January 2024 (30)
Google Workspace 2SV Policy Disabled
2 rules 1 TTPAn adversary may disable 2-Step Verification (2SV) in Google Workspace to weaken account security and facilitate unauthorized access.
Google Workspace Drive Encryption Key Accessed by Anonymous User
2 rules 2 TTPsAn external (anonymous) user has viewed, copied, or downloaded an encryption key file from a Google Workspace drive, potentially leading to unauthorized access to sensitive data or authentication on behalf of users via rogue access links.
Google Workspace MFA Enforcement Disabled
2 rules 3 TTPsDetection of multi-factor authentication (MFA) enforcement being disabled for Google Workspace users, potentially weakening security controls and leading to account compromise.
Gotenberg ExifTool Argument Injection via Metadata Values
2 rules 1 TTPGotenberg version 8.30.1 and earlier is vulnerable to argument injection, where an unauthenticated attacker can inject arbitrary ExifTool pseudo-tags via newline characters in metadata values, leading to arbitrary file manipulation within the container filesystem.
Graphiti JSONAPI Arbitrary Method Execution Vulnerability (CVE-2026-33286)
2 rules 1 TTPGraphiti versions prior to 1.10.2 are vulnerable to arbitrary method execution via maliciously crafted JSONAPI payloads, allowing attackers to invoke public methods on model instances, classes, or associations.
Heimdall Authorization Bypass via Path Normalization Mismatch
2 rules 2 TTPsHeimdall is vulnerable to an authorization bypass due to a path normalization mismatch between Heimdall and downstream components, potentially leading to unauthorized access and privilege escalation.
Heimdall Host Matching Case-Sensitivity Vulnerability
2 rules 1 TTPHeimdall performs case-sensitive host matching, which can lead to policy bypass because HTTP hostnames are case-insensitive, potentially leading to unauthorized access, data modification, or privilege escalation if the request host is part of the rule.
Helm Plugin Verification Bypass Vulnerability
2 rules 2 TTPs 1 CVEHelm versions 4.0.0 through 4.1.3 fail to enforce plugin signature verification when the .prov file is missing, allowing installation of unsigned plugins and potentially leading to arbitrary code execution.
High Number of Cloned GitHub Repos From PAT
2 rules 2 TTPsThis rule detects a high number of unique private repository clone events originating from a single Github personal access token (PAT) within a short time period, potentially indicating unauthorized access and exfiltration of sensitive code.
High Number of Process and/or Service Terminations Detected
2 rules 2 TTPsA high number of process terminations (stop, delete, or suspend) from the same Windows host within a short time period may indicate malicious activity such as an attacker attempting to disable security measures or prepare for ransomware deployment.
Hysteria Server Out-of-Memory Vulnerability via Malformed QUIC Packet
2 rules 1 TTPA specially constructed QUIC package can crash the Hysteria server due to an out-of-memory (OOM) condition when the 'sniff' option is enabled, leading to a denial of service.
IIS HTTP Logging Disabled
2 rules 1 TTPAn attacker with IIS server access can disable HTTP Logging using appcmd.exe with the /dontLog parameter as an anti-forensics measure.
Image File Execution Options (IFEO) Injection for Persistence and Defense Evasion
2 rules 3 TTPsAdversaries abuse Image File Execution Options (IFEO) in the Windows Registry by modifying Debugger or MonitorProcess keys to intercept legitimate file executions, enabling persistence and defense evasion.
Impossible Travel Detection in Azure AD
2 rules 1 TTPThis brief describes the detection of 'impossible travel' events in Azure AD, where a user appears to log in from geographically distant locations within an implausibly short time frame, potentially indicating account compromise.
Incus WebUI Authentication Bypass Vulnerability (CVE-2026-33898)
3 rules 1 TTPIncus versions prior to 6.23.0 are vulnerable to an authentication bypass in the `incus webui` component, allowing local attackers to gain elevated privileges or remote attackers to access system resources by exploiting the incorrect validation of authentication tokens.
