Severity
Vulnerabilities in MISP cti-transmute
3 IOCsThe MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.
Integrity Vulnerability in Thermo Fisher Genetic Analyzer Software
Thermo Fisher Applied Biosystems Genetic Analyzer software lacks integrity checks for output data files, enabling local users to modify DNA analysis results (CVE-2026-17583).
Remote Code Execution Vulnerability in Zyxel Firewalls
1 TTPA vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.
Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus
1 TTPMultiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.
Multiple Denial of Service Vulnerabilities in PJSIP pjmedia
1 TTPMultiple vulnerabilities in the PJSIP pjmedia library can be exploited by a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting telecommunications services.
Multiple Vulnerabilities in PaperCut NG/MF
2 CVEsMultiple vulnerabilities, including CVE-2026-8793 and CVE-2026-8794, affect PaperCut NG/MF versions prior to 26.0.3, potentially allowing for data confidentiality breaches and security policy bypass.
Detection of Destructive NFS File Operations
2 TTPsDetection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.
Apache HttpComponents Denial of Service Vulnerability
1 TTPA vulnerability in Apache HttpComponents allows a remote, unauthenticated attacker to trigger a Denial of Service condition on targeted applications.
Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes
1 TTPA vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.
Suspicious Cross-User Process Spawning Behavior
1 rule 2 TTPsDetection of common user-space applications being spawned under different user contexts, which often indicates privilege escalation testing or sacrificial process execution.
Detection of Suspicious Offline Registry Library Usage
1 rule 1 TTPDetection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.
Detection of Suspicious Explicit Credential Local Logon
1 rule 1 TTPDetection logic for monitoring Windows Event ID 4648 to identify potential privilege escalation through unauthorized explicit credential usage.
Incorrect Default Permissions in Synology Assistant
1 CVESynology Assistant versions prior to 7.0.7-50095 contain a vulnerability allowing local users to perform arbitrary file operations and trigger denial-of-service during the installation process.
Better Auth Path Normalization Vulnerability (CVE-2025-71399)
1 CVEBetter Auth versions prior to 1.4.5 contain a path normalization vulnerability in the rou3 library that allows attackers to bypass disabledPaths configurations and rate limits via URL path manipulation.
Unauthorized Memcached Data Manipulation via CVE-2026-29093
1 rule 1 TTP 1 CVEUnauthorized actors can leverage the lack of native authentication in Memcached to perform data manipulation or session hijacking, as identified in CVE-2026-29093.
Detection of Data Exfiltration via Curl Utility
1 rule 3 TTPsAdversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.
Unauthorized NFS Root Access via AUTH_SYS Credentials
1 rule 2 TTPsDetection of unauthorized NFS client access where a remote system asserts root-equivalent (UID 0) privileges over weak RPC/UNIX authentication, facilitating data collection and traversal.
Sylius Mollie Plugin Payment Status Forgery Vulnerability
1 rule 1 CVEThe Sylius Mollie Plugin is susceptible to an unauthenticated payment status forgery via the webhook handler, allowing attackers to mark arbitrary orders as paid by reusing valid payment IDs.
Detection of SIP REGISTER Brute Force and Credential Spraying
1 rule 2 TTPsDetection of malicious SIP REGISTER authentication attempts targeting VoIP infrastructure through anomalous 401, 403, and 407 response code patterns.
Detection of Unauthorized Apache Thrift RPC Invocations from External Networks
1 rule 1 TTP 1 CVEDetection logic targeting unauthorized Apache Thrift RPC method invocations from external IP addresses to identify exposed internal microservices or potential exploitation of data platforms.
Redis Authenticated Remote Code Execution Vulnerability
1 TTPA vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.
Detection of Malicious AMQP Multi-Queue Message Purging
1 TTPAdversaries may perform rapid multi-queue purges in AMQP-based messaging systems, such as RabbitMQ, to facilitate data destruction or cause widespread application disruption following credential compromise.
Denial of Service in gnome-remote-desktop via Connection Throttling Bypass
1 TTP 1 CVEA vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to exhaust system resources by bypassing connection throttling when RDP is enabled in system mode on Red Hat Enterprise Linux.
Multiple Vulnerabilities in Red Hat Enterprise Linux ABRT
1 TTPMultiple vulnerabilities in the Automatic Bug Reporting Tool (abrt) within Red Hat Enterprise Linux allow a local attacker to perform privilege escalation, manipulate data, or trigger a denial-of-service condition.
Detection of Unusual AWS IAM Guardrail Policy Deletion
1 rule 2 TTPsThis threat brief identifies a detection strategy for attackers attempting defense evasion or persistence by deleting sensitive AWS IAM managed policies using previously unseen identities.
Unusual AWS Batch Job Container Command Override Detection
1 rule 1 TTPThis detection targets the abuse of AWS Batch 'containerOverrides.command' parameters by infrequent users to inject malicious commands or data exfiltration logic into production compute environments.
Insufficient Redirect URI Validation in MaxKey
2 TTPs 1 CVEMaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.
Credential Exfiltration via koku-metrics-operator SSRF
1 TTPAn SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.
IBM WebSphere Application Server Security Bypass Vulnerability
1 TTPIBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.
Detection of Unauthorized AWS NACL Modification by New Identities
1 TTPAdversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.
AWS S3 Bucket ACL Modification to Public Access by New Identity
1 rule 1 TTPDetection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.
Easy!Appointments Excessive Data Exposure and Appointment Takeover
1 rule 1 TTP 1 CVEAn excessive data exposure vulnerability in Easy!Appointments version 1.5.2 allows authenticated attackers to retrieve sensitive appointment hashes and hijack other providers' appointments.
Req Library Unbounded Archive/Compression Extraction Denial-of-Service
1 TTP 1 CVEThe Elixir library 'Req' (versions >= 0.1.0, < 0.6.1) is susceptible to a denial-of-service vulnerability (CVE-2026-49755) caused by unbounded archive and compression extraction, which an attacker can leverage by providing a malicious HTTP response with a crafted 'content-type' or 'content-encoding' header, leading to memory exhaustion and application crashes.
Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)
1 TTP 1 CVE 4 IOCsA critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).
Detection of Container Tunneling and Port Forwarding Tools
1 rule 2 TTPsElastic has released a detection rule for its Defend for Containers integration, identifying the use of tunneling and port forwarding tools within Linux containers, indicating potential threat actor activity such as command-and-control, data exfiltration, or lateral movement.
DebugFS Execution Detected via Defend for Containers
1 rule 2 TTPsAttackers can leverage the Linux `debugfs` utility within privileged containers to access and manipulate host file systems (e.g., /dev/sd*), enabling privilege escalation and container escape to the underlying host machine.
SSH Authorized Key File Activity Detected in Containers
1 rule 4 TTPsAdversaries may modify the Secure Shell (SSH) authorized_keys file inside Linux containers to maintain persistence, achieve lateral movement, or escalate privileges by adding their own public keys, with this activity detected by Elastic Defend for Containers.
Suspicious Interactive Interpreter Execution in Containers
1 rule 6 TTPsThis brief describes the detection of suspicious inline command execution by scripting interpreters (Perl, PHP, Lua, Python, Ruby) within Linux containers, indicating potential malicious code execution, data exfiltration, or command-and-control by an attacker without dropping files, requiring decoding payloads and investigation of container integrity.
Netcat Listener or File Transfer Detected in Containers
1 rule 3 TTPsThis threat brief details the detection of malicious Netcat usage within Linux containers, indicating potential backdoor establishment, persistence, command and control, or data exfiltration by adversaries.
Container Compromise via File Creation in System Binary Locations
1 rule 4 TTPsAdversaries leverage tools like wget, curl, or busybox to create files within critical system binary directories such as /etc, /root, /bin, /usr/bin, /usr/local/bin, or /entrypoint inside running Linux containers to establish persistence, execute commands, or evade detection.
Suspicious File Creation and Execution within Linux Containers
1 rule 2 TTPsAn Elastic Defend for Containers rule detects suspicious activity in Linux containers where a process creates a file in a writable directory and immediately executes it, indicating potential hands-on intrusion, container breakout, unauthorized host access, privilege escalation, or evasion of security controls.
Direct Kubernetes API Request Detected via Elastic Defend for Containers
1 rule 4 TTPsAdversaries leveraging initial access within a container may execute direct Kubernetes API requests using tools like curl, wget, or kubectl, often with bearer tokens and insecure TLS, for cluster enumeration, lateral movement, or privilege escalation, which can be detected by Elastic Defend for Containers.
Detection of Encoded Payload Deobfuscation in Linux Containers
1 rule 5 TTPsAttackers are leveraging encoded payloads within Linux containers for defense evasion, using common decoding tools like base64, xxd, or scripting language one-liners to deobfuscate and execute malicious code, allowing for covert command and control, staging, and further compromise.
Kubernetes Service Account Token and Certificate Credential Access
2 rules 2 TTPs 5 IOCsA detection rule from Elastic identifies adversaries reading Kubernetes service account tokens or CA certificates within containers, typically using utilities like `cat` on `/var/run/secrets/kubernetes.io/serviceaccount/token` and `ca.crt` to authenticate to the Kubernetes API server and escalate privileges or expand access within the cluster.
Sensitive File Compression Detected in Linux Containers for Credential Access
3 rules 8 TTPs 1 IOCElastic Defend for Containers detects the use of compression utilities like tar or zip within Linux containers to collect sensitive files such as SSH keys, AWS credentials, or system configurations, indicating potential credential access and data collection attempts by adversaries.
Cloud Credential Search in Containers Detected
1 rule 2 TTPsAn attacker using system search utilities like `grep` or `find` within a containerized environment to locate cloud credentials (AWS, Azure, GCP) indicates an attempt to gain unauthorized access to sensitive cloud resources or perform a container breakout to compromise the underlying cloud infrastructure.
Detecting Interactive File Downloads in Linux Containers via Curl and Wget
1 rule 3 TTPsThis threat brief details how adversaries download files from the internet into Linux containers using `curl` or `wget` to stage tools, payloads, or establish application-layer command and control (C2), which detection engineers can identify by monitoring process execution within containers and correlating with audit logs.
Curl SOCKS Proxy Detected via Elastic Defend for Containers
1 rule 2 TTPsAttackers utilize the `curl` command-line tool with SOCKS proxy options inside Linux containers to bypass network restrictions, enabling command and control communications or data exfiltration, which defenders can detect by monitoring process execution within container environments for suspicious `curl` arguments and network tunneling activity.
Apache Tomcat Vulnerability Allows Denial of Service
1 TTPA vulnerability in Apache Tomcat allows a remote, anonymous attacker to perform a Denial of Service attack, potentially disrupting service availability for applications hosted on the affected server.
Broadcom Brocade SANnav Vulnerabilities Allow Information Disclosure, SQL Injection, and Data Manipulation
3 TTPsMultiple vulnerabilities in Broadcom Brocade SANnav can be exploited by an attacker from an adjacent network to achieve information disclosure, execute SQL injection attacks, and manipulate data within the system.
Tanium Endpoint Management Vulnerability Allows Authenticated SQL Injection
2 TTPsA remote, authenticated attacker can exploit a SQL injection vulnerability in Tanium Endpoint Management, enabling the execution of arbitrary SQL commands and potentially leading to data manipulation or unauthorized access.
IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service
1 TTPMultiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.
datamodel-code-generator Vulnerable to SSRF Protection Bypass via DNS Rebinding
4 TTPs 1 IOCThe `datamodel-code-generator` tool is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass, identified as CVE-2026-55391, due to a time-of-check/time-of-use (TOCTOU) race condition through DNS rebinding, allowing attackers to access internal services like cloud instance metadata endpoints when processing attacker-influenced URLs.
IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)
2 CVEsA denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.
Progress Software Security Advisory Addresses Multiple Vulnerabilities
5 CVEsProgress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.
SIPSorcery: Malformed UDP Packet Can Remotely Terminate Media Sessions (DoS)
2 TTPsA denial-of-service vulnerability (CVE-2026-54632) exists in the SIPSorcery NuGet package versions <= 10.0.8, allowing an unauthenticated attacker to remotely terminate an active RTP or WebRTC media session by sending a single malformed inbound UDP packet to the RTP/ICE socket, which exploits insufficient length checks and an exception handling flaw.
Poweradmin Vulnerable to Host Header Injection in Authentication Redirects
3 TTPs 1 CVE 1 IOCPoweradmin versions earlier than 4.2.4 and from 4.3.0 up to, but not including, 4.3.3 are vulnerable to CVE-2026-54588, a critical Host Header Injection flaw in OIDC, SAML, and logout authentication flows that allows an unauthenticated attacker to manipulate the HTTP_HOST header, poisoning callback URLs to redirect authorization codes to an attacker-controlled server, leading to full account takeover and potential full DNS zone control.
QTINeon NeonRelay Unauthenticated Denial-of-Service Amplification Vulnerability
3 TTPsAn unauthenticated attacker can exploit an unbounded RECONNECT_REQUEST forwarding vulnerability in QTINeon's NeonRelay component to amplify denial-of-service attacks against a connected host. By sending spoofed RECONNECT_REQUEST packets, the relay forwards each one to the host without proper deduplication or rate limiting, consuming host resources. Additionally, excessive spoofed IPs can reset legitimate rate limiting, further impacting service availability. This vulnerability affects Java, Python, and TypeScript implementations of NeonRelay.
Cross-origin OAuth token-request redirects can expose signed request metadata
3 TTPsThe 'oauth' Ruby gem versions 0.5.5 through 1.1.5 are vulnerable to a critical issue (CVE-2026-54605) where the 'OAuth::Consumer#token_request' method improperly handles HTTP 3xx redirects during OAuth 1.0 token exchanges, enabling an attacker to redirect the request to a malicious host, exposing sensitive OAuth 1.0 metadata, and facilitating Server-Side Request Forgery (SSRF) and confused-deputy behavior.
Pterodactyl Panel Global Rate-Limit Vulnerability Enables Unauthenticated DoS (CVE-2026-61609)
1 rule 2 TTPsAn unauthenticated attacker can exploit CVE-2026-61609, a global rate-limit vulnerability in Pterodactyl Panel versions up to and including 1.12.4, by sending approximately 10 requests per minute to authentication endpoints, leading to a panel-wide denial of service for all legitimate users and administrators attempting to log in or complete 2FA.
GitHub MCP Server Nil Pointer Dereference DoS in completion/complete Handler (CVE-2026-47427)
1 TTPA nil pointer dereference vulnerability, tracked as CVE-2026-47427, in the GitHub MCP Server's `completion/complete` handler allows an unauthenticated attacker to cause a complete denial of service by sending a malformed JSON-RPC request with missing or empty parameters for the `ref` field, leading to an immediate server crash.
Lettré Library TLS Hostname Verification Bypass Vulnerability (CVE-2026-46428)
3 TTPs 1 CVEAn inverted-boolean bug (CVE-2026-46428) in the `lettre` library's `boring-tls` integration silently disables TLS hostname verification for callers using the default strict configuration, allowing an on-path attacker with any chain-valid certificate to intercept SMTP submission, including credentials and message contents, from affected `lettre` clients.
Multiple Vulnerabilities in Samba
3 TTPs 1 CVEMultiple vulnerabilities have been discovered in Samba, a network file sharing service, which could allow a remote attacker to trigger a denial of service, compromise data confidentiality, and bypass security policies.
Multiple Vulnerabilities in Apache Wicket Allow XSS and Security Bypass
2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in Apache Wicket to perform Cross-Site Scripting (XSS) attacks and bypass existing security measures, potentially leading to unauthorized client-side script execution and further compromise of user sessions or data.
binutils: Vulnerability Enables Denial of Service and Data Disclosure
2 TTPsA local attacker can exploit a vulnerability in binutils to cause a Denial of Service condition and disclose sensitive data.
Netty: Vulnerability Enables Denial of Service
1 TTPA denial of service vulnerability exists in Netty, which an unauthenticated, remote attacker can exploit, allowing the attacker to disrupt the availability of affected systems or services.
CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout
1 TTP 1 CVEA low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.
Credential Manager Access By Uncommon Applications
1 rule 1 TTPA SigmaHQ detection rule identifies suspicious processes accessing Windows credential manager and vault files, potentially indicating credential theft by tools like Mimikatz, enabling lateral movement and data exfiltration.
Msiexec Quiet Installation for Proxy Execution
1 rule 1 TTPAdversaries leverage the Windows Installer utility msiexec.exe to proxy the quiet execution of malicious payloads, bypassing traditional security controls by masquerading as legitimate installation processes.
Suspicious WSMAN Provider Image Loads
1 rule 2 TTPsA detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.
PowerShell Core DLL Loaded By Non PowerShell Process
1 rule 1 TTPThis threat brief details a detection for the suspicious loading of PowerShell Core DLLs by non-PowerShell processes, a technique often employed by attackers to execute PowerShell code stealthily and evade security monitoring.
PSScriptPolicyTest Creation By Uncommon Process
1 rule 1 TTPThis brief describes a detection opportunity for the stealthy creation of the 'PSScriptPolicyTest' PowerShell script by processes other than standard PowerShell executables or legitimate Windows components, a behavior potentially indicative of advanced adversaries attempting to bypass PowerShell logging and security policies.
Suspicious System Process Names in Unusual File Locations
1 rule 1 TTPThis brief detects an attacker's attempt to evade detection and maintain persistence by creating executable files with names identical to legitimate Windows system processes in non-standard directories, a tactic associated with stealth and defense evasion.
Suspicious Access to Windows DPAPI Master Keys by Uncommon Applications
1 rule 1 TTPAdversaries can access Windows Data Protection API (DPAPI) master keys using uncommon applications like Mimikatz to decrypt user credentials and sensitive data, indicating credential theft activities.
The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)
2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.
Detection of Unauthorized WinSCP Credential Access
1 rule 1 TTP 2 IOCsThis analytic detects unauthorized access to the WinSCP security configuration folder, which stores sensitive SSH and FTP credentials, by processes other than WinSCP, leveraging Windows Security Event 4663 to identify abnormal read or access attempts often indicative of credential-stealing malware like Phantom Stealer.
Abuse of MSIExec for Remote File Download and Execution
1 rule 2 TTPsThis brief details the abuse of the Windows utility msiexec.exe by attackers to download and execute remote files via HTTP or HTTPS URLs, often leading to unauthorized code execution, system compromise, or further malware deployment.
Windows AppCertDLL Modification for Persistence and Privilege Escalation
1 rule 2 TTPsAttackers can modify Windows AppCertDLL registry keys via command-line utilities to achieve persistence and privilege escalation by registering malicious DLLs to be loaded early in the system startup process.
Detection of Local LLM Framework DNS Queries
1 rule 3 TTPs 18 IOCsThis brief details the detection of DNS queries originating from local Large Language Model (LLM) frameworks like Ollama, LM Studio, and GPT4All on Windows endpoints, leveraging Sysmon Event ID 22 to identify potential unauthorized AI tool usage or data exfiltration risks associated with model downloads, updates, and telemetry from repositories such as huggingface.co and ollama.ai.
Detection of Local LLM Model File Creation on Endpoints
2 rules 5 TTPsThis brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.
Detecting Rclone Execution with Network Activity for Data Exfiltration
1 rule 1 TTPThis detection identifies the malicious use of 'rclone', a legitimate file synchronization utility, for data exfiltration or cloud abuse by flagging `rclone.exe` execution when specific suspicious command-line arguments are used, such as those indicating synchronization to remote cloud storage providers like `mega:`, `ftp:`, or generic `remote:`, especially in conjunction with flags like `--transfers`, `--ignore-existing`, or `--auto-confirm`, which is a critical indicator of compromise abused by threat actors for stealthy data exfiltration.
AWS Bedrock Guardrail Deleted
2 rules 2 TTPsA detection rule has been developed for Amazon Bedrock that identifies the deletion of guardrails, indicating a potential attempt by an attacker or insider to disable AI model safety controls and facilitate unsafe or unauthorized responses.
etcd TLS Listener Denial of Service Vulnerability
1 TTPA denial-of-service vulnerability in etcd's TLS listener allows a network attacker to exhaust server memory by spawning unbounded goroutines through multiple TCP connections without sending ClientHello messages, leading to loss of availability for etcd clusters and dependent services like Kubernetes.
py-libp2p yamux Connection DoS via Oversized Data Frame
1 TTPA denial-of-service vulnerability in py-libp2p versions up to 0.6.0 allows an authenticated attacker to send a specially crafted 12-byte DATA or SYN frame with an oversized length field, causing the victim's yamux read loop to block indefinitely and freezing all streams on the affected connection.
Unbounded WebSocket Message Aggregation Leads to Denial of Service in http4s-blaze-server
1 TTPA vulnerability in `http4s-blaze-server` allows an attacker to cause a denial of service by exploiting unbounded WebSocket message aggregation, enabling an attacker to drive unbounded heap growth in the server's JVM by sending an unterminated fragmented WebSocket message, leading to an `OutOfMemoryError` and server termination, affecting any http4s application serving WebSocket routes over `BlazeServerBuilder` and triggerable by unauthenticated or authenticated clients.
Poweradmin: Broken Access Control (IDOR) Allows DNS Record Modification
3 TTPs 5 IOCsA low-privilege authenticated user in Poweradmin (a web front-end for PowerDNS) can exploit an Insecure Direct Object Reference (IDOR) vulnerability, allowing them to modify any DNS record on the server, even those they do not own, by manipulating POST request parameters to bypass access control checks and achieve DNS record repointing, disabling, or hijacking, leading to data integrity and availability issues, and potentially cross-tenant DNS takeover.
@anephenix/hub Unauthenticated WebSocket RPC Waiter Resource Exhaustion (CVE-None)
1 TTPAn unauthenticated Denial-of-Service vulnerability in `@anephenix/hub` versions prior to 0.2.16 allows attackers to exhaust server CPU and memory resources by opening numerous WebSocket connections and ignoring server-initiated RPC messages, leading to unbounded timers and heap entries.
Netty XmlFrameDecoder CPU Exhaustion Denial of Service
1 TTPAn unauthenticated remote attacker can cause a Denial of Service (DoS) in Netty servers utilizing XmlFrameDecoder by sending a specially crafted XML payload containing repeated '</' characters, leading to CPU exhaustion of the server's EventLoop thread and unresponsiveness.
React Router RSC Mode CSRF Bypass
1 TTP 1 CVEA high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.
js-yaml Denial of Service via Exponential Parsing Time in Flow Collections
1 TTPA denial of service vulnerability exists in the js-yaml library (versions 5.0.0 through 5.2.1) due to an exponential parsing time bug in flow collections, allowing attackers to craft a small YAML document which, when processed by `load()` or `loadAll()` functions, consumes significant CPU resources and blocks the Node.js event loop.
Account Takeover via Pre-Account Hijacking in Better Auth Library
3 TTPsAn attacker can perform a pre-account hijacking attack against the `better-auth` library if it uses magic-link or email-OTP plugins alongside open email and password registration and allows unverified accounts. The attacker first registers an account using the victim's email with a password they control. When the legitimate victim later uses a passwordless flow to verify their account, the attacker's pre-set password remains active, granting them persistent, unauthorized access to the victim's account and data, potentially leading to account takeover and user lockout.
Account Takeover and Stale Access via SCIM Provider-ID Collision in @better-auth/scim
5 TTPsThe `@better-auth/scim` package is affected by multiple vulnerabilities, including a critical provider-ID collision flaw that allows authenticated users to craft SCIM tokens impersonating existing account providers, leading to unauthorized account access, profile modification, and user deletion, while additional issues include failed user deactivation and email update vulnerabilities bypassing uniqueness checks in versions `1.4.0-beta.27` through `1.6.21` and `1.7.0-beta.0` through `1.7.0-beta.9`.
LiquidJS pop Filter Bypasses Memory Limit Accounting
1 TTP 1 CVEA vulnerability (CVE-2026-55575) in the LiquidJS templating library's `pop` filter, affecting versions up to and including 10.27.0, allows an attacker to bypass the `memoryLimit` accounting, leading to uncontrolled memory allocation and potential denial of service when processing untrusted, large arrays in templates.
React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)
1 TTPAn unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.
Multiple Vulnerabilities in MongoDB Core Server and Compass
2 TTPs 5 CVEs 52 IOCsNumerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.
FFmpeg: Multiple Vulnerabilities Allow Code Execution and DoS
2 TTPsMultiple vulnerabilities in FFmpeg allow an attacker to achieve arbitrary code execution or cause a denial-of-service condition.
Multiple Netty Vulnerabilities Enable Denial of Service Attacks
1 TTPMultiple vulnerabilities in Netty can be exploited by an attacker to conduct Denial of Service (DoS) attacks, impacting the availability of services utilizing the Netty framework.
RabbitMQ: Multiple Vulnerabilities Allowing Denial of Service and Security Bypass
1 TTPA remote, authenticated attacker can exploit multiple undisclosed vulnerabilities in RabbitMQ to conduct denial-of-service attacks and bypass existing security measures, impacting the availability and integrity of messaging systems.
Red Hat Quay Vulnerability Allows Authenticated Remote Attacker to Bypass Security
1 TTPAn authenticated remote attacker can exploit a vulnerability in Red Hat Quay to bypass security measures, circumventing established security controls within the container registry.
QT Vulnerability Enables File Manipulation
1 TTPA remote, anonymous attacker can exploit a vulnerability in QT to manipulate files, potentially affecting data integrity or system functionality.
Suspicious Child Process Creation by Wscript or Cscript
1 rule 2 TTPs 1 IOCAdversaries commonly use Wscript or Cscript to launch suspicious child processes, including LOLBINs and scripting interpreters, as a defense evasion and execution technique, which can lead to further system compromise or data destruction.
Apache Tomcat mod_jk Connector: Vulnerability Enables Security Bypass or Information Disclosure
2 TTPsA vulnerability in the Apache Tomcat mod_jk Connector allows a remote, unauthenticated attacker to bypass security measures or disclose sensitive information, which could enable an adversary to gain unauthorized access or collect confidential data.
Malware Employs Web Services for Victim IP Reconnaissance
1 rule 1 TTP 27 IOCsMalware, including Trickbot and various stealers, utilizes DNS queries to public IP checking web services for reconnaissance purposes, aiming to determine the victim's external IP address, which can facilitate further attacks or lateral movement.
Windows DNS Query Request by Telegram Bot API
1 rule 2 TTPs 1 IOCAn analytic detects DNS queries to `api.telegram.org` originating from non-Telegram processes on Windows systems, indicating potential malware command and control (C2) communication or data exfiltration via the Telegram Bot API.
Windows Curl Download to Suspicious Path Detection
1 rule 1 TTPThis analytic detects the use of Windows Curl.exe to download files to suspicious locations, such as AppData, ProgramData, or Public directories, leveraging Endpoint Detection and Response (EDR) data by focusing on command-line executions that include the -O or --output options; this activity is significant as it can indicate an attempt to bypass security controls or establish persistence, potentially leading to unauthorized code execution, data exfiltration, or further system compromise.
Windows Autostart Execution in Startup Folder for Persistence
1 rule 1 TTPAdversaries leverage the Windows %startup% folder to establish persistence by creating malicious files that execute automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.
Anti-Virus Product Reconnaissance via PowerShell or WMI
1 rule 1 TTPThis brief details the detection of suspicious PowerShell script execution that targets the discovery of installed anti-virus and anti-spyware products using WMI or PowerShell commands, a common reconnaissance tactic employed by malicious actors to map security applications and potentially evade defenses.
Denial of Service Vulnerability in find-my-way Node.js Router
1 rule 2 TTPsA remotely triggerable Denial of Service (DoS) vulnerability exists in the 'find-my-way' router when used with Node.js HTTP/2 servers. Malicious HTTP/2 method values, such as 'constructor' or '__proto__', can be passed to the 'lookup()' function, which then indexes these values against internal data structures. This leads to a crash when the code attempts to access properties of these unexpected values, such as 'currentNode.prefix.length', causing the server to become unavailable. Users are advised to upgrade to version 9.7.0 or validate HTTP methods before processing.
PHPSpreadsheet Denial of Service via Malformed XLS/OLE Sector Chain
1 TTPPhpSpreadsheet's OLE reader contains a denial-of-service vulnerability where it fails to detect cycles in attacker-controlled XLS/OLE sector chains, leading to infinite loops and memory exhaustion when parsing specially crafted, small malformed XLS/OLE files, which can cause PHP workers to crash and deny service to web applications processing untrusted spreadsheet uploads.
PhpSpreadsheet Gnumeric Reader Unbounded Gzip Expansion Leads to Denial of Service
1 TTPThe PhpOffice PhpSpreadsheet library is vulnerable to a denial of service (DoS) attack, identified as CVE-2026-59932, where its Gnumeric reader processes attacker-supplied `.gnumeric` files containing gzipped content without enforcing a decompressed-size limit, causing memory exhaustion and application crashes.
Auth.js getToken() Vulnerability Leads to Denial of Service
1 TTPA vulnerability in the Auth.js `getToken()` helper function (next-auth and @auth/core) allows unauthenticated attackers to trigger an uncaught exception via a malformed `Authorization: Bearer` header, leading to a per-request denial of service in affected applications.
Exim: Multiple Vulnerabilities Allow Local Command Execution and Privilege Escalation
2 TTPsMultiple vulnerabilities in Exim allow a local attacker to execute arbitrary commands and escalate privileges on the affected system, enabling a local adversary to gain higher control over the mail transfer agent and potentially the underlying operating system.
Internet Systems Consortium BIND: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.
Intel Ethernet Products: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities exist in various Intel Ethernet products, which an attacker can exploit to trigger a denial-of-service condition and expose confidential information.
Excon Redirection Vulnerability (CVE-2026-54171)
1 CVEA vulnerability, CVE-2026-54171, has been identified in the Excon library concerning the redaction of sensitive or risky headers when following redirects, which could potentially expose confidential information if not properly addressed.
HAProxy Denial of Service Vulnerability (CVE-2026-26080)
1 CVEA denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.
Next.js: Denial of Service in App Router using Server Actions
1 TTPA high-severity denial-of-service vulnerability (CVE-2026-64641) in Next.js applications utilizing the App Router with Server Actions allows an unauthenticated attacker to cause excessive CPU usage, leading to a complete service outage.
Netty Bzip2Decoder Infinite Loop Vulnerability Leads to Event-Loop Thread Hang (CVE-2026-59901)
1 TTPA denial-of-service vulnerability exists in the `Bzip2Decoder` handler within Netty's `netty-codec-compression` and `netty-codec` libraries, allowing a remote attacker to exploit CVE-2026-59901 by providing a specially crafted bzip2 stream, which causes an infinite loop in the run-length encoding state machine, leading to the permanent hang of an event-loop thread and application denial of service.
Netty HAProxyMessageDecoder Vulnerability Leads to Unbounded Memory Exhaustion
1 CVEA vulnerability, CVE-2026-55851, in Netty's `HAProxyMessageDecoder` can lead to unbounded memory exhaustion when an attacker sends a specific PROXY protocol v2 binary prefix followed by a version byte of `0xFF`, causing a signed-byte sentinel collision that traps the decoder in a version-detection loop and ultimately exhausts the JVM's direct memory allocation, resulting in a denial of service.
Netty SPDY SETTINGS Frame Denial of Service Vulnerability
3 TTPs 1 CVE 1 IOCA high-severity vulnerability, CVE-2026-55831, in Netty's SPDY SETTINGS decoder allows a remote unauthenticated attacker to trigger a denial of service by sending a crafted SPDY/3.1 SETTINGS frame that leads to excessive heap growth and CPU consumption due to unbounded map entries in `DefaultSpdySettingsFrame`.
Question2Answer Session Invalidation Vulnerability
2 TTPs 1 CVEAttackers can exploit CVE-2026-64829, a session invalidation vulnerability in Question2Answer through version 1.8.8, where the forgot-password reset flow fails to clear the sessioncode field, allowing an attacker with a previously obtained remember-me cookie to retain authenticated access even after the account's password has been reset.
CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability
1 CVEAn attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.
Multiple Vulnerabilities in Elastic Products
5 CVEsCERT-FR has issued an advisory detailing multiple vulnerabilities in Elastic products, including CVE-2026-42397 and CVE-2026-49092, which could allow an attacker to cause remote denial of service, compromise data confidentiality and integrity, and perform Server-Side Request Forgery (SSRF).
Multiple Vulnerabilities in GLPI
3 TTPsMultiple vulnerabilities have been discovered in GLPI, specifically affecting versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26, which allow an attacker to compromise data confidentiality and integrity, and bypass security policies.
Veeam Backup & Replication: Vulnerability Enables Privilege Escalation
1 TTPA vulnerability in Veeam Backup & Replication allows a local attacker to escalate privileges on the affected system.
Ansible: Local Code Execution Vulnerability
1 TTPA local attacker can exploit a vulnerability within Ansible software to execute arbitrary code on the affected system, potentially leading to further compromise or unauthorized actions on the host where Ansible is running.
Avahi Vulnerability Allows Local Denial of Service
1 TTPA vulnerability in the avahi service allows a local attacker to perform a Denial of Service (DoS) attack, potentially leading to the unavailability of services or the system itself.
Libarchive Vulnerability Enables Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in libarchive to initiate a Denial of Service attack, disrupting the availability of services or systems utilizing the affected library.
fast-xml-parser: Repeated DOCTYPE Declarations Bypass Entity Expansion Limits Leading to DoS
1 TTPA vulnerability in fast-xml-parser allows an attacker to bypass entity expansion limits by crafting XML documents with multiple DOCTYPE declarations, leading to excessive CPU usage, memory exhaustion, and denial of service.
Jackson-core Async Parser Max Number Length Bypass via Chunked Digit Accumulation
1 TTPAn incomplete fix for GHSA-72hv-8253-57qq in `jackson-core` versions 2.18.6, 2.21.1, and potentially 3.0.x/3.1.x, allows attackers to bypass `maxNumberLength` constraints in the non-blocking JSON parser by streaming JSON numbers in small chunks, leading to unbounded memory accumulation and denial of service in reactive applications.
Denial of Service in websocket-driver-ruby via Malformed Host Header (CVE-2026-61666)
1 rule 1 TTPA denial of service vulnerability (CVE-2026-61666) exists in the websocket-driver-ruby library when used to implement a WebSocket server via `WebSocket::Driver.server()`, allowing a remote attacker to send a malformed `Host` header causing a `URI::InvalidURIError` exception and subsequent server process crash if unhandled.
OPNsense: Multiple Vulnerabilities
4 TTPsAn attacker can exploit multiple vulnerabilities in OPNsense to bypass security controls, disclose information, perform Cross-Site Scripting (XSS) attacks, and execute Denial of Service (DoS) attacks.
CUPS (libcupsfilters, cups-filters) Denial of Service Vulnerability
1 TTPA vulnerability in CUPS, specifically affecting libcupsfilters and cups-filters, allows a remote, unauthenticated attacker to exploit the system, leading to a denial-of-service condition that disrupts the availability of the printing system.
ethtool RSS Resource Leak on get_rxfh Failure
1 CVEA vulnerability, CVE-2026-63999, has been identified in the `ethtool` utility on Linux systems, involving a resource leak of `indir_table` and `hkey` when the `get_rxfh` function related to Receive Side Scaling (RSS) functionality fails, which could lead to system instability or resource exhaustion.
