Skip to content
Threat Feed

July 2026 (30)

high advisory

Renamed Sysinternals Sdelete Utility Execution

The execution of a renamed Microsoft Sysinternals Sdelete utility is a highly suspicious technique often employed by adversaries to destroy data on Windows systems, leading to severe impact on system integrity and data availability.

data-destruction living-off-the-land windows impact defense-evasion
1r 2t
high advisory

Detecting Renamed ProcDump Execution for Evasion

This brief focuses on the detection of renamed Sysinternals ProcDump executables, a technique often employed by threat actors to evade security controls and perform credential dumping from LSASS memory on Windows systems, leading to potential lateral movement and privilege escalation.

Windows Sysinternals ProcDump stealth credential-dumping sysinternals evasion windows
1r 2t
high advisory

Potential Defense Evasion Via Rename Of Highly Relevant Binaries

This brief details a defense evasion technique where attackers rename legitimate Windows system binaries to mask malicious activity, bypassing security solutions that rely on process names for detection.

defense-evasion windows process-creation
1r 1t
medium advisory

Detecting Suspicious GrantedAccess Flags on LSASS

This brief details a detection for potentially suspicious `GrantedAccess` flags when a process attempts to access `LSASS.exe`, indicating possible credential dumping attempts by adversaries, which can lead to lateral movement and privilege escalation on Windows systems.

credential-dumping windows post-exploitation
1r 2t
high advisory

Potential Credential Dumping Activity via LSASS Process Access

Adversaries frequently target the Local Security Authority Subsystem Service (LSASS) process on Windows systems to dump credentials, employing tools like Mimikatz, NanoDump, or Procdump to extract sensitive authentication material for lateral movement and persistence.

credential-access post-exploitation windows
1r 1t
high advisory

HackTool - SysmonEnte Execution for Sysmon Evasion

This brief details the SysmonEnte hacktool, an open-source utility developed by codewhitesec, designed to attack the integrity of Microsoft Sysmon processes to impair endpoint detection and bypass security monitoring on Windows systems.

Microsoft Sysmon defense-evasion endpoint windows hacktool
1r
medium advisory

Suspicious CredUI.DLL Loading by Uncommon Processes

Attackers may attempt to load the Windows Credential UI DLL (credui.dll) from an unusual or non-standard process to capture or access user credentials, facilitating credential theft and further malicious activity on a compromised system.

windows credential-access image-load-detection
1r 1t
medium advisory

Suspicious Process Monitor Driver Creation by Non-Sysinternals Binary

This brief details a detection strategy for malicious actors attempting to establish persistence or elevate privileges by creating a Process Monitor driver file (`.sys`) from an unauthorized process, indicating potential kernel-level compromise on Windows systems.

persistence privilege-escalation windows detection
1r 2t
high advisory

Malware Abusing Process Explorer Driver for Privilege Escalation

Malware and hack tools are observed creating Sysinternals Process Explorer drivers via non-Sysinternals processes to elevate privileges and bypass security controls on Windows systems.

Process Explorer driver-abuse privilege-escalation defense-evasion windows
1r 4t
medium advisory

Suspicious PROCEXP152.sys Driver Creation in Temporary Folders

This brief details the suspicious creation of the PROCEXP152.sys driver file, associated with Sysinternals Process Explorer, in temporary application data folders, a technique leveraged by tools like KDU and Ghost-In-The-Logs for defense evasion and bypassing Windows Event Logging on affected Windows systems.

defense-evasion driver-abuse windows endpoint
1r
medium advisory

Potential Privileged System Service Operation - SeLoadDriverPrivilege

This brief details the detection of `SeLoadDriverPrivilege` usage on Windows systems, a critical privilege enabling attackers to load malicious kernel drivers for advanced defense evasion and privilege escalation, leading to full system compromise.

windows defense-evasion privilege-escalation detection
1r 2t
high advisory

Legitimate Application Dropped Script Detection

This brief describes the detection of Living Off The Land Binaries (LOLBINs) and legitimate Windows applications being abused to drop various script files to disk, indicating malware staging or script-based code execution attempts.

living-off-the-land stealth execution windows
1r 2t
medium advisory

Potentially Suspicious AccessMask Requested From LSASS

This brief describes the detection of suspicious access mask requests to the Local Security Authority Subsystem Service (LSASS) process, a common post-exploitation technique used by threat actors for credential dumping on Windows systems.

credential-dumping post-exploitation windows security-event
1r 1t
high advisory

Detection of Web Shell via Antivirus Signature

This brief describes the detection of web shells by antivirus solutions, emphasizing the importance of investigating these alerts as they signify a compromised web server and potential post-exploitation activity by an attacker.

