July 2026 (30)
Renamed Sysinternals Sdelete Utility Execution
1 rule 2 TTPsThe execution of a renamed Microsoft Sysinternals Sdelete utility is a highly suspicious technique often employed by adversaries to destroy data on Windows systems, leading to severe impact on system integrity and data availability.
Detecting Renamed ProcDump Execution for Evasion
1 rule 2 TTPsThis brief focuses on the detection of renamed Sysinternals ProcDump executables, a technique often employed by threat actors to evade security controls and perform credential dumping from LSASS memory on Windows systems, leading to potential lateral movement and privilege escalation.
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
1 rule 1 TTPThis brief details a defense evasion technique where attackers rename legitimate Windows system binaries to mask malicious activity, bypassing security solutions that rely on process names for detection.
Detecting Suspicious GrantedAccess Flags on LSASS
1 rule 2 TTPsThis brief details a detection for potentially suspicious `GrantedAccess` flags when a process attempts to access `LSASS.exe`, indicating possible credential dumping attempts by adversaries, which can lead to lateral movement and privilege escalation on Windows systems.
Potential Credential Dumping Activity via LSASS Process Access
1 rule 1 TTPAdversaries frequently target the Local Security Authority Subsystem Service (LSASS) process on Windows systems to dump credentials, employing tools like Mimikatz, NanoDump, or Procdump to extract sensitive authentication material for lateral movement and persistence.
HackTool - SysmonEnte Execution for Sysmon Evasion
1 ruleThis brief details the SysmonEnte hacktool, an open-source utility developed by codewhitesec, designed to attack the integrity of Microsoft Sysmon processes to impair endpoint detection and bypass security monitoring on Windows systems.
Suspicious CredUI.DLL Loading by Uncommon Processes
1 rule 1 TTPAttackers may attempt to load the Windows Credential UI DLL (credui.dll) from an unusual or non-standard process to capture or access user credentials, facilitating credential theft and further malicious activity on a compromised system.
Suspicious Process Monitor Driver Creation by Non-Sysinternals Binary
1 rule 2 TTPsThis brief details a detection strategy for malicious actors attempting to establish persistence or elevate privileges by creating a Process Monitor driver file (`.sys`) from an unauthorized process, indicating potential kernel-level compromise on Windows systems.
Malware Abusing Process Explorer Driver for Privilege Escalation
1 rule 4 TTPsMalware and hack tools are observed creating Sysinternals Process Explorer drivers via non-Sysinternals processes to elevate privileges and bypass security controls on Windows systems.
Suspicious PROCEXP152.sys Driver Creation in Temporary Folders
1 ruleThis brief details the suspicious creation of the PROCEXP152.sys driver file, associated with Sysinternals Process Explorer, in temporary application data folders, a technique leveraged by tools like KDU and Ghost-In-The-Logs for defense evasion and bypassing Windows Event Logging on affected Windows systems.
Potential Privileged System Service Operation - SeLoadDriverPrivilege
1 rule 2 TTPsThis brief details the detection of `SeLoadDriverPrivilege` usage on Windows systems, a critical privilege enabling attackers to load malicious kernel drivers for advanced defense evasion and privilege escalation, leading to full system compromise.
Legitimate Application Dropped Script Detection
1 rule 2 TTPsThis brief describes the detection of Living Off The Land Binaries (LOLBINs) and legitimate Windows applications being abused to drop various script files to disk, indicating malware staging or script-based code execution attempts.
Potentially Suspicious AccessMask Requested From LSASS
1 rule 1 TTPThis brief describes the detection of suspicious access mask requests to the Local Security Authority Subsystem Service (LSASS) process, a common post-exploitation technique used by threat actors for credential dumping on Windows systems.
Detection of Web Shell via Antivirus Signature
1 rule 1 TTPThis brief describes the detection of web shells by antivirus solutions, emphasizing the importance of investigating these alerts as they signify a compromised web server and potential post-exploitation activity by an attacker.
Detection of Malicious Remote Access Tools by Antivirus
1 rule 1 TTPThis brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.
Antivirus - Ransomware Signature Detection
1 rule 1 TTPThis brief describes a critical Sigma rule designed to detect highly relevant Antivirus alerts reporting known ransomware families, enabling detection engineers to ensure immediate investigation even when the malware has been blocked.
Antivirus Alert for Password Dumper and Stealer Activity
1 rule 4 TTPsThis brief details the detection of highly relevant antivirus alerts indicating the presence of password dumpers and stealers on endpoints, emphasizing the critical need for investigation even if the malware is blocked, to prevent credential compromise and subsequent attacks.
Antivirus Alert for Hacktools or Attack Tools
1 rule 1 TTPThis brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.
Detection of Advanced Persistent Threat (APT) Malware Signatures in Antivirus Logs
1 rule 1 TTPThis brief details a detection rule for critical antivirus alerts that report Advanced Persistent Threat (APT) malware signatures, enabling detection engineers to identify and investigate sophisticated threats that have reached endpoints.
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
1 rule 1 TTPThreat actors are observed abusing the legitimate Windows utility `SystemSettingsAdminFlows.exe` to disable or modify Windows Defender settings, a defense impairment technique utilized in post-exploitation stages of campaigns, including ransomware.
Suspicious Legitimate Application Dropping Executable
1 rule 3 TTPsThis brief details a detection method for identifying malicious activity where legitimate Windows applications, including Living-Off-The-Land Binaries (LOLBINs) and common productivity software, are abused to drop executable files onto the disk, often indicating malware staging, persistence mechanisms, or process injection attempts.
New Agent Skills Installation Attempt Via Node.EXE
1 rule 1 TTPA new detection identifies the use of `npx skills add` commands via `node.exe` on Windows systems, a potentially abusable mechanism for attackers to install malicious AI agent skills or 'skill worms' that can execute arbitrary commands and infect infrastructure.
FortiGate VPN SSL Settings Modified
1 rule 2 TTPsDetection of FortiGate VPN SSL settings modification, such as authentication rules, linked to observed exploitation campaigns (e.g., CVE-2024-535), which threat actors leverage for persistence and unauthorized access after initial compromise.
FortiGate User Group Modification Detected
1 rule 2 TTPsAn attacker with initial access to a Fortinet FortiGate firewall may modify existing user groups to establish persistence or elevate privileges, potentially granting unauthorized VPN access to internal networks.
FortiGate - New VPN SSL Web Portal Added
1 rule 2 TTPsThis brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.
FortiGate - New Local User Creation Detection
1 rule 1 TTPThis brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.
FortiGate - New Firewall Policy Added
1 rule 1 TTPThis brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.
Detection of FortiGate Firewall Address Object Addition
1 ruleThis brief details the detection of firewall address objects being added on Fortinet FortiGate devices, a configuration change that, while potentially legitimate, can also indicate post-compromise activity or unauthorized access, especially when tied to vulnerabilities like FG-IR-24-535, enabling threat actors to bypass security controls or facilitate command and control.
FortiGate - New Administrator Account Created
1 rule 1 TTPThis brief describes how to detect the creation of new administrator accounts on Fortinet FortiGate firewalls, a behavior often used by attackers for persistence (ATT&CK T1136.001) or to maintain unauthorized access after initial compromise.
Suspicious User-Agents Related To Recon Tools
1 rule 3 TTPsThis brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.