CVE-2026-64117 Vulnerability in Linux Kernel mac80211 Wi-Fi Subsystem
1 CVEA vulnerability, CVE-2026-64117, has been disclosed in the Linux kernel's mac80211 Wi-Fi subsystem, potentially leading to unexpected behavior or information exposure due to incorrect handling of fast-RX rates and `skb->cb` buffer reuse in mesh networking contexts.
CVE-2026-64097: AMD Display Module Vulnerability in Linux Kernel
1 CVEA vulnerability, CVE-2026-64097, affects the `drm/amd/display` module in the Linux kernel due to insufficient validation of GPIO pin LUT table size, potentially leading to system instability or other security impacts on Linux systems utilizing AMD display drivers.
File Browser Symlink Following Vulnerability Allows Out-of-Scope File Deletion (CVE-2026-55667)
2 TTPs 2 CVEsA File Browser user with only `Create` permission can exploit CVE-2026-55667, an incomplete fix for CVE-2026-54094, to delete arbitrary files and directories outside their authorized scope by abusing the `ScopedFs.RemoveAll` function's symlink-following behavior during failed upload cleanup, leading to data loss, cross-tenant data deletion, or denial of service.
LLM-Based Triage of Wget Activity on Linux Hosts
1 rule 3 TTPs 13 IOCsElastic has developed a detection rule that monitors non-allowlisted `wget` activity on Linux hosts using Auditd Manager or Auditbeat, leveraging an Elastic LLM to triage `wget` executions for potential ingress tool transfer, command and control, or data exfiltration attempts to untrusted destinations, generating alerts only for high-confidence positive or suspicious verdicts.
LLM-Based Detection of Suspicious Curl Activity on Linux
3 TTPsElastic's LLM-based detection rule identifies suspicious `curl` activity on Linux systems, aiming to detect command and control, data exfiltration, or ingress tool transfer by analyzing command-line parameters and network destinations via Auditd Manager or Auditbeat logs, which, if left unaddressed, could lead to system compromise or data breach.
Detection of Generative AI Processes Connecting to Unusual Domains
1 rule 1 TTPAdversaries may compromise macOS-based Generative AI (GenAI) tools through prompt injection, malicious Model Context Protocol (MCP) servers, or poisoned plugins to establish Command and Control (C2) channels or exfiltrate sensitive data by causing them to connect to unusual domains.
LG Monitors Auto-Install Adware-Like App on Windows PCs
1 TTPConnecting certain LG monitors to Windows PCs triggers Windows Update to automatically install the 'LG Monitor App Installer' without user consent, which then runs at system startup and frequently displays advertisements for McAfee antivirus trials.
Detection of XDG-Open Command Execution on Linux Systems
1 rule 2 TTPsAttackers abuse the `xdg-open` utility on Linux to trick users into opening malicious documents or URLs, leading to potential code execution and system compromise through user interaction.
Linux Interpreter Downloads and Pipes Payload for Execution
1 rule 3 TTPsThis detection rule targets a Linux defense evasion technique where an interpreter downloads a malicious payload from an external address and immediately pipes its content into another interpreter for in-memory execution, allowing attackers to establish persistence, exfiltrate data, or run stagers without writing files to disk.
AWS IAM Session Token Used from Multiple Addresses
1 TTPThis threat brief describes a detection for suspicious activity where an AWS IAM user's temporary session token is accessed from multiple distinct IP addresses, networks, cities, and user agents within a short timeframe, indicating potentially compromised credentials used for initial access and resource manipulation.
Detect Potential Sudo Binary Hijacking on Linux Systems
1 rule 3 TTPsAttackers may hijack the default sudo binary on Linux systems, located at `/usr/bin/sudo` or `/bin/sudo`, replacing it with a malicious version to capture user passwords for credential access, elevate privileges, or establish persistence on the system every time the sudo binary is executed.
Linux Privilege Escalation via CAP_SETUID/SETGID Capabilities
3 TTPsThis brief details a Linux privilege escalation technique where attackers leverage misconfigurations in applications with CAP_SETUID or CAP_SETGID capabilities to elevate their privileges to root (UID/GID 0), enabling unauthorized system control and further malicious activities.
Potential Privilege Escalation via SUID/SGID Proxy Execution on Linux
1 rule 4 TTPsAttackers may exploit SUID/SGID binaries like pkexec, su, or sudo on Linux systems to execute commands with elevated privileges, by identifying instances where a process runs with root privileges (user ID 0 or group ID 0) while the real user or group ID is non-root, allowing a low-privilege foothold to gain full system control.
Suspicious Command Execution via Linux Web Server
1 rule 14 TTPsThis brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.
Multiple Vulnerabilities in Proxmox Virtual Environment
1 TTPAn attacker can exploit multiple vulnerabilities in Proxmox Virtual Environment to conduct Cross-Site Scripting attacks, bypass security measures, and disclose confidential information, potentially leading to unauthorized data access or session hijacking.
ProFTPD: Vulnerability Enables Denial of Service
1 TTPAn authenticated remote attacker can exploit a vulnerability within ProFTPD to initiate a denial-of-service attack, leading to the unavailability of the FTP service. This flaw could be triggered by legitimate users or adversaries with valid credentials, causing operational disruption.
CVE-2026-63825: gcov Utility Concurrent Access Crash Vulnerability
1 CVEA vulnerability, CVE-2026-63825, has been disclosed for the 'gcov' utility, which is part of the GNU Compiler Collection, involving concurrent access crashes fixed by using atomic counter updates to ensure thread-safe operations, potentially leading to system instability or denial of service due to race conditions during data access.
Potential Out-of-Bounds Write in rust-openssl AES-KW-PAD Cipher Operations
1 CVEA potential out-of-bounds write vulnerability, CVE-2026-45784, has been identified in the `rust-openssl` library's `CipherCtxRef::cipher_update_inplace` function when processing AES-KW-PAD ciphers, which could lead to unexpected behavior or potential exploitation by corrupting memory.
KVM Guest-Triggerable Denial-of-Service Vulnerability (CVE-2026-63806)
1 CVEA denial-of-service vulnerability (CVE-2026-63806) has been identified in KVM's ioeventfd datamatch handling, allowing a guest virtual machine to trigger a BUG_ON() condition on the host, leading to a system crash.
Accepted Default Telnet Port Connection
1 rule 4 TTPsThis threat brief details how threat actors exploit the insecure Telnet protocol on its default port 23 for initial access, lateral movement, and command and control, leveraging its unencrypted nature to compromise systems and exfiltrate data, emphasizing the need for robust detection and mitigation strategies.
Suspicious Child Process Execution via Azure VM CustomScript Extension
1 rule 4 TTPsAttackers with access to an Azure subscription or VM management plane can leverage the Azure VM CustomScript extension to execute arbitrary code with SYSTEM privileges on Windows virtual machines, leading to various malicious activities such as reconnaissance, malware deployment, and persistence.
AWS Cognito Unauthenticated Identity Pool Credentials Issued
1 rule 2 TTPsThis threat involves adversaries obtaining temporary AWS credentials from a misconfigured Cognito Identity Pool without authentication. If a Cognito Identity Pool is set to allow unauthenticated (guest) access and its associated unauthenticated IAM role has overly broad permissions, attackers can discover the pool ID, call `GetId`, and then `GetCredentialsForIdentity` to acquire AWS credentials. This grants them unauthorized access to AWS resources and sensitive data, bypassing typical authentication mechanisms.
AWS CloudTrail Management Events Disabled via PutEventSelectors
1 rule 1 TTPA malicious actor uses the AWS CloudTrail `PutEventSelectors` API call to explicitly disable logging of management API calls for a trail by setting `includeManagementEvents` to `false`, effectively blinding defenders to subsequent sensitive activities while the trail appears active.
AWS Attempt to Leave Organization
1 rule 2 TTPsAn adversary attempting to remove an AWS member account from its AWS Organization via the LeaveOrganization API constitutes a critical defense evasion maneuver, as it strips the account of security controls and centralized monitoring, requiring immediate investigation by detection engineers.
AWS IAM User Console Login Without MFA
1 rule 1 TTPThis brief identifies successful logins to the AWS Management Console by standard IAM users without Multi-Factor Authentication (MFA). It focuses on the first observed occurrence within a 7-day history window for each user. An adversary who obtains a user's password can gain access if MFA is not enforced, representing a significant initial access vector. This event signals a critical posture gap that allows adversaries to achieve initial access using compromised credentials, leading to potential privilege escalation, data exfiltration, or resource deployment.
CVE-2026-15392: DBD::File Module Symlink Vulnerability
1 CVECVE-2026-15392 is a medium-severity vulnerability affecting versions of the Perl module DBD::File prior to 1.651, where the module fails to prevent symlinks to untrusted locations, potentially allowing local attackers to achieve information disclosure or local privilege escalation through symlink following.
Libsoup Vulnerability CVE-2026-15714 Allows Out-of-Bounds Read
1 CVEA vulnerability identified as CVE-2026-15714 in the Libsoup library's soupmultipartinputstream component allows an out-of-bounds read when processing an oversized multipart boundary string, potentially leading to information disclosure or application instability.
CoreDNS: Multiple Vulnerabilities Enable Denial of Service
1 TTP 1 CVEMultiple vulnerabilities exist in CoreDNS that allow a remote, unauthenticated attacker to execute a Denial of Service (DoS) attack against the service, potentially leading to service disruption and unavailability for affected systems utilizing CoreDNS.
File Creation in World-Writable Directory by Unusual Process
1 rule 1 TTPAn Elastic detection rule identifies when an unusual process creates files within world-writable directories on Linux systems, a tactic employed by attackers for defense evasion and lateral movement by staging payloads and hiding malicious activities.
MCP Python SDK Vulnerability Allows Cross-Client Task Access and Cancellation (CVE-2026-52870)
3 TTPs 1 CVEA high-severity vulnerability (CVE-2026-52870) in the MCP Python SDK's experimental task handlers, specifically in versions 1.23.0 through 1.27.1, allows any connected client to observe, read results from, and cancel tasks belonging to other clients due to a lack of session validation, potentially leading to unauthorized data access and denial of service.
Rockwell Automation Communication Modules Denial-of-Service Vulnerability
1 TTP 1 CVEA denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.
NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability
1 TTPA high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.
Privilege Escalation Vulnerability in SALTO ProAccess Space
1 TTP 1 CVEAn authenticated attacker can exploit CVE-2026-11889, a privilege escalation vulnerability in SALTO ProAccess Space versions prior to 6.13, to bypass authorization controls and access spaces outside their assigned partition within the same installation, provided the partitioning feature is enabled.
Rockwell Automation Flex 5000 Adapter Vulnerability Leads to Denial of Service
2 TTPs 1 CVEA denial-of-service vulnerability (CVE-2026-12659), categorized as a Double Free issue (CWE-415), exists in Rockwell Automation Flex 5000 Adapter version 6.011 due to improper handling of crafted CIP packets, which could allow an unauthenticated attacker to cause a denial-of-service condition requiring a power cycle to recover.
Rockwell Automation CompactLogix and ControlLogix Vulnerabilities Lead to Denial-of-Service
2 TTPs 3 CVEsMultiple Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product versions are vulnerable to denial-of-service conditions through CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, which an attacker can exploit via buffer overflows by loading invalid project files or writing invalid data, causing controllers to enter a major non-recoverable fault.
Denial-of-Service Vulnerability Affects ESET Endpoint Antivirus and Server Security Products (CVE-2026-6424)
1 TTP 1 CVEA vulnerability, identified as CVE-2026-6424, has been discovered in various ESET Endpoint Antivirus and Server Security product versions, allowing an attacker to cause a denial of service, impacting the availability of the affected systems.
X.Org X11 Server (libXfont2): Multiple Vulnerabilities Allow Arbitrary Code Execution with Administrator Rights
1 TTPMultiple vulnerabilities in X.Org X11 Server and libXfont2 allow a local attacker to gain elevated privileges and execute arbitrary code with root rights, posing a significant risk for systems utilizing the X.Org display server.
Multiple Vulnerabilities in Absolute Secure Access
2 TTPsAn attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.
Drupal Core: Multiple Vulnerabilities Allowing Information Disclosure and XSS
2 TTPsA remote, unauthenticated attacker can exploit multiple vulnerabilities in Drupal Core to achieve information disclosure and Cross-Site Scripting (XSS) attacks, potentially compromising user data or session integrity.
Apache Ivy: Vulnerability Allows File Manipulation
1 TTPA remote, authenticated attacker can exploit a vulnerability in Apache Ivy to manipulate files on the system, leading to unauthorized modification of data and potential integrity compromise.
7-Zip: Vulnerability Enables Code Execution
1 TTPA remote, anonymous attacker can exploit an unspecified vulnerability in 7-Zip to execute arbitrary code, leading to potential compromise of the system running the vulnerable software.
F5 BIG-IP and BIG-IP Next Vulnerability Enables Denial of Service
1 TTPAn unauthenticated, remote attacker can exploit a vulnerability in F5 BIG-IP and BIG-IP Next to perform a Denial of Service attack, potentially disrupting services.
Detecting Unusually Large Prompts to AWS Bedrock Claude Models
1 rule 3 TTPsThis brief outlines a detection strategy for identifying unusually large prompts sent to AWS Bedrock Claude models, which may indicate prompt injection attacks, data exfiltration attempts, or abuse of the AI service, warranting investigation by detection engineers.
Gitea: Multiple Vulnerabilities
2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in Gitea to manipulate data or trigger a denial of service.
Argo CD: Multiple Vulnerabilities
2 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in Argo CD, including Cross-Site Scripting (XSS) and information disclosure flaws, which could lead to sensitive information exposure and potentially allow the attacker to gain administrator privileges.
Red Hat Quay: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in Red Hat Quay allow a remote, authenticated attacker to execute arbitrary code and perform Server-Side Request Forgery (SSRF) attacks.
dd-trace-rb: Improper Parsing of W3C Baggage Headers Leads to DoS
1 TTPA vulnerability (CVE-2026-50276) in Datadog tracing libraries, specifically `dd-trace-rb` versions prior to 2.32.0, allows a remote and unauthenticated attacker to perform a Denial of Service (DoS) by sending HTTP requests with malformed W3C baggage headers, leading to unbounded CPU and memory consumption.
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression
1 TTP 1 IOCPomerium proxy deployments using the stateless authentication flow (Pomerium Zero or hosted authenticate) are vulnerable to a pre-authentication memory exhaustion denial of service, allowing an unauthenticated attacker to send specially crafted HPKE-encrypted zstd payloads to the `/.pomerium/callback` endpoint, leading to excessive memory allocation and potential proxy crashes.
Datadog dd-trace-go Library Vulnerability May Lead to Denial of Service
1 TTPA vulnerability, CVE-2026-50274, in Datadog's `dd-trace-go` library (versions <= 1.24.1 and v2 < 2.8.1) allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending HTTP requests with oversized W3C baggage headers, leading to unbounded CPU and memory consumption in instrumented services.
Datadog dd-trace-dotnet Improper W3C Baggage Header Parsing Leads to DoS
1 TTPA Denial of Service (DoS) vulnerability exists in Datadog tracing libraries (`dd-trace-dotnet`) due to improper parsing of W3C baggage HTTP headers, allowing remote, unauthenticated attackers to send requests with arbitrarily large baggage headers, causing unbounded CPU and memory consumption and leading to service unavailability for any HTTP service instrumented with affected library versions where baggage propagation is enabled by default. The issue, tracked as CVE-2026-50273, is resolved in version 3.43.0 and later.
Datadog dd-trace-js W3C Baggage Header Denial of Service Vulnerability
1 TTPThe Datadog `dd-trace-js` library, specifically versions older than 5.100.0, is vulnerable to a Denial of Service (DoS) attack where improper parsing of W3C baggage HTTP headers allows a remote, unauthenticated attacker to send requests with an arbitrarily large number of comma-separated key-value pairs, leading to unbounded CPU and memory consumption and enabling a remote DoS against any HTTP service instrumented with the affected library where baggage propagation is enabled.
Datadog dd-trace-py Improper Parsing of W3C Baggage Headers Leads to DoS
1 TTPThe Datadog dd-trace-py tracing library, versions prior to 4.8.2, is vulnerable to a Denial of Service (DoS) attack due to improper parsing of W3C baggage HTTP headers, which fails to enforce item-count or byte-size limits on the extraction path, allowing an unauthenticated attacker to send a request with an arbitrarily large baggage header causing unbounded CPU and memory consumption.
Datadog dd-trace-java DoS Vulnerability via W3C Baggage Headers
1 TTPA denial-of-service vulnerability, CVE-2026-50270, exists in Datadog tracing libraries (dd-trace-java prior to version 1.62.0) that implement W3C baggage propagation. Remote, unauthenticated attackers can exploit this by sending HTTP requests with W3C baggage headers containing an arbitrarily large number of comma-separated key-value pairs. The tracer, when extracting these headers, fails to enforce item-count or byte-size limits, leading to unbounded CPU and memory consumption as it allocates hash-map entries for each pair, thereby causing a denial of service against the instrumented HTTP service.
Message Corruption Vulnerability in websocket-driver Library (CVE-2026-54466)
A critical vulnerability, CVE-2026-54466, in the `websocket-driver` npm library allows remote attackers to cause message corruption by sending specially crafted WebSocket frames that exploit improper handling of the protocol's length header, leading to incorrect parsing of subsequent payload data.
Unbounded Recursion Depth in Elixir Protobuf Decoder Causes Denial of Service
1 TTPAn unauthenticated attacker can trigger a denial-of-service condition in services that decode untrusted protobuf messages using the `Protobuf.Decoder` (Hex package `protobuf`) versions between 0.8.0 and 0.16.1 by crafting deeply nested self-referential message types, leading to memory exhaustion and service crashes.
NGINX Ingress Controller Injection Vulnerability via CRDs/Annotations (CVE-2026-55723)
2 TTPs 1 CVEAn injection vulnerability exists in the NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. An authenticated attacker with write permissions to these CRDs or annotations via the Kubernetes API can craft values to inject arbitrary NGINX configuration directives. This can lead to creating or deleting files and disabling services, affecting the control plane without exposing the data plane.
Vulnerability in Veeam Backup & Replication Allows Privilege Escalation
1 IOCA privilege escalation vulnerability has been discovered in Veeam Backup & Replication, affecting versions prior to 12.3.0.65, which allows an attacker to elevate their privileges within the system.
Perl Denial of Service Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Perl to cause a Denial of Service condition.
Multiple WebKitGTK Vulnerabilities
4 TTPsMultiple vulnerabilities exist in WebKitGTK that can be exploited by a remote, unauthenticated attacker for information disclosure, denial of service, data manipulation, and security mechanism bypass.
Devolutions Server: Multiple Vulnerabilities Allow Authenticated Attackers to Manipulate Data, Bypass Security, and Disclose Information
4 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to manipulate data, bypass security measures, and disclose information.
Netty: Multiple Vulnerabilities
1 TTPAn attacker can exploit multiple vulnerabilities within the Netty framework to bypass security checks, manipulate requests or headers, circumvent certificate validations, and cause a denial of service.
AWS Bedrock Model Prompt or Completion Containing Credentials
1 rule 1 TTPA detection rule identifies AWS access key IDs, Amazon Bedrock API keys, PEM private-key blocks, and GitHub/GitLab tokens within Amazon Bedrock model prompts or completions, indicating a critical credential exposure event through misconfiguration, data leakage, or prompt injection that necessitates immediate secret rotation and investigation.
Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service
1 TTPA vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.
Citrix Secure Access Client for Windows Vulnerabilities Lead to Privilege Escalation and Information Disclosure
2 TTPsMultiple vulnerabilities in Citrix Systems Secure Access Client for Windows can be exploited by a local attacker to achieve privilege escalation and information disclosure on affected Windows systems.
Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution
1 TTPMultiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.
OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision
1 TTP 1 CVEA high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.
Perl Regex Engine Vulnerability Allows Silently Incorrect Matches
1 CVEA vulnerability exists in Perl versions up to and including 5.43.9 where regular expression matches can be silently incorrect when an alternation of more than 65535 fixed string branches is compiled into a trie within the Perl_study_chunk function, potentially leading to incorrect logic or data processing.
Multiple Vulnerabilities in Python Lead to Denial of Service
1 TTPRemote and unauthenticated attackers can exploit multiple unspecified vulnerabilities within Python to conduct Denial of Service attacks, potentially disrupting the availability of services or applications running on the language.
Denial-of-Service Vulnerability in Pillow EPS Parser (CVE-2026-59203)
1 TTP 1 CVEA denial-of-service vulnerability, CVE-2026-59203, exists in the Python imaging library Pillow, affecting versions 12.0.0 through 12.2.0, where a specially crafted EPS file with a negative byte count in the `%%BeginBinary` directive can cause an infinite loop and resource exhaustion when processed by the `Image.open()` function, leading to application unresponsiveness.
Netty StompSubframeDecoder Denial of Service Vulnerability (CVE-2026-44891)
1 TTPA high-severity denial of service vulnerability, identified as CVE-2026-44891, exists in the `StompSubframeDecoder` component of Netty's `netty-codec-stomp` library, allowing an unauthenticated attacker to exhaust server memory and cause an `OutOfMemoryError` by sending a STOMP message with an excessive number of headers, leading to application crashes.
This rule detects changes to AWS CloudTrail configurations that could indicate a security risk, specifically disabling or altering trails, or failing a security configuration check. Such actions can significantly reduce visibility into AWS activity.
Ivanti Xtraction Vulnerabilities CVE-2026-14902 and CVE-2026-14903
2 CVEsIvanti has published a security advisory (AV26-696) on July 14, 2026, to address two vulnerabilities, CVE-2026-14902 and CVE-2026-14903, affecting Ivanti Xtraction version 2026.2 and prior, urging users to apply necessary updates to mitigate potential risks.
Hoverfly Process Crash via Concurrent Map Write Race Condition
1 TTPHoverfly, when running in Diff mode, is vulnerable to a denial-of-service condition due to a concurrent map write race condition in the `AddDiff()` function. Multiple proxy requests processed simultaneously cause unsynchronized writes to the shared `responsesDiff` map, triggering Go's built-in race detector and a `fatal error`, which immediately terminates the Hoverfly process. This vulnerability is trivially exploitable by sending multiple concurrent requests to the proxy port, leading to a full denial of service that cannot be recovered without a restart.
MKP Pod Log Read Vulnerability Leads to Memory Exhaustion and Denial of Service
2 TTPsAn unauthenticated remote attacker can exploit a vulnerability in the MKP (Model Context Protocol for Kubernetes) server to exhaust its memory and cause a denial of service by sending a crafted `tools/call` request that manipulates `limitBytes` or `tailLines` parameters, leading to unbounded Kubernetes pod log reads into memory.
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
A vulnerability, identified as CVE-2026-47282, in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose sensitive information over a network due to insufficiently protected credentials.
Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)
1 TTP 1 CVEA critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.
Apache ActiveMQ Cross-Site Scripting Vulnerability
1 TTPA remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Apache ActiveMQ to execute malicious scripts within a victim's browser.
OpenSSH Vulnerability Allows Privilege Escalation
1 TTPA local attacker can exploit an unspecified vulnerability in OpenSSH to elevate their privileges on the affected system.
Ollama: Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability in Ollama to execute a Denial of Service (DoS) attack, disrupting service availability.
Potential AWS S3 Bucket Ransomware Note Uploaded
1 rule 3 TTPs 2 IOCsAdversaries exploit misconfigured AWS S3 buckets or compromised credentials to upload ransomware notes, often after deleting or encrypting data, aiming to extort victims.
SAP Approuter HTTP Request Smuggling Vulnerability Allows Confidentiality and Availability Impact (CVE-2026-27690)
3 TTPs 1 CVEAn HTTP Request Smuggling vulnerability (CVE-2026-27690, CWE-444) in SAP Approuter allows an unauthenticated attacker to send a specially crafted HTTP request leading to request-response desynchronization, which can result in the exposure of user responses and cause a denial of service by making the system unavailable.
Circular JSON Schema $ref Causes Unbounded CPU DoS in json_repair Library
1 TTPAn unbounded CPU Denial-of-Service vulnerability exists in the `json_repair` library's `SchemaRepairer.resolve_schema()` function, allowing an unauthenticated attacker to provide a specially crafted JSON schema containing a circular `$ref` pointer, leading to indefinite CPU consumption and service unavailability.
Decidim JWT Replay Vulnerability Allows Cross-Organization Data Access
2 TTPsA vulnerability, CVE-2026-45414, in Decidim allows an attacker to replay a JSON Web Token (JWT) issued for one organization against another organization's API, permitting an authenticated user from Org 1 to access and retrieve sensitive data, such as GraphQL `participantDetails` and `proposal.answer` mutation paths, from Org 2, effectively bypassing cross-organizational access controls.
Checkmk: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in Checkmk allow an attacker to escalate privileges and bypass security measures, potentially leading to unauthorized access and control within the affected system.
libTIFF Vulnerability Enables Arbitrary Code Execution and Denial of Service
1 TTPA local attacker can exploit a vulnerability in libTIFF to execute arbitrary code and perform a denial of service attack against the system where the library is used.
Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS
2 TTPsAttackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.
Linux Kernel Vulnerability (xfrm: iptfs) Allows Local DoS and Data Manipulation
2 TTPsA local attacker can exploit a vulnerability in the Linux Kernel's xfrm: iptfs component to potentially trigger a denial-of-service condition or manipulate data on affected systems.
Wget Vulnerability Allows Security Bypass and Server-Side Request Forgery
1 TTPA local attacker can exploit a vulnerability in wget to bypass existing security measures and perform a Server-Side Request Forgery (SSRF) attack, enabling requests to internal or restricted resources from the local system.
Multiple Vulnerabilities in SaltStack Salt
2 TTPsMultiple vulnerabilities in SaltStack Salt allow an attacker to execute arbitrary program code on affected systems and bypass security measures, potentially leading to unauthorized access and control over managed infrastructure.
Django, Debian, and Ubuntu Vulnerability Allows Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Django, Debian Linux, and Ubuntu Linux to initiate a Denial of Service attack, potentially disrupting services and making them unavailable to legitimate users.
Django Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability in Django to conduct a Denial of Service attack, which could disrupt the availability of services running on the affected Django application.
CPython Vulnerability Enables Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability within CPython to launch a Denial of Service attack, affecting the CPython interpreter across various operating systems.
CVE-2026-59869: js-yaml Vulnerability Leading to Quadratic CPU Consumption and DoS
2 TTPs 1 CVEA vulnerability, CVE-2026-59869, in the `js-yaml` library allows attackers to craft malicious YAML merge-key chains, which can lead to quadratic CPU consumption and a Denial of Service condition in applications processing the input.
CVE-2026-59928 Mistune block_parser: Quadratic-Time Parsing Leading to Denial of Service
1 CVECVE-2026-59928 identifies a vulnerability in the Mistune block_parser component where quadratic-time parsing of long lists of repeated reference-link definitions can be exploited by an attacker to cause a denial-of-service condition due to excessive resource consumption.
Out-of-Bound Read Vulnerability in mtr (CVE-2026-14461)
1 CVECVE-2026-14461 identifies an out-of-bound read vulnerability in the mtr network diagnostic tool that could lead to information disclosure or denial of service on Linux and macOS systems.
Setuptools Unicode Normalization Collision Bypass on macOS
1 CVEA vulnerability, CVE-2026-59890, affects the setuptools project, allowing a MANIFEST.in exclusion bypass during source distribution package creation due to Unicode normalization collisions (NFC/NFD) on macOS systems using APFS or HFS+ file systems.
Mistune Markdown Parser Vulnerability CVE-2026-59930 Allows HTML ID Collision
1 CVEA vulnerability, CVE-2026-59930, in the Mistune markdown parser's TableOfContents directive creates predictable HTML heading IDs, enabling an attacker to inject content with colliding IDs for client-side content manipulation.
Perl DBI Out-of-Bounds Read Vulnerability CVE-2026-14740
1 CVECVE-2026-14740 describes an out-of-bounds read vulnerability in DBI versions prior to 1.650 for Perl, occurring during the preparse stage when deleting an initial SQL comment, which can lead to information disclosure or denial of service.
OpenSSH sshd GSSAPI Behavior Vulnerability CVE-2026-59998
1 CVECVE-2026-59998 describes an undocumented security-relevant behavior in sshd, a component of OpenSSH, specifically in versions prior to 10.4, where the GSSAPIStrictAcceptorCheck setting reportedly has no value when the server is operating within a Windows Active Directory environment.
Excelize Unbounded Row Index Allocation Denial-of-Service Vulnerability
1 TTPAn unbounded row index allocation vulnerability (CWE-770) exists in the `checkSheet()` function of the `github.com/xuri/excelize/v2` library, allowing an unauthenticated attacker to craft a malicious XLSX file with a specially crafted row index value that triggers an out-of-memory error or runtime panic, leading to a denial-of-service condition in Go applications processing untrusted spreadsheets.
CPU DoS Vulnerability in libp2p gossipsub
1 TTPA critical vulnerability in the `@libp2p/gossipsub` library allows an unauthenticated attacker to cause a CPU-based Denial of Service by sending oversized IHAVE and IWANT control messages, which are synchronously processed, leading to Node.js event loop exhaustion and service disruption.
Potential System DLL Sideloading From Non System Locations
1 rule 3 TTPsThis brief describes a common defense evasion technique where malicious actors bypass security controls by loading legitimate system DLLs from non-standard directories, enabling arbitrary code execution within trusted processes.
CPython Denial-of-Service Vulnerability
1 TTP 1 CVE 1 IOCA remote denial-of-service vulnerability, CVE-2026-15308, has been discovered in CPython, allowing an attacker to cause service disruption to affected systems not running the latest security patch.
Multiple Python Vulnerabilities Allow Code Execution and DoS
2 TTPsMultiple vulnerabilities in Python allow an attacker to execute arbitrary code or cause a Denial of Service condition, potentially leading to system compromise or service disruption.
Python: Vulnerability Enables File Manipulation
1 TTPAn authenticated remote attacker can exploit a vulnerability in Python to manipulate files, which could lead to unauthorized modification of data or disruption of system integrity across Windows, Linux, and macOS environments.
Tesla Elixir Client Decompression Bomb (CVE-2026-48594)
1 TTP 1 CVEA critical vulnerability, CVE-2026-48594, in the Tesla Elixir HTTP client library allows an attacker to cause a denial of service by serving a specially crafted HTTP response with multiple `content-encoding` headers that, when processed by vulnerable versions (0.6.0 through 1.18.2) of the client using `Tesla.Middleware.DecompressResponse` or `Tesla.Middleware.Compression`, leads to exponential memory expansion and application crashes.
Tesla HTTP Client Library Vulnerable to Atom Exhaustion Leading to Denial of Service (CVE-2026-48597)
1 TTP 1 CVEA high-severity denial-of-service vulnerability (CVE-2026-48597) in the `Tesla.Adapter.Mint` component of the Elixir Tesla HTTP client library, affecting versions 1.3.0 through 1.18.2, allows an unauthenticated attacker to crash the underlying BEAM VM by supplying untrusted URL schemes, leading to atom exhaustion.
Mistune Markdown Parser Vulnerable to CPU Exhaustion DoS (CVE-2026-49851)
1 TTP 1 CVEThe Mistune Python Markdown parser is vulnerable to a CPU exhaustion Denial of Service (DoS) attack, identified as CVE-2026-49851, due to a superlinear (O(n²)) parsing behavior in the `parse_link_text` function when processing specially crafted input containing repeated square brackets, allowing an attacker to significantly degrade application performance with a small payload.
Mint HTTP/2 Client Vulnerable to Unbounded CONTINUATION Frame Accumulation (CVE-2026-49754)
1 TTP 1 CVEA malicious or compromised HTTP/2 server can exploit CVE-2026-49754 in the Elixir Mint HTTP/2 client by sending an endless chain of CONTINUATION frames without an END_HEADERS flag, leading to unbounded memory accumulation, process exhaustion, and remote unauthenticated denial-of-service.
Mint HTTP/2 Client Unbounded Stream Map Growth Denial-of-Service (CVE-2026-48862)
1 TTP 1 CVEA malicious or compromised HTTP/2 server can exploit CVE-2026-48862 in Mint HTTP/2 clients by flooding them with PUSH_PROMISE frames and withholding corresponding HEADERS, leading to unbounded memory consumption and denial-of-service.
CVE-2026-57028: Juniper Junos OS Evolved License Exhaustion via Improper Communication Channel Restriction
2 TTPs 1 CVEA vulnerability, CVE-2026-57028, in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to gain unauthorized access to internal license management processes via an exposed internal port, leading to license exhaustion and ultimately a denial-of-service condition.
CVE-2026-57026 - Improper Validation of SIP Input in Juniper Junos OS Leads to DoS
1 TTP 1 CVEAn unauthenticated, network-based attacker can exploit CVE-2026-57026, an improper input validation vulnerability, in the SIP plugin of Juniper Networks Junos OS. If the SIP ALG is enabled on affected MX Series with SPC3 or SRX Series devices, processing a malformed SIP invite packet will cause the flow processing daemon (flowd) to crash and restart, leading to a complete denial of service until the system recovers.
CVE-2026-57023: Juniper Junos OS TCP Proxy Denial of Service
1 TTP 1 CVEAn Improper Validation of Specified Quantity in Input vulnerability (CVE-2026-57023) in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS) by sending a specifically malformed TCP header packet, crashing the flow processing daemon (flowd) until automated recovery.
Schneider Electric Easergy MiCOM Px40 Series Information Disclosure via Hard-coded Credentials (CVE-2026-4832)
2 TTPs 1 CVESchneider Electric Easergy MiCOM Px40 Series products are vulnerable to CVE-2026-4832, a hard-coded credentials flaw (CWE-798) that allows unauthenticated attackers to interrogate the SNMP port and expose basic device identification information from critical manufacturing, energy, and transportation systems assets globally.
CVE-2026-60109 - Zeek Kerberos Protocol Analyzer Null Pointer Dereference
1 TTP 1 CVEA null pointer dereference vulnerability (CVE-2026-60109) exists in Zeek's Kerberos protocol analyzer before version 8.0.9, allowing unauthenticated remote attackers to crash a Zeek sensor by sending a specially crafted KRB_ERROR message with error-code 25 and specific PA-DATA elements, leading to a denial-of-service condition.
CVE-2026-60108 - Zeek FTP Analyzer Uncontrolled Memory Consumption leading to DoS
1 TTP 1 CVEAn uncontrolled memory consumption vulnerability in the Zeek FTP analyzer, versions prior to 8.0.9, allows unauthenticated remote attackers to cause process termination and denial of service of the Zeek sensor. This occurs when a crafted FTP control session with AUTH GSSAPI and a large ADAT control line exploits the NVT_Analyzer component's lack of a maximum line length check, leading to an unbounded internal buffer during base64 decoding.
AppLocker Audit Events Indicate Potential Policy Violations
1 rule 6 TTPsThis brief describes the detection of Windows AppLocker audit events (Event IDs 8003, 8006, 8021, 8024) that indicate applications, DLLs, scripts, MSIs, or packaged apps would have been blocked by an active AppLocker policy, providing insight into unauthorized software execution attempts or policy violations in audit mode.
