Skip to content
Threat Feed

Product

Splunk Enterprise Security

263 briefs RSS
high advisory

Windows AD Domain Root ACL Deletion

The analytic detects ACL deletion on the domain root object in Active Directory by monitoring Windows Event Log Security event ID 5136, identifying significant AD changes with potentially high impact.

Splunk Enterprise +3 active-directory acl privilege-escalation persistence windows
2r 2t
medium advisory

Detect Large ICMP Traffic

This analytic identifies ICMP traffic to external IP addresses with total bytes greater than 1,000 bytes, leveraging the Network_Traffic data model to detect potential information smuggling, covert communication, or command-and-control (C2) activities.

Palo Alto Network Traffic +4 network command-and-control icmp
2r 1t
high advisory

Windows SQL Server xp_cmdshell Configuration Change Detected

Detection of changes to the xp_cmdshell configuration in SQL Server, a feature often abused by attackers for privilege escalation and lateral movement by enabling execution of operating system commands.

SQL Server +3 sql_server xp_cmdshell privilege_escalation lateral_movement windows
2r 1t
high advisory

SQL Server Critical Procedures Enabled Leading to Potential Code Execution or Reconnaissance

Modification of critical SQL Server configuration options, such as 'Ad Hoc Distributed Queries', 'external scripts enabled', 'Ole Automation Procedures', 'clr enabled', and 'clr strict security', can enable attackers to perform Active Directory reconnaissance and execute arbitrary code, potentially leading to code execution or reconnaissance activities.

SQL Server +3 sql-server code-execution reconnaissance windows
2r 2t
medium threat

Windows Cabinet File Extraction via Expand.exe

Detection of expand.exe being used to extract Microsoft Cabinet (CAB) archives, specifically when extracting to C:\ProgramData or similar staging locations, potentially indicating ingress tool transfer and payload staging by threat actors like APT37.

Splunk Enterprise +2 APT37 cabinet_extraction expand.exe windows endpoint
2r 2t
high advisory

SLUI RunAs Elevated Privilege Escalation

Detection of the Microsoft Software Licensing User Interface Tool (`slui.exe`) being executed with elevated privileges using the `-verb runas` parameter, indicating a potential privilege escalation attempt.

Splunk Enterprise Security +2 privilege-escalation defense-evasion windows
2r 1t
medium advisory

ESXi External Root Login Detection

This detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user, which bypasses role-based access controls and may indicate risky behavior or unauthorized activity.

ESXi +3 vmware root_login privilege_escalation
2r 1t
high advisory

Windows AD CS ESC1 Certificate Authentication Abuse

This analytic detects the issuance of a suspicious certificate with a Subject Alternative Name (SAN) using Active Directory Certificate Services (AD CS) and its immediate use for authentication, indicating potential exploitation of improperly configured certificate templates for privilege escalation.

Active Directory Certificate Services +3 adcs certificate_abuse privilege_escalation windows
2r 2t
high advisory

Windows Privilege Escalation via Suspicious Process Elevation

This analytic detects when a process running with low or medium integrity spawns an elevated process with high or system integrity in suspicious locations, potentially indicating successful privilege escalation by a threat actor.

Splunk Enterprise +2 privilege-escalation windows
2r 3t
high advisory

Windows AD ServicePrincipalName Added To Domain Account

This Splunk analytic detects the addition of a Service Principal Name (SPN) to a domain account by monitoring Windows Event Code 5136 and changes to the servicePrincipalName attribute, potentially indicating Kerberoasting attempts leading to unauthorized access.

Splunk Enterprise +2 kerberoasting active_directory spn persistence
2r 1t
high advisory

Windows AD sIDHistory Attribute Modification Detection

This analytic detects changes to the sIDHistory attribute of user or computer objects within the same domain using Windows Security Event Codes 4738 and 4742, which can be abused by adversaries to gain unauthorized access, maintain persistence, or escalate privileges by inheriting permissions from another account.

Splunk Enterprise +2 sidhistory active-directory privilege-escalation persistence windows
2r 2t
medium advisory

Windows AD Object Owner Updated

This Splunk search detects when the owner of an Active Directory object is updated, potentially granting full control privileges and enabling object hiding, focusing on Windows Event Log ID 5136, and includes lookups for SID resolution.

Splunk Enterprise +3 active-directory privilege-escalation persistence
2r 2t
high advisory

Windows AD Hidden Organizational Unit Creation

This analytic detects when an ACL is applied to an organizational unit (OU) to deny listing the objects residing in it; this activity, combined with modifying the owner of the OU, can hide Active Directory objects, even from domain administrators.

Splunk Enterprise +2 active-directory persistence privilege-escalation windows t1222.001 t1484
2r 2t
high advisory

Windows AD Domain Root ACL Modification

Modification of Access Control Lists (ACLs) on the Active Directory domain root object can grant attackers persistent and escalated privileges.

Splunk Enterprise +3 active-directory persistence privilege-escalation
2r 2t
high advisory

Windows AD Domain Replication ACL Addition

This analytic detects the addition of permissions required for a DCSync attack, specifically DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set, leveraging Windows Security Event Log 5136 to identify when these permissions are granted, which indicates potential preparation for replicating AD objects and exfiltrating sensitive data.

Active Directory +3 attack.persistence attack.privilege_escalation attack.t1484 windows active-directory
2r 2t
high advisory

Windows AD DCShadow Privilege Escalation via ACL Modification

This detection identifies an Active Directory access-control list (ACL) modification event, which applies the minimum required extended rights to perform the DCShadow attack by modifying permissions on the domainDNS object.

Active Directory +3 dcshadow active_directory acl privilege_escalation persistence
2r 3t
high advisory

Active Directory User ACL Modification with Dangerous Permissions

Detection of Active Directory user object ACL modifications that grant dangerous permissions, such as full control or the ability to modify permissions, potentially indicating privilege escalation or malicious activity.

Active Directory +3 active-directory privilege-escalation acl windows
2r 2t
high advisory

Prohibited Network Traffic Allowed

This analytic detects instances where prohibited network traffic is allowed, highlighting potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration, ultimately allowing attackers to bypass network defenses.

Secure Firewall Threat Defense +3 network policy-violation firewall traffic-monitoring
2r 1t
medium advisory

Unauthorized Asset Detection via DHCP Request Analysis

This analytic identifies potentially unauthorized devices attempting to connect to an organization's network by inspecting DHCP request packets and comparing MAC addresses against a list of known authorized devices.

Splunk Enterprise +2 asset-tracking unauthorized-access network
2r 1t
high advisory

Azure AD User ImmutableId Attribute Modification for Persistence

The following analytic identifies modifications to the SourceAnchor (ImmutableId) attribute for an Azure Active Directory user, which is a step in setting up an Azure AD identity federation backdoor that allows an attacker to impersonate any user and bypass MFA.

Splunk Enterprise +3 azuread persistence identityfederation backdoor cloud
2r 1t
medium advisory

Monitor Email for Brand Abuse via Domain Permutations

This analytic identifies emails claiming to originate from domains similar to those being monitored for abuse by cross-referencing sender addresses with a lookup table of domain permutations, indicating potential phishing or brand impersonation.

Splunk Enterprise +2 brand-abuse email phishing impersonation
2r 1t
high advisory

Cisco Privileged Account Creation with Suspicious SSH Activity

This analytic detects a correlation between privileged account creation on Cisco IOS devices and subsequent inbound SSH connections to non-standard ports or sshd_operns, indicating persistence establishment following initial compromise.

IOS +4 network persistence initial-access
3r 2t
high advisory

Windows Post Exploitation Risk Behavior Detection

This analytic identifies potential post-exploitation behaviors on a Windows system by monitoring multiple risk events and their associated MITRE ATT&CK tactics, indicating potential malicious actions following an initial compromise.

Splunk Enterprise +2 post-exploitation windows splunk
2r 8t
medium advisory

Windows Registry Modification Risk Behavior Detection

This analytic identifies instances where three or more distinct registry modification events associated with MITRE ATT&CK Technique T1112 are detected, leveraging Splunk's Risk data model to detect persistence, hiding malicious configurations, or erasing forensic evidence.

Splunk Enterprise +2 registry persistence defense-evasion windows
2r 2t
high advisory

Steal or Forge Authentication Certificates Behavior Identified

The analytic identifies potential threats related to the theft or forgery of authentication certificates by detecting when five or more analytics from the Windows Certificate Services story trigger within a specified timeframe, indicating an ongoing attack aimed at compromising authentication mechanisms that could grant unauthorized access to sensitive systems and data.

Splunk Enterprise +2 credential-access t1649 endpoint
1r 1t
medium advisory

Living Off The Land Activity Detection

This correlation search identifies multiple risk events associated with 'Living Off The Land' activity, leveraging the Risk data model to aggregate events, focusing on systems with a high count of distinct sources, potentially enabling attackers to execute code, escalate privileges, or persist within the environment using trusted system utilities.

Splunk Enterprise +2 living-off-the-land persistence privilege-escalation execution
2r 5t
high advisory

Linux Persistence and Privilege Escalation Risk Behavior Detected

A Splunk correlation search identifies potential Linux persistence and privilege escalation activities based on risk scores and event counts from various Linux-related data sources, highlighting behaviors that could allow an attacker to maintain access or gain elevated privileges on a Linux system.

Splunk Enterprise +2 persistence privilege-escalation linux
2r 2t
high advisory

Active Directory Privilege Escalation Identified via Correlated Risk Events

This correlation analytic identifies potential privilege escalation activities within an organization's Active Directory (AD) environment by correlating multiple analytics from the Active Directory Privilege Escalation analytic story within a specified time frame, helping identify coordinated attempts to gain elevated privileges which could lead to unauthorized access to sensitive systems and data.

Splunk Enterprise +2 active-directory privilege-escalation
2r 1t
high advisory

Active Directory Lateral Movement Identified via Splunk Correlation

This correlation identifies potential lateral movement activities within an Active Directory environment by correlating multiple analytics from the Active Directory Lateral Movement analytic story within a specified time frame, potentially leading to privilege escalation, access to sensitive information, and persistence within the environment.

