Product
high
advisory
Detection of Attacker Tools on Endpoints
1 rule 3 TTPsThis analytic detects the execution of tools commonly used by attackers for activities such as unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, leveraging process activity data from Endpoint Detection and Response (EDR) agents to identify known attacker tool names.
Sysmon +6
attacker-tools
endpoint-detection
post-exploitation
EDR
windows
1r
3t
high
advisory
Cisco Security Updates — July 2026
5 CVEs 55 IOCsRoundup of Cisco security advisories published in July 2026.
PoC
Cisco devices +54
roundup
5c
55i
updated
high
advisory
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
PoC
PowerShell +511
roundup
11c
354i
updated
high
advisory
Detection of Attacker Tools on Endpoints
2 rules 3 TTPsThis analytic detects the execution of attacker tools used for unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, based on process activity data from EDR agents and focusing on known attacker tool names.
Splunk Enterprise +3
attacker-tool
endpoint
privilege-escalation
data-exfiltration
2r
3t