Ruby CSS Parser Vulnerable to SSRF and Local File Disclosure via `read_remote_file`
4 TTPsThe `css_parser` library, specifically in versions up to and including 2.2.0, is vulnerable to Server-Side Request Forgery (SSRF) and local file disclosure through improper URI validation in the `CssParser::Parser#read_remote_file` method, allowing attackers to access internal network resources or read local files when processing attacker-controlled CSS.
Soup Sieve Memory Exhaustion via Large Comma-Separated Selector Lists (CVE-2026-49476)
1 TTPA memory exhaustion vulnerability (CVE-2026-49476) in the soupsieve CSS selector parser, an indirect dependency of Beautiful Soup 4, allows an unauthenticated attacker to cause a denial of service by supplying a crafted, large comma-separated CSS selector string to applications using `soupsieve.compile()` or Beautiful Soup's `.select()`/`.select_one()`, leading to unbounded memory allocation and system resource exhaustion.
CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS
2 TTPs 1 CVEA stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.
MailPit: Multiple Vulnerabilities Lead to Denial of Service
1 TTPMultiple vulnerabilities in MailPit allow an attacker to perform a Denial of Service attack against the application, leading to disruption of service for users.
Wazuh Denial of Service Vulnerability
1 TTPA vulnerability in Wazuh allows a remote, authenticated attacker to perform a denial of service attack, which could disrupt the availability of the Wazuh platform.
Multiple Vulnerabilities in Red Hat Enterprise Linux Components libsolv and aardvark-dns
3 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux components libsolv and aardvark-dns could allow an attacker to perform a Denial of Service attack, manipulate data, or disclose confidential information.
Red Hat Enterprise Linux: Golang Component Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Golang components within Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a Denial of Service attack, leading to service disruption.
CVE-2026-59999: OpenSSH sshd Configuration Bypass via PermitTunnel
1 CVEA logic error in OpenSSH's sshd daemon before version 10.4 allowed the PermitTunnel configuration to take precedence over DisableForwarding=yes, leading to unintended SSH tunnel establishment and potential unauthorized network access through the tunnel feature.
OpenSSH sshd Denial-of-Service via GSSAPI Authentication (CVE-2026-60000)
1 CVEA high-severity denial-of-service vulnerability, CVE-2026-60000, affects OpenSSH versions prior to 10.4, allowing remote attackers to exhaust server resources through excessive and mishandled GSSAPI authentication attempts, leading to service unavailability.
CVE-2026-59995: OpenSSH SFTP Arbitrary File Placement Vulnerability
1 CVECVE-2026-59995 describes a vulnerability in the OpenSSH sftp client, specifically versions before 10.4, that allows an attacker to control the location of downloaded files when a user executes 'sftp server:/path .' against an attacker-controlled server, potentially leading to arbitrary file placement and subsequent system compromise.
CVE-2026-59996: OpenSSH scp File Placement Vulnerability
1 CVECVE-2026-59996 details a vulnerability in OpenSSH's `scp` utility, allowing a remote attacker to cause a copied file to be placed in a parent directory of the intended destination during a remote-to-remote transfer, potentially leading to unintended file system modification.
OpenSSH internal-sftp Vulnerability (CVE-2026-59997) Allows Security Property Bypass
1 CVECVE-2026-59997 describes a vulnerability in the internal-sftp component of OpenSSH's sshd service, affecting versions before 10.4, where the service only processes the first nine command-line arguments, potentially leading to a bypass of security controls or unintended configuration.
Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification
1 TTPMultiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.
CVE-2026-47241: Net::IMAP Denial of Service Vulnerability
1 CVEA Denial of Service vulnerability, identified as CVE-2026-47241, exists in the Net::IMAP library due to incomplete raw argument validation, potentially allowing an attacker to cause an application crash or unresponsiveness.
Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover
3 TTPs 1 CVEThe Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.
Detection of Failed WMI Event Log Clear Attempts
1 rule 1 TTPThis brief details the detection of failed attempts by an adversary to clear Windows event logs using the WMI `ClearEventLog` method, indicating an unsuccessful defense impairment action due to insufficient privileges or other issues.
CVE-2026-59803: rpcx Denial-of-Service Vulnerability
1 TTP 1 CVEA denial-of-service vulnerability (CVE-2026-59803) in rpcx through version 1.9.3 allows an unauthenticated attacker to trigger out-of-memory conditions and service unavailability by sending a small, compressed message that expands to gigabytes of memory during decompression.
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
3 TTPsAn XML injection vulnerability (CVE-2026-0284) in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI
3 TTPsA command injection vulnerability, CVE-2026-0286, in the management plane of Palo Alto Networks PAN-OS software allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series) devices, potentially leading to high system compromise.
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
3 TTPsA server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-0285, exists in the management web interface of Palo Alto Networks PAN-OS software, allowing an authenticated administrator with network access to make unauthorized requests from the firewall to internal services, potentially leading to information disclosure or further network compromise.
CVE-2026-0283: Authentication Bypass in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN)
1 TTPAn authentication bypass vulnerability, CVE-2026-0283, in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to establish an unauthorized site-to-site VPN connection when LSVPN functionality with configured satellites is enabled, leading to potential access to internal network resources.
CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
1 TTPCVE-2026-0278 describes multiple protection mechanism failures in the Prisma Access Agent's Data Loss Prevention (DLP) component for Windows, allowing a local user to bypass DLP policy enforcement controls and exfiltrate sensitive data on affected versions prior to 26.2.1.
CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS
1 TTPAn improper certificate validation vulnerability (CVE-2026-0277) in the Prisma Access Agent for iOS, affecting versions prior to 26.2.1, enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic, leading to potential compromise of data confidentiality and integrity.
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
1 TTPMultiple denial of service vulnerabilities, tracked as CVE-2026-0287, in Palo Alto Networks PAN-OS software allow an unauthenticated attacker to cause a DoS condition by sending specially crafted network traffic, potentially forcing the firewall into maintenance mode.
CVE-2026-56250: Capgo R2 Bundle Object Deletion via Mutable r2_path
2 TTPs 1 CVE 2 IOCsA critical vulnerability, CVE-2026-56250, in Capgo before version 12.128.2 allows an authenticated attacker with upload-scoped API keys to manipulate the app_versions.r2_path field via PostgREST, leading to arbitrary R2 bundle object deletion and denial of service.
Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.
New Abuse of ClickOnce Technology: Understanding Internals
2 TTPsCrowdStrike details the internal mechanisms of Microsoft's ClickOnce technology, a legitimate software deployment method that offers minimal user interaction and no administrative privilege requirements, making it a double-edged sword with significant potential for threat actor abuse in malware distribution and persistence.
CrowdStrike Uncovers New Prompt Injection Techniques
5 TTPsCrowdStrike has identified 18 new prompt injection techniques, expanding its taxonomy to over 200 methods, which enable adversaries to manipulate AI systems and agents through hidden context, delayed triggers, semantic constraints, boundary spoofing, and social engineering to bypass security measures, leading to modified behavior, data exfiltration, or malicious command execution in AI-driven applications and agents like chatbots or those running in Kubernetes.
CrowdStrike Uncovers New Prompt Injection Techniques Targeting AI Agents
6 TTPsAdversaries are leveraging sophisticated prompt injection techniques, including hidden rules, token suppression, payload decomposition, and special token injection, against AI agents to manipulate their behavior, bypass safety mechanisms, and achieve objectives such as data exfiltration or arbitrary command execution, posing a critical threat to AI-powered systems.
AI Agents Mimic Adversarial Behavior, Triggering Security Detections
9 TTPs 9 IOCsAI coding agents such as Claude Code, Cursor, Codex, and GStack are increasingly exhibiting behaviors on Windows endpoints that mimic adversarial tradecraft, including credential access, LOLBin usage for ingress, command-line obfuscation, and persistence mechanisms, thereby triggering existing security detection rules designed for malicious activity and posing significant false positive challenges for detection engineers.
Multiple Vulnerabilities in Postfix Mail Server
1 TTP 1 IOCMultiple vulnerabilities have been identified in various versions of the Postfix mail server, potentially allowing an attacker to cause a denial of service (DoS) and other unspecified security issues, requiring immediate patching across affected installations.
Multiple Vulnerabilities in PHP (CVE-2026-12184, CVE-2026-14355)
1 CVEMultiple critical vulnerabilities (CVE-2026-12184, CVE-2026-14355) have been discovered in various PHP versions, allowing an attacker to cause an unspecified security issue, as reported by CERT-FR on July 7, 2026.
Hashicorp Terraform: Information Disclosure Vulnerability
1 TTPA vulnerability in Hashicorp Terraform allows a remote, authenticated attacker to disclose sensitive information, which could lead to the exposure of confidential data.
Detecting Hostile Prompt Sentiment in AWS Bedrock Claude
1 ruleThis brief outlines the detection of hostile or aggressive prompt sentiment sent to AWS Bedrock Claude large language models, indicating potential abuse, harassment, or attempts at model manipulation, requiring the configuration of Bedrock model invocation logging and Splunk ingestion.
Detecting Linux Payload Downloaded and Piped to Interpreter
1 rule 2 TTPsThis brief details a common Linux technique where attackers use scripting interpreters to download malicious payloads from external sources and immediately pipe them into another interpreter for execution, often for purposes like persistence or data exfiltration.
Suspicious XDG-Open Command Execution on Linux
1 rule 2 TTPsThis brief details a detection rule for the `xdg-open` command on Linux systems, which attackers abuse to trick users into opening malicious documents or URLs, leading to user execution and potential system compromise.
Shell Execution via Elastic Endpoint on Linux
1 rule 3 TTPsThis brief details the detection of shell command execution initiated by the Elastic Endpoint agent on Linux systems, indicating potential post-exploitation activity such as remote access or command and control via misuse of the endpoint's response capabilities.
GKE Pod Created With HostIPC Sharing
1 rule 2 TTPsA privilege escalation threat in Google Kubernetes Engine (GKE) involves an attacker creating or modifying a pod to enable host Inter-Process Communication (IPC) namespace sharing, which exposes host IPC mechanisms and can lead to privilege escalation within the cluster by allowing the pod to interact directly with the underlying host's processes.
Linux Shared Object Load via LoLBin
1 rule 3 TTPsAdversaries can leverage Living Off The Land Binaries (LoLBins) such as `openssl`, `python`, or `ruby` to load malicious shared object files (`.so`) into memory on Linux systems, aiming to evade detection by disguising the payload as legitimate process activity; detection engineers must investigate the full command line, parent process chain, executing user, and the reputation/location of the referenced shared object file to differentiate malicious activity from legitimate development or administration tasks.
Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes
1 rule 193 IOCsThis brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.
Multiples vulnérabilités dans OpenSSH
2 TTPsMultiple vulnerabilities in OpenSSH versions prior to 10.4 allow attackers to bypass security policies, cause denial of service, and exploit other unspecified security issues, requiring users to update to OpenSSH 10.4 or later.
dhcpcd Denial of Service Vulnerability
1 TTPA vulnerability in the dhcpcd DHCP client daemon allows an attacker from an adjacent network to execute a Denial of Service attack, potentially disrupting network connectivity on affected Linux systems.
Kubernetes Secret Access by Node or Pod Service Account
1 rule 1 TTPAttackers who have compromised a Kubernetes pod or node are observed attempting to `get` or `list` Kubernetes Secret objects via the API, a common post-compromise technique by various threat actors to achieve credential access and gather sensitive information such as tokens, registry credentials, TLS keys, or application configurations.
CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service
1 TTP 1 CVEAn authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.
Potential DNS Exfiltration via Excessive Chunked Queries
1 rule 2 TTPsThis brief details the technique of DNS exfiltration where threat actors use chunked DNS queries with subdomain labels following an 'index-payload.base_domain' pattern to exfiltrate data from compromised Windows hosts, allowing them to bypass volume-based detection and extract sensitive information.
Detecting Potential ICMP Tunneling Activity for Covert C2 and Exfiltration
1 rule 2 TTPsThis brief describes a critical network threat where attackers leverage ICMP tunneling, a technique to embed command and control (C2) or exfiltrated data within large ICMP Echo payloads, enabling covert communication channels that bypass traditional firewall rules, posing a significant risk of data theft and unauthorized system control.
Detection of Deprecated TLS Version or Weak Cipher Negotiated Externally
1 rule 2 TTPsThis rule identifies successful outbound TLS sessions initiated by internal hosts to external destinations that utilize deprecated protocol versions (SSLv3, TLS 1.0, TLS 1.1) or weak cipher suites such as RC4, 3DES, NULL, EXPORT, or anonymous Diffie-Hellman. Such negotiations can indicate an Adversary-in-the-Middle attack or communication with legacy malware, allowing for traffic interception or decryption. Detection engineers should investigate the `source.ip`, `destination.ip`, `tls.version`, and `tls.cipher` to determine if the destination is a legitimate legacy system or a potential compromise, checking for concurrent alerts on the source host.
Potential DHCP Starvation via High Client MAC Cardinality
1 TTPAttackers utilize DHCP starvation by flooding network segments with DHCP DISCOVER messages containing a high cardinality of distinct client MAC addresses to exhaust the DHCP lease pool, potentially leading to denial of service for legitimate clients and facilitating rogue DHCP server deployment.
Suspicious Java Execution from User-Writable Paths with DNS Lookup
1 rule 3 TTPsThis brief describes the detection of suspicious `javaw.exe` execution on Windows systems by adversaries leveraging recently dropped or modified Java payloads from user-writable directories (e.g., `Users`, `ProgramData`, `Windows\Temp`) to establish command and control via immediate DNS lookups, thereby evading application control mechanisms.
AWS Lambda Event Source Mapping Abuse for Persistence and Data Exfiltration
1 rule 3 TTPsAdversaries can exploit the creation of AWS Lambda event source mappings to establish stealthy persistence and execution, or to continuously siphon records from event sources like Amazon SQS, Kinesis, DynamoDB, MSK, Kafka, or MQ, by mapping an event source to an attacker-controlled Lambda function, enabling durable execution and data exfiltration without requiring further interactive access.
AWS Lambda Function Deletion
1 rule 2 TTPsAdversaries may delete AWS Lambda functions to disrupt business operations, remove evidence of their presence, or impede incident response, an action detectable by monitoring for `DeleteFunction` calls in `aws.cloudtrail` logs and correlating with expected change windows.
AWS Lambda Layer Shared Externally
1 rule 2 TTPsThis brief identifies the critical risk of an AWS Lambda layer's permission policy being modified, typically via the `AddLayerVersionPermission` API, to grant external AWS accounts, AWS Organizations, or the public access, potentially leading to the leakage of proprietary code or secrets and creating a supply-chain vector for attacker-influenced code execution in downstream functions.
Systemd Service Override Configuration File Creation for Persistence
1 rule 2 TTPsAttackers can leverage the creation or renaming of Systemd override configuration files in standard or user service directories to achieve persistence or privilege escalation on Linux systems, altering service behavior to execute malicious commands during system startup or at predefined intervals via timers, thereby maintaining unauthorized access or evading detection.
VNC (Virtual Network Computing) to the Internet
1 rule 2 TTPsThis brief details the risk of VNC (Virtual Network Computing) traffic originating from internal networks and destined for the internet, indicating potential unauthorized access or a backdoor, as VNC is frequently exploited by threat actors when exposed externally via specific TCP ports (5800-5810).
BadPatch Malware Using SMTP on Port 26 for Command and Control
1 rule 3 TTPsThe BadPatch malware family utilizes SMTP on TCP port 26 for covert command and control of Windows systems, an atypical port for SMTP, posing a significant risk of unauthorized access and data exfiltration.
AWS Lambda Function Invoked by Unusual Principal
1 rule 1 TTPDetects the first direct invocation of an AWS Lambda function by a principal within a 14-day period, excluding AWS service invocations, which can indicate adversary lateral movement, credential abuse, or unauthorized data retrieval in AWS environments.
AWS Lambda Function Invoked from Unusual Source ASN
1 rule 1 TTPAttackers are abusing stolen AWS execution-role or user credentials to invoke AWS Lambda functions from unusual source networks (ASNs) not previously associated with the legitimate principal, indicating a credential compromise leading to potential unauthorized access or data exfiltration.
AWS KMS Imported Key Material Deleted
1 rule 1 TTPAdversaries leverage the `DeleteImportedKeyMaterial` API call against AWS KMS customer managed keys (CMKs) with external material, instantly rendering encrypted data inaccessible with no recovery window, facilitating cloud ransomware or data destruction attacks.
AWS Lambda Function Invoked Cross-Account
1 TTPAdversaries leverage cross-account access to invoke AWS Lambda functions from a different account than the function owner, enabling code execution or data retrieval, which requires AWS Lambda data event logging to detect.
AWS IAM Permissions Boundary Modification for Privilege Escalation
1 rule 1 TTPAn adversary can achieve privilege escalation within an AWS environment by modifying or removing an existing IAM permissions boundary on an IAM user or role, thereby unlocking previously restricted permissions defined in attached identity policies.
AWS IAM Inline Policy Added to a Group
1 rule 2 TTPsAdversaries can escalate privileges and establish persistence within AWS by leveraging the `PutGroupPolicy` API call to attach an inline policy to an IAM group, granting broad permissions to all group members, including themselves.
IPSEC NAT Traversal Port Activity Used for Command and Control
1 rule 3 TTPsA detection rule identifies suspicious outbound IPSEC NAT Traversal (NAT-T) tunnels, characterized by UDP traffic where both source and destination ports are 4500, originating from an internal host to an external destination, a technique frequently abused by threat actors to establish covert command and control channels or exfiltrate data while evading network defenses.
AWS IAM Login Profile Created or Modified for an IAM User
1 rule 1 TTPThis rule detects the creation or modification of console login profiles for AWS IAM users via the CreateLoginProfile or UpdateLoginProfile APIs. Adversaries with stolen programmatic credentials can use these actions to establish persistent interactive console access, reset other users' passwords to take over accounts, and maintain access even after original access keys are rotated. Since IAM user console access is increasingly managed through federation or IAM Identity Center, direct use of these APIs, especially by unexpected principals, warrants investigation as a strong indicator of persistence or account compromise.
Interactive File Download in Linux Containers via Curl/Wget Detected
1 rule 3 TTPsAn Elastic Defend for Containers rule detects interactive sessions within Linux containers where `curl` or `wget` are used to download files from the internet, indicating potential adversary command and control or execution activity as threat actors often use such methods to stage payloads, tools, or data for subsequent malicious actions within compromised containerized environments.
Suspicious Activity: Multiple Remote Management Tool Vendors on Same Host
1 TTPThis brief describes a behavioral detection for Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tools from different vendors are observed starting processes within an eight-minute window, indicating potential compromise, shadow IT, or attacker staging of redundant access.
AWS IAM User Console Login from Multiple Geolocations
2 TTPsAdversaries leverage adversary-in-the-middle (AiTM) phishing and session theft to compromise AWS IAM user credentials, leading to concurrent successful AWS Management Console logins from multiple distinct geographic locations, indicating account compromise and enabling unauthorized access to cloud resources despite MFA.
AWS ECR Repository or Registry Policy Granted Public Access
1 rule 1 TTPA malicious actor or misconfigured legitimate user can modify an Amazon ECR repository or registry policy to grant public access using a wildcard principal (`Principal:"*"`), which can lead to the exfiltration of proprietary container images and embedded secrets, or facilitate supply-chain implantation if push permissions are also granted.
First Time Seen Remote Monitoring and Management Tool Detection
1 rule 3 TTPs 5 IOCsAdversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.
Detecting Malicious Kernel Module Loading via Built-in Utilities on Linux
1 rule 1 TTPThreat actors with root privileges can leverage built-in Linux utilities like `insmod` or `modprobe` to load kernel object files, often for installing rootkits that grant complete system control and enable evasion of security products, representing a significant persistence and defense evasion technique.
Web Server Cloud Metadata SSRF Exploitation
1 rule 2 TTPs 7 IOCsAttackers are actively exploiting Server-Side Request Forgery (SSRF) vulnerabilities in public-facing web applications to access cloud instance metadata services, such as those on AWS, GCP, and Azure, to harvest temporary credentials and sensitive instance details.
Detection of Sysmon Configuration Updates for Defense Evasion
1 ruleThis brief describes how to detect an attacker updating or replacing the Sysmon configuration with a bare bones one to avoid monitoring without completely shutting down the service, leveraging Sysmon's `-c` command-line option for defense impairment.
Linux Container Escape via Kernel core_pattern Modification
1 rule 1 TTPAttackers can exploit a Linux kernel vulnerability allowing a process inside a container to modify the `/proc/sys/kernel/core_pattern` file, enabling the execution of arbitrary code as root on the host system upon a core-dump, thereby achieving a full container-to-host escape and privilege escalation.
Suspicious Linux C2 Activity: Network Connection Followed by File Creation
2 rules 2 TTPsThis brief identifies suspicious Command and Control (C2) activity on Linux systems where a C2 agent, such as Poseidon or Athena, connects outbound from a sensitive temporary directory and subsequently creates a file in a similar location, indicative of receiving and executing commands from a C2 framework like Mythic.
Unusual File Download From File Sharing Websites - File Stream
1 rule 3 TTPsThis brief details the detection of suspicious file types (batch, command, PowerShell scripts) downloaded from well-known public file and paste sharing domains, leveraging the `Zone.Identifier` Alternate Data Stream to signal potential malware delivery or covert data transfer, which could lead to system compromise and data exfiltration.
Application Removal Via Wmic.EXE
1 rule 1 TTPAdversaries are leveraging the Windows Management Instrumentation Command-line (WMIC) utility, `wmic.exe`, to uninstall legitimate or security applications as a method of defense evasion and system impact within Windows environments.
Application Termination Attempt via Wmic.EXE
1 rule 2 TTPsAdversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to terminate applications, specifically security products, as a defense evasion technique.
Registry Manipulation via WMI Stdregprov for Evasion
1 rule 3 TTPsAttackers are leveraging `wmic.exe` to modify the Windows registry through the WMI `StdRegProv` class, specifically using methods like `CreateKey` and `SetStringValue`, to evade detection and bypass traditional security monitoring focused on `reg.exe` or `regedit.exe`.
Detection of Service Manipulation via WMIC.exe
1 rule 1 TTPThis brief describes the detection of adversaries leveraging the native Windows Management Instrumentation Command-line (WMIC.exe) utility to start or stop services on compromised Windows systems, a common technique for persistence, privilege escalation, or lateral movement.
WMIC Remote Command Execution Detection
1 rule 1 TTPThis brief focuses on detecting the abuse of the Windows Management Instrumentation Command-line (WMIC) utility to execute commands or query information on remote systems, a common technique used by attackers for lateral movement and reconnaissance within compromised networks.
System Disk And Volume Reconnaissance Via Wmic.EXE
1 rule 2 TTPsThreat actor Volt Typhoon is observed using the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility to perform system and volume discovery, gathering critical system information that can facilitate further network exploitation and data exfiltration.
Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
1 rule 2 TTPs 1 CVEAttackers and pentesters commonly use `wmic.exe` to query Windows service configurations for unquoted paths, a reconnaissance technique that identifies potential privilege escalation opportunities.
Uncommon WMIC System Information Discovery by Aurora Stealer
1 rule 1 TTPAurora Stealer has been observed using the Windows Management Instrumentation Command-line (WMIC) utility to perform extensive system reconnaissance, gathering details like OS version, CPU, GPU, disk drives, memory, and display resolution, indicating early-stage information gathering for subsequent data exfiltration or malware deployment.
Service Reconnaissance Via Wmic.EXE
1 rule 1 TTPAdversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to perform service reconnaissance on remote systems, querying for existing services as a prelude to identifying potential targets for lateral movement or privilege escalation.
Potential Product Class Reconnaissance Via Wmic.EXE
1 rule 2 TTPsAdversaries are leveraging `wmic.exe` on Windows systems to perform reconnaissance, specifically enumerating installed antivirus, antispyware, and firewall products to aid in evasion and subsequent attack planning, posing a medium risk to affected organizations.
WMIC Product Reconnaissance for Defense Evasion
1 rule 2 TTPsA threat brief details the use of `wmic.exe` by attackers to perform product reconnaissance, specifically to identify installed firewall and antivirus software, facilitating defense evasion and tailored attack execution.
Potential Process Reconnaissance via Wmic.EXE
1 rule 2 TTPsAdversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility with the 'process' flag to perform discovery of running processes on compromised systems, enabling further stages of attack such as privilege escalation or lateral movement.
Windows Hotfix Updates Reconnaissance Via Wmic.EXE
1 rule 1 TTPAttackers and pentesters utilize `wmic.exe` with the 'qfe' flag to enumerate installed hotfix updates on Windows systems, a common reconnaissance technique often preceding privilege escalation.
Hardware Model Reconnaissance Via Wmic.EXE
1 rule 6 TTPsAdversaries leverage the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility with the `csproduct` command to perform hardware model and vendor reconnaissance on target systems, a technique observed in campaigns utilizing infostealers like Kuraystealer, enabling further tailored attacks.
Computer System Reconnaissance Via Wmic.EXE
1 rule 1 TTPThis brief details the use of `wmic.exe` with the `computersystem` flag for reconnaissance, a technique observed in campaigns by adversaries such as DEV-0270 (Phosphorus), to gather system information like domain, username, and model.
Process Creation Attempt via Wmic.EXE
1 rule 1 TTPAdversaries utilize the `wmic.exe` utility on Windows systems to create and execute processes, a technique detected by observing specific command-line arguments, indicating an attempt to run malicious code on compromised hosts.
Suspicious Use of PsLogList for Event Log Discovery and Evasion
1 rule 3 TTPsAdversaries are leveraging the legitimate Sysinternals utility PsLogList to perform account and system discovery by dumping Windows event logs, and for defense evasion by clearing or exporting these logs, increasing their ability to operate undetected and further compromise systems.
Suspicious Service Installation for Defense Evasion
1 ruleAttackers are installing suspicious services, specifically NalDrv or PROCEXP152, via registry modifications to non-system32 folders to facilitate defense evasion by tools like Ghost-In-The-Logs, aiming to disable or impair security monitoring capabilities.
Abuse of Microsoft Sysinternals PsSuspend Utility
1 rule 4 TTPsUnidentified threat actors may leverage the legitimate Microsoft Sysinternals PsSuspend utility to suspend critical processes on Windows systems, enabling evasion of security controls or disruption of operations.
Detection of Sysinternals PsService Execution
1 rule 3 TTPsThis brief details the detection of Sysinternals PsService, a legitimate utility that can be abused by threat actors for service reconnaissance, manipulation, and persistence on Windows systems, potentially leading to privilege escalation or system disruption.
Procdump Execution Detection
1 rule 1 TTPThis brief details the detection of Procdump, a legitimate Sysinternals utility, which is frequently abused by attackers for credential dumping from sensitive processes like LSASS, enabling privilege escalation and lateral movement on Windows systems.
Permission Check Via Accesschk.EXE
1 rule 1 TTPAttackers are abusing the legitimate Sysinternals `Accesschk.exe` utility to perform permission discovery on Windows systems, a common step in privilege escalation attacks, allowing them to identify misconfigurations for gaining higher privileges.
Detecting Suspicious GrantedAccess Flags on LSASS
1 rule 2 TTPsThis brief details a detection for potentially suspicious `GrantedAccess` flags when a process attempts to access `LSASS.exe`, indicating possible credential dumping attempts by adversaries, which can lead to lateral movement and privilege escalation on Windows systems.
Suspicious CredUI.DLL Loading by Uncommon Processes
1 rule 1 TTPAttackers may attempt to load the Windows Credential UI DLL (credui.dll) from an unusual or non-standard process to capture or access user credentials, facilitating credential theft and further malicious activity on a compromised system.
Suspicious Process Monitor Driver Creation by Non-Sysinternals Binary
1 rule 2 TTPsThis brief details a detection strategy for malicious actors attempting to establish persistence or elevate privileges by creating a Process Monitor driver file (`.sys`) from an unauthorized process, indicating potential kernel-level compromise on Windows systems.
Suspicious PROCEXP152.sys Driver Creation in Temporary Folders
1 ruleThis brief details the suspicious creation of the PROCEXP152.sys driver file, associated with Sysinternals Process Explorer, in temporary application data folders, a technique leveraged by tools like KDU and Ghost-In-The-Logs for defense evasion and bypassing Windows Event Logging on affected Windows systems.
Potential Privileged System Service Operation - SeLoadDriverPrivilege
1 rule 2 TTPsThis brief details the detection of `SeLoadDriverPrivilege` usage on Windows systems, a critical privilege enabling attackers to load malicious kernel drivers for advanced defense evasion and privilege escalation, leading to full system compromise.
Potentially Suspicious AccessMask Requested From LSASS
1 rule 1 TTPThis brief describes the detection of suspicious access mask requests to the Local Security Authority Subsystem Service (LSASS) process, a common post-exploitation technique used by threat actors for credential dumping on Windows systems.
New Agent Skills Installation Attempt Via Node.EXE
1 rule 1 TTPA new detection identifies the use of `npx skills add` commands via `node.exe` on Windows systems, a potentially abusable mechanism for attackers to install malicious AI agent skills or 'skill worms' that can execute arbitrary commands and infect infrastructure.
FortiGate User Group Modification Detected
1 rule 2 TTPsAn attacker with initial access to a Fortinet FortiGate firewall may modify existing user groups to establish persistence or elevate privileges, potentially granting unauthorized VPN access to internal networks.
FortiGate - New VPN SSL Web Portal Added
1 rule 2 TTPsThis brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.
FortiGate - New Local User Creation Detection
1 rule 1 TTPThis brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.
FortiGate - New Firewall Policy Added
1 rule 1 TTPThis brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.
Detection of FortiGate Firewall Address Object Addition
1 ruleThis brief details the detection of firewall address objects being added on Fortinet FortiGate devices, a configuration change that, while potentially legitimate, can also indicate post-compromise activity or unauthorized access, especially when tied to vulnerabilities like FG-IR-24-535, enabling threat actors to bypass security controls or facilitate command and control.
FortiGate - New Administrator Account Created
1 rule 1 TTPThis brief describes how to detect the creation of new administrator accounts on Fortinet FortiGate firewalls, a behavior often used by attackers for persistence (ATT&CK T1136.001) or to maintain unauthorized access after initial compromise.
Suspicious User-Agents Related To Recon Tools
1 rule 3 TTPsThis brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.
Potentially Suspicious WDAC Policy File Creation
1 rule 1 TTPAttackers may create Windows Defender Application Control (WDAC) policy files from abnormal processes to bypass Endpoint Detection and Response (EDR) or Antivirus (AV) solutions while allowing their own malicious code to execute on compromised Windows systems, impacting defense capabilities.
Suspicious PowerShell Start-Process with PassThru for Stealth Execution
1 rule 1 TTPThis brief details a PowerShell defense evasion technique where adversaries utilize the `Start-Process` cmdlet with the `-PassThru` parameter to execute commands or programs in a hidden, background manner, enabling covert persistent access or malicious payload execution on Windows systems.
Splunk User Enumeration Attempt Detection
1 TTP 1 CVEAn attacker is attempting to enumerate valid Splunk usernames by repeatedly submitting failed authentication attempts from a single source, as detected by monitoring the `_audit` index for multiple login failures, which is a precursor to credential-based attacks like password spraying or brute force, potentially leading to unauthorized access and sensitive data exposure.
Windows Process Injection With Public Source Path
1 rule 1 TTPThis brief details a hunting analytic that detects process injection attempts on Windows systems using the CreateRemoteThread technique (Sysmon Event ID 8), often employed by advanced malware like Brute Ratel C4 to evade detection and escalate privileges, by monitoring processes originating from non-standard file paths.
Windows Autostart Persistence via Startup Folder
1 rule 2 TTPsAdversaries commonly leverage file creation in the Windows `%startup%` folder (T1547.001) to establish persistence, ensuring malicious code executes automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.
@conform-to/dom Vulnerable to CPU Exhaustion via Crafted Form Submissions
A CPU exhaustion vulnerability (CVE-2026-49250) exists in Conform's `parseSubmission` API when parsing `FormData` or `URLSearchParams` with many unique field names, allowing an attacker to craft a submission that causes excessive synchronous CPU work and potential denial of service by repeatedly scanning submitted entries.
Zebra Block Suppression Vulnerability (CVE-2026-52736) via P2P Body Poisoning
2 TTPsA remote unauthenticated attacker can exploit CVE-2026-52736 in Zebra's `zebrad` node (versions up to and including `v4.4.1`) to permanently stall a targeted blockchain node by poisoning its sent-hash cache, leading to a denial of service.
JSONata $toMillis Function Vulnerability Leads to Denial of Service (CVE-2026-52746)
1 TTPA high-severity vulnerability, CVE-2026-52746, in JSONata versions prior to 2.2.0 allows unauthenticated attackers to cause a denial of service by exploiting superlinear backtracking in the ISO-8601 validation regex through malicious inputs to the `$toMillis` function, leading to resource exhaustion and application unresponsiveness.
Zebra Node Denial-of-Service via IPv4-Mapped Mempool Misbehavior Panic (CVE-2026-52829)
1 TTPA remote unauthenticated peer can exploit an address normalization mismatch in Zebra's address book when connecting via IPv4 to a dual-stack IPv6 listener on a Linux host, by then advertising an invalid mempool transaction, which triggers a deterministic assertion panic after a 30-second delay, causing the `zebrad` process to terminate, leading to persistent denial of service.
SimpleSAMLphp Vulnerable to Denial-of-Service via Malicious XPath Transform
1 TTPSimpleSAMLphp and its SAML2 library are vulnerable to CVE-2026-49289, allowing attackers to perform a Denial-of-Service attack by sending specially crafted SAML messages containing XPath transforms, leading to resource exhaustion and service unavailability.
Steeltoe.Discovery.Eureka Deserialization Denial-of-Service (CVE-2026-50196)
1 CVEThe Steeltoe.Discovery.Eureka client contains a vulnerability (CVE-2026-50196) where its `DataCenterInfo.FromJson` method throws an `ArgumentException` if a `DataCenterInfo.name` value other than 'MyOwn' or 'Amazon' is encountered, specifically missing the valid 'Netflix' value from the Java Eureka specification, which causes the local service registry to become permanently empty or stale, leading to a complete service discovery outage for all connected Steeltoe Eureka clients.
dnsmasq Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in dnsmasq to initiate a Denial of Service attack, disrupting the service's availability.
ClamAV Vulnerabilities Lead to Denial of Service in Cisco Secure Endpoint Products
1 TTP 7 CVEsMultiple vulnerabilities (CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244) in ClamAV, as integrated into Cisco Secure Endpoint Connector, allow a remote attacker to cause a denial of service (DoS) condition by interrupting scanning operations, with a High severity impact on Windows platforms and Medium on Linux/Mac.
CVE-2026-56081: Cap-go Authentication Logic Flaw Leading to Account Takeover
2 rules 2 TTPsAn authentication logic flaw in Cap-go versions prior to 12.128.2 allows attackers to register an account with a victim's unverified email address, then enable two-factor authentication on this pre-registered account to gain full control, read/modify data, enforce organization-level policies, and deny the legitimate user access.
