Product
high
advisory
Detection of Attacker Tools on Endpoints
1 rule 3 TTPsThis analytic detects the execution of tools commonly used by attackers for activities such as unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, leveraging process activity data from Endpoint Detection and Response (EDR) agents to identify known attacker tool names.
Sysmon +6
attacker-tools
endpoint-detection
post-exploitation
EDR
windows
1r
3t
high
advisory
Cisco Security Updates — July 2026
5 CVEs 55 IOCsRoundup of Cisco security advisories published in July 2026.
PoC
Cisco devices +54
roundup
5c
55i
updated
high
advisory
Detection of Attacker Tools on Endpoints
2 rules 3 TTPsThis analytic detects the execution of attacker tools used for unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, based on process activity data from EDR agents and focusing on known attacker tool names.
Splunk Enterprise +3
attacker-tool
endpoint
privilege-escalation
data-exfiltration
2r
3t