Product
high
advisory
Oracle Database SQL Injection Leads to OS-Level RCE and khunt Toolkit Deployment
3 TTPs 1 IOCA threat actor exploited SQL injection in a public-facing application to achieve OS-level remote code execution by abusing Oracle Java Source to deploy the custom 'khunt' post-exploitation toolkit.
Oracle Database
sqli
remote-code-execution
khunt
oracle
credential-theft
3t
1i
high
threat
The Gentlemen Ransomware Group Activity
1 rule 3 TTPsThe Gentlemen ransomware group leverages VPN/firewall exploits to gain initial access, utilizes BYOVD techniques to disable security tools, and propagates ransomware via the NETLOGON share.
FortiGate +5
The Gentlemen
1r
3t
medium
advisory
Suspicious LSASS Process Access
3 rules 1 TTPThis rule identifies suspicious access attempts to the LSASS process, potentially indicating credential dumping attempts by filtering out legitimate processes and access patterns to focus on anomalies.
Windows Defender +3
credential-access
lsass
windows
3r
1t