Skip to content
Threat Feed

September 2026 (30)

low advisory

Abuse of POSIX Shell Trap Command for Persistence and Privilege Escalation

Adversaries leverage the POSIX shell 'trap' built-in to bind malicious payloads to interrupt signals, enabling automated execution for persistence or privilege escalation when specific signals are received.

persistence privilege-escalation linux macos
1r 2t
medium advisory

Monitoring Unauthorized Modifications to Sudoers Configuration

Adversaries may attempt to escalate privileges on Unix-like systems by modifying the sudoers configuration file to grant unauthorized users or groups elevated permissions.

privilege-escalation linux macos file-integrity
1r 1t
low advisory

Detection of SUID/SGID Bit Modification for Privilege Escalation

Adversaries may use chmod or install to set SUID or SGID bits on files, allowing malicious code to execute with elevated privileges for persistence or escalation.

privilege-escalation persistence defense-evasion linux macos
1r 1t
medium advisory

Detection of Unauthorized SSH Authorized Keys Modification

Adversaries modify SSH authorized_keys files to establish persistent access and facilitate lateral movement by injecting unauthorized public keys for password-less authentication.

persistence lateral-movement ssh linux macos
1r 2t
medium advisory

Detecting Persistence via Unix Shell Profile Modification

Adversaries maintain persistence on Linux and macOS systems by modifying shell configuration files to execute malicious payloads automatically upon user login or shell session initialization.

persistence linux macos
1r 1t
high advisory

Correlation of Multiple Machine Learning Alerts by Influencer Field

This detection rule identifies potential account compromise by correlating three or more distinct machine learning alert triggers associated with the same non-system influencer field.

Elastic Security threat-detection machine-learning elastic-security behavioral-analysis
3t
high advisory

Cross-Telemetry Correlation of Endpoint and Network Security Alerts

Detection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.

Elastic Defend +5 correlation multi-datasource network-security endpoint-security phishing email-security
3t
high advisory

Detection of Potential Lateral Movement via Alert Correlation

This detection capability monitors for lateral movement by identifying sequences where a host IP address from one security alert subsequently appears as the source IP in alerts from a different host.

lateral-movement threat-detection esql detection-engineering
1t
low advisory

Detection of New USB Storage Device Mounting

Detection rule identifies first-time seen USB storage devices mounted on Windows and macOS endpoints to help analysts monitor for potential initial access, lateral movement, or data exfiltration.

endpoint device-control threat-detection
2t
critical advisory

Detecting Malicious Activity within Package Manager Installation Ancestry

This detection logic identifies suspicious subprocess activity originating from software package manager installation processes (npm, pip, uv, poetry, cargo) to surface potential supply-chain compromises.

supply-chain endpoint-detection initial-access elastic-defend
1t
critical advisory

Suspicious Activity Detection from GenAI Coding Utilities

This detection rule identifies suspicious endpoint activity, such as malicious file creation or shellcode execution, originating from or triggered by AI-assisted coding and assistant tools indicating potential supply chain or prompt injection abuse.

supply-chain endpoint-security llm-security unauthorized-ai-usage
1r 1t
high advisory

Detection of Newly Observed Processes with High CPU Usage

This detection capability monitors for unauthorized resource hijacking, such as cryptomining or exploit payload execution, by identifying new processes exhibiting sustained CPU usage above 90 percent.

impact resource-hijacking cryptomining detection-rule
1t
medium advisory

Detection of Security Alerts Correlated with High CPU Utilization

A cross-platform detection methodology correlates security alerts with processes exhibiting sustained high CPU utilization to identify potential resource abuse or post-compromise activity.

threat-detection impact system-monitoring resource-abuse cryptomining
1t
medium advisory

Suspicious Python Shell Command Execution

This detection logic identifies potentially malicious activity where a Python process rapidly spawns multiple shell commands via '-c' arguments for host profiling, discovery, or lateral movement.

execution script-based-execution python linux macos
1r 1t
high advisory

Detection of Reverse Shell Activity via Shell Command-Line Arguments

This brief outlines detection logic for identifying reverse shell activity on Unix-like systems by monitoring shell processes for suspicious command-line network device redirection.

execution c2 linux macos
1r 2t
high advisory

Detection of Privileged Container Creation with Host Directory Mount

Attackers exploit misconfigured privileged containers using host bind-mounts to escape container isolation and gain unauthorized control over the underlying host.