Indico LaTeX Injection Vulnerability (CVE-2026-33046)
2 rules 2 TTPsA critical vulnerability in Indico versions prior to 3.3.12 allows specially-crafted LaTeX snippets to achieve local file read or arbitrary code execution due to insufficient sanitization of LaTeX input, impacting systems where server-side LaTeX rendering is enabled.
iSelect 1.4.0-2+b1 Local Buffer Overflow Vulnerability
2 rules 1 TTPiSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability, allowing local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter and overflowing a 1024-byte stack buffer.
Java-SDK DNS Rebinding Vulnerability in MCP Server
2 rules 2 TTPsA DNS rebinding vulnerability exists in java-sdk versions prior to 1.0.0, allowing an attacker to access a locally or network-private java-sdk MCP server via a victim's browser, potentially enabling unauthorized tool calls to the server.
JetBrains TeamCity CVE-2023-42793 RCE Attempt
2 rules 1 TTPAn attacker attempts to exploit the CVE-2023-42793 vulnerability in JetBrains TeamCity On-Premises by sending a malicious POST request to gain administrative access and achieve remote code execution.
Kubeletctl Execution Inside Container Detected
3 rules 3 TTPsThis rule detects the execution of kubeletctl inside a container, which can be used to enumerate the Kubelet API or other resources inside the container, potentially indicating lateral movement attempts within the pod.
Kubernetes Access Scanning Detection
2 rules 1 TTPThis analytic detects potential reconnaissance activities within a Kubernetes environment by identifying repeated failed access attempts or unusual API requests from unauthenticated users based on Kubernetes audit logs, indicating a potential attacker's preliminary reconnaissance.
Kubernetes Anonymous Request Authorized by Unusual User Agent
2 rules 1 TTPThis rule detects when an unauthenticated user request is authorized within a Kubernetes cluster via an unusual user agent, potentially indicating an attacker attempting to gain initial access or avoid attribution by exploiting anonymous accounts.
Kubernetes Pod with Host Network Attachment Detected
2 rules 1 TTPDetection of Kubernetes pods configured to use the host network namespace via audit logs, potentially allowing attackers to monitor all node network traffic for sensitive data and privilege escalation.
Kubernetes Secrets Enumeration from Non-Loopback Client
2 rules 2 TTPsDetection of Kubernetes Secrets listing from non-loopback clients targeting cluster-wide secrets or sensitive namespaces, potentially indicating unauthorized credential access or discovery.
Lanman NullSessionPipe Registry Modification for Lateral Movement
2 rules 2 TTPsAdversaries may modify the NullSessionPipe registry key to enable anonymous access to named pipes, facilitating lateral movement and defense evasion by allowing unauthorized access to network resources.
Lateral Movement via Startup Folder File Creation
2 rules 4 TTPsAdversaries may move laterally by dropping malicious scripts or executables into a remote system's startup folder via RDP or SMB, enabling execution upon reboot or user logon.
Lazarus Group's macOS 'Fileless' Implant
3 rules 3 TTPs 3 IOCsThe Lazarus APT group is distributing a trojanized macOS application named UnionCryptoTrader.dmg that installs a launch daemon for persistence, downloads and executes secondary payloads in-memory, and communicates with the command and control server unioncrypto.vip.
link-preview-js vulnerable to IPv6 and internal loopback attacks
3 rules 1 TTPlink-preview-js versions 4.0.0 and earlier are vulnerable to IPv6 and internal loopback attacks, allowing potential internal data leaks by resolving addresses to internal IPs; patched in version 4.0.1.
Linksys E1200 Authenticated Stack Buffer Overflow
2 rules 1 TTP 1 CVEA stack buffer overflow vulnerability in Linksys E1200 firmware version 2.0.04 and earlier allows an authenticated attacker to achieve remote code execution by sending a crafted HTTP POST request to the apply.cgi endpoint.
Linux Auditd Daemon (Re)Initialization Detection
3 rules 1 TTPDetection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.