Splunk Enterprise +2 lateral-movement threat-detection active-directory
2r 1t
high advisory

High-Risk Repository Activity in DevSecOps Environments

This analytic identifies high-risk activities within repositories by correlating repository data with risk scores in DevSecOps environments, focusing on scores above 100 and sources with more than three occurrences to highlight potential vulnerabilities leading to data breaches or infrastructure compromise.

Splunk Enterprise +3 devsecops risk-analysis splunk
2r 1t
high advisory

AWS S3 Exfiltration Behavior Identified

This analytic identifies potential AWS S3 exfiltration behavior by correlating multiple risk events related to Collection and Exfiltration techniques, leveraging AWS sources and focusing on instances where multiple unique analytics and distinct MITRE ATT&CK IDs are triggered for a specific risk object.

S3 +3 cloud exfiltration aws
2r 1t
high advisory

Okta User Risk Threshold Exceeded via Aggregated Suspicious Activities

This correlation identifies when a user exceeds a risk threshold based on multiple suspicious Okta activities by aggregating risk events from 'Suspicious Okta Activity,' 'Okta Account Takeover,' and 'Okta MFA Exhaustion' analytic stories, highlighting potentially compromised user accounts exhibiting multiple TTPs that could lead to unauthorized access, privilege escalation, or persistence.

Okta +3 account-takeover risk-framework
2r 2t
medium advisory

Monitor Web Traffic For Brand Abuse

This analytic identifies web requests to domains that closely resemble a monitored brand's domain, indicating potential brand abuse indicative of phishing or malware distribution attempts.

Splunk Enterprise +2 brand-abuse phishing network
2r 1t
high advisory

O365 BEC Email Hiding Rule Creation

This analytic detects the creation of suspicious mailbox rules in Office 365, a common technique used in Business Email Compromise (BEC) to hide emails by identifying rules with short or nonsensical names, marking emails as read, or moving them to specific folders.

Office 365 +4 bec o365 email mailboxrule splunk threat-hunting
2r 1t
medium threat

Cisco Secure Firewall - High Volume of Intrusion Events Per Host

This analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window using Cisco Secure Firewall Threat Defense logs, identifying hosts triggering more than 15 Snort-based signatures, which may indicate suspicious activity like malware execution, command-and-control communication, vulnerability scanning, or lateral movement.

exploited Secure Firewall Threat Defense +3 network intrusion_detection anomaly_detection
2r 3t
high advisory

Windows EFI Bootloader File Modification Detection

A process writing to critical EFI bootloader files (bootmgfw.efi or bootx64.efi) within the \EFI\Boot\ directory may indicate a bootkit installation, malicious code persistence at the firmware level, or tampering with the system boot process.

Splunk Enterprise +2 bootkit persistence efi bootloader windows
2r 1t 1c
high advisory

Windows MSI Rollback Script Deletion by Non-Msiexec Process

Detection of a rollback script (.rbs) file deletion under C:\Config.Msi by a non-msiexec.exe process, indicating a potential MSI rollback privilege escalation attack.

Splunk Enterprise +2 privilege-escalation rollback windows
2r 2t 1c
high advisory

Crowdstrike RTR Script Execution via PowerShell

Detection of PowerShell execution initiated via Crowdstrike Real Time Response (RTR) 'runscript' command, potentially indicating malicious actors leveraging compromised Crowdstrike Dashboard access to execute commands on remote hosts using encoded commands.

Splunk Enterprise +3 living-off-the-land rtr script-execution
2r 1t
high advisory

Detecting Windows Remote Image Loading for Malicious Activities

This analytic detects instances where a process loads a file from a remote share path, potentially indicating execution, defense evasion, or lateral movement by attackers loading code from attacker-controlled infrastructure.

Windows +3 remote-image-load defense-evasion lateral-movement sysmon
2r 5t
medium advisory

GitHub Enterprise Audit Log Streaming Paused

Detection of a user pausing audit log event streaming in GitHub Enterprise, potentially indicating an attempt to evade detection by disabling the audit trail.

GitHub Enterprise +3 github audit-log defense-evasion
2r 2t
medium advisory

IIS HTTP Logging Disabled via AppCmd.exe

Detection of adversaries disabling HTTP logging on IIS servers using AppCmd.exe, potentially evading detection by removing evidence of their actions.

IIS +3 httplogging appcmd defense-evasion persistence windows
2r 2t
high advisory

Suspicious MSBuild Spawned by WMI Provider Process

The analytic identifies instances where wmiprvse.exe spawns msbuild.exe, an unusual process relationship indicative of potential COM object misuse and unauthorized code execution on Windows systems.

Splunk Enterprise +3 living-off-the-land defense-evasion msbuild
2r 1t
high advisory

PowerShell P/Invoke Process Injection API Chain Detection

This analytic detects PowerShell code that uses P/Invoke to call Windows API functions associated with process injection, such as VirtualAlloc, WriteProcessMemory, and CreateRemoteThread, indicating potential malicious activity.

PowerShell +3 process-injection pinvoke defense-evasion
2r 8t
high advisory

Detection of Event Log Disabling via WevtUtil

Detection of the 'wevtutil.exe' command-line utility being used to disable event logs, a common tactic employed by ransomware actors to evade detection and hinder forensic analysis on compromised Windows systems.

Splunk Enterprise +2 defense-evasion ransomware windows wevtutil
2r 1t
high threat

Detect PowerShell AppLocker Policy Import Activity

Detection of PowerShell commands to import AppLocker policy via Import-Module Applocker and Set-AppLockerPolicy, potentially used to enforce restrictive policies or disable security products like antivirus.

Splunk Enterprise +2 Azorult applocker powershell defense-evasion endpoint
2r 1t
medium advisory

Cisco ASA Logging Message Suppression

Detection of 'no logging message' command usage on Cisco ASA devices, potentially indicating an adversary suppressing security-critical log events to evade detection.

ASA +3 defense-evasion impair-defenses network
2r 1t
high advisory

Detection of Windows Defender Service Disabling via Registry Modification

This brief covers the detection of adversaries disabling Windows Defender services by modifying specific registry keys to set the 'Start' value to '0x00000004', indicating an attempt to evade detection and maintain persistence.

Windows Defender +3 defense-evasion persistence windows registry-abuse
2r
high advisory

Windows Defender SpyNet Reporting Disabled via Registry Modification

Attackers disable Windows Defender SpyNet reporting by modifying specific registry keys, preventing telemetry data from being sent and allowing malicious activities to go undetected.

Splunk Enterprise +3 windows registry_modification defender_evasion
2r
high advisory

Windows Registry Modification to Disable Show Hidden Files

This analytic detects modifications to the Windows registry that disable the display of hidden files, a technique commonly used by malware to evade detection and conceal malicious activities.

Splunk Enterprise +2 defense-evasion registry-modification windows
2r 2t
high advisory

Windows Registry Modification to Disable Registry Tools

This analytic detects modifications to the Windows registry, specifically targeting the 'DisableRegistryTools' key, which is a common tactic used by malware for persistence and defense evasion by preventing the removal of malicious entries.

Windows +3 defense-evasion registry-modification persistence
2r 2t
high advisory

O365 Advanced Audit Disabled

Detection of O365 advanced audit being disabled for a specific user, potentially allowing attackers to operate with reduced risk of detection, leading to unauthorized data access, data exfiltration, or account compromise.

Office 365 +3 cloud o365 audit defense-evasion persistence
2r 1t
medium advisory

Windows Downdate Attack Registry Modification

The Windows Downdate attack involves modifying specific registry keys to force a Windows downgrade, enabling exploitation of older, vulnerable versions, which this detection identifies through monitoring for the creation or modification of the pending.xml file in unusual locations.

Splunk Enterprise +2 defense-evasion privilege-escalation windows registry-modification
2r 1t
high advisory

Suspicious PowerShell Script Using Cryptography Namespace

The analytic detects suspicious PowerShell script execution involving the cryptography namespace (excluding SHA and MD5) via EventCode 4104, often associated with malware that decrypts or decodes additional malicious payloads leading to further code execution, privilege escalation, or persistence.

Splunk Enterprise +2 powershell cryptography malware asyncrat xworm vip keylogger
2r 1t
medium advisory

Suspicious PowerShell TabExpansion Direct Call

This detection identifies PowerShell scripts that directly call the TabExpansion internal function, which is uncommon and may indicate malicious activity, such as TabShell, potentially bypassing sandboxes by loading PowerShell functions via directory traversal.

Splunk Enterprise +2 powershell tabexpansion bypass endpoint
2r 2t
high advisory

Non-Firefox Process Accessing Firefox Profile Directory

This analytic detects non-Firefox processes accessing the Firefox profile directory, potentially indicating malware attempting to harvest sensitive user data like login credentials, browsing history, and cookies.

Firefox +3 credential-access malware
2r 1t
medium advisory

Windows Time-Based Evasion via Choice Exec

Detection of choice.exe used in batch files for time-based evasion, a technique observed in SnakeKeylogger malware, indicating potential stealthy code execution and persistence.

Windows +3 time-based-evasion malware persistence defense-evasion
2r 1t
medium threat

Windows Theme File Creation in Unusual Location

Detects the creation of Windows theme files in unusual locations, such as Desktop, Documents, Downloads, or Temp directories, which can be indicative of remote code execution or NTLM coercion attacks.

exploited Splunk Enterprise +2 windows theme-file code-execution credential-theft
2r 3t
high advisory

Windows Shell Execution from IIS Installation Directory

Detection of command-line tools executing from the IIS installation directory on Windows systems, potentially indicating exploitation of IIS-reliant software like Microsoft Exchange.

Exchange Server +3 iis web-shell command-execution windows
2r 2t
high advisory

Windows Service Security Descriptor Tampering via sc.exe

Adversaries may modify service security descriptors to deny access to specific groups, potentially escalating privileges and hindering security services, by using sc.exe to set new deny ACEs (Access Control Entries) on Windows services.

Splunk Enterprise +2 defense-evasion privilege-escalation windows
2r 2t
medium advisory

Windows Folder Options Disabled via Registry Modification

Attackers modify the Windows registry to disable the Folder Options feature, preventing users from showing hidden files and file extensions, commonly used by malware to conceal malicious files and deceive users with fake file extensions.