Azure VM Managed Run Command Abuse for Execution and Persistence
2 rules 1 TTPAdversaries can abuse the Azure VM Managed Run Command feature (MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMANDS/WRITE) to achieve code execution as System or root and establish persistence on Azure Virtual Machines or Virtual Machine Scale Sets by an unusual identity, potentially evading detections focused solely on action-based Run Commands.
undici WebSocket Client Vulnerable to Denial of Service (CVE-2026-12151)
2 rules 1 TTPThe `undici` WebSocket client is vulnerable to CVE-2026-12151, a high-severity denial of service attack where a malicious WebSocket server can stream numerous small continuation frames that bypass `maxPayloadSize` checks, causing unbounded memory growth and exhaustion in affected client processes.
Vim Denial of Service Vulnerability
2 rules 1 TTPA vulnerability in the vim text editor allows a remote, unauthenticated attacker to perform a Denial of Service attack by exploiting a weakness to disrupt the service without requiring prior authentication.
libssh2 Vulnerability: Denial of Service and Information Disclosure
3 rules 2 TTPsA vulnerability in the libssh2 library allows a remote, unauthenticated attacker to perform a Denial of Service (DoS) attack or disclose sensitive information, potentially leading to service disruption or unauthorized data exposure.
Multiple Vulnerabilities in expat XML Parser Library
2 rules 2 TTPsMultiple vulnerabilities have been discovered in the expat XML parser library that can be exploited by a local attacker, potentially leading to a Denial of Service condition or allowing for arbitrary code execution on the affected system.
OpenBSD Information Disclosure Vulnerability
3 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in OpenBSD to disclose sensitive information, potentially leading to unauthorized data exposure.
PHP JWT Library PBES2-HS*+A*KW Unbounded p2c Iteration Count Leads to DoS
2 rules 1 TTPAn unauthenticated attacker can exploit a vulnerability in the PHP JWT Library's PBES2AESKW::unwrapKey() function when processing JWE tokens that use PBES2-HS*+A*KW algorithms by crafting a JWE with an excessively large 'p2c' (PBKDF2 iteration count) parameter in the JOSE header, forcing the server to perform an unbounded and CPU-intensive PBKDF2 computation, resulting in a CPU-amplification denial of service.
spomky-labs/otphp Unbounded Digits Parameter Leads to Denial of Service
2 rules 1 TTPThe spomky-labs/otphp library is vulnerable to a denial of service (GHSA-g7m4-839x-ch6v) where an unbounded 'digits' parameter in an otpauth provisioning URI causes a DivisionByZeroError, leading to unhandled fatal errors in applications trying to generate or verify OTPs.
Azure VM Serial Console Exploitation for Lateral Movement
3 rules 2 TTPsAdversaries with privileged Azure RBAC roles are exploiting the Azure VM Serial Console to gain SYSTEM/root access on virtual machines, bypassing network controls like NSGs and JIT policies, with detections focusing on unusual user and source network combinations.
CVE-2026-55204: HAProxy Null Pointer Dereference Leads to Denial of Service
2 rules 1 TTPAn unauthenticated attacker can exploit CVE-2026-55204, a null pointer dereference vulnerability in HAProxy through version 3.4.0, by triggering excessive HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash and resulting in a denial of service.
Entra ID OAuth Application Redirect URI Modified
2 rules 2 TTPsAdversaries are modifying OAuth application redirect URIs (ReplyUrls) in Microsoft Entra ID to intercept OAuth authorization codes and steal tokens, granting unauthorized access without new application registration or user consent.
Microsoft Entra ID Guest Account Promoted to Member
1 rule 1 TTPA sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.
Google Workspace Custom Admin Role Created for Persistence
1 rule 2 TTPsAdversaries may create custom administrative roles in Google Workspace to establish persistence with tailored, elevated permissions, which are then assigned to compromised or attacker-controlled accounts to bypass security controls, grant OAuth access, or modify mail routing.
Google Workspace Admin Role Deletion
2 rules 2 TTPsAdversaries with elevated privileges within Google Workspace may delete custom administrative roles to impede security operations, remove delegated administrator access, or obfuscate their activities during an active incident, leading to disrupted delegated administration, loss of security team access, or hindrance of incident response efforts.
Pipecat Telephony Runner Unauthenticated Call-Control Abuse
1 rule 3 TTPs 3 IOCsAn unauthenticated remote attacker can leverage a missing authorization vulnerability (CWE-862) in the Pipecat development runner's `/ws` WebSocket endpoint to supply a crafted `callSid` in a handshake message, compelling the server to use its configured Twilio, Telnyx, or Plivo credentials to issue authenticated API requests that terminate active calls, resulting in denial of service and credential abuse.
Multiple Vulnerabilities in Microsoft Edge Allow Security Policy Bypass
2 rules 2 TTPs 5 CVEs 48 IOCsMultiple vulnerabilities, including CVE-2026-10883, CVE-2026-10892, and others, have been discovered in Microsoft Edge versions prior to 149.0.4022.53, enabling an attacker to bypass security policies and potentially cause other unspecified security issues within the browser environment.
Multiple Vulnerabilities in Microsoft .Net (CVE-2026-45491, CVE-2026-45591)
2 rules 2 TTPs 2 CVEsMultiple vulnerabilities, CVE-2026-45491 and CVE-2026-45591, have been discovered in Microsoft .Net and ASP.NET Core versions, allowing a remote attacker to cause a denial of service and compromise data integrity across Windows, Linux, and macOS platforms.
Kimsuky APT Domains and URLs from Maltrail Feed
2 rules 2 TTPs 50 IOCsThis brief summarizes newly published IOCs consisting of domains and URLs associated with the Kimsuky APT group as of June 2nd, 2026, sourced from a Maltrail feed.
FreePBX Hardcoded Credentials Vulnerability (CVE-2026-46376)
2 rules 1 TTP 1 CVEA critical vulnerability, CVE-2026-46376, exists in FreePBX due to the use of hard-coded credentials in the User Control Panel (UCP) generic template setup process, allowing an unauthenticated, remote attacker to gain unauthorized access to user accounts and manipulate user settings if default template credentials are not immediately changed by the administrator after enabling UCP.
Red Hat Cloud Services npm Packages Hijacked
2 rulesMultiple npm packages within the legitimate @redhat-cloud-services namespace have been hijacked with malicious code, posing a supply chain risk.
SourceCodester SEO Meta Tag Extractor 1.0 - Server-Side Request Forgery (SSRF) - CVE-2026-10287
2 rules 1 TTP 1 CVESourceCodester SEO Meta Tag Extractor 1.0 is vulnerable to server-side request forgery (SSRF) via manipulation of the 'url' argument in the get_headers function of the /index.php file, potentially allowing a remote attacker to make requests to internal or external systems.
Unusual Child Process Execution from Linux Web Servers
2 rules 4 TTPsThis rule detects unusual child process executions originating from web server processes on Linux systems, which attackers may use to maintain persistence on a compromised system by exploiting web server vulnerabilities.
Suspicious Command Execution via Web Server on Linux
2 rules 3 TTPsIdentifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.
Unusual Child Execution via Web Server
2 rules 4 TTPsThis rule detects unusual child process executions originating from web server processes on Linux systems, potentially indicating attackers exploiting web servers for persistence.
Suspicious Command Execution via Web Server on Linux
3 rules 2 TTPsIdentifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.
Laravel Security Policy Bypass Vulnerability
1 rule 1 TTPA vulnerability in Laravel allows an attacker to bypass the security policy; specifically, laravel/framework versions 12.x before 12.60.0 and 13.x before 13.10.0 are affected (CVE-2026-48019).
Azure Run Command Correlated with Process Execution
2 rules 2 TTPsThis rule detects the abuse of Azure Virtual Machine Run Command to execute scripts remotely, correlating Azure Activity Log events with endpoint process starts, identifying instances where adversaries use Run Command to run scripts as SYSTEM or root.
Azure Run Command Script Child Process
2 rules 3 TTPsThis rule identifies suspicious process start events where the parent process matches Azure Virtual Machine Run Command execution patterns on Windows (PowerShell with `-ExecutionPolicy Unrestricted` and `script?.ps1`) or Linux (waagent running `script.sh` under `/var/lib/waagent/run-command/`), exposing on-guest payloads.
CISA ICS Advisories Address Vulnerabilities in Multiple Vendor Products
2 rulesCISA published ICS advisories between May 25 and 31, 2026, addressing vulnerabilities across various vendors including ABB, CP Plus, Eppendorf, Frontier, Jinan USR IOT, KMW, MacGregor, Schneider Electric, and XCharge, impacting industrial control systems and related applications.
Dell Security Advisory Addressing Multiple Product Vulnerabilities
2 rulesDell released security advisories in May 2026 to address vulnerabilities in PowerEdge Server Chipset Driver, Data Lakehouse, Dell Enterprise SONiC Distribution, and Dell Unity/UnityVSA/Unity XT.
Multiple Vulnerabilities in ImageMagick
2 rules 3 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in ImageMagick to cause a denial of service condition, disclose information, and bypass security mechanisms.
PostgreSQL JDBC Driver Vulnerability Allows Denial of Service
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in the PostgreSQL JDBC Driver to perform a denial-of-service attack, impacting availability.
Kubernetes Static Pod Manifest File Access
3 rules 2 TTPsThis rule detects Linux process executions that reference /etc/kubernetes/manifests in process arguments, which may indicate tampering with static pod manifests for persistence or privilege escalation in Kubernetes environments.
Kubernetes Admission Webhook Created or Modified by Non-System Identity
2 rules 2 TTPsThe creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities can allow attackers to inject malicious sidecars or block security tooling deployments for persistence and defense evasion.
AWS SSM Session Manager Child Process Execution
3 rules 3 TTPsThis rule detects process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which can indicate remote execution and lateral movement by adversaries abusing legitimate AWS credentials.
Maltrail IOC List Analysis - June 1, 2026
2 rules 1 TTP 50 IOCsThis brief analyzes a Maltrail IOC list from June 1, 2026, identifying domains and IP addresses associated with various malware and threat actors, including android_fvncbot, lummac2, magentocore, sectoprat, apt_lazarus, offloader, android_joker, cyberstrikeai, and nightshadec2, potentially used for command and control, malware distribution, or phishing campaigns.
Fujitsu ServerView Multiple Vulnerabilities Allow Privilege Escalation
1 rule 1 TTPA local attacker can exploit multiple vulnerabilities in Fujitsu ServerView to escalate privileges on the targeted system.
Node.js Permission Model Bypass via Unix Domain Sockets (CVE-2026-21711)
2 rules 1 TTP 1 CVECVE-2026-21711 allows code running under the Node.js permission model without network access to create and expose local IPC endpoints via Unix Domain Sockets, bypassing intended network restrictions and enabling inter-process communication.
CVE-2026-21717 Node.js V8 Hash Collision Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-21717 is a vulnerability in V8's string hashing mechanism within Node.js that allows attackers to cause hash collisions via predictable integer-like strings in JSON input, leading to denial-of-service by degrading the performance of the Node.js process.
CVE-2026-44839: RabbitMQ Management UI XSS via Unsanitized vhost Names
2 rules 1 TTP 1 CVECVE-2026-44839 is a cross-site scripting (XSS) vulnerability in the RabbitMQ management UI that arises from unsanitized virtual host (vhost) names, potentially allowing an attacker to execute arbitrary JavaScript in the context of a user's browser.
CVE-2026-42790 nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification
2 rules 1 CVECVE-2026-42790 is a vulnerability in Microsoft products related to name constraints DNS bypass via subject CommonName fallback in public_key hostname verification.
WinMTR 0.91 Denial of Service Vulnerability (CVE-2018-25426)
1 rule 1 TTP 1 CVEWinMTR 0.91 is vulnerable to a denial-of-service attack where a malformed payload file containing a buffer overflow can crash the application (CVE-2018-25426).
CVE-2026-41184 ServiceAccount Token Disclosure via install-cni Container Logs
2 rules 1 TTP 1 CVECVE-2026-41184 is a ServiceAccount token disclosure vulnerability in container logs addressed by a Microsoft security update.
Stigmem-node Federation Peer Token Timestamp Validation Vulnerability
1 rule 1 TTPA timestamp handling issue in Stigmem-node's federation peer token validation could cause valid peer tokens to be incorrectly treated as expired, impacting availability and reliability of authenticated federation flows, affecting versions prior to 0.9.0a2.
Gotenberg Denial-of-Service Vulnerability via Multipart downloadFrom Handling
2 rules 1 TTPGotenberg is vulnerable to a remote denial-of-service (DoS) in multipart `downloadFrom` handling, where a crafted multipart request with multiple `downloadFrom` entries causes concurrent goroutines to write to shared maps without synchronization, leading to process termination.
External User Added to Google Workspace Group
2 rules 2 TTPsDetects an external Google Workspace user account being added to an existing group, potentially allowing adversaries to intercept shared files or emails.
Linux Segfault from Sensitive Process Detected
2 rules 3 TTPsThis rule detects segfault messages in kernel logs originating from sensitive processes on Linux systems, indicating potential exploitation attempts that could lead to arbitrary code execution or credential access.
yamcs-core Authentication Endpoint Brute-Force Vulnerability (CVE-2026-44596)
1 rule 1 TTPA public exploit has been published for CVE-2026-44596, a vulnerability in yamcs-core where the /auth/token authentication endpoint lacks rate limiting, allowing unauthenticated remote attackers to perform unlimited password guessing attempts against any user account, fixed in version 5.12.7.
M365 Exchange Inbox Forwarding Rule Created
2 rules 1 TTPThis rule detects the creation of new inbox forwarding rules in Microsoft 365, which can be abused by attackers to intercept and exfiltrate email data to external addresses.
Microsoft Edge Security Update Released
2 rulesMicrosoft released a security update on May 28, 2026, to address vulnerabilities in Microsoft Edge Stable Channel versions prior to 148.0.3967.96, advising users to apply the necessary updates.
OpenShift Router SSRF via FQDN EndpointSlice (CVE-2026-42965)
1 rule 1 TTP 1 CVECVE-2026-42965 describes a server-side request forgery (SSRF) vulnerability in the OpenShift Router where a user with EndpointSlice write access can expose instance credentials by creating a service that proxies requests to a cloud metadata endpoint.
M365 Exchange Inbox Rule with Obfuscated Name
2 rules 2 TTPsThis rule detects when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters, which adversaries may use to evade detection and hide malicious forwarding or deletion rules.
Azure VM Extension Deployment by Interactive User
2 rules 3 TTPsSuccessful deployment of a high-risk Azure Virtual Machine extension by an interactive user principal can lead to arbitrary code execution, backdoor account creation, credential harvesting, and persistence on Azure-hosted virtual machines.
Media Library Assistant WordPress Plugin vulnerable to CSRF (CVE-2026-6075)
2 rules 1 TTP 1 CVEThe Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery (CVE-2026-6075) due to missing nonce verification, allowing unauthenticated attackers to trick an administrator into performing unauthorized bulk actions.
Mautic SQL Injection Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Mautic to perform a SQL injection attack, potentially leading to unauthorized data access or modification.
CVE-2025-11262: WordPress Link Whisper Free Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS), allowing unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user accesses the injected page, affecting versions up to and including 0.9.0.
CVE-2026-46174: AMD Zen2 Improper Isolation of Shared Resources in Op Cache
2 rules 1 CVECVE-2026-46174 describes a vulnerability in AMD Zen2 processors related to improper isolation of shared resources within the operation cache, potentially leading to information disclosure or other security impacts.
CVE-2026-46185 Out-of-Bounds Read in SMB Client symlink_data()
2 rules 1 TTP 1 CVECVE-2026-46185 is an out-of-bounds read vulnerability in the SMB client component within the symlink_data() function, potentially leading to information disclosure or denial of service.
CVE-2026-46153: 8021q Delete Cleared Egress QoS Mappings Vulnerability
2 rules 1 CVEMicrosoft published information regarding CVE-2026-46153, a vulnerability in 8021q that allows deleting cleared egress QoS mappings.
CVE-2026-46155: Out-of-bounds Read in SMB Client
2 rules 1 TTP 1 CVECVE-2026-46155 describes an out-of-bounds read vulnerability within the smb2_compound_op() function of the SMB client, requiring a security update from Microsoft to address the issue.
CVE-2026-46107 dm-thin Metadata Refcount Underflow
2 rules 1 CVECVE-2026-46107 is a reported vulnerability in dm-thin, leading to a metadata refcount underflow.
CVE-2026-46172 Vulnerability in IPv6 xfrm6_rcv_encap()
2 rules 1 TTP 1 CVECVE-2026-46172 is a vulnerability related to ipv6: xfrm6: release dst on error in xfrm6_rcv_encap(), potentially leading to a denial-of-service condition.
Red Hat OpenShift Tempo Vulnerabilities Allow Remote Exploitation
1 rule 3 TTPsMultiple vulnerabilities in Red Hat OpenShift Tempo allow an unauthenticated remote attacker to bypass security measures, disclose sensitive information, manipulate data, or cause a denial of service condition.
strongSwan 5.9.13 Denial-of-Service Vulnerability (CVE-2026-35333)
2 rules 1 TTPA denial-of-service vulnerability exists in strongSwan version 5.9.13 due to a flaw in the eap-radius plugin when built with DAE enabled, allowing remote attackers to exhaust worker threads by sending a crafted RADIUS Access-Request (CVE-2026-35333).
CVE-2026-46835 - Oracle Database Server Net Service Denial of Service
2 rules 1 CVECVE-2026-46835 is an easily exploitable vulnerability in Oracle Database Server's Net Service component, affecting versions 23.4.0 to 23.26.2, allowing an unauthenticated attacker with network access via TLS to cause a complete denial-of-service (DoS).
CVE-2026-46834 - Oracle Database Server Net Service Denial of Service
2 rules 1 TTP 1 CVECVE-2026-46834 is a vulnerability in the Net Service component of Oracle Database Server versions 23.4.0 to 23.26.2 that allows an unauthenticated attacker with network access via TLS to cause a denial-of-service (DoS) condition.
CVE-2026-46829: Oracle REST Data Services Unauthenticated Denial of Service
2 rules 1 TTP 1 CVEAn unauthenticated attacker with network access via HTTPS can exploit CVE-2026-46829 in Oracle REST Data Services versions 24.2.0 through 26.1.0, leading to a denial of service.
CVE-2026-46828 - Oracle Payroll Vulnerability Allows Unauthorized Data Access and Modification
2 rules 1 TTP 1 CVECVE-2026-46828 is an easily exploitable vulnerability in Oracle Payroll versions 12.2.3-12.2.15, allowing a low-privileged attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of critical payroll data, as well as gain unauthorized access to sensitive information.
CVE-2026-46823 - Oracle Public Sector Financials (International) Unauthorized Data Access
1 rule 1 TTP 1 CVECVE-2026-46823 is an easily exploitable vulnerability in Oracle Public Sector Financials (International) versions 12.2.6-12.2.15, allowing a low privileged attacker with network access via HTTPS to gain unauthorized access to critical data or complete access to all accessible data, potentially impacting additional products.
CVE-2026-46821 - Oracle E-Business Suite Financials Common Modules Unauthorized Data Access
2 rules 1 TTP 1 CVECVE-2026-46821 is an easily exploitable vulnerability in Oracle Financials Common Modules of Oracle E-Business Suite versions 12.2.3-12.2.15, allowing a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data.
CVE-2026-46820: Oracle Financials Common Modules Vulnerability in E-Business Suite
2 rules 1 TTP 1 CVECVE-2026-46820 is a vulnerability in Oracle Financials Common Modules within Oracle E-Business Suite versions 12.2.3-12.2.15, allowing a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data and modify some data, resulting in a confidentiality and integrity impact.
CVE-2026-35266: Oracle REST Data Services Vulnerability Allows Unauthorized Data Access and Modification
2 rules 1 CVEA vulnerability exists in Oracle REST Data Services versions 24.2.0 to 26.1.0, where a low-privileged attacker with network access via HTTPS can, with human interaction, gain unauthorized data access, modification, and cause a partial denial of service.
Detect Large ICMP Traffic
2 rules 1 TTPThis analytic identifies ICMP traffic to external IP addresses with total bytes greater than 1,000 bytes, leveraging the Network_Traffic data model to detect potential information smuggling, covert communication, or command-and-control (C2) activities.
Windows Cabinet File Extraction via Expand.exe
2 rules 2 TTPsDetection of expand.exe being used to extract Microsoft Cabinet (CAB) archives, specifically when extracting to C:\ProgramData or similar staging locations, potentially indicating ingress tool transfer and payload staging by threat actors like APT37.
ESXi External Root Login Detection
2 rules 1 TTPThis detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user, which bypasses role-based access controls and may indicate risky behavior or unauthorized activity.
Windows AD Object Owner Updated
2 rules 2 TTPsThis Splunk search detects when the owner of an Active Directory object is updated, potentially granting full control privileges and enabling object hiding, focusing on Windows Event Log ID 5136, and includes lookups for SID resolution.
Tanium Connect Multiple Vulnerabilities
3 rulesTanium released security advisories addressing vulnerabilities in Connect versions prior to Update 25 (v5.26.191), Update 19 (v5.29.237), and Update 9 (v5.37.140), potentially leading to unauthorized access and data compromise.
Unauthorized Asset Detection via DHCP Request Analysis
2 rules 1 TTPThis analytic identifies potentially unauthorized devices attempting to connect to an organization's network by inspecting DHCP request packets and comparing MAC addresses against a list of known authorized devices.
Monitor Email for Brand Abuse via Domain Permutations
2 rules 1 TTPThis analytic identifies emails claiming to originate from domains similar to those being monitored for abuse by cross-referencing sender addresses with a lookup table of domain permutations, indicating potential phishing or brand impersonation.
Windows Registry Modification Risk Behavior Detection
2 rules 2 TTPsThis analytic identifies instances where three or more distinct registry modification events associated with MITRE ATT&CK Technique T1112 are detected, leveraging Splunk's Risk data model to detect persistence, hiding malicious configurations, or erasing forensic evidence.
Living Off The Land Activity Detection
2 rules 5 TTPsThis correlation search identifies multiple risk events associated with 'Living Off The Land' activity, leveraging the Risk data model to aggregate events, focusing on systems with a high count of distinct sources, potentially enabling attackers to execute code, escalate privileges, or persist within the environment using trusted system utilities.
Monitor Web Traffic For Brand Abuse
2 rules 1 TTPThis analytic identifies web requests to domains that closely resemble a monitored brand's domain, indicating potential brand abuse indicative of phishing or malware distribution attempts.
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
2 rules 3 TTPsThis analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window using Cisco Secure Firewall Threat Defense logs, identifying hosts triggering more than 15 Snort-based signatures, which may indicate suspicious activity like malware execution, command-and-control communication, vulnerability scanning, or lateral movement.
phpMyFAQ Unauthenticated Password Reset Vulnerability (CVE-2026-35676)
2 rules 1 TTP 1 CVEphpMyFAQ before 4.1.3 is vulnerable to an unauthenticated password reset, allowing attackers to change account passwords without token validation by sending crafted PUT requests to the /api/index.php/user/password/update endpoint.
Google Workspace Drive Data Transfer or Takeout Export Initiated
2 rules 2 TTPsThis rule detects when Google Workspace administrators initiate bulk movement or export of user Drive data, including admin data transfer requests and Customer Takeout export jobs which can be abused by adversaries with administrative access to stage or exfiltrate sensitive files.
Zimbra Security Advisory Addresses Vulnerabilities in Zimbra Daffodil
2 rulesZimbra released a security advisory on May 28, 2026, addressing unspecified vulnerabilities in Zimbra Daffodil versions prior to v10.1.17, urging users to apply necessary updates.
Google Workspace Device Registration Burst for Single User
1 rule 3 TTPsDetects bursts of Google Workspace device registration events for a single user exceeding three distinct device registrations within one minute, indicative of AiTM phishing or stolen OAuth token replay attacks.
Google Workspace User Sign-in from Atypical Device Type
2 rules 2 TTPsThis rule detects when a Google Workspace user authenticates from a device type that hasn't been observed for that user in the past 14 days, potentially indicating account compromise via AiTM kits or stolen OAuth refresh tokens.
Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass
2 rules 2 TTPs 5 CVEsMultiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.
Gitea Unauthenticated Container Registry Access (CVE-2026-27771)
2 rules 1 TTP 1 CVE 2 IOCsA vulnerability in Gitea's built-in container registry (CVE-2026-27771) allows unauthenticated attackers to pull private container images, potentially exposing source code, secrets, and production infrastructure details, affecting over 30,000 deployments.
AWS S3 Credential File Retrieved from Bucket
2 rules 2 TTPsThis rule detects successful S3 GetObject calls targeting high-value credential and secret files commonly stored in S3 buckets, indicating potential credential access.
WordPress SlimStat Analytics Plugin Stored XSS Vulnerability (CVE-2026-7634)
2 rules 1 TTP 1 CVEThe SlimStat Analytics plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via the User-Agent header, allowing unauthenticated attackers to inject arbitrary web scripts if the 'show_complete_user_agent_tooltip' setting is enabled.
HT Contact Form WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7052)
2 rules 1 TTP 1 CVEThe HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting (CVE-2026-7052) via the 'file_upload' parameter in versions up to 2.8.2, allowing unauthenticated attackers to inject arbitrary web scripts.
Apache Tika Vulnerability Allows Information Disclosure or Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Apache Tika to read sensitive data or trigger malicious requests to internal resources or third-party servers.
VMware Tanzu Spring Framework Denial of Service Vulnerability
1 rule 1 TTPA remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to perform a denial of service attack.
VMware Tanzu Spring Security Vulnerability Allows File Manipulation
2 rules 1 TTPA local attacker can exploit a vulnerability in VMware Tanzu Spring Security to manipulate files, potentially leading to privilege escalation.
Multiple Vulnerabilities in Vim Could Lead to Arbitrary Code Execution or Denial of Service
2 rules 3 TTPsMultiple vulnerabilities in Vim could allow an attacker to execute arbitrary code or cause a denial of service condition.
IBM DB2 Multiple Vulnerabilities Leading to Denial of Service
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in IBM DB2 to perform a denial of service attack, potentially disrupting database services.
CVE-2026-46099: IPv6 NOREF DST Use Vulnerability in seg6 and rpl lwtunnels
2 rules 1 CVECVE-2026-46099 describes a vulnerability in the IPv6 network stack related to NOREF dst use in seg6 and rpl lwtunnels, requiring a security update to address potential exploitation.
CVE-2026-46072 ntfs3 Buffer Boundary Check Vulnerability
2 rules 1 CVECVE-2026-46072 is a buffer boundary check vulnerability in ntfs3 affecting an unspecified Microsoft product, requiring further investigation upon patch application to understand exploitation vectors and develop detections.
CVE-2026-45842: Unspecified Vulnerability in Microsoft Products
2 rules 1 TTP 1 CVECVE-2026-45842 is an unspecified vulnerability affecting Microsoft products, requiring further investigation to determine the specific attack vector, impact, and affected systems.
CVE-2026-44899 Mistune Image Directive CSS Injection Vulnerability
2 rules 1 CVECVE-2026-44899 is a CSS Injection vulnerability in the Mistune Image Directive, potentially allowing for malicious CSS injection if user-supplied content is not properly sanitized.
CVE-2025-71305 Published - Insufficient DP MST VCPI Protection
2 rules 1 CVEMicrosoft published CVE-2025-71305, addressing a vulnerability related to insufficient protection against zero VCPI values in DisplayPort Multi-Stream Transport (MST), although specifics on exploitation and impact are not detailed in the provided source.
CVE-2026-45843 slip: bound decode() vulnerability
1 rule 1 CVECVE-2026-45843 is a Microsoft vulnerability with unspecified details at the time of this brief.
CVE-2026-44844 eml_parser Recursion Denial-of-Service
2 rules 1 TTP 1 CVECVE-2026-44844 is a denial-of-service vulnerability in Microsoft's eml_parser due to recursion in nested message/rfc822 attachments, potentially causing a service outage.
CVE-2026-45932 bpf: Fix tcx/netkit Detach Permissions
2 rules 1 CVECVE-2026-45932 is a vulnerability affecting the bpf component, related to tcx/netkit detach permissions when the prog fd isn't given, requiring a security update from Microsoft.
CVE-2026-45991 UDF Partition Descriptor Append Bookkeeping Vulnerability
2 rules 1 CVECVE-2026-45991 is a security vulnerability affecting a Microsoft product, related to UDF partition descriptor append bookkeeping.
CVE-2026-46084 RDMA/mana_ib: Disable RX steering on RSS QP destroy
2 rules 1 CVECVE-2026-46084 is a vulnerability related to RDMA/mana_ib that requires disabling RX steering on RSS QP destroy, potentially leading to denial of service or privilege escalation.
Pimcore CustomReports Share Bypass Vulnerability
1 rule 2 TTPsPimcore's CustomReports feature has a share bypass vulnerability due to inconsistent authorization checks between the report listing endpoint and the report detail endpoint, allowing low-privileged users to access report configurations without explicit sharing permissions.
Google Chrome Security Update Released
2 rulesGoogle released a security update on May 27, 2026, to address vulnerabilities in Chrome for Desktop versions prior to 0.7778.216/217 for Windows, 148.0.7778.215/216 for Mac, and 148.0.7778.215 for Linux, requiring users to apply the necessary updates to mitigate potential exploitation.
Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
2 rules 1 TTP 36 IOCsCyber threat actors are conducting spoofing attacks against FIFA websites in advance of the 2026 FIFA World Cup to steal personal information and facilitate monetary scams.
Kaspersky Anti Targeted Attack Platform Multiple XSS Vulnerabilities
2 rules 2 TTPs 2 CVEsMultiple vulnerabilities have been discovered in Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7, allowing an attacker to cause a remote cross-site scripting (XSS) vulnerability, tracked as CVE-2026-28348 and CVE-2026-28350.
CVE-2026-8180: IBM Aspera High-Speed Transfer Denial of Service
2 rules 1 TTP 1 CVEIBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 are vulnerable to a denial-of-service (DoS) attack where an unauthenticated user can crash the asperahttpd service.
IBM Langflow OSS Uncontrolled Resource Consumption Denial-of-Service (CVE-2026-7528)
2 rules 1 TTP 1 CVEIBM Langflow OSS versions 1.0.0 through 1.9.0 are vulnerable to a denial-of-service (DoS) attack due to uncontrolled resource consumption as tracked by CVE-2026-7528.
Samba NTFS Reparse Point Vulnerability (CVE-2026-1933)
2 rules 1 TTP 1 CVECVE-2026-1933 describes a vulnerability in Samba's handling of NTFS-style reparse points on read-only shares, allowing authenticated users with filesystem write permissions to modify reparse point metadata and potentially alter SMB-visible file behavior.
IBM Db2 Vulnerable to Denial-of-Service via Crafted Query (CVE-2026-1718)
2 rules 1 TTP 1 CVEIBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 are vulnerable to a denial-of-service (DoS) attack via a specially crafted query when autonomous transactions are enabled, potentially leading to service disruption.
Suspicious Instance Metadata Service (IMDS) API Request
3 rules 4 TTPs 1 IOCThis rule detects suspicious network activity from tools or scripts attempting to access the cloud service provider's Instance Metadata Service (IMDS) API endpoint, potentially retrieving sensitive instance-specific information and credentials.
Suspicious Instance Metadata Service (IMDS) API Command Line Execution
2 rules 4 TTPsThe rule identifies command-line executions that attempt to access cloud service provider's Instance Metadata Service (IMDS) API endpoints, potentially retrieving sensitive instance information and temporary security credentials, ultimately leading to credential access and privilege escalation within the cloud environment.
OpenVPN Connect MacOS Local Privilege Escalation Vulnerability
2 rules 1 TTPA local attacker can exploit a vulnerability in OpenVPN Connect on MacOS to escalate their privileges.
HBook WordPress Plugin Stored XSS Vulnerability (CVE-2026-8143)
2 rules 1 TTP 1 CVEThe HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'hb_country_iso', 'hb_usa_state_iso', and 'hb_canada_province_iso' parameters (CVE-2026-8143) in versions up to 2.1.6, potentially leading to arbitrary script execution in the administrator's browser.
LiteSpeed Cache Plugin Stored XSS Vulnerability (CVE-2026-3375)
1 rule 1 TTP 1 CVEThe LiteSpeed Cache plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints, affecting versions up to 7.7, allowing unauthenticated attackers to inject arbitrary JavaScript into CCSS/UCSS content by bypassing IP-based access controls.
Multiple Vulnerabilities in IBM DB2
2 rules 3 TTPsMultiple vulnerabilities in IBM DB2 allow a remote, authenticated, or local attacker to disclose information, bypass security measures, or cause a denial of service.
Fedify LD-Signature Bypass via JSON-LD Named-Graph Restructuring
2 rulesFedify is vulnerable to CVE-2026-42462, a Linked Data Signature bypass via JSON-LD Named-Graph Restructuring, allowing attackers to alter third-party signed activities by manipulating the document structure without invalidating the signature, potentially leading to integrity, availability, and confidentiality issues.
GnuTLS Certificate Spoofing Vulnerability (CVE-2026-42012)
2 rules 1 TTP 1 CVECVE-2026-42012 describes a vulnerability in GnuTLS where a remote attacker can spoof legitimate services or intercept sensitive information by presenting a specially crafted certificate with URI or SRV SANs, causing the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN).
JeecgBoot Improper Access Control Vulnerability (CVE-2026-9580)
1 rule 1 TTP 1 CVEJeecgBoot up to version 3.9.1 is vulnerable to improper access control in the LoginController.selectDepart function, allowing remote attackers to bypass intended restrictions.
CVE-2026-3603: IBM Engineering Lifecycle Management XXE Vulnerability
2 rules 1 TTP 1 CVEIBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 are vulnerable to XML external entity injection (XXE), allowing an authenticated attacker to expose sensitive information or consume memory resources.
CVE-2026-8856 - IBM HTTP Server Denial of Service Vulnerability
2 rules 1 TTP 1 CVEIBM HTTP Server 8.5 and 9.0 is vulnerable to a denial of service (DoS) in configurations where an attacker possesses write access to server configuration files, as tracked by CVE-2026-8856.
CVE-2026-8854 - IBM HTTP Server mod_mem_cache Denial-of-Service
2 rules 1 TTP 1 CVEIBM HTTP Server 8.5 and 9.0 are vulnerable to a denial-of-service (DoS) attack due to a flaw in the optional `mod_mem_cache` module that can be triggered remotely.
CVE-2026-8835: IBM HTTP Server Invalid Pointer Dereference Vulnerability
2 rules 1 TTP 1 CVEIBM HTTP Server versions 8.5 and 9.0 are susceptible to an invalid pointer dereference, potentially allowing a privileged, authenticated user to expose sensitive information or cause a denial of service.
CVE-2026-8620: IBM WebSphere Application Server HTTP Request Smuggling Vulnerability
2 rules 1 TTP 1 CVEIBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5 and 9.0 are vulnerable to HTTP request smuggling due to inconsistent interpretation of HTTP requests, potentially leading to unauthorized access and data manipulation.
D-Link DSL2600U 'rom-0' Admin Password Disclosure Vulnerability
2 rulesA hardware exploit has been published on Exploit-DB for D-Link DSL2600U, detailing a 'rom-0' Admin Password Disclosure vulnerability that allows unauthorized access to the device's administration interface.