webshell antivirus detection persistence
1r 1t
critical advisory

Detection of Malicious Remote Access Tools by Antivirus

This brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.

remote-access-trojan rat antivirus detection malware windows
1r 1t
critical advisory

Antivirus - Ransomware Signature Detection

This brief describes a critical Sigma rule designed to detect highly relevant Antivirus alerts reporting known ransomware families, enabling detection engineers to ensure immediate investigation even when the malware has been blocked.

ransomware antivirus windows
1r 1t
critical advisory

Antivirus Alert for Password Dumper and Stealer Activity

This brief details the detection of highly relevant antivirus alerts indicating the presence of password dumpers and stealers on endpoints, emphasizing the critical need for investigation even if the malware is blocked, to prevent credential compromise and subsequent attacks.

credential-access password-stealer password-dumper antivirus endpoint
1r 4t
high advisory

Antivirus Alert for Hacktools or Attack Tools

This brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.

antivirus hacktool post-exploitation detection incident-response malware
1r 1t
critical advisory

Detection of Advanced Persistent Threat (APT) Malware Signatures in Antivirus Logs

This brief details a detection rule for critical antivirus alerts that report Advanced Persistent Threat (APT) malware signatures, enabling detection engineers to identify and investigate sophisticated threats that have reached endpoints.

detection antivirus apt malware endpoint
1r 1t
high advisory

Windows Defender Disabled Via SystemSettingsAdminFlows.EXE

Threat actors are observed abusing the legitimate Windows utility `SystemSettingsAdminFlows.exe` to disable or modify Windows Defender settings, a defense impairment technique utilized in post-exploitation stages of campaigns, including ransomware.

Windows Defender defense-evasion lolbin windows ransomware
1r 1t
high advisory

Suspicious Legitimate Application Dropping Executable

This brief details a detection method for identifying malicious activity where legitimate Windows applications, including Living-Off-The-Land Binaries (LOLBINs) and common productivity software, are abused to drop executable files onto the disk, often indicating malware staging, persistence mechanisms, or process injection attempts.

living-off-the-land LOLBIN persistence malware-staging process-injection windows
1r 3t
medium advisory

New Agent Skills Installation Attempt Via Node.EXE

A new detection identifies the use of `npx skills add` commands via `node.exe` on Windows systems, a potentially abusable mechanism for attackers to install malicious AI agent skills or 'skill worms' that can execute arbitrary commands and infect infrastructure.

ai node.js supply-chain attack.execution attack.t1059.007
1r 1t
high threat

FortiGate VPN SSL Settings Modified

Detection of FortiGate VPN SSL settings modification, such as authentication rules, linked to observed exploitation campaigns (e.g., CVE-2024-535), which threat actors leverage for persistence and unauthorized access after initial compromise.

exploited FortiGate persistence initial-access network-device
1r 2t
medium advisory

FortiGate User Group Modification Detected

An attacker with initial access to a Fortinet FortiGate firewall may modify existing user groups to establish persistence or elevate privileges, potentially granting unauthorized VPN access to internal networks.

FortiGate fortinet firewall persistence privilege-escalation
1r 2t
medium advisory

FortiGate - New VPN SSL Web Portal Added

This brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.

FortiGate Firewall fortigate vpn configuration-change network-device persistence initial-access
1r 2t
medium advisory

FortiGate - New Local User Creation Detection

This brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.

FortiGate network detection persistence
1r 1t
medium advisory

FortiGate - New Firewall Policy Added

This brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.

FortiGate defense-impairment firewall network
1r 1t
medium advisory

Detection of FortiGate Firewall Address Object Addition

This brief details the detection of firewall address objects being added on Fortinet FortiGate devices, a configuration change that, while potentially legitimate, can also indicate post-compromise activity or unauthorized access, especially when tied to vulnerabilities like FG-IR-24-535, enabling threat actors to bypass security controls or facilitate command and control.

FortiGate network-device firewall defense-evasion
1r
medium advisory

FortiGate - New Administrator Account Created

This brief describes how to detect the creation of new administrator accounts on Fortinet FortiGate firewalls, a behavior often used by attackers for persistence (ATT&CK T1136.001) or to maintain unauthorized access after initial compromise.

FortiGate Firewall attack.persistence attack.t1136.001 network-device fortinet
1r 1t
medium advisory

Suspicious User-Agents Related To Recon Tools

This brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.

reconnaissance web-security attack.initial-access attack.t1190
1r 3t