Splunk Enterprise +3 defense-evasion registry-modification windows
2r
high advisory

Windows EFI Volume Mount Attempt via Mountvol

Detection of attempts to mount the EFI volume on Windows systems using mountvol.exe, potentially leading to system compromise.

Splunk Enterprise +2 efi mountvol windows persistence defense-evasion
2r 3t
high advisory

Windows Defender Real-Time Behavior Monitoring Disabled via Registry Modification

Attackers modify Windows Registry keys associated with Windows Defender to disable real-time behavior monitoring, a common tactic used by malware to evade detection and persist on compromised systems.

Windows Defender +3 defense-evasion endpoint registry-modification
2r
high advisory

Windows Computer Account Changed to Domain Controller

Detects modifications to a Windows computer account's User Account Control flags, specifically the `SERVER_TRUST_ACCOUNT` flag, potentially indicating unauthorized domain controller promotion or privilege escalation within Active Directory.

Splunk Enterprise +3 active-directory privilege-escalation persistence windows
2r 2t
high advisory

Windows Binary Execution from Archive-Related Paths

Detects the execution of a binary from archive-related paths within a user's Temp directory, potentially indicating attempts to bypass Mark-of-the-Web (MOTW) or exploit vulnerabilities like CVE-2025-0411.

Splunk Enterprise +2 binary-execution archive-bypass motw-bypass
2r 1t 1c
high advisory

Windows Audit Policy Restored via Auditpol.exe

Attackers may use auditpol.exe with the /restore argument to replace the existing audit policy with a malicious one, disabling auditing to evade detection, potentially leading to full machine compromise or lateral movement.

Splunk Enterprise +2 auditpol audit-policy defense-evasion windows
2r 1t
high advisory

Suspicious MSIExec Remote Download

The analytic detects the execution of msiexec.exe with an HTTP or HTTPS URL, which indicates an attempt to download and execute potentially malicious software from a remote server, leading to potential unauthorized code execution, system compromise, or malware deployment.

Splunk Enterprise +3 endpoint msiexec remote-download windows
2r 2t
high advisory

Suspicious Child Processes Spawned by WScript or CScript

Detects suspicious processes spawned by WScript or CScript, a common technique used by adversaries to execute LOLBINs, PowerShell, or inject code into suspended processes for defense evasion.

Splunk Enterprise +2 wscript cscript lolbin malware defense-evasion
2r 3t
medium advisory

Detect Windows Entra User Management Via Azure CLI

This analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.

Azure CLI +3 azure entra-id user-management persistence windows
2r 3t
medium advisory

Attrib.exe Used to Hide Files and Directories

Detection of attrib.exe being used with the +h flag to hide files and directories on Windows systems, a technique used by attackers for defense evasion and persistence.

Splunk Enterprise +2 defense-evasion persistence windows
2r 1t
high advisory

Windows Eventlog Cleared Via Wevtutil

Adversaries may clear Windows event logs using `wevtutil.exe` to remove evidence of their activity and hinder forensic investigations.

Splunk Enterprise +2 defense-evasion windows event-logs
2r 1t
high advisory

Windows Defender Controlled Folder Access Disabled via Registry Modification

An attacker modifies the Windows registry to disable Windows Defender Controlled Folder Access, a defense evasion technique that weakens protections against unauthorized access and ransomware.

Splunk Enterprise +3 defense-evasion registry-modification windows-defender
2r 1t
medium advisory

MSIExec Spawning Discovery Commands

Detection of msiexec.exe spawning discovery commands indicating potential reconnaissance activity by attackers for system information gathering and lateral movement.

Splunk Enterprise +2 msiexec discovery windows
2r 1t
high advisory

Suspicious PowerShell Command Removing Windows Defender Directory

A PowerShell command attempting to remove the Windows Defender directory is detected via PowerShell Script Block Logging, potentially indicating an attacker's attempt to disable endpoint protection for further malicious activities.

Windows Defender +3 powershell defense-evasion windows-defender endpoint
2r 1t
high advisory

Windows DISM Used to Remove Windows Defender

The analytic detects the use of `dism.exe` to remove Windows Defender, potentially allowing adversaries to evade detection and carry out further malicious actions.

Windows Defender +3 defense-evasion endpoint windows
2r 1t
high threat

Suspicious Process Accessing Browser Password Store

Detection of non-browser processes accessing browser user data folders, a tactic used by malware such as Snake Keylogger to steal credentials and sensitive information.

Splunk Enterprise +2 Snake Keylogger credential-access stealer windows
2r 1t
high advisory

ETW Registry Disabled via Registry Modification

Attackers may disable Event Tracing for Windows (ETW) for the .NET Framework by modifying the ETWEnabled registry value, allowing them to evade endpoint detection and response (EDR) tools and hide malicious activity.

.NETFramework +3 etw registry defense-evasion windows t1127 t1685
2r 1t
medium advisory

WinPEAS PowerShell Script Execution Detection

This brief documents the detection of the WinPEAS PowerShell script execution on Windows systems, a tool commonly used for identifying privilege escalation paths by identifying specific function names used within the script.

Splunk Enterprise +2 privilege-escalation post-exploitation windows
2r 8t
medium advisory

Windows Software Discovery via PowerShell Registry Queries

Attackers use PowerShell to query the Windows registry's Uninstall key to discover installed software and identify potential vulnerabilities for exploitation.

Splunk Enterprise +2 software-discovery powershell registry reconnaissance
2r 3t
high advisory

Windows Service Disabled Detection

Detection of a Windows service being disabled via Event ID 7040, a common tactic used by adversaries to evade defenses and maintain control over compromised systems.

Splunk Enterprise +2 defense-evasion service-disabled windows
2r 1t
high advisory

Windows Remote Desktop Network Bruteforce Attempt

This detection identifies potential RDP brute force attacks by monitoring network traffic for RDP application activity by detecting source IPs that have made more than 10 connection attempts to the same RDP port on a host within a one-hour window.

Secure Access Firewall +3 rdp bruteforce credential-access windows network
2r 1t
high advisory

Windows Registry Modification to Disable Task Manager

Attackers modify the Windows registry to disable Task Manager, preventing users from terminating malicious processes and allowing persistence.

Splunk Enterprise +3 defense-evasion privilege-escalation registry-modification
2r
high advisory

Windows Registry Deletion of Scheduled Task Security Descriptor

Attackers may delete a scheduled task's Security Descriptor (SD) from the registry to remove evidence of the task for defense evasion.

Splunk Enterprise +2 defense-evasion persistence windows
2r 1t
high advisory

Windows PowerShell Used to Disable HTTP Logging

Adversaries may use PowerShell with specific commands to disable HTTP logging on Windows systems to evade detection and hinder forensic investigations.

Splunk Enterprise +2 powershell defense-evasion iis
2r 1t
high advisory

Windows Potato Privilege Escalation Tool Execution

Detects the execution of known Potato-family privilege escalation tools on Windows systems, which are used to escalate privileges from restricted contexts to SYSTEM by exploiting Windows token impersonation and privilege abuse.

Splunk Enterprise +2 privilege-escalation windows
2r 1t
medium advisory

Windows Netsh Tool Used for Firewall Discovery

The analytic detects the execution of the Windows built-in tool netsh.exe to display the state, configuration, and profile of the host firewall, potentially leading to unauthorized network access or data exfiltration.

Splunk Enterprise +2 discovery windows netsh firewall
2r 1t
medium advisory

Windows Guest Account Enabled via net.exe

The Windows guest account, typically restricted, can be enabled via `net.exe` for malicious activities like malware installation or data theft, potentially indicating persistence, defense evasion, privilege escalation or initial access.

Splunk Enterprise +2 guest-account persistence windows
2r 1t
medium advisory

Windows Firewall Rule Modification Detection

This detection identifies instances where a Windows Firewall rule has been modified, potentially indicating an attempt to weaken security policies and allow malicious traffic or prevent legitimate communications.

Windows +3 firewall anomaly
2r
medium advisory

Windows Firewall Rule Deletion Detection

Detection of Windows Firewall rule deletion events (Event ID 4948) indicating potential attacker attempts to bypass security controls or malware disabling protections for persistence and command-and-control.

Windows +3 firewall endpoint
2r 1t
medium advisory

Windows Firewall Rule Added via Event ID 4946

This detection identifies instances where a Windows Firewall rule is added by monitoring Event ID 4946 in the Windows Security Event Log, potentially indicating unauthorized changes or malicious activity such as attackers allowing traffic for backdoors or persistence mechanisms.

Splunk Enterprise +2 firewall persistence windows
2r
high advisory

Windows Firewall Modification with Suspicious Process Path

This analytic detects suspicious modifications to system firewall rules to allow execution of applications from notable and potentially malicious file paths, indicating an attempt to bypass firewall restrictions for malicious code execution.

Splunk Enterprise +2 firewall defense-evasion windows
2r
high advisory

Windows Files and Dirs Access Rights Modification via Icacls

Detection of icacls.exe, cacls.exe, or xcacls.exe being used to modify file or directory permissions, often used by APTs and coinminers for defense evasion and persistence.

Splunk Enterprise +2 defense-evasion persistence windows access-control
2r 1t
high advisory

Windows EventLog Security Descriptor Tampering

This analytic detects suspicious modifications to the EventLog security descriptor registry value, specifically the 'CustomSD' value, within the registry path 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\<Channel>\CustomSD', which can be used for defense evasion by attackers.

Sysmon +3 defense-evasion eventlog registry tampering
2r 1t
high advisory

Windows Event Logging Service Shutdown Detection

Detection of the Windows Event Log service shutdown, indicated by Event ID 1100, which can signify attempts to evade detection by disabling logging.

Splunk Enterprise +3 defense-evasion windows event-logging
2r 1t
high advisory

Windows Defender Web Content Evaluation Disabled via Registry Modification

An attacker modifies the Windows registry to disable Windows Defender web content evaluation, potentially allowing malicious web content to bypass security checks and compromise the system.

Windows Defender +3 defense-evasion registry-modification windows
2r
medium advisory

Windows Defender Tracing Level Modification

The following analytic detects modifications to the Windows registry specifically targeting the 'WppTracingLevel' setting within Windows Defender, potentially impairing its diagnostic capabilities and allowing attackers to evade detection.