ABB PPT30 Operating System Vulnerability (CVE-2025-11482)
1 rule 1 TTP 1 CVEA vulnerability, CVE-2025-11482, exists in ABB's PPT30 Operating System related to handling concurrent connections in the PPT30 OPC-UA Server, affecting versions prior to 1.8.0.
KLiK SocialMediaWebsite Unrestricted File Upload Vulnerability (CVE-2026-9421)
2 rules 1 TTP 1 CVECVE-2026-9421 is an unrestricted file upload vulnerability in the File Handler component of KLiK SocialMediaWebsite 1.0 that can be exploited remotely.
NordVPN Denial-of-Service Vulnerability (CVE-2018-25368)
2 rules 1 TTP 1 CVENordVPN version 6.14.31 is vulnerable to a denial-of-service attack (CVE-2018-25368) where an unauthenticated attacker can crash the application by submitting an excessively long string in the password field.
userSpice Username Enumeration Vulnerability (CVE-2018-25350)
2 rules 1 TTP 1 CVEuserSpice 4.3.24 contains a username enumeration vulnerability, allowing unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint and analyzing the response for the 'taken' string.
ItzCrazyKns Vane SSRF Vulnerability (CVE-2026-9372)
2 rules 3 TTPs 1 CVEA server-side request forgery (SSRF) vulnerability, identified as CVE-2026-9372, exists in ItzCrazyKns Vane up to version 1.12.1, allowing a remote attacker to manipulate the baseURL argument in the Model Provider API component and potentially conduct internal reconnaissance or access sensitive data.
CVE-2026-26147: Azure Compute Gallery Information Disclosure via Improper Input Validation
2 rules 1 TTP 1 CVECVE-2026-26147 is an improper input validation vulnerability in Azure Compute Gallery that allows an authorized attacker to disclose information over a network.
CVE-2022-31231 - Dell ECS Improper Access Control in IAM Module
2 rules 1 TTPDell ECS versions 3.5 and 3.6 contain an improper access control vulnerability (CVE-2022-31231) in the Identity and Access Management (IAM) module, potentially allowing a remote unauthenticated attacker to gain unauthorized read access to data.
Dell PowerFlex Manager Directory Listing Vulnerability (CVE-2025-32749)
2 rules 1 TTP 1 CVEDell PowerFlex Manager versions 4.6.2 and earlier contain a directory listing vulnerability (CVE-2025-32749) that allows an unauthenticated remote attacker to expose sensitive information.
CVE-2025-32747: Dell PowerFlex Manager Incorrect Privilege Assignment Vulnerability
1 rule 1 TTPDell PowerFlex Manager versions 4.6.2 and earlier contain an Incorrect Privilege Assignment vulnerability (CVE-2025-32747) that allows a low-privileged attacker with local access to elevate privileges.
CVE-2025-26483: Dell PowerFlex Manager Open Redirect Vulnerability
2 rules 1 TTPDell PowerFlex Manager versions 4.6.2 and prior contains an open redirect vulnerability (CVE-2025-26483) that allows an unauthenticated attacker to redirect a targeted user to an arbitrary web URL, potentially enabling phishing attacks.
Mattermost Uncontrolled Resource Consumption Vulnerability (CVE-2026-5308)
2 rules 1 TTPMattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints, allowing an attacker to cause a denial of service via crafted oversized HTTP requests.
Mattermost File Access Vulnerability (CVE-2026-3473)
1 rule 1 TTP 1 CVEMattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, allowing an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.
Firefox for iOS Security Policy Bypass Vulnerability
2 rules 1 TTPA vulnerability in Firefox for iOS versions prior to 151.1 allows an attacker to bypass the security policy (CVE-2026-9078).
Spring AI Data Integrity Vulnerability (CVE-2026-41863)
2 rulesA data integrity vulnerability exists in Spring AI versions 1.1.x before 1.1.7, potentially allowing an attacker to compromise data integrity, as identified by CVE-2026-41863.
CPython Unspecified Vulnerability (CVE-2026-8328)
2 rules 1 CVEAn unspecified vulnerability in CPython, tracked as CVE-2026-8328, allows an attacker to cause an unspecified security issue.
Ivanti Secure Access Client: Local Privilege Escalation Vulnerabilities
2 rules 1 TTPA local attacker can exploit vulnerabilities in Ivanti Secure Access Client to manipulate files or escalate privileges, potentially gaining elevated access to the system.
Multiple Vulnerabilities in Devolutions Server
2 rulesMultiple vulnerabilities in Devolutions Server could allow an attacker to bypass security measures, disclose information, and manipulate files.
Multiple Vulnerabilities in PuTTY Allow for DoS, Data Manipulation, and Spoofing
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in PuTTY to perform a denial of service attack, manipulate data, and possibly carry out spoofing attacks.
Intel NPU Driver Vulnerabilities Allow Privilege Escalation and DoS
2 rules 2 TTPsMultiple vulnerabilities in the Intel NPU Driver allow a local attacker to escalate privileges and cause a denial of service.
macOS TCC Database Modification for Privacy Control Bypass
2 rules 2 TTPs 1 CVEAdversaries may attempt to bypass macOS privacy controls by directly modifying the Transparency, Consent, and Control (TCC) SQLite database using sqlite3, potentially gaining unauthorized access to sensitive resources.
CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products
2 rulesCISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.
Suspicious AWS S3 Connection via Script Interpreter
2 rules 5 TTPsThe rule detects script interpreters (osascript, Node.js, Python) making outbound connections to AWS S3 or CloudFront domains on macOS, which may indicate command and control or data exfiltration activity.
Parse Server Pre-authentication Denial of Service via Client Version Header
2 rules 1 TTPA denial-of-service vulnerability, CVE-2026-47138, exists in Parse Server due to inefficient regular expression handling of the client SDK version field in HTTP requests, allowing an unauthenticated attacker to exhaust server resources by sending a crafted request with a malicious `X-Parse-Client-Version` header or `_ClientVersion` body field.
Nezha Monitoring RoleMember SSRF with Full Response Body Reflection
2 rules 3 TTPsNezha Monitoring is vulnerable to a server-side request forgery (SSRF) vulnerability, where a low-privilege RoleMember user can call notification routes and send HTTP requests to a user-controlled URL, with the entire response body reflected back to the caller, potentially exposing intranet resources and causing denial of service.
Rare Connection to WebDAV Target via Rundll32
2 rules 2 TTPsThis rule identifies rare connection attempts to a Web Distributed Authoring and Versioning (WebDAV) resource, where attackers may inject WebDAV paths in files or features opened by a victim user to leak their NTLM credentials via forced authentication using rundll32.exe.
HPE Telco Universal SLA Management Multiple Vulnerabilities
2 rulesHPE published a security advisory addressing multiple unspecified vulnerabilities in HPE Telco Universal SLA Management version 4.6 and prior, prompting users to apply necessary updates.
Microsoft Releases Security Update for Edge Stable Channel
2 rulesMicrosoft released a security update on May 21, 2026, to address vulnerabilities in Microsoft Edge Stable Channel versions prior to 148.0.3967.83, urging users to apply the update.
Stormshield Network Security (SNS) Remote Denial-of-Service Vulnerability
2 rules 1 TTP 1 CVEA remote denial-of-service vulnerability exists in Stormshield Network Security (SNS) versions 4.3.x before 4.3.43, 4.4.x to 4.8.x before 4.8.16, and 5.x before 5.0.6, allowing an attacker to disrupt service availability.
Multiple Vulnerabilities in Tenable Sensor Proxy
1 rule 1 TTP 5 CVEsMultiple vulnerabilities in Tenable Sensor Proxy versions prior to 1.4.0 could allow a remote attacker to cause a denial of service, data confidentiality breaches, and other unspecified security impacts.
SPIP Security Policy Bypass Vulnerability
2 rules 1 TTPA vulnerability in SPIP versions prior to 4.4.15 allows an attacker to bypass the security policy, potentially leading to unauthorized actions.
Sparx Systems Enterprise Architect Security Bypass Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Sparx Systems Enterprise Architect to bypass security precautions.
TeamViewer Vulnerability Allows Privilege Escalation
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in TeamViewer to escalate privileges on a compromised system.
Royal Elementor Addons Vulnerability Allows Cross-Site Scripting
2 rules 1 TTPA remote, unauthenticated attacker can exploit a cross-site scripting (XSS) vulnerability in the Royal Elementor Addons plugin for WordPress.
XWiki Multiple Vulnerabilities Allow File Manipulation and Information Disclosure
2 rules 2 TTPsAn authenticated remote attacker can exploit multiple vulnerabilities in XWiki to manipulate files and disclose information.
CVE-2026-9011: Ditty WordPress Plugin Authorization Bypass Vulnerability
2 rules 1 TTP 1 CVEThe Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress versions up to 3.1.65 is vulnerable to an authorization bypass (CVE-2026-9011) that allows unauthenticated attackers to retrieve the full content of non-public Dittys by exploiting the ditty_init AJAX endpoint.
AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)
2 rules 1 TTPThe AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.
cPanel cPanel/WHM Vulnerability Allows Header Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in cPanel cPanel/WHM to perform an HTTP response header injection, enabling cross-site scripting (XSS), open redirect attacks, and cache or header manipulation.
Multiple Vulnerabilities in PHP Allow for Information Disclosure, DoS, SSRF, and Unknown Impacts
2 rules 3 TTPsA remote attacker can exploit multiple vulnerabilities in PHP to disclose information, cause a denial-of-service condition, perform a Server-Side Request Forgery (SSRF) attack, or achieve unknown impacts.
PowerDNS Authoritative Server Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in PowerDNS Authoritative Server allow an attacker to disclose information, manipulate data, and cause a denial-of-service condition.
js-libp2p Gossipsub Memory Exhaustion via Subscription Flood
1 rule 2 TTPsA memory exhaustion vulnerability exists in `@libp2p/gossipsub` due to unbounded subscription handling, allowing a single attacker to exhaust a Node.js heap by flooding unique topic subscriptions, leading to denial-of-service.
Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT
2 rules 1 TTPAttackers are compromising npm packages to distribute a RAT linked to PolinRider, directly injecting malicious code into the software supply chain.
@hulumi/policies Evidence Bypass Vulnerability
2 rules@hulumi/policies versions before 1.3.2 allowed unrelated compliant-looking evidence to suppress violations for different zones, hostnames, origins, or repositories in the same stack, bypassing Cloudflare and deployment-governance guardrails.
Entra ID OAuth User Impersonation to Microsoft Graph
2 rules 2 TTPsThis rule detects potential session hijacking or token replay in Microsoft Entra ID, identifying cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, which may indicate a successful OAuth phishing attack, session hijacking, or token replay attack.
Nimiq Primitives Trie Chunk Processing Denial-of-Service (CVE-2026-46545)
2 rules 1 TTPA remote denial-of-service vulnerability (CVE-2026-46545) exists in Nimiq primitives where an unauthenticated peer can send a malicious chunk with an empty key, leading to a panic when `put_raw` attempts to store a value at the root node, causing the node process to abort.
LMDeploy Hardcoded trust_remote_code Enables Remote Code Execution (CVE-2026-46517)
2 rules 2 TTPs 1 IOCLMDeploy <= 0.12.3 is vulnerable to remote code execution (CVE-2026-46517) because it hardcodes `trust_remote_code=True` when calling `transformers.AutoConfig.from_pretrained()`, allowing a malicious Hugging Face repository to execute arbitrary Python code when loaded without user opt-out.
Open ISES Tickets Hardcoded Database Credentials Vulnerability
2 rules 1 CVEOpen ISES Tickets before version 3.44.2 contains hardcoded MySQL database connection credentials in import_mdb.php, allowing unauthorized database access.
BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers
2 rules 1 TTP 6 IOCsA commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.
ConnectWise Automate Vulnerability Addressed in Security Update
2 rulesConnectWise released a security advisory addressing a vulnerability in ConnectWise Automate versions prior to 2026.5, prompting users to apply the necessary updates.
Hitachi Energy GMS600 Vulnerable to Bleichenbacher Attack via CVE-2022-4304
2 rules 1 TTP 1 CVEHitachi Energy GMS600 versions 1.3.0 and 1.3.1 are affected by CVE-2022-4304, a vulnerability in the OpenSSL RSA Decryption implementation; an attacker could exploit this timing-based side channel to recover plaintext across a network in a Bleichenbacher-style attack by sending trial messages to the server and recording processing times, eventually decrypting application data.
ABB B&R Automation Runtime Multiple Vulnerabilities
2 rules 1 TTP 3 CVEsABB B&R Automation Runtime versions before 6.4 are vulnerable to predictable number generation (CVE-2025-3449), reflected XSS (CVE-2025-3448), and CSV injection (CVE-2025-11498), potentially allowing attackers to hijack sessions or execute arbitrary code in a user's browser context.
ABB Terra AC Wallbox Vulnerabilities Allow Remote Control and Firmware Alteration
2 rules 2 TTPs 3 CVEsMultiple buffer overflow vulnerabilities in ABB Terra AC Wallbox versions <=1.8.33, exploitable via Bluetooth hijacking, could allow an attacker to remotely control the device and alter its firmware.
Trend Micro Security Advisory Addressing Apex One and Vision One Vulnerabilities
2 rulesTrend Micro released a security advisory addressing vulnerabilities in Apex One (on-premise), Apex One as a service, and Trend Vision One Endpoint, prompting users to apply necessary updates to mitigate potential risks.
SolarEdge CSRF and Out-of-Band Injection Vulnerability
2 rules 1 TTP 1 IOCA CSRF-OOB-Injection vulnerability exists in SolarEdge Monitoring Platform's `/solaredge-web/p/initClient` endpoint due to improper validation of session parameters, allowing attackers to manipulate headers to initiate requests to attacker-controlled domains, potentially leading to session compromise and unauthorized system control.
Lenovo LegionSpace 1.7.11.2 Unquoted Service Path Vulnerability
2 rules 1 TTPA local exploit has been published for Lenovo LegionSpace 1.7.11.2, detailing an Unquoted Service Path vulnerability in the 'DAService', potentially leading to local privilege escalation.
BookStack 25.12.1 Denial-of-Service Vulnerability
2 rules 1 TTPA denial-of-service vulnerability exists in BookStack version 25.12.1, and a public exploit (EDB-52571) is available, increasing the risk to unpatched systems.
Multiple Vulnerabilities in Apereo Java CAS Client
2 rules 1 TTP 1 IOCMultiple vulnerabilities have been discovered in Apereo Java CAS client versions prior to 4.1.1, potentially leading to data confidentiality breaches as detailed in the casc-jwt-vuln security bulletin.
Internet Systems Consortium BIND Multiple Vulnerabilities Lead to DoS
1 rule 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in Internet Systems Consortium BIND to trigger memory corruption or cause a denial-of-service condition.
MongoDB Compass Vulnerability Allows File Manipulation and Potential Code Execution
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in MongoDB Compass to manipulate files and potentially execute arbitrary code.
ffmpeg Vulnerability Allows Code Execution and Potential Denial of Service
2 rules 1 TTPA vulnerability in ffmpeg allows an attacker to execute arbitrary program code and potentially conduct a denial of service attack.
vllm Vulnerability Allows Information Disclosure and DoS
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in vllm to disclose information or cause a denial-of-service condition.
CVE-2026-45736: Uninitialized Memory Disclosure Vulnerability in Microsoft Products
2 rules 1 CVECVE-2026-45736 is an uninitialized memory disclosure vulnerability affecting Microsoft products, potentially allowing an attacker to read sensitive information from process memory.
CVE-2026-44390 Unbounded Name Compression Denial-of-Service Vulnerability
2 rules 1 TTP 1 CVECVE-2026-44390 is a denial-of-service vulnerability in Microsoft products due to unbounded name compression.
CVE-2026-47783: memcached Timing Side Channel Vulnerability in SASL Authentication
2 rules 1 TTP 1 CVECVE-2026-47783 is a timing side channel vulnerability in memcached before 1.6.42, affecting SASL password database authentication due to premature loop exit upon finding a valid username, potentially leading to information disclosure.
TeamPCP Leaks Shai-Hulud Worm Source Code, European Governments Seek Secure Messaging Alternatives
2 rules 1 TTPThe TeamPCP hacking group released the source code of the Shai-Hulud worm impacting npm and PyPI, prompting European governments to seek secure messaging alternatives due to phishing risks and data sovereignty concerns, while historical analysis reveals the Fast16 malware targeted Iran's nuclear program by tampering with simulation software.
Maltrail IOCs for APT Kimsuky, Lummac2, MagentoCore, and FakeApp Campaigns
3 rules 1 TTP 50 IOCsThis brief summarizes indicators of compromise (IOCs) from a Maltrail feed update on 2026-05-20, detailing network activity associated with APT Kimsuky, Lummac2, MagentoCore, and FakeApp campaigns, providing actionable intelligence for detection and response.
Taiko AG1000-01A SMS Alert Gateway Stored XSS (CVE-2026-9144)
2 rules 1 TTP 1 CVETaiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 is vulnerable to stored cross-site scripting (CVE-2026-9144) in the web configuration interface, allowing authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields for persistent code execution.
Splunk Releases Security Advisory Addressing Multiple Products
2 rulesSplunk released security advisories on May 20, 2026, addressing vulnerabilities in Splunk User Behavior Analytics, AppDynamics Agents, Universal Forwarder, Enterprise, Cloud Platform, and AI Toolkit, prompting users to apply necessary updates.
Splunk Enterprise and Cloud Platform Information Disclosure Vulnerability (CVE-2026-20239)
2 rules 2 TTPs 1 CVESplunk Enterprise and Cloud Platform versions prior to 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13 are vulnerable to information disclosure (CVE-2026-20239), allowing users with access to the `_internal` index to view sensitive data.
Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)
2 rules 1 TTP 1 CVECVE-2026-45498 is a denial-of-service vulnerability in Microsoft Defender that could disrupt endpoint protection capabilities, requiring timely mitigation per vendor instructions.
CVE-2026-7613: Cost of Goods by PixelYourSite WordPress Plugin Stored XSS
2 rules 1 CVEThe Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an injected page.
CVE-2026-5783: CityPLus Reflected XSS Vulnerability
2 rules 1 TTP 1 CVECVE-2026-5783 is a reflected cross-site scripting (XSS) vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus before version V24.29750.1.0, allowing attackers to inject malicious scripts into web pages viewed by users.
Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability
2 rules 1 TTPCVE-2026-20206 describes a command injection vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent where an authenticated remote attacker with transaction test management privileges could execute arbitrary commands within the BrowserBot container as the node user.
Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability
2 rules 1 TTPCVE-2026-20199 - A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user.
Cisco Nexus 3000 and 9000 Series Switches BGP Denial of Service Vulnerability
2 rules 1 TTPCVE-2026-20171 describes a vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 and 9000 Series Switches that could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial-of-service (DoS) condition.
Plug Multipart Header Parsing Denial-of-Service Vulnerability (CVE-2026-8468)
2 rules 1 TTP 1 CVEPlug versions 1.4.0 to 1.19.1 are vulnerable to denial-of-service (CVE-2026-8468) due to unbounded buffer accumulation in multipart header parsing, allowing an unauthenticated attacker to exhaust server memory by sending a crafted multipart/form-data request.
FreePBX Security Advisories for Security-Reporting Module Vulnerabilities
2 rules 1 TTPFreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.
Multiple Vulnerabilities in Symfony Framework
3 rules 1 TTPMultiple vulnerabilities in Symfony, including CVE-2026-45070, CVE-2026-45077, CVE-2026-45304, CVE-2026-45305, CVE-2026-45753, CVE-2026-45754, CVE-2026-45755, CVE-2026-45756, CVE-2026-46626, and CVE-2026-47212, can lead to remote denial of service, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks.
Wireshark Remote Denial of Service Vulnerability
2 rules 1 TTPA vulnerability in Wireshark versions 4.4.x before 4.4.16 and 4.6.x before 4.6.6 allows a remote attacker to cause a denial of service.
CVE-2026-3039: BIND TKEY Authentication Memory Consumption Vulnerability
2 rules 1 TTP 1 CVEBIND servers configured for TKEY-based authentication using GSS-API tokens are susceptible to excessive memory consumption upon receiving and processing crafted packets, impacting availability.
CVE-2026-5946: BIND 9 `named` Assertion Failure Vulnerability
2 rules 1 CVEMultiple flaws in BIND 9's `named` component, specifically versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1, can be exploited by sending specially crafted DNS requests with non-`IN` CLASS or meta-classes, leading to assertion failures and potential denial-of-service.
Squid Vulnerability Allows Security Bypass and Information Disclosure
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in Squid to bypass security precautions and disclose information, potentially leading to unauthorized access or data leakage.
CVE-2026-9064: 389-ds-base Unauthenticated Remote Denial-of-Service
2 rules 1 TTP 1 CVECVE-2026-9064 describes a denial-of-service vulnerability in 389-ds-base where an unauthenticated attacker can send a crafted LDAP request with excessive controls, causing excessive CPU consumption and heap allocation, leading to latency degradation, worker thread starvation, or out-of-memory termination.
CVE-2026-43492 Integer Underflow in mpi_read_raw_from_sgl()
1 rule 1 CVECVE-2026-43492 is an integer underflow vulnerability in the mpi_read_raw_from_sgl function within the lib/crypto component that could lead to unexpected behavior or denial-of-service.
CVE-2026-45585: Windows BitLocker Security Feature Bypass Vulnerability ('YellowKey')
2 rulesCVE-2026-45585 is a security feature bypass vulnerability in Windows BitLocker, known as 'YellowKey', for which a public proof of concept exists, prompting Microsoft to release mitigation guidance prior to a security update.
SQLFluff Uncontrolled Resource Consumption Vulnerability (CVE-2026-46374)
2 rules 1 TTPSQLFluff versions prior to 4.2.0 are vulnerable to uncontrolled resource consumption (CVE-2026-46374), allowing an attacker to cause a denial of service by submitting a maliciously crafted, long SQL query.
Dasel Selector Lexer Index-Out-of-Range Panic on Trailing Backslash (CVE-2026-46377)
2 rulesThe dasel selector lexer is vulnerable to an index-out-of-range panic when tokenizing a quoted string that ends with a trailing backslash (e.g., `"\` or `'\`), leading to a process crash if an attacker can control the selector string.
Dasel Denial-of-Service Vulnerability via Unterminated Regex
2 rules 1 TTPDasel versions 3.0.0 to 3.3.1 are vulnerable to a denial-of-service attack (CVE-2026-46378) where the selector lexer enters a non-terminating loop when tokenizing an unterminated regex pattern, causing 100% CPU usage on one core, which can be triggered by an attacker-controlled selector/query string.
@libp2p/kad-dht Unvalidated PUT_VALUE Records Allow Unbounded Disk Exhaustion
2 rules 2 TTPsAn unauthenticated remote peer can exhaust the disk storage of any `@libp2p/kad-dht` node running in server mode by sending an unbounded stream of `PUT_VALUE` messages with crafted keys to bypass validation and cause disk exhaustion.
Dell Security Advisory Addresses Vulnerabilities in Multiple Products
2 rulesDell published security advisories between May 11 and 17, 2026, addressing vulnerabilities in Dell Enterprise Sonic Distribution, Dell Live Optics Collector, Intel 800 Series Ethernet Adapters, Dell PowerEdge with AMD Graphics, and PowerScale InsightIQ, prompting users to apply necessary updates.
Wire Protobuf Negative Length Vulnerability (CVE-2026-45799)
2 rules 2 TTPsA vulnerability in Wire's protobuf group-skipping logic allows a crafted payload with a negative length to cause a runtime exception and potentially crash services decoding untrusted protobuf, addressed in version 6.3.0.
Bandit HTTP/1 Chunked Request Trailer Denial of Service
2 rules 1 TTP 1 CVEBandit versions 1.6.0 through 1.11.0 are vulnerable to an unauthenticated denial-of-service (CVE-2026-39806) via a chunked request with trailers, where sending a request with `Transfer-Encoding: chunked` and a trailer field causes the connection's worker process to spin forever in an infinite recursion, exhausting the listener pool and rendering the server unresponsive.
Bandit HTTP/1 Chunked Request DoS Vulnerability
1 rule 1 TTP 1 CVEBandit's HTTP/1 chunked-body reader silently drops the request size cap, leading to excessive memory buffering. An unauthenticated attacker can crash Bandit-fronted Phoenix/Plug applications by sending a single 'Transfer-Encoding: chunked' request to any URL, causing BEAM memory exhaustion and a denial-of-service.
Mozilla Firefox Security Updates Released
1 ruleMozilla released security updates on May 19, 2026, addressing vulnerabilities in Firefox versions prior to 151, Firefox ESR versions prior to 115.36, and Firefox ESR versions prior to 140.11.
libcrux-chacha20poly1305: Potential Panic on Overlong Ciphertext Buffer
1 TTPAn application that passes an overlong ciphertext buffer to `libcrux_chacha20poly1305::encrypt` or `libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` can experience a panic, leading to a crash if the buffer length is attacker-controlled, affecting libcrux-chacha20poly1305 versions prior to 0.0.8.
GitHub Actions GITHUB_TOKEN Disclosure via Composer Validation Failure
2 rules 1 TTPComposer leaks GitHub OAuth tokens in GitHub Actions logs if they do not match the expected format due to a validation regex, leading to potential unauthorized access.
Kieback & Peter DDC Building Controllers Cross-Site Scripting Vulnerability (CVE-2026-4293)
2 rules 1 TTPA cross-site scripting vulnerability, CVE-2026-4293, exists in multiple Kieback & Peter DDC Building Controllers that could allow an attacker to take control of the victim's browser.
Mailpit Unauthenticated Remote Memory Exhaustion DoS Vulnerability
3 rules 1 TTPMailpit is vulnerable to an unauthenticated remote memory-exhaustion denial-of-service attack due to missing size limits on incoming SMTP DATA and HTTP requests, leading to unbounded memory and disk growth, potentially crashing the application.
Keycloak OIDC Implicit Flow Bypass Vulnerability (CVE-2026-7571)
2 rules 1 TTP 1 CVECVE-2026-7571 describes a vulnerability in Keycloak where a low-privilege user can bypass security controls intended to disable the implicit flow in OpenID Connect (OIDC) clients by manipulating client data during session restart, potentially exposing access tokens.
Apache Tomcat Security Bypass Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Apache Tomcat to bypass security measures.
Podman Vulnerability Allows File Manipulation
1 rule 1 TTPA remote, authenticated attacker can exploit a vulnerability in Podman to manipulate files on the host system.
Unbound Cache Poisoning Vulnerability
1 ruleA vulnerability in Unbound allows an attacker from an adjacent network to manipulate the cache, potentially leading to domain hijacking.
Red Hat Enterprise Linux Valkey Vulnerabilities Lead to File Manipulation and Denial of Service
2 rules 1 TTPAn authenticated or anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux regarding Valkey to manipulate files or cause a denial-of-service condition.
Multiple Vulnerabilities in Mattermost Products
2 rulesMultiple unspecified vulnerabilities in Mattermost Desktop App and Mattermost Server allow an attacker to cause an unspecified security issue.
Multiple Vulnerabilities in Docker Allow Privilege Escalation and DoS
2 rules 3 TTPsMultiple vulnerabilities in Docker allow a local attacker to execute arbitrary code with administrator privileges, cause a denial-of-service condition, or manipulate data.
Keycloak Security Bypass Vulnerability
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Keycloak to bypass security measures.
Multiple Vulnerabilities in Red Hat Build of Quarkus
2 rules 2 TTPsAn authenticated or unauthenticated remote attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Quarkus to perform a denial of service attack, disclose sensitive information, or manipulate data.
BigBlueButton Vulnerability Allows Cross-Site Scripting
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in BigBlueButton to conduct a Cross-Site Scripting (XSS) attack.
Multiple Vulnerabilities in Ruby Allow for DoS and Information Disclosure
2 rules 3 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Ruby to cause a denial-of-service condition and disclose confidential information.
CVE-2026-7168 Cross-Proxy Digest Authentication State Leak
2 rules 1 CVEMicrosoft published information regarding CVE-2026-7168, a cross-proxy Digest authentication state leak.
CVE-2026-37459: FRRouting BGP UPDATE Message Integer Underflow DoS
2 rules 1 TTP 1 CVEAn integer underflow vulnerability, CVE-2026-37459, in FRRouting (FRR) versions stable/10.0 to stable/10.6 allows a remote attacker to cause a Denial of Service (DoS) by sending a crafted BGP UPDATE message.
CVE-2026-5773: SMB Connection Reuse Vulnerability
2 rules 1 CVEMicrosoft published information about CVE-2026-5773, a vulnerability related to the incorrect reuse of SMB connections.
CVE-2026-6429 netrc Credential Leak Vulnerability
1 rule 1 CVECVE-2026-6429 is a credential leak vulnerability affecting Microsoft products.
FRRouting CVE-2026-37458 Denial of Service Vulnerability
1 rule 1 TTP 1 CVEA denial-of-service vulnerability, identified as CVE-2026-37458, exists in the MP_REACH_NLRI component of FRRouting versions stable/10.0 to stable/10.6, where authenticated attackers can trigger a DoS by sending a crafted UPDATE message due to missing input validation.
CVE-2026-31704 ksmbd u16 DACL Size Overflow Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-31704 is a vulnerability in ksmbd related to the use of check_add_overflow() to prevent a u16 DACL size overflow, potentially leading to denial of service or privilege escalation.
LiteLLM SQL Injection Vulnerability (CVE-2025-45809)
2 rules 1 TTP 1 IOCA SQL Injection vulnerability (CVE-2025-45809) in LiteLLM versions prior to 1.81.0 allows unauthenticated attackers to potentially steal database contents and read server files via time-based blind SQL injection in the `/key/block` and `/key/unblock` endpoints.
OpenTelemetry eBPF Instrumentation (OBI) Memcached Integer Overflow DoS
1 rule 2 TTPsA remotely reachable integer overflow in OpenTelemetry eBPF Instrumentation's (OBI) memcached text protocol parser can crash the OBI process, causing a denial of service due to unchecked arithmetic when handling large payload sizes in memcached storage commands.
OpenTelemetry eBPF Instrumentation MongoDB Parser Denial-of-Service
2 rules 1 TTPMalformed MongoDB wire messages can trigger uncaught panics in the OpenTelemetry eBPF Instrumentation agent's MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service.
OpenTelemetry eBPF Instrumentation Postgres Parser Vulnerable to Panic via Malformed BIND Payloads (CVE-2026-45678)
2 rules 1 TTPThe OpenTelemetry eBPF Instrumentation (OBI) Postgres protocol parser is vulnerable to a remote availability issue - when processing BIND messages, the parser assumes payloads contain a valid NUL-terminated portal name; a crafted empty or unterminated payload can cause OBI to slice beyond the end of the captured buffer, triggering a runtime panic and crashing the agent.
Multiparty Denial of Service via Prototype Pollution (CVE-2026-8161)
2 rules 1 TTP 1 CVEMultiparty versions 4.2.3 and lower are vulnerable to denial of service via prototype pollution, where a crafted multipart/form-data request with a field name colliding with an Object.prototype property triggers a TypeError, leading to an uncaught exception and process crash.
parse-nested-form-data Prototype Pollution Vulnerability (CVE-2026-45302)
1 rule 1 TTPparse-nested-form-data versions 1.0.0 and earlier are vulnerable to prototype pollution via crafted FormData field names, allowing an unauthenticated remote client to mutate `Object.prototype` and potentially corrupt application state, alter control flow, or cause denial of service.
form-data-objectizer Prototype Pollution Vulnerability (CVE-2026-46510)
2 rules 1 TTPThe form-data-objectizer npm package version 1.0.0 is vulnerable to prototype pollution (CVE-2026-46510) via crafted form keys, allowing an attacker to modify Object.prototype and potentially cause denial-of-service, bypass security checks, or inject unintended values.
GnuTLS DTLS Packet Reordering Vulnerability (CVE-2026-42009)
2 rules 1 TTP 1 CVEA remote attacker could exploit a flaw in GnuTLS's DTLS packet reordering logic (CVE-2026-42009) to cause unstable packet ordering or undefined behavior, resulting in a denial of service.
AWS EKS Control Plane Logging Disabled
2 rules 1 TTPThis rule detects successful Amazon EKS UpdateClusterConfig requests that disable control plane logging, potentially indicating defense evasion via compromised AWS credentials or unauthorized administrative access that reduces visibility into cluster activity.
Avro Map Decoder Vulnerable to Denial-of-Service via Unbounded Memory Allocation
2 rules 1 TTPThe Avro map decoder accepted attacker-controlled block-element counts, leading to unbounded map growth and potential denial-of-service via memory exhaustion; upgrading to v2.33.0 requires explicit configuration of MaxMapAllocSize to mitigate the vulnerability.
macOS Finder Sync Plugin Persistence via Pluginkit
2 rules 1 TTPThis rule detects suspicious Finder Sync plugin registrations on macOS, where adversaries abuse the pluginkit process to establish persistence by repeatedly executing malicious payloads.
Q1 2026 Mobile Threat Landscape: SparkCat and Triada Updates
2 rules 1 TTPThe Q1 2026 mobile threat landscape saw a decrease in overall attack volume driven by reduced adware and RiskTool detections, while the number of unique users targeted remained stable, with new SparkCat variants on app stores and increased banking Trojan and Triada backdoor activity.
Kubernetes Static Pod Manifest File Access
2 rules 2 TTPsThis rule detects Linux process executions that access Kubernetes static pod manifest files, potentially indicating malicious tampering for persistence or privilege escalation.
Entra ID Register Device with Unusual User Agent (Azure AD Join)
2 rules 1 TTPDetects suspicious Microsoft Entra ID audit events for device registration where details indicate an Azure AD join and the user agent is not a standard registration client, potentially indicating scripted registration, third-party tooling, or malicious device registration for persistence or token abuse.
Entra ID Microsoft Authentication Broker Sign-In to Unusual Resource
2 rules 2 TTPsDetects successful Microsoft Entra ID sign-ins where the client application is the Microsoft Authentication Broker (MAB) and the requested resource identifier is outside a short list of commonly observed first-party targets, potentially indicating abuse to obtain tokens for unexpected APIs or enterprise applications.
Curl or Wget Execution from Container Context
2 rules 1 TTPDetects execution of curl or wget from processes running inside OCI/runc-backed containers, potentially indicating ingress tool transfer or data exfiltration after a container breakout.
Kubernetes Multi-Resource Discovery
2 rules 1 TTPDetects potential reconnaissance activity in Kubernetes environments where adversaries or automated scripts attempt to map the environment by rapidly querying multiple API resource kinds, indicative of initial setup before actions like privilege escalation or data exfiltration.
Kubernetes Secret Access by Node or Pod Service Account
2 rules 1 TTPThis rule detects Kubernetes audit events where node or pod service accounts are accessing secrets via `get` or `list` operations, which may indicate credential access attempts by attackers sweeping Secret objects for sensitive information.
AWS SSM Session Manager Child Process Execution
3 rules 3 TTPsThis rule identifies process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which adversaries may abuse for remote execution and lateral movement using legitimate AWS credentials and IAM permissions.
Tycoon2FA AiTM Phishing via Microsoft Entra ID Sign-Ins
2 rules 2 TTPsDetects Microsoft Entra ID sign-ins consistent with Tycoon2FA phishing-as-a-service (PhaaS) adversary-in-the-middle (AiTM) activity targeting Microsoft 365 and Gmail, where the Microsoft Authentication Broker requests tokens for Microsoft Graph or Exchange Online, or the Office web client application authenticates to itself, combined with Node.js-style user agents (node, axios, undici).
