Product
high
threat
Suspicious File Download via Headless Browser
1 rule 2 TTPs 26 IOCsThe DUCKTAIL threat actor leverages Chromium-based web browsers (such as Microsoft Edge and Chrome) running in headless mode with the `--dump-dom` argument to stealthily download malicious content from the internet via suspicious file-sharing domains, impacting compromised endpoints.
Brave Browser +4
DUCKTAIL
headless-browser
file-download
data-exfiltration
malware-delivery
endpoint
network
1r
2t
26i
high
advisory
Google Security Updates — July 2026
5 CVEs 41 IOCsRoundup of Google security advisories published in July 2026.
golang.org/x/crypto/ssh +74
roundup
5c
41i
updated
medium
advisory
RMM Domain DNS Queries from Non-Browser Processes
2 rules 75 IOCsDetects DNS queries to commonly abused remote monitoring and management (RMM) or remote access software domains from non-browser processes, potentially indicating unauthorized remote access or command and control activity.
Elastic Defend +9
command-and-control
rmm
dns
2r
75i