Windows Defender +3 defense-evasion registry-modification windows
2r
medium advisory

Windows Defender Throttle Rate Modification

An attacker modifies the Windows Defender ThrottleDetectionEventsRate registry setting to reduce the frequency of logged detection events, potentially evading detection.

Splunk Enterprise +2 windows defender registry defense-evasion
2r 1t
high advisory

Windows Defender Threat Action Modification via Registry

An attacker modifies the Windows Defender ThreatSeverityDefaultAction registry setting to weaken defenses, potentially leading to unaddressed threats and system compromise.

Windows Defender +3 windows endpoint registry defense-evasion
2r
high advisory

Windows Defender SmartScreen Prompt Override via Registry Modification

Attackers modify the Windows registry to disable SmartScreen prompt overrides, potentially allowing users to bypass security warnings and execute harmful content, leading to system compromise.

Edge +3 defense-evasion registry-modification smartscreen
2r
high advisory

Windows Defender SmartScreen App Install Control Disabled via Registry Modification

Attackers modify the Windows Registry to disable Windows Defender SmartScreen App Install Control, potentially allowing the installation of malicious web-based applications without restrictions, leading to system compromise and sensitive information exposure.

Splunk Enterprise +3 defense-evasion registry-abuse windows
2r
medium advisory

Windows Defender Signature Retirement Disabled via Registry Modification

An attacker disables Windows Defender's signature retirement feature by modifying a registry key, potentially reducing its effectiveness in detecting threats by allowing older, less relevant signatures to persist.

Windows Defender +3 defense-evasion windows-registry windows-defender
2r 1t
medium advisory

Windows Defender Scan On Update Disabled via Registry Modification

An attacker modifies the Windows registry to disable the Windows Defender Scan On Update feature, potentially evading detection and establishing persistence.

Windows Defender +3 defense-evasion registry-modification windows-defender
2r 1t
high advisory

Windows Defender Real-time Signature Delivery Disabled via Registry Modification

The following analytic detects modifications to the Windows registry that disable the Windows Defender real-time signature delivery feature, preventing timely malware definition updates and potentially leading to system compromise.

Splunk Enterprise +3 defense-evasion windows-defender registry-modification endpoint
2r 1t
high advisory

Windows Defender Protocol Recognition Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender protocol recognition, hindering its ability to detect and respond to malware, potentially leading to successful data exfiltration or system compromise.

Windows Defender +3 defense-evasion windows registry-modification
2r 1t
high advisory

Windows Defender Profile Registry Key Deletion

Detection of Windows Defender profile registry key deletion, indicating potential defense evasion by malware or threat actors aiming to disable security controls.

Windows Defender +3 defense-evasion registry-abuse windows
2r 1t
high advisory

Windows Defender Phishing Filter Override via Registry Modification

The analytic detects modifications to the Windows registry that disable the Windows Defender phishing filter, potentially allowing attackers to deceive users into visiting malicious websites without browser warnings.

Microsoft Edge +3 defense-evasion windows registry-abuse
2r 1t
high advisory

Windows Defender Logging Disabled via Registry Modification

Attackers may disable Windows Defender logging by modifying specific registry keys to evade detection and conceal malicious activities.

Windows Defender +3 defense-evasion registry-modification windows
2r 1t
high advisory

Windows Defender Infection Reporting Disabled via Registry Modification

Attackers modify the Windows registry to disable Windows Defender's infection reporting, preventing detailed threat information from reaching Microsoft and potentially allowing malware to evade detection.

Windows Defender +3 defense-evasion registry-modification windows
2r
high advisory

Windows Defender File Hash Computation Disabled via Registry Modification

Attackers may disable Windows Defender's ability to compute file hashes by modifying the EnableFileHashComputation registry value, impairing its malware detection capabilities.

Windows Defender +3 defense-evasion registry-modification windows-defender
2r 1t
high advisory

Windows Defender Exclusion Registry Modification

Adversaries modify Windows Defender exclusion registry entries to bypass antivirus and execute malicious code undetected, potentially leading to persistence and further malicious activities.

Windows Defender +3 windows endpoint registry defender exclusion defense-evasion malware
2r 1t
high advisory

Windows Defender Exclusion Added or Modified via Command Line

Adversaries use Add-MpPreference or Set-MpPreference commands to add exclusions in Windows Defender, allowing malicious code to execute undetected, and this activity can be detected via Endpoint Detection and Response (EDR) agents.

Windows Defender +3 windowsdefender exclusion defense-evasion endpoint
2r
high advisory

Windows Defender Enhanced Notification Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender's Enhanced Notification feature, preventing users from receiving security alerts and potentially allowing malicious activities to go unnoticed, ultimately enabling persistence and evasion.

Windows Defender +3 registry-modification windows-defender persistence evasion
2r 1t
high threat

Windows Defender Disabled via Registry Modification

An attacker modifies the Windows Registry key 'DisableAntiSpyware' to disable Windows Defender, a technique commonly associated with Ryuk ransomware to evade defenses.

Windows Defender +3 Ryuk defense-evasion registry-modification ransomware windows
2r 1t
high threat

Windows Defender BlockAtFirstSeen Feature Disabled via Registry Modification

An attacker modifies the Windows Registry to disable the Windows Defender BlockAtFirstSeen feature, potentially allowing malware to bypass initial detection and increasing the risk of system compromise.

exploited Windows Defender +3 registry_modification defender blockatfirstseen
2r
high advisory

Windows Defender ASR or Threat Configuration Tampering

Adversaries tamper with Windows Defender's Attack Surface Reduction (ASR) rules or threat default actions using Add-MpPreference or Set-MpPreference commands, aiming to bypass the security tool for undetected malicious code execution.

Windows Defender +3 defense-evasion windows-defender endpoint
2r 1t
high advisory

Windows Defender Application Guard Auditing Disabled via Registry Modification

Attackers modify the Windows Registry to disable auditing for Windows Defender Application Guard, hindering security monitoring and enabling malicious activity to go unnoticed.

Windows Defender +3 defense-evasion registry-modification windows
2r 1t
high advisory

Windows Defender Antivirus Disabled via Registry Modification

Attackers modify Windows Defender registry settings to disable antivirus and antispyware protections, evading detection and maintaining persistence.

Windows Defender +3 defense-evasion registry-modification antivirus
2r 1t
high advisory

Windows Control Panel Disabled via Registry Modification

This analytic detects registry modifications that disable the Control Panel on Windows systems by monitoring changes to the registry path '*\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel' with a value of '0x00000001', which is commonly used by malware to prevent users from accessing the Control Panel and hindering remediation efforts.

Splunk Enterprise +2 defense-evasion registry-modification windows
2r 2t
high advisory

Windows AutoLogger Session Disabled via Registry Modification

An attacker disables Windows AutoLogger sessions by modifying specific registry values to evade defenses and blind EDR and log ingest tools.

Splunk Enterprise +3 defense-evasion windows registry-abuse
2r 1t
medium advisory

Windows Auditpol ResourceSACL Clearing for Defense Evasion

Adversaries may clear the global object access auditing policy using `auditpol.exe` with the `/resourceSACL` flag and either `/clear` or `/remove` arguments to evade detection by removing audit configurations.

Splunk Enterprise +3 defense-evasion windows
2r
high advisory

Windows Audit Policy Exclusion via Auditpol

Adversaries may attempt to disable or modify security tools to evade detection; this analytic identifies the execution of `auditpol.exe` with the `/set` and `/exclude` command-line arguments to exclude specific users' events from audit logs, potentially evading detection and enabling further malicious activities.

Splunk Enterprise +2 defense-evasion endpoint windows
2r 1t
high advisory

Windows Audit Policy Disabled via Legacy Auditpol

Adversaries may disable Windows audit policies using the legacy auditpol.exe utility to evade detection by limiting the data available for security monitoring and incident response.

Windows +3 auditpol defense-evasion
2r 1t
high advisory

Windows Audit Policy Disabled

Detection of disabled important audit policies via Windows EventCode 4719, indicating potential attacker attempts to evade detection on a compromised domain controller, leading to data theft, privilege escalation, and network compromise.

Splunk Enterprise +2 audit-policy defense-evasion windows
3r
high threat

Windows Audit Policy Cleared via Auditpol

The execution of `auditpol.exe` with the `/clear` or `/remove` command-line arguments indicates potential defense evasion by adversaries or Red Teams, aiming to limit data that can be leveraged for detections and audits, potentially leading to full machine compromise or lateral movement.

Windows +3 defense-evasion audit-tampering
2r 1t
medium advisory

Windows Application Hotkey Disablement via Registry Modification

Attackers disable Windows application hotkeys by modifying specific registry entries to hinder incident response and evade detection.

Splunk Enterprise +2 registry-modification defense-evasion persistence hotkey-disablement
2r 1t
high advisory

Windows AppCertDLL Registry Modification via Command Line

Attackers modify the AppCertDLL registry key via command-line utilities to load malicious DLLs during system startup, achieving persistence and privilege escalation.

Splunk Enterprise +2 persistence privilege-escalation windows
2r 2t
medium advisory

Windows AD GPO Disabled

Detection of Active Directory Group Policy being disabled using the Group Policy Management Console, potentially indicating malicious attempts to weaken security controls.

Splunk Enterprise +3 active_directory group_policy persistence
3r 1t
high advisory

Windows AD Domain Controller Audit Policy Disabled

Detection of disabled audit policies on a Windows domain controller by monitoring Windows Security Event Logs for EventCode 4719, indicative of an attacker attempting to evade detection and potentially leading to data theft, privilege escalation, and full network compromise.

Windows Event Log Security +3 defense-evasion windows
2r 1t
high advisory

Windows .Key File Creation in Root Directory

This search detects the creation of a .key file in the root directory of the system drive, an activity associated with ransomware execution before file encryption.

Splunk Enterprise +2 ransomware file_creation windows
2r 1t
high advisory

Unexpected Linux Auditd Daemon Shutdown

This analytic detects unexpected shutdowns of the Linux auditd daemon, potentially indicating attempts to disable security monitoring and evade detection by attackers.