Microsoft Graph Multi-Category Reconnaissance Burst
2 rules 2 TTPsThe rule detects Microsoft Graph activity from delegated user tokens where a single user session and source IP rapidly touches multiple high-value Graph paths indicative of reconnaissance, suggesting a broad enumeration playbook.
Potential macOS SSH Brute Force Detected
2 rules 2 TTPsThis rule identifies a high number of inbound SSH login attempts on a macOS host within a short time window by monitoring the `sshd-keygen-wrapper` process, indicating potential brute-force attacks against exposed SSH services.
Vercel AI Server-Side Request Forgery Vulnerability (CVE-2026-8768)
2 rules 1 TTP 1 CVEVulnerability CVE-2026-8768 describes a server-side request forgery (SSRF) flaw in the validateDownloadUrl function of the provider-utils component in Vercel AI versions up to 3.0.97, enabling remote attackers to potentially make internal requests.
Fuel CMS 1.4.13 Blind SQL Injection Vulnerability (CVE-2021-47980)
2 rules 1 TTP 1 CVEFuel CMS 1.4.13 is vulnerable to blind SQL injection via the 'col' parameter in the Activity Log interface, allowing authenticated attackers to manipulate database queries and extract information through time-based delays (CVE-2021-47980).
WP Learn Manager Stored XSS Vulnerability (CVE-2021-47975)
1 rule 1 TTP 1 CVEWP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability (CVE-2021-47975) that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter via a POST request to the jslm_fieldordering page, resulting in arbitrary JavaScript execution when administrators view the field ordering interface.
Sticky Notes Widget Denial-of-Service Vulnerability (CVE-2021-47973)
1 rule 1 TTP 1 CVESticky Notes Widget 3.0.6 is vulnerable to a denial-of-service attack (CVE-2021-47973), where an attacker can crash the application on iOS devices by pasting excessively long character strings into note fields.
Sticky Notes & Color Widgets 1.4.2 Denial of Service Vulnerability (CVE-2021-47972)
2 rules 1 TTP 1 CVESticky Notes & Color Widgets 1.4.2 is vulnerable to denial of service via excessively long character strings (CVE-2021-47972), allowing attackers to crash the application.
My Notes Safe 5.3 Denial-of-Service Vulnerability (CVE-2021-47971)
2 rules 1 TTP 1 CVEMy Notes Safe 5.3 is vulnerable to a denial-of-service attack (CVE-2021-47971) where an attacker can crash the application by pasting excessively long character strings into note fields.
Macaron Notes 5.5 Denial of Service Vulnerability (CVE-2021-47970)
2 rules 1 TTP 1 CVEMacaron Notes 5.5 is vulnerable to a denial-of-service condition (CVE-2021-47970) due to its handling of excessively long character strings in notes, leading to application crashes.
Color Notes 1.4 Denial-of-Service Vulnerability (CVE-2021-47969)
2 rules 1 TTP 1 CVEColor Notes 1.4 is vulnerable to a denial-of-service attack (CVE-2021-47969) where pasting excessively long character strings into note fields can crash the application, achieved by generating and pasting a 350,000-character payload twice into a new note.
CVE-2026-43490: ksmbd inherited ACE SID length validation vulnerability
2 rules 1 CVEMicrosoft published information about CVE-2026-43490, a vulnerability in ksmbd related to the validation of inherited ACE SID length.
LSASS Memory Dump Handle Access
2 rules 1 TTPDetection of handle requests to the LSASS process with specific access masks commonly used by tools to dump memory, indicating potential credential access attempts.
CVE-2021-47959: WPGraphQL Plugin Denial of Service via Batched Queries
2 rules 1 TTP 1 CVEThe WordPress Plugin WPGraphQL version 1.3.5 is vulnerable to a denial-of-service attack where unauthenticated attackers can exhaust server resources by sending batched GraphQL queries with duplicated fields, potentially causing server out-of-memory conditions and MySQL connection errors.
phpMyFAQ Unauthenticated Information Disclosure via Solution ID Enumeration
2 rules 1 TTP 1 CVEphpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via predictable URL patterns.
phpMyFAQ Unauthenticated TOTP Bypass via Brute-Force (CVE-2026-45010)
2 rules 1 TTP 1 CVEphpMyFAQ before 4.1.2 is vulnerable to improper restriction of excessive authentication attempts in the /admin/check endpoint, allowing unauthenticated attackers to brute-force any user's six-digit TOTP code and bypass two-factor authentication, potentially gaining full administrative access (CVE-2026-45010).
epa4all-client Library Vulnerable to TLS Certificate Validation Issue (CVE-2026-45574)
2 rules 1 TTP 1 IOCThe epa4all-client library before version 1.2.2 is vulnerable to a TLS certificate validation issue, allowing a man-in-the-middle attacker to intercept SOAP traffic and sensitive patient data by presenting a malicious TLS certificate.
Better Auth Rate Limiter Bypass via IPv6 Prefix Rotation (CVE-2026-45364)
2 rulesBetter Auth versions before 1.4.17 and pre-release versions before 1.5.0-beta.9 are vulnerable to CVE-2026-45364, a rate-limiting bypass that allows IPv6 clients to rotate through numerous source addresses or vary the textual encoding of one IPv6 address, effectively defeating rate limiting on authentication endpoints, potentially leading to credential stuffing, account enumeration, and amplification of password-reset email fan-out.
Nimiq nimiq-keys Ed25519 Signature Length Vulnerability (CVE-2026-40092)
2 rules 1 TTPA malicious network peer can crash a Nimiq full node by publishing a crafted Kademlia DHT record due to unchecked Ed25519 signature length in `TaggedPublicKey::verify` (CVE-2026-40092).
PureLogs Infostealer Delivered via PawsRunner Steganography
2 rules 1 TTPA steganography-based malware campaign uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery methods.
Windows Snipping Tool NTLMv2 Hash Hijack Vulnerability (CVE-2026-33829)
2 rules 1 TTP 1 CVEA local exploit has been published for Windows Snipping Tool (CVE-2026-33829), enabling NTLMv2 Hash Hijacking by forcing authentication to a remote SMB server via a crafted ms-screensketch:edit URI, potentially leading to credential theft and lateral movement.
Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing
2 rules 1 TTPA local exploit has been published for Remote Sunrise Helper for Windows 2026.14, detailing an unauthenticated file/directory listing vulnerability. Successful exploitation allows unauthenticated attackers to list files and directories on the affected system.
Multiple Vulnerabilities in Shibboleth Products Leading to DoS and Security Policy Bypass
2 rules 1 TTP 1 CVEMultiple vulnerabilities have been discovered in Shibboleth Identity Provider and OpenSAML Java library that allow an attacker to cause a remote denial of service and security policy bypass, addressed in versions 5.2.2 and later.
Shibboleth Identity Provider Vulnerabilities Leading to SMTP Injection and Denial of Service
1 rule 1 TTPMultiple vulnerabilities in Shibboleth Identity Provider allow an attacker to perform SMTP injection or cause a denial of service.
File Creation in World-Writable Directory by Unusual Process
2 rules 1 TTPThis rule detects the creation of files in world-writable directories on Linux systems by an unusual process, which is a common defense evasion tactic for potential lateral movement or malicious payload staging.
Maltrail IOC Feed Update - 2026-05-15
3 rules 2 TTPs 50 IOCsThis brief summarizes a Maltrail IOC feed update on 2026-05-15, containing indicators associated with APT_Kimsuky, CyberstrikeAI, Android_Joker, Sectoprat, EK_Landupdate808, and MagentoCore campaigns involving suspicious domains and IP addresses.
Multiple Vulnerabilities in GStreamer
2 rules 3 TTPsMultiple vulnerabilities in GStreamer can be exploited by a remote, anonymous attacker to disclose information, conduct a denial-of-service attack, corrupt data, or execute arbitrary code.
GNU libc Vulnerabilities Allow DNS Response Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses, potentially leading to redirection to malicious sites.
Multiple Vulnerabilities in GIMP
2 rules 3 TTPsMultiple vulnerabilities in GIMP could allow an attacker to execute arbitrary code, disclose sensitive information, manipulate data, or cause a denial-of-service condition.
Multiple Vulnerabilities in AMD EPYC, Athlon, and Ryzen Processors
2 rules 7 TTPsMultiple vulnerabilities in AMD EPYC, Athlon, and Ryzen processors can be exploited by an attacker to execute arbitrary code, escalate privileges, bypass security measures, cause a denial-of-service condition, disclose sensitive information, or manipulate data.
CVE-2026-4094: FOX – Currency Switcher Professional for WooCommerce Plugin Vulnerability
2 rules 1 TTP 1 CVEThe FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss (CVE-2026-4094) due to a missing capability check, allowing authenticated attackers with Contributor-level access or higher to delete the multi-currency configuration.
Open WebUI Broken Authorization Allows Task Cancellation
2 rules 1 TTP 1 CVEOpen WebUI is vulnerable to broken object-level authorization, allowing low-privilege authenticated users to enumerate and stop global background tasks across the system, leading to a denial-of-service condition and is tracked as CVE-2026-45399 and CVE-2025-63681.
Svelte devalue Denial-of-Service via Sparse Array Deserialization (CVE-2026-42570)
2 rules 1 TTPThe `devalue` package is vulnerable to a denial-of-service (DoS) attack (CVE-2026-42570) due to excessive memory allocation during sparse array deserialization via `devalue.parse`, affecting versions 5.6.3 through 5.8.0.
CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability
2 rules 2 TTPs 1 CVE 7 IOCsCVE-2026-42897 is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server that allows an attacker to perform spoofing attacks by injecting malicious scripts into web pages.
Synapse CPU Starvation Denial of Service Vulnerability
2 rules 1 TTP 1 IOCA denial-of-service vulnerability exists in Synapse where local authenticated users can cause CPU starvation, leading to request failures for other users (CVE-2026-45078).
Kubernetes Ephemeral Container Added to Pod for Privilege Escalation
2 rules 2 TTPsThis rule detects allowed updates to Kubernetes pods/ephemeralcontainers subresource by non-system identities, which can be abused for privilege escalation, lateral movement, or persistence by injecting tooling into running pods.
MongoDB Timeseries Collection Vulnerability (CVE-2026-8053)
1 rule 1 CVEMongoDB published a security advisory to address CVE-2026-8053, an undefined behavior vulnerability when inserting data with duplicate field names into timeseries collections, affecting versions 5.0.0 through 8.3.1.
AWS EKS Access Entry Modification Detected
2 rules 2 TTPsSuccessful Amazon EKS Access Entries API operations that create, update, attach, detach, or delete authentication mappings between IAM principals and the cluster, potentially indicating persistence or privilege escalation are detected.
Vvveb Uncontrolled Recursion Denial of Service (CVE-2026-41935)
1 rule 2 TTPs 1 CVEVvveb before version 1.0.8.3 is vulnerable to an uncontrolled recursion vulnerability in the admin controller dispatch cycle that allows a low-privilege attacker to cause denial of service by exhausting PHP memory.
Siemens SIPROTEC 5 Insufficient Session ID Randomness Leads to Session Hijacking (CVE-2024-54017)
2 rules 1 TTP 1 CVESiemens SIPROTEC 5 devices are vulnerable to session hijacking (CVE-2024-54017) due to the use of insufficiently random numbers in session identifier generation, potentially allowing an unauthenticated remote attacker to brute-force a valid session and gain unauthorized read access.
Siemens SIMATIC HMI Unified Comfort Panels Unauthenticated Access Vulnerability
2 rules 1 TTP 1 CVESiemens SIMATIC HMI Unified Comfort Panels before V21.0 are vulnerable to unauthenticated access via the help link and Control Panel (CVE-2026-27662), potentially leading to unauthorized configuration changes and discovery of backdoors.
Siemens Ruggedcom Rox Improper Access Control Vulnerability
2 rules 1 TTP 1 CVESiemens Ruggedcom Rox is vulnerable to improper access control, allowing an authenticated remote attacker to read arbitrary files with root privileges from the underlying operating system's filesystem via the web server's JSON-RPC interface, as tracked by CVE-2025-40948.
FlowiseAI Exposes Basic Auth Credentials via API
2 rules 1 TTPFlowiseAI exposes a basic authentication endpoint without rate limiting, allowing attackers to brute-force credentials and gain unauthorized access to the application.
Kubernetes API Server Proxying Request to Kubelet
2 rules 3 TTPsDetection of non-system identities using the Kubernetes nodes/proxy API to proxy requests through the API server directly to a node's Kubelet, potentially leading to privilege escalation and sensitive information exposure.
Strapi Unauthenticated Account Takeover via Relational Filtering Vulnerability (CVE-2026-27886)
2 rules 1 TTPStrapi versions prior to 5.37.0 are vulnerable to an unauthenticated boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field, via the 'where' query parameter on publicly accessible content-types; extracting an admin reset token via this oracle makes full administrative account takeover possible without authentication.
Absinthe GraphQL Fragment Validation Denial-of-Service (CVE-2026-43967)
2 rules 1 TTP 1 CVEA denial-of-service vulnerability exists in the Absinthe GraphQL library (versions 1.2.0 to 1.10.1), where an unauthenticated attacker can exhaust server resources by submitting a crafted GraphQL query with a large number of fragment definitions due to the quadratic complexity of fragment name uniqueness validation.
Absinthe GraphQL Atom Table Exhaustion Vulnerability
2 rules 1 TTP 1 CVEAbsinthe versions 1.5.0 before 1.10.2 are vulnerable to a denial-of-service attack (CVE-2026-42793) due to unbounded atom creation when parsing GraphQL SDL documents, allowing an attacker to exhaust the Erlang VM's atom table and crash the entire node by submitting a crafted document with numerous unique directive names.
CVE-2026-3892 - WordPress Motors Plugin Arbitrary File Deletion
1 rule 1 TTP 1 CVEThe Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in versions up to 1.4.107 due to insufficient file path validation in the become-dealer logo upload flow, allowing authenticated attackers with subscriber level access and above to delete arbitrary files on the server.
ManageWP Worker Plugin Vulnerable to Stored XSS via HTTP Header
2 rules 1 TTP 1 CVEThe ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'MWP-Key-Name' HTTP request header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator visits the plugin's connection management page with debug parameters; this affects all versions up to and including 4.9.31.
HPE Security Advisory for Telco Intelligent Assurance Vulnerabilities
2 rulesHPE released a security advisory addressing multiple vulnerabilities in Telco Intelligent Assurance version 4.2.14, prompting users to apply necessary updates to mitigate potential risks.
CVE-2026-42409 - F5 BIG-IP TMM Process Termination via HTTP/2 and iRules
2 rules 1 TTP 1 CVECVE-2026-42409 describes a vulnerability in F5 BIG-IP where undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate when an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, potentially leading to denial of service.
CVE-2026-41956: F5 TMM Termination Vulnerability on UDP Virtual Servers
2 rules 1 TTP 1 CVECVE-2026-41956 describes a vulnerability in F5 Networks' Traffic Management Microkernel (TMM) where undisclosed requests can cause TMM termination when a classification profile is configured on a UDP virtual server, leading to a denial-of-service condition.
Lenovo Personal Cloud Storage Improper File Path Validation Vulnerability (CVE-2026-6282)
2 rules 1 TTP 1 CVECVE-2026-6282 describes a potential improper file path validation vulnerability in Lenovo Personal Cloud Storage devices, allowing a remote authenticated user to move or access files belonging to other users.
CVE-2026-42920 - F5 BIG-IP TMM Termination Vulnerability
2 rules 1 TTP 1 CVECVE-2026-42920 describes a vulnerability where undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate when a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server.
CVE-2026-41227: F5 Networks Traffic Management Microkernel (TMM) Process Termination via HTTP/2 Traffic
2 rules 1 TTP 1 CVECVE-2026-41227 describes a vulnerability in an F5 Networks product where undisclosed traffic on an HTTP/2 virtual server with Layer 7 DoS Protection enabled can lead to increased memory consumption and termination of the Traffic Management Microkernel (TMM) process.
CVE-2026-40629: F5 Networks Virtual Server Denial of Service
1 rule 1 TTP 1 CVECVE-2026-40629 describes a vulnerability in F5 Networks products where, when SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections, leading to a denial of service.
BIG-IP VE TMM Termination Vulnerability (CVE-2026-40618)
2 rules 1 TTP 1 CVECVE-2026-40618 describes a vulnerability in F5 BIG-IP Virtual Edition (VE) where specific traffic can cause the Traffic Management Microkernel (TMM) to terminate when an SSL profile is configured without Intel QuickAssist Technology (QAT) or with crypto.hwacceleration disabled, potentially leading to a denial-of-service.
CVE-2026-40423: F5 Traffic Management Microkernel (TMM) Termination Vulnerability
2 rules 1 TTP 1 CVECVE-2026-40423 describes a vulnerability in F5 Networks products where undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate when a SIP profile is configured on a virtual server, leading to a denial-of-service condition.
F5 BIG-IP APM Undisclosed Traffic Denial-of-Service Vulnerability (CVE-2026-40067)
2 rules 1 TTP 1 CVEA vulnerability exists in F5 BIG-IP APM where, when an APM access policy is configured on a virtual server, undisclosed network traffic can cause the apmd process to terminate, resulting in a denial of service (CVE-2026-40067).
BIG-IP Advanced WAF/ASM Denial-of-Service Vulnerability (CVE-2026-40060)
2 rules 1 TTP 1 CVECVE-2026-40060 describes a vulnerability in F5 BIG-IP Advanced WAF and ASM security policies where undisclosed requests can cause the `bd` process to terminate, leading to a denial-of-service condition.
BIG-IP Configuration Utility LDAP Authentication Denial-of-Service (CVE-2026-39455)
2 rules 1 TTP 1 CVECVE-2026-39455 describes a denial-of-service vulnerability in the BIG-IP Configuration utility when configured with LDAP authentication, where undisclosed traffic can cause the httpd process to exhaust file descriptors.
Kuicms Php EE 2.0 Persistent Cross-Site Scripting Vulnerability (CVE-2020-37222)
2 rules 1 TTP 1 CVEKuicms Php EE 2.0 is vulnerable to persistent cross-site scripting (CVE-2020-37222), allowing unauthenticated attackers to inject malicious scripts via the bbs reply endpoint, leading to arbitrary script execution in users' browsers.
Joomla com_fabrik Directory Traversal Vulnerability (CVE-2020-37219)
2 rules 1 TTP 1 CVEJoomla com_fabrik 3.9.11 is vulnerable to a directory traversal attack (CVE-2020-37219) where an unauthenticated attacker can list arbitrary files by manipulating the folder parameter in a GET request to the onAjax_files method, using path traversal sequences to access system directories outside the web root.
CVE-2026-0259 Arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire Appliance
2 rulesCVE-2026-0259 allows a low-privileged user to read sensitive information and delete arbitrary files on Palo Alto Networks WildFire WF-500 and WF-500-B appliances running in the default non-FIPS configuration.
CVE-2026-0243: Prisma SD-WAN Denial-of-Service via Crafted IPv6 Packet
2 rules 1 TTPAn unauthenticated, adjacent attacker can disrupt Palo Alto Networks Prisma SD-WAN ION devices by sending a specially crafted IPv6 packet, leading to a denial-of-service condition.
CVE-2026-0245 Prisma Access Agent Information Disclosure Vulnerability
1 rule 1 TTPCVE-2026-0245 describes multiple information disclosure vulnerabilities in Palo Alto Networks Prisma Access Agent before version 26.2.1 on macOS and Windows, allowing a local user to access sensitive configuration data and credentials.
CVE-2026-0257 PAN-OS GlobalProtect Authentication Bypass Vulnerability
1 rule 1 TTPAn authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVE-2026-0257) when authentication override cookies are enabled, allowing an attacker to establish an unauthorized VPN connection.
CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities
2 rules 1 TTPCVE-2026-0249 describes multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect app that could allow an attacker to intercept encrypted communications and potentially compromise the endpoint, especially on macOS, Android, and ChromeOS.
CVE-2026-0239 Chronosphere Chronocollector Information Disclosure Vulnerability
1 ruleCVE-2026-0239 is an information disclosure vulnerability in Chronosphere Chronocollector versions earlier than v0.116.0, allowing an unauthenticated attacker with network access to retrieve sensitive information.
CVE-2026-0256 PAN-OS Stored Cross-Site Scripting (XSS) Vulnerability
2 rules 1 TTPA stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS allows a malicious authenticated administrator to inject a JavaScript payload via the web interface, potentially impacting other administrators.
CVE-2026-0244 Prisma SD-WAN ION Improper Certificate Validation Vulnerability
2 rules 1 TTPCVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION that allows a man-in-the-middle (MitM) attacker to impersonate the controller.
CVE-2026-0261 PAN-OS Authenticated Admin Command Injection Vulnerability
2 rules 1 TTPCVE-2026-0261 describes multiple command injection vulnerabilities in Palo Alto Networks PAN-OS software that allow an authenticated administrator to bypass system restrictions and execute arbitrary commands as root.
CVE-2026-0242: Trust Protection Foundation SQL Injection Vulnerability
2 rules 1 TTPA SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database, potentially leading to sensitive data exposure, data modification, and privilege escalation.
CVE-2026-0241: Trust Protection Foundation Authorization Bypass Vulnerabilities
2 rules 1 TTPCVE-2026-0241 describes multiple incorrect authorization vulnerabilities in Palo Alto Networks Trust Protection Foundation that allow attackers to bypass access controls and perform unauthorized actions on restricted resources.
CVE-2026-0258 PAN-OS SSRF vulnerability in IKEv2 certificate URL fetching
2 rules 1 TTPCVE-2026-0258 is a medium severity server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS that allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations, potentially leading to a denial of service (DoS).
CVE-2026-0250 Palo Alto Networks GlobalProtect App Buffer Overflow Vulnerability
2 rules 1 TTPCVE-2026-0250 is a medium severity buffer overflow vulnerability in Palo Alto Networks GlobalProtect App that could allow a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges by intercepting and manipulating requests and responses between the Portal and Gateway.
CVE-2026-0240 Trust Protection Foundation Sensitive Information Disclosure Vulnerability
2 rules 2 TTPsCVE-2026-0240 is a medium severity information disclosure vulnerability in Palo Alto Networks Trust Protection Foundation, allowing an authenticated attacker to obtain sensitive information from the server's vault, potentially leading to user impersonation and arbitrary modification of configuration settings.
CVE-2026-0262 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Parsing
2 rules 2 TTPsUnauthenticated attackers can cause a denial of service (DoS) condition on Palo Alto Networks PAN-OS firewalls by sending specially crafted network traffic, as described in CVE-2026-0262.
CVE-2026-0246 Prisma Access Agent Local Privilege Escalation Vulnerability
2 rules 1 TTPA local privilege escalation vulnerability exists in Palo Alto Networks Prisma Access Agent versions prior to 26.2.1 on Linux, macOS, and Windows, allowing a locally authenticated non-administrative user to gain root or NT AUTHORITY\SYSTEM privileges and execute arbitrary code.
CVE-2026-0251: Palo Alto Networks GlobalProtect App Local Privilege Escalation
3 rules 1 TTPMultiple local privilege escalation vulnerabilities exist in Palo Alto Networks GlobalProtect App, allowing a local user to escalate privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, enabling arbitrary command execution with administrative privileges.
CVE-2026-0248 Prisma Access Agent Improper Certificate Validation Vulnerability
2 rules 2 TTPsCVE-2026-0248 is an improper certificate validation vulnerability in Prisma Access Agent for Android and Chrome OS, enabling a man-in-the-middle (MitM) attack to intercept VPN traffic and capture sensitive device information by presenting a certificate issued by a trusted Certificate Authority.
CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities
2 rules 1 TTPMultiple authorization bypass vulnerabilities exist in the Endpoint DLP component of Prisma Access Agent, allowing a local attacker to bypass authentication controls and execute privileged operations on macOS and Windows systems with Endpoint DLP enabled; versions prior to 26.2.1 are affected.
CVE-2026-6177 - Custom Twitter Feeds WordPress Plugin Stored XSS
2 rules 1 TTP 1 CVEThe Custom Twitter Feeds plugin for WordPress is vulnerable to stored cross-site scripting (XSS) in versions up to and including 2.5.4 due to insufficient output escaping, allowing unauthenticated attackers to inject arbitrary web scripts.
coreActivity: Activity Logging for WordPress Plugin Vulnerable to PHP Object Injection (CVE-2026-7635)
2 rules 1 TTP 1 CVEThe coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7635), allowing unauthenticated attackers to inject a crafted PHP serialized payload via the User-Agent header, leading to a persistent Denial of Service condition.
Anchor: InterfaceAccount Allows Account Substitution
2 rulesThe `InterfaceAccount` in `anchor-lang` allows an unexpected account type to be passed due to disabled discriminator checking, patched in version 1.0.0-rc.2 and later.
Goobi Viewer Unauthenticated Solr Streaming Expression Proxy Vulnerability
2 rules 1 TTPThe Goobi viewer REST endpoint accepted an arbitrary Solr streaming expression from unauthenticated network clients, enabling attackers to read, modify, or delete the complete Solr index; this was resolved by removing the affected API endpoint.
Leveraging Linux Cgroups for Threat Detection and Investigation
2 rulesThis brief outlines how Linux cgroups, a kernel feature for resource management, can be repurposed to provide valuable telemetry for detecting malicious processes, particularly in systemd, Docker, and Kubernetes environments, aiding in investigations of server compromises.
Kyverno Vulnerability Allows Cross-Site Scripting
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Kyverno to perform a cross-site scripting attack.
Devolutions Server Vulnerability Allows File Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Devolutions Server to manipulate files.
Multiple Vulnerabilities in Zoom Workplace and Rooms
2 rules 1 TTPA local attacker can exploit multiple vulnerabilities in Zoom Video Communications Workplace and Zoom Video Communications Rooms to disclose information or escalate privileges.
Pega Platform Vulnerability Allows Cross-Site Scripting
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Pega Platform to perform a cross-site scripting (XSS) attack, potentially leading to session hijacking or malicious script execution in a user's browser.
Multiple Vulnerabilities in Adobe Creative Cloud Applications
2 rules 3 TTPsA local attacker can exploit multiple vulnerabilities in Adobe Creative Cloud applications to execute arbitrary program code, disclose confidential information, or cause a denial-of-service condition.
Fortinet FortiAnalyzer and FortiManager Vulnerability Allows Denial of Service
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Fortinet FortiAnalyzer and FortiManager to perform a denial-of-service attack, disrupting normal operations.
VMware Tanzu Spring Framework Security Bypass Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in VMware Tanzu Spring Framework to bypass security measures.
Keycloak Vulnerability Allows Arbitrary Email Sending
2 rules 1 TTPAn anonymous, remote attacker can exploit a vulnerability in Keycloak to send arbitrary emails, potentially leading to phishing or social engineering attacks.
Intel Server Firmware Update Utility Software Privilege Escalation Vulnerability
2 rules 1 TTPA local attacker can exploit a vulnerability in Intel Server Firmware Update Utility Software to escalate their privileges on the targeted system.
Langflow Vulnerability Allows Denial of Service
1 rule 1 TTPAn authenticated remote attacker can exploit a vulnerability in Langflow to perform a denial-of-service attack, impacting system availability.
nginx-ui Information Disclosure Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in nginx-ui to disclose sensitive information.
Klever-Go MultiDataInterceptor Remote OOM via Compressed Payload
2 rules 2 TTPsKlever-Go's MultiDataInterceptor is vulnerable to a remote denial-of-service (DoS) attack. By sending a crafted compressed P2P payload, an unauthenticated attacker can trigger excessive memory allocation on the receiving node, leading to an out-of-memory (OOM) condition and potentially disrupting chain liveness.
UltraJSON Memory Leak in ujson.dump() on Write Failure (CVE-2026-44660)
2 rules 1 TTPA memory leak vulnerability exists in UltraJSON's `ujson.dump()` function; when writing to a file-like object, if the write operation raises an exception, the serialized JSON string object is not properly de-referenced, leading to a memory leak (CVE-2026-44660).
SillyTavern Session Reuse After Password Change
2 rules 1 TTPSillyTavern versions 1.17.0 and earlier do not invalidate existing sessions after a password change, allowing attackers with stolen session cookies to retain access, even after the victim resets their password, and nullifies the password reset as a recovery measure against session theft.
CAI Content Credentials Uncontrolled Resource Consumption Vulnerability (CVE-2026-34665)
2 rules 1 TTP 1 CVECAI Content Credentials versions 0.78.2, 0.7.0 and earlier are susceptible to an uncontrolled resource consumption vulnerability, potentially leading to a denial-of-service condition by exhausting system resources.
CVE-2026-34652: Adobe Commerce Dependency on Vulnerable Third-Party Component Leading to DoS
2 rules 1 TTP 1 CVEAdobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, and 2.4.4-p17 and earlier are vulnerable to a denial-of-service due to a dependency on a vulnerable third-party component, which an attacker can exploit to crash the application without user interaction.
CVE-2026-34651 - Adobe Commerce Uncontrolled Resource Consumption Vulnerability
2 rules 1 TTP 1 CVEAdobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to uncontrolled resource consumption, potentially leading to application denial-of-service due to an attacker's ability to exhaust system resources without user interaction.
Adobe Commerce Uncontrolled Resource Consumption Vulnerability (CVE-2026-34650)
2 rules 1 TTP 1 CVEAdobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are susceptible to an uncontrolled resource consumption vulnerability (CVE-2026-34650) that allows an unauthenticated attacker to cause a denial-of-service condition by exhausting system resources.
CVE-2026-34649: Adobe Commerce Uncontrolled Resource Consumption Vulnerability
2 rules 1 TTP 1 CVEAdobe Commerce versions 2.4.9-beta1 and earlier are susceptible to an uncontrolled resource consumption vulnerability (CVE-2026-34649), allowing an unauthenticated attacker to trigger a denial-of-service condition by exhausting system resources.
Adobe Commerce SSRF Vulnerability (CVE-2026-34647)
2 rules 1 TTP 1 CVEAdobe Commerce versions 2.4.9-beta1 and earlier are vulnerable to Server-Side Request Forgery (SSRF) via a maliciously crafted URL, potentially leading to security feature bypass and unauthorized read access.
LSASS Process Access via Windows API
2 rules 2 TTPsThis rule identifies access attempts to the LSASS handle, which may indicate an attempt to dump credentials from LSASS memory by detecting specific API calls (OpenProcess, OpenThread, ReadProcessMemory) targeting the 'lsass.exe' process.
Intel Addresses Vulnerabilities in Multiple Software Products
3 rulesIntel released security advisories addressing vulnerabilities in Display Virtualization for Windows OS driver software, Intel EMA software, AI Playground software, and Intel Vision software, requiring users to update to the latest versions.
CVE-2026-42899 - ASP.NET Core Infinite Loop Denial of Service
2 rules 1 TTP 1 CVECVE-2026-42899 describes an infinite loop vulnerability in ASP.NET Core that allows an unauthorized attacker to perform a denial of service attack over a network.
CVE-2026-42832 - Microsoft Office Improper Access Control Vulnerability Leading to Spoofing
2 rules 2 TTPs 1 CVECVE-2026-42832 is an improper access control vulnerability in Microsoft Office that allows an unauthorized attacker to perform local spoofing.
CVE-2026-41102: Microsoft PowerPoint Improper Access Control Vulnerability Leading to Local Spoofing
2 rules 1 TTP 1 CVECVE-2026-41102 is an improper access control vulnerability in Microsoft Office PowerPoint that allows an authorized attacker to perform spoofing locally.
CVE-2026-41101: Microsoft Office Word Improper Access Control Vulnerability Leading to Local Spoofing
2 rules 1 TTP 1 CVECVE-2026-41101 is a vulnerability in Microsoft Office Word due to improper access control, which allows an authorized attacker to perform spoofing locally, with a CVSS v3.1 base score of 7.1.
CVE-2026-40414: Windows TCP/IP Null Pointer Dereference Denial-of-Service
2 rules 3 TTPs 1 CVEA null pointer dereference vulnerability exists in Windows TCP/IP, allowing an unauthorized attacker on an adjacent network to cause a denial-of-service condition.
CVE-2026-40413: Windows TCP/IP Null Pointer Dereference Denial of Service
2 rules 1 TTP 1 CVECVE-2026-40413 is a null pointer dereference vulnerability in Windows TCP/IP that allows an unauthenticated attacker on an adjacent network to cause a denial-of-service condition.
CVE-2026-40406 - Windows TCP/IP Use-After-Free Information Disclosure
2 rules 1 TTP 1 CVECVE-2026-40406 is a use-after-free vulnerability in Windows TCP/IP that allows an unauthorized attacker to disclose sensitive information over a network.
CVE-2026-40405 - Windows TCP/IP Null Pointer Dereference DoS
2 rules 1 TTP 1 CVECVE-2026-40405 describes a null pointer dereference vulnerability in Windows TCP/IP, allowing an unauthenticated attacker to cause a denial of service over a network.
CVE-2026-40401 - Windows TCP/IP Null Pointer Dereference Denial of Service
2 rules 1 TTP 1 CVECVE-2026-40401 is a null pointer dereference vulnerability in Windows TCP/IP that allows a local, unauthorized attacker to cause a denial of service.
CVE-2026-40360: Microsoft Excel Out-of-Bounds Read Information Disclosure
2 rules 1 TTP 1 CVECVE-2026-40360 is an out-of-bounds read vulnerability in Microsoft Office Excel that allows an unauthorized attacker to disclose sensitive information locally.
CVE-2026-35424: Windows IKE Protocol Memory Leak Denial-of-Service
1 rule 1 CVECVE-2026-35424 is a denial-of-service vulnerability in the Windows Internet Key Exchange (IKE) Protocol caused by a missing release of memory after its effective lifetime, allowing an unauthenticated remote attacker to trigger a denial of service over a network.
CVE-2026-34336 - Windows DWM Core Library Buffer Over-Read Information Disclosure
2 rules 2 TTPs 1 CVECVE-2026-34336 is a buffer over-read vulnerability in the Windows DWM Core Library, allowing a local, authenticated attacker to disclose sensitive information.
Ivanti Addresses Multiple Vulnerabilities in Various Products
2 rules 4 CVEsIvanti released security advisories on May 12, 2026, to address vulnerabilities in Xtraction, Endpoint Manager (EPM), Virtual Traffic Manager (vTM), and Secure Access Client (Windows), urging users to apply necessary updates to mitigate potential risks from CVE-2026-8043, CVE-2026-8051, CVE-2026-7431, and CVE-2026-7432.
Dalfox Unauthenticated Remote DoS via Closed-Channel Write in ParameterAnalysis
2 rules 1 TTPDalfox is vulnerable to an unauthenticated remote denial-of-service (DoS) vulnerability (CVE-2026-45090) due to a closed channel write in the `ParameterAnalysis` function, triggered by a crafted POST request that crashes the Dalfox server process.
