to unauthorized HTTP POST requests and potential comment manipulation.

WeKan ssrf cve-2026-41455
2r 1t 1c
medium advisory

Windows Admin Account Brute Force Detection

This rule identifies potential password guessing/brute force activity from a single source IP targeting multiple Windows accounts with 'admin' in the username, indicating an attempt to compromise privileged accounts.

Windows Security Event Logs credential-access brute-force windows
2r 2t
high threat

Windows Audit Policy Security Descriptor Tampering via Auditpol

Detection of `auditpol.exe` execution with arguments to modify the audit policy security descriptor, indicative of defense evasion by adversaries aiming to limit audit logging.

Splunk Enterprise +2 auditpol security descriptor defense evasion windows
2r 1t
medium advisory

Windows Command Obfuscation via Environment Variable Substrings

Attackers obfuscate commands in Windows by dynamically constructing them using substrings extracted from environment variables, a technique observed in malware families such as Cobalt Strike and Meterpreter.

Splunk Enterprise +2 command-obfuscation defense-evasion windows
2r 1t
medium advisory

Windows Credential Manager Abuse via VaultCmd

Adversaries may abuse VaultCmd to list or dump credentials stored in the Windows Credential Manager to obtain saved usernames and passwords, potentially for lateral movement.

Windows credential-access vaultcmd
2r 2t
high advisory

Windows Defender Firewall and Network Protection Disabled via Registry Modification

An attacker modifies the Windows registry to disable the Windows Defender Firewall and Network Protection settings, potentially weakening the system's security posture and increasing vulnerability to further attacks.

Windows Defender Security Center +3 defense-evasion registry-modification windows
2r 1t
medium advisory

Windows Defender PUA Protection Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender Potentially Unwanted Application (PUA) protection, increasing the risk of malware installation and system compromise.

Windows Defender +3 defense-evasion windows registry-modification
2r
medium advisory

Windows Defender Quick Scan Interval Modification

Detection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.

Splunk Enterprise +3 defense-evasion windows-registry windows-defender endpoint
2r 1t
medium advisory

Windows Defender SmartScreen Level Downgrade to 'Warn'

This analytic detects modifications to the Windows Registry to set Windows Defender SmartScreen level to 'Warn', which can reduce user suspicion and increase the risk of malware execution.

Splunk Enterprise +3 defense-evasion registry-modification windows
2r 1t
low advisory

Windows Event Logs Cleared

Attackers attempt to clear Windows event logs to evade detection and remove forensic evidence of their activities.

Windows defense-evasion
2r 1t
high advisory

Windows HVCI Disabled via Registry Modification

Detection of Hypervisor-protected Code Integrity (HVCI) being disabled by modifying specific Windows registry keys, potentially allowing the execution of malicious kernel-mode code.

Splunk Enterprise +2 defense-evasion registry-modification windows
2r 1t 1c
low advisory

Windows Peripheral Device Discovery via fsutil

Adversaries may use the Windows file system utility, fsutil.exe, with the fsinfo drives command to enumerate attached peripheral devices and gain information about a compromised system.

Microsoft Defender XDR +1 discovery windows fsutil
2r 1t