Splunk Enterprise +3 auditd linux defense-evasion endpoint
3r 1t
high advisory

Unauthorized Access to Chrome Local State File

Detection of non-Chrome processes accessing the Chrome 'Local State' file, potentially leading to extraction of the master key used for decrypting saved passwords.

Chrome +3 credential-access password-stealing
2r 1t
high threat

Suspicious WMIC Application Uninstallation

This analytic identifies the use of the WMIC command-line tool to uninstall applications non-interactively, a technique used to evade detection by removing security software, as observed in IcedID campaigns.

Splunk Enterprise +2 IcedID defense-evasion application-uninstall wmic
2r
high advisory

Suspicious Process Terminating LSASS Process

Detection of a process attempting to terminate the Lsass.exe process, indicating a potential attempt to perform credential dumping, privilege escalation, or evasion of security policies.

Splunk Enterprise +2 lsass process-termination windows
2r
high advisory

Suspicious Process Execution from Unusual File Paths

Attackers may execute malicious code from unusual file paths such as Windows fonts or debug directories to evade defenses and gain unauthorized access, as detected by endpoint detection and response (EDR) agents.

Splunk Enterprise +2 defense-evasion persistence windows
2r 2t
medium advisory

Suspicious PowerShell Module DLL Creation

The creation of a DLL file within PowerShell module directories can indicate malicious PowerShell activity, such as installing new modules or attempts at ScriptBlock smuggling, and this activity is detected using Sysmon Event ID 11.

Splunk Enterprise +2 powershell module dll filecreation scriptblocksmuggling
2r 3t
high advisory

Suspicious MSBuild Execution from Non-Standard Path

Detection of msbuild.exe execution from a non-standard path, indicating potential attempts to evade detection and execute malicious code.

Splunk Enterprise +2 msbuild lolbas living-off-the-land defense-evasion
3r 2t
medium advisory

Suspicious Microsoft Workflow Compiler Usage

The use of Microsoft Workflow Compiler (microsoft.workflow.compiler.exe), a rarely utilized executable typically found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319, can indicate malicious intent such as code execution or persistence mechanisms, potentially leading to unauthorized access.

Splunk Enterprise +2 living-off-the-land proxy-execution endpoint
2r 1t
high advisory

Suspicious Microsoft Workflow Compiler Rename

Detection of the renaming of microsoft.workflow.compiler.exe, a technique used by attackers to evade security controls and potentially execute arbitrary code for privilege escalation or persistence.

Splunk Enterprise +3 lolbin defense-evasion living-off-the-land masquerading
3r 2t
high advisory

Suspicious Firewall Modification to Allow Network Discovery

Detection of 'netsh' command execution to enable network discovery in the firewall, a technique commonly used by ransomware such as REvil and RedDot to discover and compromise additional machines on the network.

Splunk Enterprise +3 ransomware lateral-movement windows
2r
high advisory

Suspicious AppLocker XML Policy Import via PowerShell

Detection of PowerShell commands used to import AppLocker XML policies, potentially indicating an attempt to bypass security controls, as observed with Azorult malware.

Splunk Enterprise +2 applocker defense-evasion powershell
2r
medium advisory

Schtasks Run Task On Demand

Detection of on-demand execution of Windows Scheduled Tasks via the schtasks.exe command-line utility, a common technique for persistence and lateral movement.

Splunk Enterprise +2 schtasks scheduled-task persistence execution
2r 1t
high threat

Scheduled Task Disablement via Schtasks.exe

Detection of the use of schtasks.exe to disable scheduled tasks, a common tactic used by adversaries like IcedID to disable security applications and evade detection, potentially leading to persistence and further system compromise.

Splunk Enterprise +2 IcedID persistence defense_evasion windows
2r
medium advisory

Scheduled Task Creation via Group Policy Object

Detects the creation of scheduled tasks within a Group Policy Object (GPO) by monitoring for the creation of the ScheduledTasks.xml file in the SYSVOL share, potentially indicating malicious persistence.

Splunk Enterprise +3 scheduled-task gpo persistence windows
2r 2t
high threat

Regsvr32 Silent and Install Parameter DLL Loading

Detection of regsvr32.exe being used with the silent and DLL install parameter to load a DLL, a technique used by RATs like Remcos and njRAT to execute arbitrary code.

Splunk Enterprise +2 Remcos +1 lolbin dll-loading regsvr32
2r 2t
high advisory

Raccine Scheduled Task Deletion via Schtasks

Detection of adversaries deleting the Raccine Rules Updater scheduled task via `schtasks.exe` to disable the ransomware protection tool, potentially leading to data encryption and loss.

Splunk Enterprise +2 raccine ransomware defense-evasion scheduled-task windows
2r
medium advisory

Potential Cloudflared Network Tunnel Detection

This brief detects network connection events associated with the Cloudflared tool, used to create tunnels via Cloudflare, potentially for unauthorized access or exfiltration, by establishing outbound connections to Cloudflare Edge Servers.

Cloudflared +3 reverse-proxy tunneling network-tunnel
2r 1t
high advisory

Potential Abuse of Cloudflare Tunnels via Cloudflared

Attackers are increasingly abusing Cloudflare tunnels, created via the cloudflared client, for establishing stealthy command and control channels and evading network defenses by proxying traffic through Cloudflare's infrastructure.

Cloudflared +3 cloudflare reverse-proxy tunnel command-and-control
2r 2t
high advisory

Outlook Dialogs Disabled by Unusual Process

The detection identifies the modification of the Windows Registry key 'PONT_STRING' under Outlook Options by a process other than Outlook.exe, potentially indicating malware activity such as NotDoor.

Outlook +3 registry_modification malware notdoor
2r 1t
high advisory

Outbound SMB Traffic Detection

This analytic detects outbound SMB connections from internal hosts to external servers, potentially indicating lateral movement and credential theft attempts.

Secure Firewall Threat Defense +4 network smb lateral-movement privilege-escalation
2r 1t
medium advisory

OneDrive Share Mounted via Net Utility for Potential Data Exfiltration

Adversaries may mount OneDrive shares as network drives using net.exe or net1.exe to stage, access, or exfiltrate data through cloud-hosted WebDAV paths, potentially bypassing traditional file share monitoring.

OneDrive +3 data-exfiltration net.exe
2r 1t
high advisory

O365 Security Feature Modification

Attackers modify or disable Office 365 advanced security settings, such as AntiPhish, SafeLink, SafeAttachment, or Malware policies, to evade detection and operate with reduced risk within the target tenant.

Office 365 +3 o365 email_security defense_evasion persistence
2r 1t
high advisory

O365 MFA Bypassed via Trusted IP Addition

An attacker modifies trusted IP settings in Office 365 to bypass multi-factor authentication (MFA), potentially leading to unauthorized access and data compromise.

Office 365 +3 mfa_bypass o365 defense_evasion
2r 1t
high advisory

NorthStar C2 Agent Execution Detection

This brief details detection strategies for NorthStar C2 agent execution on Windows endpoints, an open-source command and control framework used for penetration testing and red teaming.

Splunk Enterprise +2 command-and-control red-teaming penetration-testing windows
2r 3t 2i
high advisory

Non-Chrome Process Accessing Chrome Login Data

This analytic identifies non-Chrome processes accessing the Chrome user data file 'login data', which is an SQLite database containing sensitive information like saved passwords, potentially leading to credential theft.

Chrome +3 credential-access password-stealing windows
2r 1t
high advisory

Network Connections from Processes in Suspicious Windows Directories

Detection of network connections originating from processes running within suspicious Windows directories, indicating potential malware execution and command-and-control activity.

Splunk Enterprise +2 network_connection windows suspicious_location
2r 1t
medium threat

Mustang Panda USB-Borne Tool Execution

This brief details detection of executables associated with Mustang Panda being launched from non-standard locations, potentially indicating compromise via USB or other removable media.

Splunk Enterprise +2 Mustang Panda mustang-panda usb-attack dll-sideloading
2r 3t
high threat

MuddyWater PowGoop Beacon Decoding Detection

This detection identifies a DLL decoding and executing the PowGoop config.txt payload, indicating a stage in the MuddyWater infection chain where an obfuscated PowerShell beacon is unwrapped and live C2 communication starts.

Splunk Enterprise +3 MuddyWater powgoop dll-sideloading powershell c2 beacon
2r 4t
high advisory

MSBuild Executed by Scripting Host

Detects the suspicious spawning of MSBuild.exe by Windows Script Host processes (cscript.exe or wscript.exe), a behavior often associated with malware executing malicious MSBuild processes via scripts.

Splunk Enterprise +2 msbuild scripting defense-evasion endpoint
2r 1t
high advisory

MpCmdRun Execution with RemoveDefinitions Argument

The execution of MpCmdRun.exe with the '-RemoveDefinitions' argument, used to remove definitions from the Windows Malware Protection Engine, can indicate potential malware activity or attempts to bypass security measures.

Windows Malware Protection Engine +3 defense-evasion endpoint mpcmdrun malware
2r
medium advisory

Microsoft 365 Risk-Based Step-Up Consent Disabled

The Microsoft 365 'risk-based step-up consent' security setting is disabled by an adversary to allow users to grant consent to malicious applications, potentially leading to unauthorized access and data breaches.

Splunk Enterprise +4 azuread o365 oauth risk-based consent defense-evasion
2r 1t
critical advisory

Metasploit Exploitation via Malicious Confluence Plugin

A Metasploit module exploits Atlassian Confluence servers by deploying a malicious Java plugin that downloads Meterpreter, granting the attacker full control over the compromised system.

Confluence Data Center +4 confluence metasploit meterpreter plugin exploitation attack
2r 3t
high advisory

Linux Defense Impairment via Process Termination

Detection of 'pkill' command execution on Linux systems, a technique used by threat actors to disable security defenses or terminate critical processes, potentially leading to data corruption or destruction.

Splunk Enterprise +2 defense-evasion process-termination linux
2r
medium advisory

Linux Auditd Daemon Abort Detection

Detection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.