Schneider Electric Security Advisory AV26-449 Addressing Multiple Vulnerabilities
2 rulesSchneider Electric published advisories on May 12, 2026, addressing vulnerabilities in multiple products including Ecostruxure Machine Expert HVAC, Easergy MiCOM C264, Easergy C5, Easergy MiCOM P30, Easergy MiCOM P40, EcoStruxure Power Automation System, iPMFLS, PowerLogic, Saitel DP, EasyLogic T150, EasyLogic T150 Remote Terminal Unit and Controller, Saitel DP Remote Terminal Unit and Controller, EcoStruxure Panel Server PAS400, PAS600, PAS600V2, PAS800, PAS800V2 and Easergy MiCOM Px40 Series related to clear text storage, insufficient entropy, improper path restrictions and insecure defaults.
Siemens Security Advisory Addressing Multiple Product Vulnerabilities
2 rulesSiemens released a security advisory on May 12, 2026, addressing vulnerabilities in a range of products including RUGGEDCOM, SCALANCE, Solid Edge, and SIMATIC, prompting users to apply necessary updates.
Multiple Vulnerabilities in Microsoft Azure
2 rules 3 CVEsMultiple vulnerabilities exist in Microsoft Azure, specifically affecting azl3 kernel and azl3 krb5, potentially leading to an unspecified security issue.
CPython Security Policy Bypass Vulnerability
2 rules 1 TTP 1 CVEA vulnerability in CPython, tracked as CVE-2026-7210, allows an attacker to bypass the security policy, requiring the latest security patch for mitigation.
LibreNMS Multiple XSS Vulnerabilities
2 rules 1 TTPMultiple reflected cross-site scripting (XSS) vulnerabilities exist in LibreNMS versions 25.12.0 to before 26.3.0, allowing an attacker to inject malicious code into a user's browser session.
Traefik Security Policy Bypass Vulnerability
1 rule 1 TTPA security policy bypass vulnerability exists in Traefik versions prior to v2.11.46, v3.6.x before v3.6.17, and v3.7.x before v3.7.1, allowing attackers to potentially circumvent intended access controls.
Siemens SIMATIC S7 PLCs Web Server Vulnerabilities Allow Cross-Site Scripting
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in Siemens SIMATIC S7 PLCs Web Server to perform cross-site scripting attacks, potentially leading to information disclosure or further unauthorized actions.
Siemens SIPROTEC 5 Information Disclosure Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Siemens SIPROTEC 5 devices to disclose sensitive information.
Siemens Teamcenter Hardcoded Key Vulnerability (CVE-2026-33893)
2 rules 2 TTPs 1 CVECVE-2026-33893 describes a vulnerability in Siemens Teamcenter where hardcoded keys used for obfuscation are stored directly within the application, potentially allowing an attacker to obtain these keys and gain unauthorized access.
Siemens Teamcenter Vulnerability CVE-2026-33862 - Cross-Site Scripting
2 rules 1 TTP 3 CVEs 3 IOCsSiemens Teamcenter versions V2312 (before V2312.0014), V2406 (before V2406.0012), V2412 (before V2412.0009), V2506 (before V2506.0005), and V2512 are vulnerable to cross-site scripting (XSS) due to improper encoding or filtering of user-supplied data, potentially leading to arbitrary code execution by other users.
CVE-2026-25789 - Firmware Update Page Filename Sanitization Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-25789 describes a vulnerability where affected devices do not properly validate and sanitize filenames on the Firmware Update page, potentially allowing a remote attacker to execute malicious JavaScript in the context of the user's session through social engineering, leading to session hijacking or credential theft.
CVE-2026-22925: Siemens SIMATIC CN 4100 Resource Exhaustion via TCP SYN Flood
1 rule 1 CVESiemens SIMATIC CN 4100 versions before V5.0 are vulnerable to resource exhaustion due to processing a high volume of TCP SYN packets, leading to a denial-of-service condition.
CVE-2025-40833 Null Pointer Dereference in Affected Devices Leads to Denial of Service
2 rules 1 TTP 1 CVEA null pointer dereference vulnerability exists in affected devices while processing specially crafted IPv4 requests, potentially allowing a remote attacker to cause a denial of service, requiring a manual restart to recover the system.
Siemens SIMATIC CN 4100 Unauthenticated Resource Exhaustion (CVE-2026-22924)
2 rules 1 TTP 1 CVESiemens SIMATIC CN 4100 versions before V5.0 are vulnerable to resource exhaustion due to improper restriction of unauthenticated connections, potentially leading to disruption of operations and unauthorized actions.
CODESYS Modbus Vulnerability Enables Denial of Service
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in CODESYS Modbus to perform a denial of service attack.
Multiple Vulnerabilities in ImageMagick Allow for DoS and Potential Data Exposure
2 rules 2 TTPsA local attacker can exploit multiple vulnerabilities in ImageMagick to perform a denial of service attack or affect confidentiality, availability, and integrity.
JetBrains TeamCity On-Premises Privilege Escalation Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in JetBrains TeamCity On-Premises to escalate privileges.
CVE-2026-6690: LifePress WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe LifePress plugin for WordPress is vulnerable to stored cross-site scripting (XSS) due to insufficient input sanitization and output escaping within the `lp_update_mds` AJAX action, allowing unauthenticated attackers to inject arbitrary web scripts via the 'n' parameter that execute when a user accesses the injected page; this affects versions up to and including 2.2.2.
Kubernetes Service Account Token Created via TokenRequest API by Non-System Identity
2 rules 1 TTPThe rule detects the creation of Kubernetes service account tokens through the TokenRequest API by non-system identities, which can be abused to escalate privileges, pivot to cloud resources, or generate persistent tokens, bypassing file system-based detection.
Sonatype Nexus Repository Manager Security Bypass Vulnerability
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Sonatype Nexus Repository Manager to bypass security precautions.
Linux Kernel: Local Privilege Escalation Vulnerabilities
2 rules 1 TTPA local attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate privileges or manipulate files.
Multiple Vulnerabilities in 7-Zip Allow File Manipulation and Information Disclosure
2 rules 2 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in 7-Zip to manipulate files or disclose sensitive information on Windows systems.
CVE-2026-7287 - Zyxel NWA1100-N Buffer Overflow Vulnerability
2 rules 2 TTPs 1 CVEA buffer overflow vulnerability in Zyxel NWA1100-N firmware allows a remote attacker to cause a denial-of-service by sending a crafted HTTP request to the webs binary.
GhostLock Tool Abuses Windows API to Block File Access
2 rules 1 TTPGhostLock is a proof-of-concept tool that abuses the Windows CreateFileW API to block access to files on local and SMB network shares, causing a denial-of-service condition.
JetBrains TeamCity Vulnerability
2 rulesA security advisory released by JetBrains on May 11, 2026, addresses a vulnerability in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5, requiring users to apply updates to mitigate potential risks.
Broadcom Patches Multiple Vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes
2 rulesBroadcom published a security advisory addressing vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes versions prior to 4.3.0, 4.2.6, 4.1.11, 4.0.20 and 3.13.15, potentially allowing an attacker to compromise the affected system.
Bird-lg-go Unbounded JSON Decode Denial of Service (CVE-2026-45047)
2 rules 1 TTPBird-lg-go is vulnerable to a denial-of-service (DoS) attack (CVE-2026-45047) where an unauthenticated remote attacker can cause an out-of-memory error by streaming an extremely large JSON payload to the apiHandler, leading to termination of the bird-lg-go daemon.
Suspicious macOS MS Office Child Process
2 rules 6 TTPsThis rule identifies suspicious child processes of Microsoft Office applications on macOS, which often result from exploitation or malicious macros, by detecting unexpected processes like curl, bash, osascript, and python spawned by Office apps, while filtering out false positives related to product version discovery, error reporting, and legitimate software.
CVE-2026-32226 .NET Framework Denial of Service Vulnerability
2 rules 1 TTP 1 CVECVE-2026-32226 is a denial of service vulnerability in the .NET Framework that can be mitigated by applying the latest security update.
Next.js Cache Components Vulnerable to Denial-of-Service via Connection Exhaustion (CVE-2026-44579)
2 rules 1 TTPNext.js applications using Partial Prerendering through Cache Components are vulnerable to connection exhaustion (CVE-2026-44579), where crafted POST requests to a server action trigger a request-body handling deadlock, consuming server capacity and leading to denial of service.
Ubuntu Linux Kernel Vulnerabilities Addressed in Security Notices
2 rulesUbuntu released security notices between May 4 and 10, 2026, addressing vulnerabilities in the Linux kernel affecting Ubuntu 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10, requiring timely updates.
Urllib3 Decompression Bomb Vulnerability in Streaming API (CVE-2026-44432)
2 rules 1 TTPUrllib3 versions before 2.7.0 are vulnerable to excessive resource consumption when using the streaming API to decompress responses, particularly when using the Brotli library or calling HTTPResponse.drain_conn() after partial decompression, leading to high CPU usage and memory allocation, potentially causing a denial-of-service condition (CVE-2026-44432).
@vitejs/plugin-rsc Denial-of-Service Vulnerability in React Server Components
2 rules 1 TTP 1 CVE@vitejs/plugin-rsc is vulnerable to a denial-of-service attack due to an embedded vulnerable version of react-server-dom-webpack, potentially causing resource exhaustion.
OpenTelemetry Prometheus Exporter Denial-of-Service via Malformed HTTP Request (CVE-2026-44902)
2 rules 1 TTPA malformed HTTP request can crash any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint has no error handling around URL parsing, so a request with an invalid URI causes an uncaught `TypeError` that terminates the process, leading to a denial of service. Update `@opentelemetry/exporter-prometheus` and `@opentelemetry/sdk-node` to version **0.217.0** or later and `@opentelemetry/auto-instrumentations-node` to version **0.75.0** or later to remediate.
Apache Airflow Providers OpenSearch and Elasticsearch Information Disclosure Vulnerabilities
1 rule 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in Apache Airflow Providers OpenSearch and Elasticsearch to disclose sensitive information.
jq Vulnerability Allows Security Bypass
1 ruleA local attacker can exploit a vulnerability in jq to bypass security measures.
HCL BigFix WebUI Information Disclosure Vulnerabilities
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in HCL BigFix WebUI applications to disclose sensitive information.
Rancher Fleet Helm Deployer Vulnerability Allows Security Bypass
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in Rancher Fleet Helm Deployer to bypass security measures and disclose sensitive information, which may enable further attacks.
FRRouting Project FRRouting Vulnerability Allows Data Manipulation
2 rulesA remote, authenticated attacker can exploit a vulnerability in FRRouting Project FRRouting to manipulate data.
Multiple Vulnerabilities in Red Hat Hardened Images RPMs
2 rules 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to cause a denial-of-service condition and possibly manipulate data or perform path traversal attacks.
CVE-2026-23377 Vulnerability
1 CVECVE-2026-23377 is a reported vulnerability with no further details available from the Microsoft Security Response Center.
CVE-2026-23276: Net Recursion Limit Vulnerability in Tunnel Xmit Functions
1 rule 1 CVECVE-2026-23276 is a net vulnerability affecting tunnel xmit functions, requiring a fix to add an xmit recursion limit.
CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup
1 CVECVE-2025-37877 is a vulnerability in the iommu component requiring proper cleanup, affecting Microsoft products.
CVE-2026-31712: ksmbd Minimum ACE Size Vulnerability
2 rules 1 TTP 1 CVECVE-2026-31712 is a security vulnerability in ksmbd requiring a minimum ACE size check in smb_check_perm_dacl(), potentially leading to unauthorized access or privilege escalation.
CVE-2026-31706 ksmbd num_aces Validation Vulnerability
2 rules 1 CVECVE-2026-31706 is a vulnerability in ksmbd related to improper validation of num_aces and insufficient hardening of the ACE walk in smb_inherit_dacl(), potentially leading to unauthorized access or privilege escalation.
CVE-2025-38717 KCM Race Condition Vulnerability
2 rules 1 CVECVE-2025-38717 is a race condition vulnerability in the kcm_unattach() function of a Microsoft product, potentially leading to denial of service or privilege escalation.
CVE-2024-26756: Unspecified Vulnerability in Microsoft Products
2 rules 1 CVEMicrosoft released details for CVE-2024-26756, an unspecified vulnerability affecting Microsoft products, but provided no further information.
CVE-2024-26757: Unspecified Vulnerability in Microsoft md
2 rules 1 CVECVE-2024-26757 is an unspecified vulnerability in a Microsoft product, potentially allowing an attacker to perform unauthorized actions.
memono Notepad 4.2 Denial of Service Vulnerability (CVE-2021-47944)
1 rule 1 TTP 1 CVEmemono Notepad 4.2 is vulnerable to a denial-of-service attack, allowing attackers to crash the application by pasting excessively long character buffers (specifically, two pastes of 350,000 repeated characters) into note fields on iOS devices, as tracked by CVE-2021-47944.
CVE-2026-39826 Escaper Bypass Leads to XSS Vulnerability
1 rule 1 TTP 1 CVECVE-2026-39826 is an escaper bypass vulnerability that leads to cross-site scripting (XSS).
free5GC NEF PATCH Handler Vulnerability Leads to Denial of Service
2 rules 1 TTP 3 IOCsA nil pointer dereference vulnerability exists in free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler when UDR access fails, causing a denial-of-service condition.
free5GC SMF Unauthenticated Process-Kill Denial-of-Service via UPI Endpoint
2 rules 1 TTP 1 IOCfree5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted POST request to the `/upi/v1/upNodesLinks` endpoint can trigger a `Fatalf` call, terminating the entire SMF process, effectively disrupting network services.
Fastify accepts-serializer Denial of Service via Unbounded Accept Header Cache Growth
2 rules 1 TTP 1 CVEThe @fastify/accepts-serializer package is vulnerable to a denial of service (DoS) attack due to unbounded cache growth, where an attacker can send many distinct Accept header variants, causing the cache to grow unbounded, exhausting the Node.js heap, and crashing the process.
Dronecode PX4 Autopilot MavlinkLogHandler Stack Buffer Overflow DoS (CVE-2026-32743)
2 rules 3 TTPs 1 CVEA stack-based buffer overflow vulnerability exists in Dronecode PX4 Autopilot versions up to and including 1.17.0-rc2 that allows an attacker with MAVLink link access to cause a denial of service by creating a deeply nested directory via MAVLink FTP and then requesting the log list, crashing the MAVLink task.
Zebra Node Denial-of-Service Vulnerability via Crafted Orchard Transactions (CVE-2026-41584)
1 rule 1 TTP 1 CVEA crafted Orchard transaction with a zero-value rk field can cause a Zebra node to crash due to a panic in the orchard crate, leading to a denial-of-service condition; this vulnerability is identified as CVE-2026-41584 and patched in zebrad version 4.3.1 and zebra-chain version 6.0.2.
Mozilla Firefox Multiple Vulnerabilities
2 rules 2 TTPsMozilla released security updates to address vulnerabilities in Firefox and Firefox ESR versions, potentially allowing for exploitation if left unpatched.
Dronecode PX4-Autopilot tattu_can Stack Buffer Overflow (CVE-2026-32707)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability exists in the `tattu_can` driver of Dronecode PX4-Autopilot versions 1.17.0-rc1 and earlier; by injecting specially crafted CAN frames, an attacker can trigger an unbounded memcpy operation, leading to a stack corruption and subsequent crash of the PX4 process, resulting in a denial of service.
Ruby Multiple Vulnerabilities Lead to DoS and Information Disclosure
2 rules 1 TTPA remote, anonymous attacker can exploit multiple unspecified vulnerabilities in Ruby to perform a denial of service attack or disclose sensitive information.
Microsoft 365 Copilot Business Chat Information Disclosure Vulnerabilities
2 rules 1 TTPMultiple vulnerabilities in Microsoft 365 Copilot Business Chat allow an anonymous remote attacker to disclose sensitive information.
Avast Antivirus Privilege Escalation Vulnerability
2 rules 1 TTPA local attacker can exploit a vulnerability in Avast Antivirus and AVG Technologies Anti-Virus to escalate privileges on a Windows system.
WordPress Auto Affiliate Links Plugin Stored XSS Vulnerability (CVE-2026-7330)
2 rules 1 TTP 1 CVEThe Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 6.8.8 due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into the admin statistics page.
CVE-2026-41675 xmldom XML Node Injection Vulnerability
2 rules 1 CVECVE-2026-41675 is an XML node injection vulnerability in the xmldom library, potentially leading to code execution or information disclosure in applications that process XML data using the affected library.
Zebra Block Validator Sigops Undercount Vulnerability
2 rulesZebra's block validator undercounts signature operations, allowing it to accept invalid blocks, leading to a network split between Zebra and zcashd nodes.
CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability
2 rules 1 TTPCVE-2026-42826 is an information disclosure vulnerability in Azure DevOps that allows unauthorized disclosure of sensitive information over a network.
CVE-2026-40379 Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability
2 rules 1 TTPCVE-2026-40379 is a spoofing vulnerability in Microsoft Enterprise Security Token Service (ESTS) where exposure of sensitive information in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35428 Azure Cloud Shell Spoofing Vulnerability
1 rule 1 TTPCVE-2026-35428 is a command injection vulnerability in Azure Cloud Shell that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33823 Microsoft Teams Information Disclosure Vulnerability
1 rule 1 TTPCVE-2026-33823 is an information disclosure vulnerability in Microsoft Teams that allows an authorized attacker to disclose sensitive information over a network due to improper authorization.
CVE-2026-33111 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
2 rules 1 TTPCVE-2026-33111 is a command injection vulnerability in Microsoft Edge's Copilot Chat feature that allows an unauthorized attacker to disclose information over a network.
CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability
2 rules 1 TTPCVE-2026-32207 is a cross-site scripting vulnerability in Azure Machine Learning, allowing an unauthorized attacker to perform spoofing over a network.
CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability
2 rules 1 TTPCVE-2026-26164 is an information disclosure vulnerability in M365 Copilot due to improper neutralization of special elements, allowing unauthorized information disclosure over a network.
DivvyDrive Stored XSS Vulnerability
2 rules 1 TTP 1 CVEDivvyDrive versions 4.8.2.9 before 4.8.3.2 are susceptible to stored cross-site scripting (XSS) due to improper neutralization of user-supplied input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.
DivvyDrive Cross-Site Scripting (XSS) Vulnerability (CVE-2026-6002)
2 rules 1 TTP 1 CVEDivvyDrive versions 4.8.2.9 before 4.8.3.2 are susceptible to cross-site scripting (XSS) due to improper neutralization of script-related HTML tags, potentially allowing an attacker to inject malicious scripts.
Proticaret E-Commerce Reflected XSS Vulnerability (CVE-2026-3953)
2 rules 1 TTP 1 CVEA reflected cross-site scripting (XSS) vulnerability exists in Gosoft Software Industry and Trade Ltd. Co.'s Proticaret E-Commerce software (versions v5.0.0 before V 6.0.1767.1383) due to improper neutralization of input during web page generation, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.
MAXHUB Pivot Client Application Vulnerability CVE-2026-6411
2 rules 1 TTPA vulnerability exists in MAXHUB Pivot client application versions prior to v1.36.2, where a hardcoded AES key allows attackers to decrypt tenant email addresses and associated metadata, and potentially cause a denial-of-service via unauthorized device enrollment through MQTT.
Google Chrome Security Update Required
2 rulesGoogle released a security advisory addressing vulnerabilities in Chrome for Desktop versions prior to 148.0.7778.96/97 on Windows/Mac and 148.0.7778.96 on Linux, requiring users to update to mitigate potential exploits.
Cisco Crosswork Network Controller and Network Services Orchestrator Connection Exhaustion Denial of Service
2 rules 1 TTPAn unauthenticated remote attacker can cause a denial-of-service condition on Cisco Crosswork Network Controller and Network Services Orchestrator by exhausting connection resources via a high volume of connection requests.
Broadcom Tanzu Jammy Stemcell Vulnerability (CVE-2026-341431)
2 rules 1 TTPA vulnerability in Broadcom's Tanzu Jammy Stemcell versions prior to 1.1193, tracked as CVE-2026-341431, requires patching to prevent potential exploitation.
CPython Multiple Vulnerabilities Allow File Manipulation and DoS
2 rules 2 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in CPython to manipulate files or cause a denial-of-service condition.
Erlang/OTP Information Disclosure Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit an unspecified vulnerability in Erlang/OTP to disclose sensitive information.
Red Hat OpenShift Service Mesh Multiple Vulnerabilities
2 rules 4 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.
CallPhantom Android Apps Falsely Promise Call History for Payment
2 rulesESET researchers discovered 28 fraudulent Android apps, named CallPhantom, on Google Play that falsely claim to provide call logs for any phone number in exchange for payment, generating random data or requesting email addresses and amassing over 7.3 million downloads before being removed.
Microsoft CVE-2026-25833 Vulnerability Published
1 CVEMicrosoft published CVE-2026-25833, a security vulnerability for which details are currently unavailable, impacting systems and requiring further investigation upon release of additional information.
Microsoft Published Information Regarding CVE-2025-66442
2 rules 1 TTP 1 CVEMicrosoft has published information regarding the vulnerability CVE-2025-66442; details are currently unavailable, limiting specific analysis and detection strategies.
Microsoft Published Information Regarding CVE-2026-25835
2 rules 1 CVEMicrosoft has published information regarding the vulnerability CVE-2026-25835, but details about the vulnerability, affected products, and exploitation are currently unavailable.
Threat Actors Use Claude AI to Target Water Utility OT Assets
2 rules 2 TTPsAn unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.
OSX.Dummy Malware Targeting Cryptocurrency Community
2 rulesOSX.Dummy is a new macOS malware targeting the cryptocurrency community, as reported by Objective-See.
Mac Adware Injecting Malicious JavaScript via Obfuscated Python Script
2 rules 2 TTPs 1 IOCA Mac adware, likely a component of OSX.Pirrit, uses multiple layers of obfuscation, including base64 encoding, zlib compression, and variable renaming, to evade detection and inject malicious JavaScript from hxxps://1049434604.rsc.cdn77.org/ij1.min.js.
Free5GC UDM Information Disclosure via Malformed Request
2 rules 2 TTPs 1 CVEThe free5GC UDM component fails to validate the `supi` path parameter in six GET handlers, allowing an unauthenticated attacker to inject control characters and trigger a `500 Internal Server Error` that exposes internal infrastructure details.
Netty HttpContentDecompressor Brotli/Zstd/Snappy Decompression Bomb Vulnerability
3 rules 1 TTPNetty's HttpContentDecompressor and DelegatingDecompressorFrameListener are vulnerable to a decompression bomb denial-of-service attack because the maxAllocation parameter is not enforced when Content-Encoding is set to br (Brotli), zstd, or snappy, allowing attackers to bypass decompression limits and cause unbounded memory allocation.
Netty Lz4FrameDecoder Resource Exhaustion Vulnerability
2 rules 1 TTPNetty's Lz4FrameDecoder is vulnerable to resource exhaustion, where an attacker can cause excessive memory allocation by sending a small, crafted header, leading to a denial-of-service condition; this affects netty-codec-compression versions up to 4.2.12.Final and netty-codec versions up to 4.1.132.Final.
Netty DNS Codec Input Validation Bypass Vulnerability
2 rules 1 TTPNetty's DNS codec fails to enforce RFC 1035 domain name constraints, leading to potential DNS cache poisoning, denial-of-service, and domain validation bypass through null byte injection, overlength labels, silent truncation, and unbounded memory allocation.
ldap3_proto LDAP Filter Stack Exhaustion Vulnerability
2 rules 1 TTPThe ldap3_proto package is vulnerable to LDAP Filter stack exhaustion due to unbounded query depth, potentially causing a denial of service in applications processing LDAP queries, affecting versions before 0.7.1.
Netty epoll Transport Denial of Service via RST on Half-Closed TCP Connection
2 rules 1 TTPNetty's epoll transport fails to properly close TCP connections that receive a RST after a half-close, leading to resource exhaustion and potential CPU busy-loops, impacting service availability.
Snappier SnappyStream Decompression Infinite Loop Vulnerability
2 rules 1 TTPSnappier versions 1.3.0 and earlier are vulnerable to a denial-of-service condition where a malformed Snappy stream input to `SnappyStream` decompression causes an infinite loop, consuming a thread until the process is terminated.
Mezo L1 Bridge Vulnerability Leads to Potential ERC-20 Drain
3 rules 2 TTPsA vulnerability in the Mezo bridge allows for the potential full drain of the L1 bridge without changing the bridged balance on Mezo due to a stale StateDB overwrite, enabling a malicious user to steal ERC-20 tokens locked in the L1 bridge.
Samsung Mobile Devices Multiple Vulnerabilities
2 rulesSamsung released a security update to address multiple vulnerabilities in Samsung mobile devices running versions prior to SMR-MAY-2026 Release 1, potentially allowing attackers to exploit these vulnerabilities for malicious purposes.
Mistune Markdown Parser Denial-of-Service Vulnerability
2 rules 1 TTPA denial-of-service vulnerability exists in Mistune version 3.2.0 due to excessive parsing and CPU consumption when processing specially crafted reference links, leading to application hangs and service unavailability.
Cisco Slido Insecure Direct Object Reference Vulnerability
2 rules 1 TTPAn insecure direct object reference in Cisco Slido's REST API could have allowed an authenticated remote attacker to access social profile data or affect quiz/poll results.
Cisco SG350 and SG350X Series Managed Switches SNMP Denial-of-Service Vulnerability
2 rules 1 TTPA remote, authenticated attacker can cause a denial-of-service condition on vulnerable Cisco SG350 and SG350X Series Managed Switches by sending a crafted SNMP request due to improper error handling.
Cisco Prime Infrastructure Information Disclosure Vulnerability
2 rules 3 TTPsCisco Prime Infrastructure is vulnerable to an information disclosure vulnerability, allowing authenticated remote attackers to download arbitrary log files due to insufficient authorization checks.
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
2 rules 1 TTPMultiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information.
Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability
2 rules 1 TTPAn authenticated attacker with agent privileges can upload malicious files to Cisco Enterprise Chat and Email (ECE) via the Lite Agent feature, leading to potential browser-based attacks against other users.
Broadcom Patches Vulnerabilities in Tanzu GemFire Management Console
2 rules 1 TTPBroadcom released a security advisory addressing vulnerabilities in Tanzu GemFire Management Console versions prior to 1.4.4, prompting users to apply necessary updates to mitigate potential risks.
Plug.Cowboy HTTP/2 Atom Table Exhaustion DoS
2 rules 1 TTP 1 CVEAn unauthenticated remote denial-of-service vulnerability in Plug.Cowboy allows attackers to exhaust the BEAM atom table via HTTP/2 requests, crashing the Erlang VM.
Dell Security Advisories Address Multiple Vulnerabilities
2 rulesDell published security advisories addressing vulnerabilities in APEX Cloud Platform, Automation Platform, Command | Monitor, CyberSense, NativeEdge Orchestrator, SmartFabric Manager, iDRAC, Disk Library, and PowerProtect Cyber Recovery, requiring users to apply necessary updates.
CISA ICS Advisories Addressing ABB and NSA Products
2 rulesCISA published ICS advisories addressing vulnerabilities in multiple ABB products including AWIN Gateways, Ability OPTIMAX, Symphony Plus Engineering, Edgenius Management Portal, PCM600, System 800xA, Symphony Plus IEC 61850, and NSA GRASSMARLIN, prompting users to apply mitigations and updates.
ABB B&R PVI Sensitive Information Logging Vulnerability
2 rules 1 CVEAn authenticated local attacker can gather credential information from ABB B&R PVI client application logs when logging is enabled, addressed in version 6.5.0 (CVE-2026-0936).
Argo CD Information Disclosure Vulnerability
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in Argo CD to disclose sensitive information.
MinIO Information Disclosure Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in MinIO to disclose sensitive information.
Multiple Vulnerabilities in Rapid7 Velociraptor
2 rules 2 TTPsMultiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to perform a denial-of-service attack or disclose sensitive information.
Phone Number Reuse in Scam Email Campaigns
2 rules 1 TTP 2 IOCsTalos has begun tracking phone numbers in emails as indicators of compromise, revealing insights into their reuse in scam campaigns where attackers use API-driven VoIP services for cost-effective operations, rotating phone number blocks to evade security filters, and maximizing reach by recycling numbers across diverse lures.
Red Hat OpenShift Container Platform Security Bypass Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Red Hat OpenShift Container Platform to bypass security measures.
X.Org X11 and Xwayland Multiple Vulnerabilities
2 rules 3 TTPsA local attacker can exploit vulnerabilities in X.Org X11 and Xwayland to perform unspecified attacks, including memory corruption, information disclosure, or a denial-of-service condition.
Multiple Vulnerabilities in OpenSSL Allow for DoS, Information Disclosure, and Ciphertext Recovery
2 rules 2 TTPsMultiple vulnerabilities in OpenSSL can be exploited by a remote attacker to conduct a denial-of-service attack, disclose information, or recover ciphertext over a network.
LatePoint WordPress Plugin Vulnerable to Stored XSS (CVE-2026-7448)
2 rules 1 TTP 1 CVEThe LatePoint WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'first_name' parameter, affecting versions up to 5.5.0, allowing unauthenticated attackers to inject malicious scripts.
Microsoft Releases Security Update for CVE-2026-43964
2 rules 1 CVEMicrosoft has released a security update to address the vulnerability CVE-2026-43964.
Multiple Vulnerabilities in Zabbix
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Zabbix versions 6.0.x before 6.0.45, 7.0.x before 7.0.24, and 7.4.x before 7.4.8 allow for data confidentiality breaches and remote cross-site scripting (XSS) attacks.
Multiple Vulnerabilities in Asterisk Allow for Remote Denial of Service
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Asterisk versions 20.18.x before 20.19.0, 21.12.x before 21.12.2, 22.8.x before 22.9.0, 23.2.x before 23.3.0, certified-asterisk 20.x before 20.7-cert10, and certified-asterisk 22.x before 22.8-cert2 allow a remote attacker to cause a denial of service.
Multiple Unspecified Vulnerabilities in Google Chrome
2 rulesMultiple unspecified vulnerabilities in Google Chrome prior to version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac could allow an attacker to cause an unspecified security issue.
Prometheus Remote Read Endpoint Denial-of-Service Vulnerability
2 rules 1 TTP 1 CVEThe Prometheus remote read endpoint is vulnerable to denial of service due to a missing validation of the declared decoded length in snappy-compressed request bodies, allowing unauthenticated attackers to exhaust memory resources.
gix-pack Denial-of-Service Vulnerabilities
2 rules 1 TTPMultiple denial-of-service vulnerabilities exist in `gix-pack`; crafted delta data can cause unchecked array indexing, leading to panics, and uncapped attacker-controlled size headers enable out-of-memory process kills, triggered by malicious pack data during clone/fetch operations.
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
2 rules 1 TTP 2 CVEsMultiple stored cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to inject malicious code into specific pages of the interface, leading to arbitrary script execution or sensitive information access.
graphql-php OverlappingFieldsCanBeMerged Quadratic Complexity Vulnerability
2 rules 1 TTP 1 CVEThe `OverlappingFieldsCanBeMerged` validation rule in `webonyx/graphql-php` has an `O(n^2 x m^2)` worst-case complexity due to flattened inline fragments, leading to potential resource exhaustion.
IObit Advanced SystemCare 19 Symlink Vulnerability (CVE-2026-7832)
2 rules 1 TTP 1 CVEIObit Advanced SystemCare 19 is vulnerable to a local symlink following attack due to improper handling in ASC.exe, potentially allowing a local attacker to escalate privileges.
OpenClaw Denial-of-Service via Oversized WebSocket Frames
2 rules 1 TTP 1 CVEOpenClaw versions prior to 2026.4.10 are vulnerable to a denial-of-service attack where remote attackers can send oversized WebSocket frames to the voice-call realtime path, causing service unavailability.
ABB B&R Automation Studio Improper Certificate Validation Vulnerability
2 rules 2 TTPs 1 CVEABB B&R Automation Studio versions before 6.5 are vulnerable to improper certificate validation (CVE-2025-11043), potentially allowing an unauthenticated attacker to intercept and interfere with data exchanges, necessitating patching and secure network configurations.
ABB B&R Automation Runtime Denial-of-Service Vulnerability
2 rules 1 TTP 1 CVEA denial-of-service vulnerability (CVE-2025-11044) exists in ABB B&R Automation Runtime versions prior to 6.5 and R4.93, where an unauthenticated attacker can exploit a race condition to cause permanent denial-of-service.
Potential Protocol Tunneling via Cloudflared
2 rules 2 TTPs 1 IOCAdversaries may abuse Cloudflare Tunnel (cloudflared) on Windows systems to proxy command and control traffic or exfiltrate data through Cloudflare's edge, evading direct connection blocking.
Microsoft Product Vulnerability CVE-2026-37457
2 rules 1 CVECVE-2026-37457 is a vulnerability affecting a Microsoft product, for which details are currently unavailable.
RTGS2017 NagaAgent Path Traversal Vulnerability
2 rules 2 TTPs 1 CVERTGS2017 NagaAgent up to version 5.1.0 is vulnerable to path traversal via manipulation of the 'Name' argument in the Skills Endpoint, potentially leading to unauthorized file access.
Argo Workflows Webhook Interceptor Vulnerable to Unauthenticated Memory Exhaustion (CVE-2026-42294)
2 rules 1 TTPArgo Workflows is vulnerable to a denial-of-service (DoS) attack due to unbounded memory allocation in the Webhook Interceptor component.
Contact Form 7 WordPress Plugin Uncontrolled Resource Consumption Vulnerability
2 rules 1 TTP 1 CVEThe Contact Form 7 WordPress plugin through version 2.6.7 is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to exhaust server memory and crash the PHP process by supplying an arbitrarily large integer value to the REST API endpoint, leading to unbounded loop execution.
Windows Port Forwarding Rule Addition via Registry Modification
2 rules 3 TTPsAn adversary may abuse port forwarding to bypass network segmentation restrictions by creating a new port forwarding rule through modification of the Windows registry.
Suspicious Zoom Child Process Execution
2 rules 6 TTPsA suspicious Zoom child process was detected, indicating a potential attempt to run unnoticed by masquerading as Zoom.exe or exploiting a vulnerability, resulting in the execution of cmd.exe, powershell.exe, pwsh.exe, or powershell_ise.exe.
Suspicious Windows PowerShell Arguments Detected
3 rules 4 TTPsThis rule identifies the execution of PowerShell with suspicious argument values, often observed during malware installation, by detecting unusual PowerShell arguments indicative of abuse, focusing on patterns like encoded commands, suspicious downloads, and obfuscation techniques.
Suspicious Execution via Windows Command Debugging Utility
2 rules 2 TTPsAdversaries can abuse the Windows command line debugging utility cdb.exe to execute commands or shellcode from non-standard paths, evading traditional security measures.
SIP Provider Modification for Defense Evasion
2 rules 1 TTPThis rule detects modifications to the registered Subject Interface Package (SIP) providers, which are used by the Windows cryptographic system to validate file signatures, potentially indicating an attempt to bypass signature validation or inject code for defense evasion.
Service DACL Modification via sc.exe
2 rules 2 TTPsDetection of service DACL modifications via `sc.exe` using the `sdset` command, potentially leading to defense evasion by denying service access to legitimate users or system accounts.
Remote Desktop File Opened from Suspicious Path
2 rules 2 TTPsAdversaries may abuse RDP files delivered via phishing from suspicious locations to gain unauthorized access to systems.
