January 2024 (30)
Abnormal Cloud Security Group API Call Activity
2 rules 2 TTPsDetection of an abnormally high number of cloud security group API calls which can indicate malicious activity such as reconnaissance, privilege escalation, or lateral movement within a cloud environment.
Abuse of Predefined BIOCs in Palo Alto Cortex XDR
2 rules 1 TTPAttackers may decrypt and abuse predefined Behavioral Indicators of Compromise (BIOCs) in Palo Alto Cortex XDR to evade detection or manipulate the system.
AdFind Tool Used for Active Directory Reconnaissance
2 rules 5 TTPsThe execution of AdFind.exe, an Active Directory query tool, is often used by threat actors for post-exploitation Active Directory reconnaissance, as observed in campaigns involving Trickbot, Ryuk, Maze, and FIN6.
Adobe InDesign Out-of-Bounds Read Vulnerability (CVE-2026-27284)
2 rules 1 TTP 1 CVEAdobe InDesign Desktop versions 20.5.2, 21.2 and earlier are vulnerable to an out-of-bounds read (CVE-2026-27284) when parsing a crafted file, potentially leading to code execution if a user opens a malicious file.
Algovate xhs-mcp Server-Side Request Forgery Vulnerability
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability exists in Algovate xhs-mcp 0.8.11 within the xhs_publish_content function, allowing a remote attacker to manipulate the media_paths argument and potentially access internal resources.
Android-ImageMagick7 Memory Leak Vulnerability (CVE-2026-33856)
2 rules 1 TTPA missing release of memory after effective lifetime vulnerability exists in MolotovCherry Android-ImageMagick7 before version 7.1.2-11, potentially leading to denial of service.
Anomalous Cloud Compute Instance Creation by Unseen User
2 rules 1 TTPDetection of cloud compute instance creation by a user with no prior history of creating instances, potentially indicating unauthorized access, account compromise, or misuse of cloud resources leading to data exfiltration, increased costs, or further exploitation.
Apko DirFS Symlink Path Traversal Vulnerability
2 rules 1 TTPA symlink-following path traversal vulnerability exists in apko versions prior to 1.2.5 allowing a malicious .apk file to create a symbolic link pointing outside the build root and subsequently modify files on the host system.
AppInit DLL Registry Persistence Detected
2 rules 2 TTPsModification of the AppInit DLLs registry keys can be used for persistence and defense evasion on Windows systems.
AVideo EncoderReceiveImage Local File Inclusion Vulnerability
2 rules 1 TTP 1 CVEAVideo is vulnerable to local file inclusion (LFI) via the EncoderReceiveImage endpoint, allowing authenticated uploaders to read sensitive server files by bypassing path traversal restrictions.
AVideo Session Fixation Vulnerability (CVE-2026-33492)
2 rules 1 TTPAVideo versions 26.0 and earlier are vulnerable to session fixation due to accepting arbitrary session IDs via the `PHPSESSID` GET parameter and disabled session regeneration, allowing attackers to hijack authenticated sessions.
AWS Bedrock GuardRails Deletion Attempt
2 rules 1 TTPDetection of AWS Bedrock GuardRails deletion, which are security controls to prevent harmful AI outputs, could indicate an adversary attempting to remove safety measures after credential compromise to enable malicious model outputs.
AWS CloudShell Environment Created
2 rules 1 TTPThe creation of a new AWS CloudShell environment is detected, potentially indicating unauthorized access for command execution within AWS by adversaries without needing local CLI credentials.
AWS CloudTrail Logging Evasion via Oversized IAM Policies
2 rules 1 TTPAttackers evade AWS CloudTrail logging by padding IAM policy documents with whitespace, exceeding logging size limits and obscuring unauthorized changes to IAM policies.
AWS Config Configuration Recorder Stopped
2 rules 2 TTPsDetection of AWS Config configuration recorder being stopped, potentially by an adversary to evade detection and obscure activity.
AWS Config Resource Deletion for Defense Evasion
2 rules 2 TTPsAn adversary may delete AWS Config resources to evade detection, hide prior activity, or weaken governance controls, which reduces security visibility and auditability within an AWS environment.
AWS Config Service Disabling Detection
2 rules 1 TTPDetection of AWS Config Service disabling, potentially indicating an attempt to impair defenses by stopping configuration recording and delivery.
AWS Credential Access via GetPasswordData API Calls
2 rules 3 TTPsDetection of anomalous GetPasswordData API calls in AWS CloudTrail logs, indicating potential attempts to retrieve encrypted administrator passwords for Windows instances, leading to unauthorized access.
AWS DynamoDB Scan by Unusual User
2 rules 3 TTPsDetection of unusual DynamoDB scan activity in AWS environments, potentially indicating exfiltration of sensitive information by an adversary using compromised credentials or a rogue insider.
AWS EC2 Network Access Control List Creation
2 rules 3 TTPsThe rule detects the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number, which adversaries may exploit to establish persistence or defense evasion by creating permissive rules.
AWS EC2 Serial Console Access Enabled
3 rules 2 TTPsThe EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer, which adversaries may enable for out-of-band communication, evading network-based security monitoring, firewalls, and VPC controls.
AWS ECR Container Scanning Findings Placeholder
2 rules 3 TTPsThis is a placeholder brief due to the provided text being a GitHub navigation page, indicating no specific threat or attack details are available, and therefore serves as a template for future threat intelligence extraction related to AWS ECR container scanning.
AWS ECR Container Upload by Unknown User
2 rules 1 TTPAn unauthorized user uploaded a new container image to AWS Elastic Container Registry (ECR), potentially leading to the deployment of malicious containers and further compromise of the AWS environment.
AWS EventBridge Rule Disabled or Deleted
2 rules 2 TTPsDetection of Amazon EventBridge rule disabling or deletion events, which can disrupt operational workflows and security monitoring.
Suspicious MS Outlook Child Process
2 rules 3 TTPsDetection of suspicious child processes spawned by Microsoft Outlook, indicative of spear phishing and malicious file execution leading to potential initial access and further exploitation.
Unusual EC2 Instance Creation with Unseen Instance Type
2 rules 1 TTPAn attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.
Use-After-Free Vulnerability in Firefox, ESR, and Thunderbird CSS Parsing (CVE-2026-4691)
2 rules 3 TTPsA use-after-free vulnerability (CVE-2026-4691) in the CSS Parsing and Computation component affects Firefox versions prior to 149, Firefox ESR versions prior to 115.34 and 140.9, and Thunderbird versions prior to 149 and 140.9, potentially leading to arbitrary code execution.
Windows Privilege Escalation via Secondary Logon Service
2 rules 2 TTPsThe rule identifies process creation with alternate credentials, which can be used for privilege escalation, by detecting successful logins via the Secondary Logon service (seclogon) from a local source IP address (::1), followed by process creation using the same TargetLogonId.
Windows Update Client DLL Loading Abuse
2 rules 2 TTPsAdversaries abuse the Windows Update Auto Update Client (wuauclt.exe) to load arbitrary DLLs from user-writable locations, achieving defense evasion and execution of malicious code.
Zebra Block Discovery Denial-of-Service via Gossip Queue Saturation and Syncer Poisoning
2 rules 1 TTP 1 CVEA denial-of-service vulnerability exists in Zebra's block discovery pipeline, allowing an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node by exploiting weaknesses in the gossip, syncer, and download subsystems.