Splunk Enterprise +3 auditd linux anomaly endpoint
2r 1t
medium advisory

IOBit Unlocker Extension DLL Registration via Regsvr32

The IOBit Unlocker Extension DLL is being registered via regsvr32.exe, a Windows utility used to unlock files or folders by terminating locking processes, which could be abused for malicious purposes.

Unlocker Extension +3 iobit unlocker regsvr32 dll windows threat-detection
2r 1t
high advisory

Hiding User Account from Sign-In Screen via Registry Modification

An attacker modifies the Windows registry to hide a user account from the login screen, potentially establishing a hidden admin account for persistence and evading detection.

Splunk Enterprise +2 persistence defense-evasion windows
2r
medium advisory

GitHub Organizations Branch Ruleset Deletion

Detection of GitHub Organizations branch ruleset deletions, which could indicate attempts to bypass code review requirements and introduce unauthorized code changes.

github.com +4 github supply-chain branch-protection
2r 2t
medium advisory

GitHub Organizations 2FA Disabled

The disabling of two-factor authentication (2FA) in GitHub Organizations is detected through audit log monitoring, potentially indicating an attacker's attempt to weaken account security and facilitate unauthorized access.

github.com +3 github 2fa security_controls supply_chain
3r 3t
medium advisory

GitHub Enterprise IP Allow List Disabled

An IP allow list was disabled in GitHub Enterprise, potentially allowing unauthorized access from untrusted networks and exposing sensitive code repositories.

GitHub Enterprise +3 github cloud ip-allow-list bypass security-control anomaly
2r 1t
high advisory

GitHub Enterprise Audit Log Event Stream Modification

An attacker modifies or disables audit log event streaming in GitHub Enterprise to evade detection by preventing security monitoring platforms from receiving audit events.

Splunk Enterprise +3 github audit-log defense-evasion supply-chain
2r 1t
high advisory

GitHub Enterprise 2FA Requirement Disabled

The disabling of two-factor authentication (2FA) in GitHub Enterprise, detected via audit logs, weakens account security and increases the risk of account takeover and supply chain compromise.

GitHub Enterprise +3 github 2fa defense-evasion
2r 1t
medium advisory

GitHub Dependabot Disabling Detection

A user disables Dependabot security features within a GitHub repository, potentially enabling attackers to exploit unpatched vulnerabilities in dependencies.

Splunk Enterprise +3 github supply-chain dependabot
2r 2t
medium advisory

GitHub Classic Branch Protection Rule Disabled

This analytic detects when classic branch protection rules are disabled in GitHub Organizations, potentially allowing malicious actors to bypass code review and security controls.

github.com +4 github branch-protection supply-chain
2r 2t
high advisory

Get-Variable.exe Hijacking for Persistence

Attackers can establish persistence by placing a malicious Get-Variable.exe in the WindowsApps folder, hijacking the legitimate PowerShell cmdlet and executing upon PowerShell window initialization, as seen with the Colibri malware.

Splunk Enterprise +2 persistence powershell windowsapps colibri
2r 1t
medium threat

Flax Typhoon Masquerading SoftEther VPN as Legitimate Windows Binaries

The Flax Typhoon group uses SoftEther VPN, masquerading the VPN client as legitimate Windows binaries like conhost.exe and dllhost.exe, to obfuscate their network activity within compromised Taiwanese organizations.

SoftEther VPN +3 Flax Typhoon +1 flax-typhoon defense-evasion lateral-movement vpn process-masquerading
2r 2t
high advisory

Firewall Modification for File and Printer Sharing

This analytic detects the modification of Windows Firewall settings to enable file and printer sharing, a common technique used by ransomware to facilitate lateral movement and broader network encryption.

Splunk Enterprise +3 ransomware lateral-movement windows
2r 1t
high advisory

Firewall Allowed Program Enable

Detection of firewall rule modification to allow specific application execution, potentially bypassing restrictions and enabling unauthorized network communication.

Splunk Enterprise +2 firewall defense-evasion windows
3r
high advisory

Execution of SymbolicLink-Testing-Tools Utility for Privilege Escalation

The execution of utilities from the `symboliclink-testing-tools` toolkit is detected, which can be used by attackers to exploit Windows symbolic link vulnerabilities to achieve local privilege escalation from a standard user to SYSTEM.

Splunk Enterprise +2 privilege-escalation symbolic-link windows
2r 2t
high advisory

Excessive Windows Service Disabling Events

An adversary may disable critical Windows services to evade defenses or disrupt system operations, detected by monitoring for an excessive number of service-disabled events on a single host.

Splunk Enterprise +2 defense-evasion service-disabling windows
2r 1t
high advisory

Excessive Taskkill Usage for Defense Evasion

Adversaries use taskkill.exe to disable security tools, and this detection identifies instances where taskkill.exe is executed excessively within a short timeframe, indicative of malicious activity aimed at defense evasion.

Splunk Enterprise +2 defense-evasion process-termination windows
2r 1t
high advisory

Excessive Service Control Start as Disabled

Detection of an excessive number of `sc.exe` processes launched with the `start= disabled` argument indicating potential attempts to disable critical services and impair system defenses.

Splunk Enterprise +2 defense-evasion windows
2r 1t
high advisory

ESXi VIB Acceptance Level Tampering Detection

This detection identifies changes to the VIB (vSphere Installation Bundle) acceptance level on an ESXi host, potentially allowing the installation of unsigned or unverified software and lowering the system's integrity enforcement.

ESXi +3 vmware vib tampering post-compromise ransomware
2r
high advisory

ESXi Syslog Configuration Changes via esxcli

Detection of ESXi syslog configuration changes via esxcli command, potentially indicating an attempt to disrupt logging and evade detection.

ESXi +3 syslog vmware defense-evasion t1562.003 t1690 black-basta
2r 1t
high advisory

ESXi Firewall Disabled Detection

This detection identifies when the ESXi firewall is disabled or set to permissive mode, potentially exposing the host to unauthorized access and network-based attacks, often preceding lateral movement, data exfiltration, or malware installation.

ESXi +3 firewall lateral_movement data_exfiltration ransomware attack.defense_evasion
2r
high advisory

ESXi Encryption Settings Modification

Detection of modifications to ESXi host encryption settings, such as disabling secure boot or executable verification, which may indicate attempts to weaken hypervisor integrity and allow unauthorized code execution.

ESXi +3 encryption vmware hypervisor attack.persistence
2r
medium advisory

ESXi Download Error Detection

Detection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.

ESXi +3 vmware syslog anomaly T1601.001 T1685 ESXi Post Compromise Black Basta Ransomware Infrastructure +1
2r 2t
high advisory

ESXi Audit Tampering Detection

Detection identifies the use of the esxcli system auditrecords commands to tamper with logging on an ESXi host, potentially evading detection and hindering forensic analysis.

ESXi +3 vmware audit-tampering defense-evasion
2r 1t
high advisory

Detects Windows XLL File Creation Outside of Typical Location

The creation of an XLL file outside of typical locations can indicate an attempt to abuse Excel COM objects to load and execute a malicious XLL payload, often used in spearphishing attacks to achieve remote code execution.

Excel +3 xll file_creation endpoint
2r 2t
high threat

Detection of Suspicious Cisco Configuration Changes via Archive Logging

This analytic detects suspicious configuration changes on Cisco devices by analyzing archive logs for activities such as backdoor account creation, SNMP community string modifications, and TFTP server configurations, potentially indicating attacker presence and lateral movement.

IOS +3 Static Tundra cisco network-security configuration-change
3r 2t 1c
medium advisory

Detection of PuTTY Suite Utility Execution

This analytic detects the execution of programs associated with the PuTTY SSH client suite, including putty.exe, pscp.exe, plink.exe, psftp.exe, and puttygen.exe, which can be used to establish unauthorized remote connections, transfer files, or execute commands on remote systems potentially leading to network compromise.

Splunk Enterprise +2 putty lateral-movement command-and-control windows
3r 2t
high threat

Detection of Processes Launching netsh.exe for Malicious Purposes

Detection of netsh.exe execution by unusual processes indicative of potential malicious activity, including persistence and network configuration changes by threat actors.

exploited Splunk Enterprise +3 netsh living-off-the-land persistence network-configuration
2r
high advisory

Detection of Process Termination via File Path Using WMIC

This analytic detects the use of `wmic.exe` with the `delete` command to terminate a process by specifying its executable path, often used to disable security tools or critical processes during the setup of malicious activities like cryptocurrency mining.

Splunk Enterprise +2 process-termination wmic cryptocurrency-mining endpoint
2r
high advisory

Detection of ETW Disabling via Registry Modification

Attackers may disable Event Tracing for Windows (ETW) by modifying specific registry keys to evade detection and hinder security monitoring, potentially leading to further system compromise.

.NETFramework +3 defense-evasion registry-modification etw ransomware windows
2r
high advisory

Detection of Default Cobalt Strike PowerShell Beacon

This brief outlines detection strategies for default Cobalt Strike PowerShell beacons, which are used for command and control, by identifying specific function and variable names within PowerShell script block logs.

Splunk Enterprise +2 cobaltstrike powershell beacon commandandcontrol windows
2r 2t
high advisory

Detection of Attacker Tools on Endpoints

This analytic detects the execution of attacker tools used for unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, based on process activity data from EDR agents and focusing on known attacker tool names.

Splunk Enterprise +3 attacker-tool endpoint privilege-escalation data-exfiltration
2r 3t
high advisory

Detecting Windows LAPS Password Gathering via PowerShell

This brief outlines detection strategies for adversaries attempting to retrieve LAPS passwords using PowerShell and the 'ms-Mcs-AdmPwd' property, potentially leading to lateral movement and privilege escalation within a Windows domain.

Splunk Enterprise +3 laps credential-access powershell windows
2r 2t
medium advisory

Detecting Spikes in Active Directory Object Modifications

This detection identifies a spike in Active Directory group or object modifications, potentially indicating unauthorized access, defense impairment, or persistence establishment by threat actors.

Splunk Enterprise +2 active-directory persistence privilege-escalation windows
2r 1t
high advisory

Detecting Disabling of Windows Defender Sample Submission

An attacker modifies the Windows registry to disable the Windows Defender Submit Samples Consent feature, preventing the submission of suspicious files for analysis, and potentially evading detection.