Docker container-escape privilege-escalation execution
1r 2t
high advisory

Detection of Coordinated Malware Infections Across Multiple Hosts

This intelligence brief details a behavioral detection strategy for identifying widespread malware infections by correlating alerts across multiple endpoints to facilitate rapid incident response.

threat-detection endpoint-security malicious-activity incident-response
1t
medium threat

Exploitation of OpenClaw and Moltbot AI Coding Agents

AI coding assistants including OpenClaw, Moltbot, and Clawdbot are being weaponized via malicious 'ClawHub' registry skills to execute unauthorized system commands and exfiltrate cryptocurrency and credential data.

exploited OpenClaw +2 ai-security supply-chain command-and-control living-off-the-land
1r 3t 3i
medium advisory

Kubernetes Service Account Token Theft and API Abuse

Adversaries are targeting Kubernetes pods to steal service account tokens and certificates, subsequently using them for cluster-wide reconnaissance and lateral movement.

Kubernetes cloud-security credential-theft lateral-movement
1r 4t
medium advisory

Detection of Interactive Kubernetes API Abuse via Container Utilities

Adversaries may move laterally or perform reconnaissance by compromising a container and using interactive shells or networking utilities to query the Kubernetes API server directly.

Kubernetes container-security discovery execution cloud
3t
medium advisory

Monitoring Azure Run Command for Unauthorized Execution

This brief outlines detection strategies for unauthorized guest execution via the Azure Virtual Machine Run Command feature, which attackers may abuse to run arbitrary scripts without interactive access.

Azure Virtual Machine azure cloud execution detection-engineering
1r 2t
low advisory

Detection of Potential Remote File Inclusion (RFI) Activity

This brief outlines the identification and response strategy for Remote File Inclusion (RFI) attacks, where adversaries exploit web server vulnerabilities to fetch remote payloads or disclose sensitive local files.

Nginx +4
2t
medium advisory

Virtual Machine Fingerprinting via Grep

Adversaries perform virtual machine fingerprinting by using grep to query hardware manufacturer identifiers, a technique used by malware like Pupy RAT for sandbox and virtualization evasion.

discovery defense-evasion sandbox-evasion reconnaissance
1r 2t
medium advisory

Detection of Security Software Discovery via Grep on macOS and Linux

Attackers utilize standard command-line tools like grep and pgrep to enumerate installed security software on macOS and Linux, enabling situational awareness for post-compromise activity.

discovery macos linux e-dr reconnaissance
1r 1t
high advisory

Kubernetes Secret Discovery via Kubectl

Adversaries may use the kubectl command-line tool to enumerate sensitive secret objects across all Kubernetes namespaces to facilitate credential theft, privilege escalation, or lateral movement.

Kubernetes container discovery credential-access
1r 2t
medium advisory

Kubernetes Permission Discovery via Kubectl

Adversaries utilize the 'kubectl auth can-i' command to enumerate effective permissions and identify security misconfigurations within Kubernetes clusters, facilitating unauthorized access and privilege escalation.

discovery kubernetes container linux macos
1r 2t
medium advisory

Command Line Obfuscation via Whitespace Padding

Detection of command-line obfuscation where attackers insert excessive whitespace sequences to evade signature-based security monitoring tools.

defense-evasion obfuscation process-monitoring
1r 2t
medium advisory

Timestomping via Touch Utility

Adversaries perform timestomping on Linux and macOS systems using the touch command to modify file timestamps and evade forensic detection.

defense-evasion timestomping linux macos
1r 1t
low advisory

Defense Evasion via Process Masquerading with Trailing Spaces

Adversaries utilize trailing space characters in binary filenames to masquerade as legitimate system tools, exploiting file handling behaviors to disguise malicious activity.

defense-evasion masquerading linux macos
1r 1t
medium advisory

Detection of Kubectl Binary Masquerading and Evasion

Adversaries may attempt to evade detection by renaming the kubectl binary or executing it from non-standard directories while retaining command-line functionality to perform unauthorized Kubernetes operations.

kubectl defense-evasion kubernetes masquerading
1r 2t