Splunk Enterprise +3 defense-evasion registry-modification windows-defender
2r
medium advisory

Detect Windows Netspy Network Scanner Execution

The Netspy network scanner, a tool for internal network discovery, is executed on a Windows endpoint to enumerate active hosts and services, potentially for reconnaissance purposes.

Splunk Enterprise +2 network-discovery windows endpoint
2r 2t
high advisory

Detect Windows Downdate Registry Activity

This detection identifies registry modifications associated with the Windows Downdate attack, specifically focusing on pending.xml file modifications outside standard locations, which could force a Windows downgrade for exploitation.

Splunk Enterprise +2 windows-downgrade registry-modification defense-evasion persistence
2r 2t
high advisory

Cobalt Strike PowerShell Loader Detection

This brief details a detection for a PowerShell loader pattern commonly used with Cobalt Strike to decompress and execute payloads, often observed in scripted web delivery attacks.

Splunk Enterprise +2 cobaltstrike powershell malware windows
2r 2t
high advisory

Cisco Secure Endpoint Uninstallation via SFC Utility

The sfc.exe utility is used with the "-u" parameter to uninstall Cisco Secure Endpoint components, potentially disabling endpoint protection and facilitating further exploitation.

Secure Endpoint +3 security-solution-tampering endpoint windows
2r
high advisory

Cisco Secure Endpoint Tampering via SFC Utility

The sfc.exe utility is being used with the '-unblock' parameter, a feature within Cisco Secure Endpoint, to remove system blocks imposed by the endpoint protection, potentially indicating an attempt to bypass security measures and execute blocked malicious payloads.

Secure Endpoint +3 defense-evasion endpoint cisco
2r
medium advisory

Cisco ASA Logging Filters Configuration Tampering

Tampering with logging filter configurations on Cisco ASA devices can allow attackers to evade detection by reducing logging levels or disabling specific log categories.

ASA +3 cisco logging evasion
2r 1t
high advisory

AWS Security Services Configuration Deletion

Detection of deletion of critical AWS Security Services configurations like CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules to evade detection, potentially leading to data breaches and unauthorized access.

CloudWatch +5 aws cloudtrail defense-evasion security-service
2r 1t
high advisory

AWS Network ACL Deletion Detected

Detection of AWS Network Access Control List (ACL) deletion via CloudTrail logs indicating potential unauthorized access or data exfiltration.

AWS CloudTrail +3 cloud aws network-acl privilege-escalation
2r
high advisory

AWS CloudWatch Log Group Deletion for Defense Evasion

Detection of AWS CloudWatch log group deletions via CloudTrail logs, excluding console-based actions, indicating potential defense evasion by attackers attempting to hide their tracks.

Splunk Enterprise +3 aws cloudwatch defense-evasion
2r 1t
medium advisory

AWS CloudTrail Update for Defense Evasion

Attackers may attempt to evade detection by altering CloudTrail logging configurations, such as changing multi-regional logging to a single region, which impairs the logging of their activities and hinders incident response.

CloudTrail +4 aws defense-evasion cloud
2r 1t
high advisory

AWS CloudTrail Logging Stopped for Defense Evasion

Detection of AWS CloudTrail `StopLogging` events indicating potential defense evasion by adversaries attempting to operate undetected within a compromised AWS environment by halting the logging of their malicious activities.

CloudTrail +4 aws defense-evasion cloud
2r 1t 1i
high advisory

AWS CloudTrail Logging Stopped for Defense Evasion

Detection of AWS CloudTrail StopLogging events indicates a potential defense evasion attempt by an attacker to operate stealthily within a compromised AWS environment and hinder incident response.

Splunk Enterprise +3 aws cloudtrail defense-evasion aws-account
2r 1t
high advisory

AWS CloudTrail Logging Evasion via UpdateTrail

Attackers modify AWS CloudTrail settings using UpdateTrail events to evade detection by disabling or limiting logging, as indicated by non-console user agents.

AWS CloudTrail +3 aws cloudtrail defense-evasion logging
2r 1t
high advisory

AWS Bedrock Model Invocation Logging Deletion Attempt

Detection of attempts to delete AWS Bedrock model invocation logging configurations, potentially indicating an adversary trying to remove audit trails of model interactions after credential compromise, to hide malicious AI model usage.

CloudTrail +3 aws bedrock logging defense-evasion
2r 1t
high advisory

AppLocker Registry Modification to Deny Security Software Execution

Attackers can modify the Windows registry via AppLocker to block the execution of security software, potentially disabling defenses and allowing further malicious activities.

Splunk Enterprise +2 applocker defense-evasion registry-modification
2r
high advisory

AMSI Disablement via Registry Modification

Attackers disable the Antimalware Scan Interface (AMSI) by modifying the Windows registry value 'AmsiEnable' to '0x00000000' to evade detection, commonly employed by ransomware, RATs, and APTs.

Windows +3 amsi defense-evasion registry-modification ransomware
2r
high advisory

AMSI Bypass via PowerShell Reflection

Detection of AMSI (Antimalware Scan Interface) tampering via PowerShell reflection, utilizing PowerShell Script Block Logging (EventCode=4104) to identify commands manipulating `system.management.automation.amsi`, potentially leading to undetected malicious code execution and system compromise.

Splunk Enterprise +2 amsi-bypass powershell reflection defense-evasion
2r 1t
medium advisory

Active Directory Group Policy Deletion Detected

Detection of Active Directory Group Policy deletion using event ID 5136, indicating potential malicious activity or misconfiguration.

Splunk Enterprise +2 active-directory group-policy gpo deletion t1484.001
2r 2t
high advisory

Abuse of dnscmd.exe to Modify DNS ServerLevelPluginDLL

Attackers can use dnscmd.exe with administrative privileges to configure the Microsoft DNS ServerLevelPluginDll setting, allowing them to load arbitrary DLLs and execute code within the DNS service context for persistence and privilege escalation.

Splunk Enterprise +3 persistence privilege-escalation windows
2r 1t
medium advisory

Windows Universal Data Link File Creation Detection

The creation of Universal Data Link (UDL) files on Windows systems can indicate a phishing technique where attackers bypass email filters and capture user credentials by tricking victims into testing a connection to a malicious server.

Splunk Enterprise +2 phishing credential-theft windows
2r 2t
high advisory

Windows File Association Modification via Ftype Command

Adversaries can use the `ftype` command to modify Windows file associations, potentially redirecting legitimate file execution to malicious payloads for persistence, execution, and defense evasion.

Splunk Enterprise +2 file-association persistence execution windows
2r 3t
high advisory

Windows Event Log Cleared

Detection of cleared Windows event logs (Security Event ID 1102 or System log event 104) indicates potential defense evasion and obfuscation by threat actors attempting to remove evidence of their activities.

Splunk Enterprise +2 defense-evasion impact windows
2r 1t
high advisory

Windows Defender Health Check Interval Modification

This analytic detects modifications to the Windows registry, specifically targeting the `ServiceKeepAlive` value, to impair Windows Defender's ability to perform timely health checks, potentially leading to a vulnerable system state.

Splunk Enterprise +3 windows registry defender defense-evasion threat
2r
high advisory

Suspicious QEMU Execution on Windows

Detects the execution of QEMU with the -nographic flag and an image file on Windows systems, a technique used for persistence and initial access by installing a rogue Linux virtual machine.

Splunk Enterprise +3 qemu virtualization persistence linux windows
2r 2t
high advisory

Suspicious DNS Queries to Telegram API by Non-Telegram Processes

Detection of a process making DNS queries to the Telegram API domain, which is indicative of malware utilizing Telegram bots for command and control (C2) communications.

Splunk Enterprise +2 telegram command-and-control dns windows
2r 2t 1i
medium advisory

Spike in Active Directory User Modification Activity

Detects an increase in modifications to AD user objects, which may indicate unauthorized access, impaired defenses, or persistence establishment.

Splunk Enterprise +2 account-manipulation persistence windows
2r 1t
high advisory

PowerShell Execution via Environment Variables

Adversaries use PowerShell to execute malicious code stored in environment variables, leveraging Invoke-Expression or its aliases to bypass static analysis and execute payloads dynamically, as seen in malware loaders and stagers like the VIP Keylogger.

Splunk Enterprise +2 powershell environment-variable invoke-expression execution
2r 1t
high threat

Non-Chrome Process Accessing Chrome Default Directory

Detection of non-Chrome processes accessing the Chrome user data directory, potentially indicating credential theft or data exfiltration attempts by malware such as RATs or APT groups.

Splunk Enterprise +2 FIN7 +2 credential-access threat-type windows
2r 1t
high advisory

Microsoft Devtunnels Execution for Covert Communication

The execution of Microsoft devtunnels.exe can be abused by attackers to expose compromised systems to the internet, establish covert communication channels, and bypass network security measures, facilitating data exfiltration or command-and-control.

Visual Studio +3 devtunnels reverse-proxy command-and-control defense-evasion windows
2r 1t
high advisory

Logon Script Registry Modification for Persistence and Privilege Escalation

This brief details the detection of UserInitMprLogonScript registry entry modifications, a technique employed by threat actors for persistence and privilege escalation by ensuring payloads execute automatically at system startup.

Splunk Enterprise +2 persistence privilege-escalation windows
2r 2t
medium advisory

Linux Stdout Redirection to /dev/null Indicates Potential Malware Activity

The redirection of standard output to /dev/null on Linux systems, particularly when observed in conjunction with other suspicious activities, can indicate attempts to hide malicious command execution, as seen in malware like Cyclops Blink, potentially leading to unauthorized system modifications and persistent access.

Splunk Enterprise +2 linux malware cyclopsblink anomaly endpoint
2r
high advisory

Linux Auditd Detects Firewall Modification or Disabling

The analytic detects suspicious disabling or modification of the system firewall on Linux systems, which can indicate unauthorized access or attempts to maintain control over a system by disabling host protections.

Splunk Enterprise +3 defense-evasion persistence privilege-escalation firewall
3r 1t
high advisory

Disabling CMD Application via Registry Modification

Attackers modify the Windows registry to disable the command prompt (cmd.exe), hindering incident response and potentially maintaining persistence.

Splunk Enterprise +2 registry-modification defense-evasion windows
2r 1t
high threat

Detection of Taskkill Command to Terminate Browser Processes

This analytic detects the use of the taskkill command to terminate known browser processes, a technique employed by malware such as Braodo stealer to steal credentials by forcefully closing browsers like Chrome, Edge, and Firefox to unlock files containing sensitive information.

Splunk Enterprise +2 Braodo Stealer credential-theft malware windows
2r
high threat

Braodo Stealer Screen Capture in TEMP Directory

This analytic detects the creation of screen capture files in the TEMP directory, specifically targeting activity associated with the Braodo stealer malware, which captures screenshots of the victim's desktop as part of its data theft activities.

Splunk Enterprise +2 Braodo Stealer stealc-stealer crypto-stealer braodo-stealer apt37 hellcat-ransomware vip-keylogger screen-capture malware
2r 1t
high advisory

AWS S3 Bucket Lifecycle Rule Abuse for Log Deletion

Attackers may abuse the AWS S3 PutBucketLifecycle API to rapidly delete CloudTrail logs by setting short expiration periods on S3 buckets, hindering incident response and forensic investigations.

CloudTrail +3 aws defense-evasion
2r 1t
high advisory

AWS Network ACL Created with All Ports Open

The analytic detects the creation or replacement of AWS Network Access Control Lists (ACLs) with rules that allow all traffic from a specified CIDR block, potentially exposing the network to unauthorized access and increasing the risk of data breaches.

CloudTrail +5 aws network-acl misconfiguration cloud security-group
2r
high advisory

AWS CloudTrail Log Deletion for Defense Evasion

An adversary may delete AWS CloudTrail logs to evade detection and operate stealthily within a compromised environment, using the `DeleteTrail` event while excluding actions from the AWS console.

AWS CloudTrail +3 aws cloudtrail defense-evasion
2r 1t
high advisory

Windows Taskkill Used for Defense Evasion

The analytic identifies the use of taskkill.exe to forcibly terminate processes, focusing on command-line executions that include specific taskkill parameters, which can indicate attempts to disable security tools or disrupt legitimate applications.

Splunk Enterprise +2 defense-evasion endpoint taskkill
3r
medium advisory

Windows Registry Modification to Disable Run Application

The following analytic detects modification of the Windows registry to disable the Run application in the Start menu by monitoring changes to the registry path '*\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun' with a value of '0x00000001', potentially hindering system cleaning and aiding malware persistence.

Splunk Enterprise +2 defense-evasion registry-modification windows
2r 1t
high advisory

Windows HVCI Disabled via Registry Modification

Detection of Hypervisor-protected Code Integrity (HVCI) being disabled by modifying specific Windows registry keys, potentially allowing the execution of malicious kernel-mode code.

Splunk Enterprise +2 defense-evasion registry-modification windows
2r 1t 1c
medium advisory

Windows Defender SmartScreen Level Downgrade to 'Warn'

This analytic detects modifications to the Windows Registry to set Windows Defender SmartScreen level to 'Warn', which can reduce user suspicion and increase the risk of malware execution.

Splunk Enterprise +3 defense-evasion registry-modification windows
2r 1t
medium advisory

Windows Defender Quick Scan Interval Modification

Detection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.

Splunk Enterprise +3 defense-evasion windows-registry windows-defender endpoint
2r 1t
medium advisory

Windows Defender PUA Protection Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender Potentially Unwanted Application (PUA) protection, increasing the risk of malware installation and system compromise.

Windows Defender +3 defense-evasion windows registry-modification
2r
high advisory

Windows Defender Firewall and Network Protection Disabled via Registry Modification

An attacker modifies the Windows registry to disable the Windows Defender Firewall and Network Protection settings, potentially weakening the system's security posture and increasing vulnerability to further attacks.

Windows Defender Security Center +3 defense-evasion registry-modification windows
2r 1t
medium advisory

Windows Command Obfuscation via Environment Variable Substrings

Attackers obfuscate commands in Windows by dynamically constructing them using substrings extracted from environment variables, a technique observed in malware families such as Cobalt Strike and Meterpreter.

Splunk Enterprise +2 command-obfuscation defense-evasion windows
2r 1t
high threat

Windows Audit Policy Security Descriptor Tampering via Auditpol

Detection of `auditpol.exe` execution with arguments to modify the audit policy security descriptor, indicative of defense evasion by adversaries aiming to limit audit logging.

Splunk Enterprise +2 auditpol security descriptor defense evasion windows
2r 1t
high advisory

Sysmon Driver Unload via fltMC.exe

Detection of the Sysmon filter driver being unloaded via `fltMC.exe`, which can blind security monitoring and allow malicious actions to go undetected.

Splunk Enterprise +3 defense-evasion impair-defenses windows
2r 1t
high advisory

Suspicious Wevtutil Usage for Clearing Windows Event Logs

Detection of wevtutil.exe being used with parameters to clear event logs, indicating potential attempts to evade detection and hinder forensic investigations by adversaries.

Splunk Enterprise +2 defense-evasion windows log-manipulation
2r
high advisory

Suspicious PowerShell Reconnaissance via WMI Queries

Detection of suspicious PowerShell activity using Windows Management Instrumentation (WMI) to gather system information, indicative of reconnaissance efforts by adversaries potentially leading to further exploitation or lateral movement.

Splunk Enterprise +2 powershell wmi reconnaissance lateral_movement windows
2r 2t
high advisory

Suspicious MSBuild Rename

The analytic detects the execution of renamed instances of msbuild.exe, a legitimate tool abused by attackers to execute malicious code while evading detection, potentially leading to system compromise, data exfiltration, or lateral movement.

Splunk Enterprise +2 lolbin msbuild defense-evasion windows
2r 2t
high advisory

Registry Modification to Disable .NET ETW Logging

Attackers may modify the Windows registry to disable ETW logging for the .NET Framework, hindering endpoint detection and response capabilities.

Splunk Enterprise +2 defense-evasion registry-modification etw
2r 1t
high advisory

PowerShell Windows Defender Exclusion Commands

Detection of PowerShell commands, specifically `Add-MpPreference` or `Set-MpPreference`, used to create Windows Defender exclusions, enabling attackers to bypass antivirus defenses and execute malicious code undetected.

Windows Defender +3 defense-evasion powershell windows-defender
2r 1t
medium advisory

Microsoft Devtunnels Image Load Detection

This detection identifies potential misuse of Microsoft Devtunnels within Visual Studio by detecting image load events, indicating that an attacker could expose a compromised system or service to the internet for covert communication and data exfiltration.

Visual Studio +3 devtunnels reverse-proxy command-and-control data-exfiltration windows
2r 2t
high advisory

Malicious MSC File Creation in Mock Trusted Directory

The creation of MSC files within a 'C:\Windows \System32' directory can be exploited to execute malicious files due to path parsing vulnerabilities in Windows, potentially leading to privilege escalation, persistence, and defense evasion.

Splunk Enterprise +2 defense-evasion privilege-escalation persistence windows
2r 3t
medium advisory

Linux Auditd Daemon (Re)Initialization Detection

Detection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.

Splunk Enterprise +4 linux auditd anomaly
3r 1t
medium advisory

GitHub Enterprise Classic Branch Protection Rule Disabled

Detection of disabled classic branch protection rules in GitHub Enterprise, indicating potential bypass of code review and security controls, leading to unauthorized code changes and supply chain compromise.

GitHub Enterprise +4 github branch_protection supply_chain
3r 2t
high advisory

ESXi Loghost Configuration Tampering

An attacker modifies the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response.

ESXi +3 syslog loghost tampering defense-evasion
2r 1t
high advisory

ESXi Lockdown Mode Disabled

The disabling of Lockdown Mode on an ESXi host may indicate a threat actor attempting to weaken host security controls to enable broader remote access for data exfiltration, lateral movement, or VM tampering.

ESXi +3 vmware lockdown_mode security_controls
2r
medium advisory

Detection of Level RMM Watchdog Task Creation

The creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.

Level remote management tool +3 rmm remote-access persistence
2r 2t
medium advisory

Detection of Level RMM PowerShell Script Installer

This brief details the detection of the Level remote management tool PowerShell installer on Windows endpoints, which can be exploited by threat actors for malicious purposes to maintain persistence and execute commands, although it's a legitimate IT tool.

Splunk Enterprise +2 remote-management powershell rmm
2r 1t 1i
high threat

AWS S3 Bucket Lifecycle Rule for Rapid Log Deletion

An attacker modifies an AWS S3 bucket lifecycle policy to rapidly expire CloudTrail logs, hindering incident response and forensic analysis.

exploited CloudTrail +4 aws defense_evasion s3
2r 1t
medium advisory

AWS Network Access Control List Deletion Detected

Detection of AWS Network Access Control List (ACL) deletion using AWS CloudTrail logs, which can remove critical access restrictions, potentially allowing unauthorized access to cloud instances and leading to data exfiltration or further compromise.

Splunk Enterprise +3 cloud aws network
2r 1t
high advisory

AWS Network Access Control List Created with All Open Ports

The analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR by monitoring `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic, potentially leading to unauthorized network access.

Splunk Enterprise +3 cloud aws network-acl misconfiguration
2r
high advisory

AWS Bedrock GuardRails Deletion Attempt

Detection of AWS Bedrock GuardRails deletion, which are security controls to prevent harmful AI outputs, could indicate an adversary attempting to remove safety measures after credential compromise to enable malicious model outputs.

Bedrock +4 aws cloudtrail defense-evasion
2r 1t
medium advisory

Large ICMP Traffic Detection

This analytic identifies excessive ICMP traffic to external IP addresses exceeding 1,000 bytes, potentially indicating command and control activity, data exfiltration, or covert communication channels.

Splunk Enterprise +4 network-traffic command-and-control data-exfiltration
2r 1t
high advisory

Detection of IIS HTTP Logging Disabled via AppCmd.exe

This analytic detects the use of AppCmd.exe to disable HTTP logging on IIS servers, allowing adversaries to evade detection by removing evidence of their actions.

Splunk Enterprise +3 iis logging defense-evasion windows
2r 2t