Potential WSUS Abuse for Lateral Movement via PsExec
2 rules 2 TTPsAdversaries may exploit Windows Server Update Services (WSUS) to execute PsExec for lateral movement within a network by abusing the trusted update mechanism to run signed binaries.
Potential WPAD Spoofing via DNS Record Creation
2 rules 1 TTPDetection of a Windows DNS record creation event (5137) with an ObjectDN attribute containing 'DC=wpad', which indicates a potential WPAD spoofing attack to enable privilege escalation and lateral movement.
Potential Pass-the-Hash (PtH) Attempt Detection
2 rules 1 TTPThis rule detects potential Pass-the-Hash (PtH) attempts in Windows environments by monitoring successful authentications with specific user IDs (S-1-5-21-* or S-1-12-1-*) and the `seclogo` logon process, where attackers use stolen password hashes to authenticate and move laterally across systems without needing plaintext passwords.
Potential NetNTLMv1 Downgrade Attack via Registry Modification
2 rules 2 TTPsThis brief details a registry modification attack that downgrades the system to NTLMv1 authentication, enabling NetNTLMv1 downgrade attacks, typically performed with local administrator privileges on Windows systems.
Potential Evasion via Windows Filtering Platform Blocking Security Software
2 rules 2 TTPsAdversaries may add malicious Windows Filtering Platform (WFP) rules to prevent endpoint security solutions from sending telemetry data, impairing defenses, which this rule detects by identifying multiple WFP block events where the process name is associated with endpoint security software.
Potential DLL Side-Loading via Trusted Microsoft Programs
2 rules 2 TTPsThis rule detects potential DLL side-loading attempts by identifying instances of Windows trusted programs (WinWord.exe, EXPLORER.EXE, w3wp.exe, DISM.EXE) being started after being renamed or from a non-standard path, which is a common technique to evade defenses by side-loading a malicious DLL into the memory space of a trusted process.
Potential Data Exfiltration via Rclone
2 rules 3 TTPsAttackers are abusing the legitimate file synchronization tool rclone, often renamed to masquerade as legitimate software, to exfiltrate data to cloud storage or remote endpoints.
Potential Computer Account NTLM Relay Activity
2 rules 2 TTPsDetection of potential NTLM relay attacks targeting computer accounts by identifying authentication events originating from hosts other than the account's owner, indicating possible credential theft and misuse.
Potential Active Directory Replication Account Backdoor
2 rules 2 TTPsAttackers can modify Active Directory object security descriptors to grant DCSync rights to unauthorized accounts, creating a backdoor to extract credential data.
Potential Account Takeover - Logon from New Source IP
2 rules 1 TTPThe rule identifies a user account that normally logs in with high volume from one source IP suddenly logging in from a different source IP, potentially indicating account takeover or use of stolen credentials from a new location.
Local Account TokenFilter Policy Modification for Defense Evasion and Lateral Movement
2 rules 4 TTPsAdversaries may modify the LocalAccountTokenFilterPolicy registry key to bypass User Account Control (UAC) and gain elevated privileges remotely by granting high-integrity tokens to remote connections from local administrators, facilitating lateral movement and defense evasion.
Code Signing Policy Modification Through Built-in Tools
2 rules 1 TTPAttackers may attempt to disable or modify code signing policies on Windows systems by using built-in tools like bcdedit.exe in order to execute unsigned or self-signed malicious code.
Multiple Vulnerabilities in Mutt Email Client Lead to Potential DoS
2 rules 3 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in mutt to bypass security measures and cause a denial-of-service condition.
libexif Vulnerability Allows Code Execution
2 rules 2 TTPsA local attacker can exploit a vulnerability in libexif to potentially execute arbitrary code, cause a denial of service, or disclose sensitive information.
Grafana Multiple Vulnerabilities Leading to XSS and Information Disclosure
2 rules 1 TTPMultiple vulnerabilities in Grafana allow a remote, anonymous attacker to conduct a Cross-Site Scripting attack or disclose information.
Tegsoft Online Support Application Reflected XSS Vulnerability (CVE-2025-14320)
2 rules 1 TTP 1 CVECVE-2025-14320 is a reflected cross-site scripting (XSS) vulnerability in Tegsoft Online Support Application versions V3 through 31122025, allowing attackers to inject arbitrary web scripts into user browsers.
Multiple Vulnerabilities in Rapid7 Velociraptor
2 rules 3 TTPsMultiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to disclose information or cause a denial of service.
osrg GoBGP Integer Underflow Vulnerability
2 rules 1 TTP 1 CVEosrg GoBGP up to version 4.3.0 is vulnerable to an integer underflow in the parseRibEntry function, potentially allowing a remote attacker to cause a denial of service or other unspecified impacts; version 4.4.0 addresses this issue.
Microsoft Product Vulnerability CVE-2026-37555
2 rules 1 CVECVE-2026-37555 is a vulnerability affecting a Microsoft product, requiring further investigation upon patch release.
NEX-Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-5063)
2 rules 1 TTP 1 CVEThe NEX-Forms WordPress plugin is vulnerable to stored XSS via POST parameter key names, allowing unauthenticated attackers to inject arbitrary web scripts.
TRENDnet TEW-821DAP Firmware Update Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA buffer overflow vulnerability exists in TRENDnet TEW-821DAP version 1.12B01, allowing a remote attacker to execute arbitrary code by manipulating the 'str' argument in the auto_update_firmware function of the Firmware Update component.
Gravity Forms Plugin Stored XSS Vulnerability (CVE-2026-5113)
2 rules 2 TTPs 1 CVEThe Gravity Forms plugin for WordPress is vulnerable to stored cross-site scripting (XSS) via Consent field hidden inputs, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the entries list page.
libssh2 Integer Overflow Vulnerability (CVE-2026-7598)
2 rules 1 TTP 1 CVEAn integer overflow vulnerability exists in libssh2 versions up to 1.11.1 within the userauth_password function of src/userauth.c, which can be triggered remotely by manipulating username_len/password_len arguments.
AWS SSM Session Manager Child Process Execution Abuse
2 rules 3 TTPsAdversaries abuse AWS Systems Manager (SSM) Session Manager to gain remote execution and lateral movement within AWS environments by spawning malicious child processes from the SSM session worker, leveraging legitimate AWS credentials and IAM permissions.
AWS EC2 Role GetCallerIdentity from New Source AS Organization
2 rules 1 TTPThe rule detects when an EC2 instance role session calls AWS STS GetCallerIdentity from a new source autonomous system (AS) organization name, indicating potential credential theft and verification from outside expected egress paths.
AWS Discovery API Calls from VPN ASN by New Identity
2 rules 1 TTPThis rule detects the initial use of AWS discovery APIs from VPN-associated ASNs by a previously unseen identity, indicating potential reconnaissance activity.
JetBrains IntelliJ IDEA Vulnerability
2 rulesA vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1 and 2026.1.1, requiring users to update to the latest versions.
Prosody Memory Exhaustion Vulnerability (CVE-2026-43506)
2 rules 1 TTP 1 CVEProsody versions before 0.12.6, versions 1.0.0 through 13.0.0, and before version 13.0.5 are vulnerable to a denial of service due to memory leaks from unauthenticated connections, leading to memory exhaustion.
Microsoft Edge Stable Channel Vulnerabilities Addressed in April 2026 Update
2 rulesMicrosoft addressed vulnerabilities in Microsoft Edge Stable Channel versions prior to 147.0.3912.98 with a security update released on April 30, 2026, requiring users to update to the latest version.
Microsoft Product Vulnerability CVE-2026-41526
1 CVECVE-2026-41526 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon patch release for exploitation details.
Libssh Denial-of-Service Vulnerability via Inefficient Regular Expression Processing (CVE-2026-0967)
2 rules 1 TTP 1 CVECVE-2026-0967 is a denial-of-service vulnerability in libssh, stemming from inefficient regular expression processing that could lead to defense evasion and impact availability on affected systems.
IBM Langflow Desktop Unauthenticated Image Access via IDOR
2 rules 1 TTP 1 CVEIBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an indirect object reference (IDOR) vulnerability (CVE-2026-4503), allowing unauthenticated users to view other users' images due to a user-controlled key.
Sentry SAML SSO Improper Authentication Allows User Identity Linking
2 rules 1 TTPA critical vulnerability (CVE-2026-42354) exists in Sentry's SAML SSO implementation that allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance, affecting self-hosted users with multiple organizations configured if a malicious user has permissions to modify SSO settings, while Sentry SaaS was patched in April and self-hosted users are advised to upgrade to version 26.4.1 or higher.
HPE Security Advisory for Telco Service Orchestrator and Activator
2 rulesHPE released a security advisory addressing multiple vulnerabilities in HPE Telco Service Orchestrator (versions prior to v5.6.0) and HPE Telco Service Activator (versions 10.5.0 and prior), urging users to apply necessary updates.
Hickory DNS Recursor Cache Poisoning via Sibling Zone Delegation
2 rulesThe experimental `hickory-recursor` crate in Hickory DNS is vulnerable to cross-zone cache poisoning due to storing DNS records keyed by record name/type instead of query, enabling an attacker to redirect queries for a victim zone to an attacker-controlled nameserver.
GNU InetUtils Vulnerabilities Prior to 2.8
2 rulesGNU released a security advisory addressing critical vulnerabilities in GNU InetUtils versions prior to 2.8, prompting users to apply necessary updates.
MeWare PDKS Improper Control of Interaction Frequency Vulnerability (CVE-2026-7402)
1 rule 1 CVEMeWare PDKS versions V16.20200313 before VMYR_3.5.2025117 are vulnerable to improper control of interaction frequency, potentially leading to flooding attacks.
ABB System 800xA and Symphony Plus IEC 61850 Denial-of-Service Vulnerability
2 rules 1 TTP 1 CVEA vulnerability in ABB's IEC 61850 communication stack allows a remote attacker with access to the IEC 61850 network to cause a denial-of-service condition by sending a specially crafted packet, leading to device faults or communication driver crashes.
ABB PCM600 Path Traversal Vulnerability (CVE-2018-1002208)
2 rules 1 TTP 1 CVEA path traversal vulnerability in ABB PCM600 versions 1.5 to 2.13 (CVE-2018-1002208) allows a local attacker with low privileges to execute arbitrary code by sending a specially crafted message to the system node.
libsndfile Vulnerability Allows Denial of Service
2 rules 1 TTPA remote, unauthenticated attacker can exploit an unpatched vulnerability in libsndfile to cause a denial of service.
DNSdist Multiple Vulnerabilities Leading to Denial of Service
2 rules 1 TTP 1 CVEMultiple vulnerabilities in DNSdist can be exploited by an attacker to perform a denial of service attack, impacting the availability of DNS services.
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate DoS Vulnerability
2 rules 1 TTP 1 CVECVE-2026-32283 is a vulnerability in crypto/tls that allows unauthenticated TLS 1.3 KeyUpdate records, leading to persistent connection retention and a denial-of-service condition.
CVE-2026-28388 NULL Pointer Dereference in Delta CRL Processing
2 rules 1 CVECVE-2026-28388 is a NULL Pointer Dereference vulnerability in an unspecified Microsoft product when processing a Delta CRL, potentially leading to a denial-of-service condition.
Microsoft Published Information on CVE-2026-32776
1 CVEMicrosoft published information regarding CVE-2026-32776, however, further details require JavaScript to be enabled, limiting the actionable intelligence at this time.
Microsoft CVE-2026-32778 Vulnerability Published
2 rules 1 CVEMicrosoft published information regarding vulnerability CVE-2026-32778, but no details regarding the vulnerability are available at this time.
CVE-2026-34073: Incomplete DNS Name Constraint Enforcement Vulnerability
2 rules 1 CVECVE-2026-34073 is a vulnerability in unspecified Microsoft products due to incomplete DNS name constraint enforcement on peer names, potentially leading to certificate validation bypass.
1024-lab smart-admin Improper Access Control Vulnerability (CVE-2026-7468)
2 rules 1 TTP 1 CVECVE-2026-7468 is an improper access control vulnerability in 1024-lab smart-admin up to version 3.30.0, affecting the /smart-admin-api/druid/index.html file, which can be exploited remotely.
Netgate pfSense XSS Vulnerability
2 rulesA cross-site scripting (XSS) vulnerability affects Netgate pfSense CE (<= 2.8.1) and pfSense Plus (<= 26.03), potentially allowing attackers to inject malicious code.
Multiple Vulnerabilities in SonicWall Products Allow for DoS and Security Policy Bypass
2 rules 2 TTPs 3 CVEsMultiple vulnerabilities in SonicWall firewalls could allow an attacker to cause a remote denial of service and security policy bypass, potentially disrupting network services and compromising security controls.
Admidio SAML Signature Validation Bypass Allows Forged AuthnRequests and LogoutRequests
2 rules 5 TTPsAdmidio's SAML Identity Provider implementation fails to properly validate signatures on SAML AuthnRequests and LogoutRequests, enabling attackers to bypass signature enforcement, potentially disclose user attributes via forged SSO requests, and terminate user sessions via forged SLO requests.
Jenkins Security Advisory Addressing Multiple Plugin Vulnerabilities
2 rulesJenkins released a security advisory on April 29, 2026, detailing vulnerabilities in Credentials Binding Plugin, GitHub Plugin, GitHub Branch Source Plugin, HTML Publisher Plugin, Matrix Authorization Strategy Plugin, Microsoft Entra ID Plugin, and Script Security Plugin, urging users to apply necessary updates.
Atomic Red Team MCP Server Automates Adversary Emulation
2 rules 4 TTPsThe Atomic Red Team Model Context Protocol (MCP) server integrates security tests from the Atomic Red Team project with AI assistants, enabling natural language interaction with security tools, bridging the gap between threat intelligence and execution, allowing for automated validation, multi-platform testing, and rapid playbook creation.
Large-Scale Smishing Campaign Impersonating Transport Authorities
2 rules 1 TTPA smishing campaign has been active since December 2025, targeting drivers in 12 countries with fraudulent text messages impersonating transport authorities, toll operators, and parking services, resulting in over 79,000 fraudulent messages sent as of April 2026.
SmarterTools SmarterMail Vulnerability Prior to Build 9610
2 rulesSmarterTools released a security advisory addressing a vulnerability in SmarterMail versions prior to Build 9610, prompting users to update their software.
OpenClaw Webhook Replay Vulnerability (CVE-2026-41395)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.28 is vulnerable to webhook replay attacks due to improper signature verification, allowing attackers to reorder query parameters and trigger duplicate voice-call processing.
OpenClaw MS Teams Webhook Resource Exhaustion Vulnerability
1 rule 1 CVEOpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to exhaust server resources by sending malicious Teams webhook payloads.
Notepad++ Vulnerability in Version 8.9.3 and Prior
2 rules 1 TTPA vulnerability exists in Notepad++ version 8.9.3 and prior, prompting a security advisory and the release of version 8.9.4 to address the issue.
Mozilla Firefox Multiple Vulnerabilities
2 rules 3 TTPsMozilla released a security advisory addressing vulnerabilities in Firefox and Firefox ESR versions prior to 150.0.1, 140.10.1, and 115.35.1, potentially leading to arbitrary code execution or information disclosure.
Citrix XenServer Vulnerabilities Addressed in Security Advisory AV26-400
2 rules 1 TTPCitrix released security advisory AV26-400 on April 28, 2026, addressing vulnerabilities in XenServer versions prior to 8.4, prompting users to apply mitigations.
Google Chrome Security Update Released
2 rulesGoogle released a security advisory to address vulnerabilities in Chrome for Desktop versions prior to 147.0.7727.137/138 on Windows/Mac and 147.0.7727.137 on Linux, prompting users to apply necessary updates.
AI-Powered Honeypots: Deceptive Environments for Automated Threat Actors
2 rules 3 TTPs 1 CVEGenerative AI can be used to rapidly deploy adaptive honeypot systems that simulate diverse environments, like Linux shells or IoT devices, to trick and observe AI-driven attacks that prioritize speed over stealth.
Multiple Vulnerabilities in GNU libc
2 rules 3 TTPs 5 CVEsA remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary program code, cause a denial-of-service condition, or disclose sensitive information.
CVE-2025-68146 filelock TOCTOU Race Condition Enables Symlink Attacks
2 rules 1 CVECVE-2025-68146 describes a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the filelock library that could allow for symlink attacks during lock file creation, potentially leading to unauthorized file access or modification.
rust-openssl Memory Leak via Unchecked Callback Length (CVE-2026-41898)
2 rules 1 CVECVE-2026-41898 describes a vulnerability in rust-openssl where unchecked callback-returned length in PSK and cookie generation can cause OpenSSL to leak adjacent memory to a network peer.
OpenTelemetry-Go Multi-Value Baggage Header Extraction DoS Vulnerability (CVE-2026-29181)
2 rules 1 TTP 1 CVEA vulnerability in OpenTelemetry-Go related to the extraction of multi-value baggage headers can lead to excessive resource allocation, resulting in a remote denial-of-service amplification.
CoreDNS DoQ Server Denial-of-Service Vulnerability
2 rules 3 TTPs 1 CVECoreDNS' DNS-over-QUIC (DoQ) server can be driven into large goroutine and memory growth by a remote client that opens many QUIC streams and stalls after sending only 1 byte, leading to denial of service in versions before 1.14.3.
OpenClaw Unauthenticated WebSocket Denial-of-Service Vulnerability
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.28 is vulnerable to a denial-of-service attack by accepting unbounded concurrent unauthenticated WebSocket upgrades, allowing attackers to exhaust server resources.
ChatGPTNextWeb NextChat Server-Side Request Forgery Vulnerability
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability in ChatGPTNextWeb NextChat up to version 2.16.1 allows remote attackers to manipulate the proxyHandler function, potentially leading to unauthorized internal resource access.
Detection of Github Delete Actions in Audit Logs
2 rules 1 TTPThis brief focuses on detecting deletion actions within GitHub audit logs, specifically targeting the deletion of codespaces, environments, projects, and repositories, potentially indicating malicious activity or insider threats.
Google Workspace Login Attempt with Government Attack Warning
2 rules 1 TTPA Google Workspace login attempt flagged as a potential attack by a government-backed threat actor, indicating potential privilege escalation, defense evasion, persistence, initial access, or impact.
Linux Persistence via Sudoers.d File Manipulation
3 rules 2 TTPsAttackers can achieve persistence and privilege escalation on Linux systems by creating or modifying files in the /etc/sudoers.d/ directory to grant unauthorized users or groups sudo privileges.
Dell Security Advisories Address Vulnerabilities in Multiple Products
2 rulesDell published security advisories addressing vulnerabilities in Dell Networking OS10, Dell Storage Monitoring and Reporting, Dell Storage Resource Manager, and Dell VxRail Appliance, urging users to apply necessary updates.
Typecho <= 1.3.0 Server-Side Request Forgery Vulnerability (CVE-2026-7025)
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability exists in Typecho up to version 1.3.0, allowing remote attackers to manipulate the X-Pingback/link argument in the Service::sendPingHandle function to potentially make arbitrary HTTP requests.
CVE-2026-31622 NFC-A Cascade Depth Bounds Check Failure
2 rules 1 TTP 1 CVECVE-2026-31622 describes a vulnerability related to an NFC bounds check issue, specifically a failure to properly validate NFC-A cascade depth in the SDD response handler within Microsoft products, potentially leading to unexpected behavior or security compromise.
CVE-2026-23398 ICMP NULL Pointer Dereference
2 rules 1 TTP 1 CVECVE-2026-23398 is a vulnerability related to a NULL pointer dereference in the ICMP protocol, potentially leading to a denial-of-service condition in affected Microsoft products.
vanna-ai vanna Improper Authorization Vulnerability (CVE-2026-6977)
2 rules 1 TTP 1 CVEAn improper authorization vulnerability (CVE-2026-6977) exists in vanna-ai vanna up to version 2.0.2 due to manipulation of an unknown function within the Legacy Flask API, potentially allowing remote attackers to bypass intended access restrictions.
Microsoft Product Vulnerability CVE-2026-41080
2 rules 1 CVECVE-2026-41080 is a vulnerability affecting a Microsoft product; the specific product, impact, and exploitation details are currently undisclosed.
OpenClaw Cross-Site Request Forgery Vulnerability
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.31 is vulnerable to cross-site request forgery (CSRF) attacks due to missing browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing attackers to perform unauthorized actions.
Argo Workflows Controller Denial-of-Service via Malformed Pod Annotation
2 rules 2 TTPsA malformed `workflows.argoproj.io/pod-gc-strategy` annotation in an Argo Workflow pod can trigger an unchecked array index in the `podGCFromPod()` function, leading to a controller-wide panic and denial-of-service.
xmldom Uncontrolled Recursion DoS Vulnerability
2 rules 1 TTPThe xmldom library is vulnerable to a denial-of-service (DoS) attack due to uncontrolled recursion in XML serialization leading to application crashes.
Cisco Integrated Management Controller (IMC) Multiple XSS Vulnerabilities
2 rules 1 TTP 5 CVEsMultiple cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct an XSS attack against a user of the interface.
Microsoft Product Vulnerability CVE-2026-22005
3 rules 1 CVECVE-2026-22005 is a newly published vulnerability affecting a Microsoft product, requiring further investigation to determine the specific product, attack vector, and potential impact.
Microsoft Discloses Information Regarding CVE-2026-22004
1 rule 1 TTP 1 CVEMicrosoft has released information regarding the vulnerability CVE-2026-22004, but details about the vulnerability and its exploitation are currently unavailable.
CVE-2026-34303 Affecting Microsoft Products
2 rules 1 CVECVE-2026-34303 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon disclosure of details.
IBM WebSphere Liberty Identity Spoofing Vulnerability (CVE-2026-3621)
2 rules 1 TTP 1 CVEIBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.4 are susceptible to identity spoofing when applications are deployed without proper authentication and authorization configurations, potentially leading to unauthorized access and privilege escalation.
Suspicious Processes Connecting to Large Language Model Endpoints
3 rules 1 TTPThis rule detects DNS queries to known Large Language Model (LLM) domains by unsigned binaries or common Windows scripting utilities, indicating potential command and control activity leveraging LLMs for dynamic actions on compromised systems.
NVIDIA KAI Scheduler Authentication Bypass Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-24177 describes an authentication bypass vulnerability in NVIDIA KAI Scheduler that could allow unauthorized access to API endpoints, leading to information disclosure.
FreeScout Privilege Escalation via Email Address Reassignment (CVE-2026-40589)
2 rules 1 TTP 1 CVEFreeScout versions before 1.8.214 are vulnerable to privilege escalation, allowing a low-privileged agent to reassign email addresses from hidden customers to visible customers, leading to information disclosure and unauthorized access to conversations.
FreeScout Incorrect Authorization Vulnerability via Save Draft
2 rules 1 TTP 1 CVEFreeScout before 1.8.215 has an incorrect authorization vulnerability where a direct POST request to the `save_draft` AJAX path can create a draft inside a hidden conversation when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, potentially allowing unauthorized access or modification of data.
FreeScout Incorrect Authorization Vulnerability (CVE-2026-41189)
2 rules 1 TTP 1 CVEFreeScout versions before 1.8.215 are vulnerable to an incorrect authorization issue where users without conversation access can edit customer threads due to a flaw in the `ThreadPolicy::edit()` function.
util-linux Vulnerability Allows DoS and Information Disclosure
2 rules 2 TTPsA local attacker can exploit a vulnerability in util-linux to perform a denial of service attack and disclose sensitive information.
BigBlueButton Vulnerabilities Allow Data Manipulation and Redirects
2 rules 1 TTPMultiple vulnerabilities in BigBlueButton can be exploited by an attacker to manipulate data and redirect users to attacker-controlled domains.
Oracle VirtualBox Unauthenticated RDP Denial-of-Service Vulnerability (CVE-2026-35245)
2 rules 1 TTP 1 CVEAn unauthenticated attacker with network access via RDP can exploit CVE-2026-35245 in Oracle VM VirtualBox version 7.2.6 to cause a denial-of-service (DOS) condition.
ConnectWise Automate Solution Center Cleartext Communication Vulnerability (CVE-2026-6066)
2 rules 1 TTP 1 CVE 1 IOCConnectWise Automate is vulnerable to CVE-2026-6066, a cleartext transmission of sensitive information vulnerability, where certain client-to-server communications could occur without transport-layer encryption, potentially allowing network-based interception of Solution Center traffic, and the issue is resolved in Automate 2026.4 by enforcing secure communication.
Cisco Catalyst SD-WAN Manager Password Disclosure Vulnerability (CVE-2026-20128)
2 rules 1 TTP 1 CVECisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing an authenticated local attacker to gain DCA user privileges by accessing a credential file.
libarchive Multiple Vulnerabilities Allow Information Disclosure and DoS
2 rules 2 TTPsMultiple vulnerabilities in libarchive can be exploited by a remote attacker to disclose information or cause a denial-of-service condition.
Microsoft CVE-2026-41254 Security Update
2 rules 1 CVEMicrosoft released a security update for CVE-2026-41254, a vulnerability with unspecified details.
Suspicious RDP File Execution
2 rules 2 TTPsThis rule identifies attempts to open a remote desktop file from suspicious paths, indicative of adversaries abusing RDP files for initial access via phishing.
CVE-2026-26149 Microsoft Power Apps Spoofing Vulnerability
2 rules 1 CVEA spoofing vulnerability exists in Microsoft Power Apps, identified as CVE-2026-26149, potentially allowing an attacker to mislead users or gain unauthorized access.
Langflow Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in Langflow allow an attacker to manipulate files, disclose sensitive information, or conduct cross-site scripting attacks.
Multiple Vulnerabilities in Gitea
1 rule 1 TTPMultiple vulnerabilities in Gitea could allow an attacker to disclose information, bypass security measures, and perform cross-site scripting attacks.
Moxi Blog v2 <= 5.2 Server-Side Request Forgery Vulnerability
2 rules 1 TTPA server-side request forgery (SSRF) vulnerability exists in moxi624 Mogu Blog v2 up to version 5.2, specifically affecting the `LocalFileServiceImpl.uploadPictureByUrl` function, allowing remote attackers to potentially interact with internal resources.
OpenClaw Webchat Media Embedding Local-Root Containment Bypass
2 rules 2 TTPsA vulnerability in OpenClaw versions 2026.4.7 to before 2026.4.15 allows a crafted tool-result media reference to cause the host to attempt local file reads or Windows UNC/network path access, potentially disclosing files or network credentials.
Movary SSRF Vulnerability (CVE-2026-40348)
2 rules 2 TTPs 1 CVEMovary versions before 0.71.1 are vulnerable to server-side request forgery (SSRF) via the `/settings/jellyfin/server-url-verify` endpoint, allowing authenticated users to probe internal network resources.
WeGIA Stored Cross-Site Scripting Vulnerability (CVE-2026-40286)
2 rules 1 TTP 1 CVEA stored Cross-Site Scripting (XSS) vulnerability exists in WeGIA versions prior to 3.6.10, allowing attackers to inject malicious scripts into the 'Member Name' field during member registration, leading to persistent execution upon user access.
Firebird FB3 Client Library Information Leak (CVE-2025-65104)
2 rules 1 TTP 1 CVEFirebird FB3 client library incorrectly handles data lengths when communicating with FB4+ servers, leading to an information leak exploitable by a local attacker.
Mobatek MobaXterm Home Edition Uncontrolled Search Path Vulnerability (CVE-2026-6421)
2 rules 1 TTP 1 CVECVE-2026-6421 is an uncontrolled search path vulnerability in Mobatek MobaXterm Home Edition up to version 26.1, affecting msimg32.dll, that can be exploited locally with high complexity.
HashiCorp Vault Denial-of-Service Vulnerability (CVE-2026-5807)
2 rules 1 TTP 1 CVEHashiCorp Vault is vulnerable to a denial-of-service (DoS) condition, identified as CVE-2026-5807, where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, preventing legitimate operators from completing these workflows.
Vault kvv2 Policy Bypass Vulnerability Leading to Denial-of-Service (CVE-2026-3605)
2 rules 1 TTP 1 CVEAn authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service, addressed in Vault versions 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Google Chrome V8 Type Confusion Vulnerability (CVE-2026-6363)
2 rules 2 TTPs 1 CVEA type confusion vulnerability (CVE-2026-6363) in Google Chrome's V8 JavaScript engine before version 147.0.7727.101 allows a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page.
PowMix Botnet Targeting Czech Workforce
3 rules 5 TTPs 1 IOCThe PowMix botnet campaign targets Czech organizations, particularly HR, legal, and recruitment agencies, using compliance-themed lures delivered via phishing emails, with the attack employing a Windows shortcut file that executes a PowerShell loader to bypass AMSI and deploy the botnet payload in memory.
Weblate Path Traversal Vulnerability in ZIP Download Feature (CVE-2026-34242)
2 rules 2 TTPs 1 CVEWeblate versions before 5.17 are vulnerable to path traversal due to improper verification of downloaded files in the ZIP download feature, potentially allowing attackers to access files outside the intended repository.
Git for Windows NTLM Hash Leak Vulnerability (CVE-2026-32631)
2 rules 1 TTP 1 CVEGit for Windows versions prior to 2.53.0.windows.3 are vulnerable to NTLM hash theft by attackers who can trick users into cloning malicious repositories or checking out malicious branches, leading to potential credential compromise.
Windows Remote Desktop Spoofing Vulnerability (CVE-2026-26151)
2 rules 2 TTPs 1 CVECVE-2026-26151 is a spoofing vulnerability in Windows Remote Desktop due to an insufficient UI warning for dangerous operations, allowing an unauthorized attacker to perform spoofing over a network.
Microsoft Excel Out-of-Bounds Read Vulnerability (CVE-2026-32188)
2 rules 1 TTP 1 CVEAn out-of-bounds read vulnerability in Microsoft Office Excel (CVE-2026-32188) allows a local attacker to potentially disclose sensitive information through a maliciously crafted Excel file.
Adobe ColdFusion Improper Input Validation Vulnerability (CVE-2026-27306)
2 rules 1 TTP 1 CVEAn improper input validation vulnerability in Adobe ColdFusion versions 2023.18, 2025.6, and earlier (CVE-2026-27306) could lead to arbitrary code execution if a privileged user opens a specially crafted malicious file.
Keycloak Cross-Site Scripting Vulnerability
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Keycloak to perform a Cross-Site Scripting attack, potentially leading to unauthorized access and data compromise.
.NET Spoofing Vulnerability (CVE-2026-32178)
2 rules 1 TTP 1 CVECVE-2026-32178 is a vulnerability in .NET that allows for network spoofing due to improper neutralization of special elements, potentially enabling attackers to impersonate legitimate entities.
Suspicious Registry Modifications by Scripting Engines
1 rule 3 TTPsScripting engines such as WScript, CScript, and MSHTA are being used to make registry modifications, potentially for persistence or defense evasion.
jq JSON Processor Hash Table Collision Denial-of-Service Vulnerability (CVE-2026-40164)
2 rules 1 TTP 1 CVEA denial-of-service vulnerability exists in jq versions prior to commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784 due to the use of a hardcoded seed in MurmurHash3, enabling attackers to craft JSON objects that trigger hash collisions and cause excessive CPU consumption.
ImageMagick XML Bomb Denial-of-Service Vulnerability (CVE-2026-33908)
2 rules 1 TTP 1 CVEImageMagick versions prior to 7.1.2-19 and 6.9.13-44 are susceptible to a denial-of-service (DoS) attack due to unbounded recursion during XML parsing, potentially leading to stack exhaustion.
UniFi Play Improper Access Control Vulnerability (CVE-2026-22566)
2 rules 1 TTP 1 CVEAn improper access control vulnerability in UniFi Play PowerAmp and Audio Port allows a malicious actor with access to the UniFi Play network to obtain WiFi credentials.
Huawei Communication Module Use-After-Free Vulnerability (CVE-2026-34856)
2 rules 1 TTP 1 CVEA use-after-free vulnerability, tracked as CVE-2026-34856, exists in Huawei's communication module due to improper synchronization in concurrent execution, potentially leading to a denial-of-service condition.
Chamilo LMS Session Fixation Vulnerability (CVE-2026-31940)
2 rules 1 TTP 1 CVEChamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 are vulnerable to session fixation due to user-controlled request parameters being used to set the PHP session ID, potentially allowing attackers to hijack user sessions.
TREK Travel Planner Missing Authorization Vulnerability (CVE-2026-40185)
2 rules 1 TTP 1 CVETREK collaborative travel planner before version 2.7.2 is vulnerable to missing authorization checks on the Immich trip photo management routes, potentially allowing unauthorized access to trip photos.
Entra ID ADRS Token Request by Microsoft Authentication Broker
2 rules 2 TTPs 1 IOCDetects suspicious OAuth 2.0 token requests where the Microsoft Authentication Broker requests access to the Device Registration Service on behalf of a user principal, potentially indicating an attempt to abuse device registration for unauthorized persistence.
GitHub Exfiltration via High Number of Repository Clones
2 rules 3 TTPsA single user rapidly cloning a high number of GitHub repositories indicates potential exfiltration of sensitive data such as proprietary code, embedded secrets, and build artifacts.
AWS STS GetCallerIdentity API Called for the First Time
2 rules 2 TTPsAn adversary with access to compromised AWS credentials may attempt to verify their validity and determine the account they are using by calling the STS GetCallerIdentity API, potentially indicating credential compromise and unauthorized discovery activity.
Azure Service Principal Sign-In Followed by Arc Cluster Credential Access
2 rules 3 TTPsDetects a service principal authenticating to Azure AD followed by listing credentials for an Azure Arc-connected Kubernetes cluster, indicating potential adversary activity with stolen service principal secrets to establish a proxy tunnel into Kubernetes clusters.
AWS EC2 LOLBin Execution via SSM SendCommand
2 rules 2 TTPsDetection of Living Off the Land Binaries (LOLBins) or GTFOBins execution on EC2 instances via AWS Systems Manager (SSM) SendCommand API, potentially indicating malicious activity.
Zootemplate Cerato Theme Reflected XSS Vulnerability (CVE-2025-58920)
2 rules 1 TTP 1 CVE 1 IOCA reflected cross-site scripting (XSS) vulnerability exists in the Zootemplate Cerato WordPress theme (versions n/a through 2.2.18) due to improper neutralization of user-supplied input, potentially allowing attackers to execute arbitrary JavaScript in a user's browser.
Gravity SMTP Plugin Missing Authorization Vulnerability (CVE-2026-4162)
2 rules 1 TTP 1 CVEThe Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access or higher to uninstall/deactivate the plugin and delete plugin options, and is also exploitable via Cross-Site Request Forgery.
Google Chrome Device Bound Session Credentials (DBSC) Mitigates Cookie Theft
2 rules 1 TTPGoogle's rollout of Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, with a future release planned for macOS, cryptographically binds authentication sessions to the user's device, rendering stolen session cookies unusable and mitigating credential access.
Juniper Junos OS and Junos OS Evolved BGP Session Reset Denial of Service (CVE-2026-33797)
3 rules 2 TTPs 1 CVECVE-2026-33797 is an improper input validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved that allows an unauthenticated adjacent attacker to reset established BGP sessions via a specific BGP packet, leading to a denial of service condition.
Saleor GraphQL Batch Query Resource Exhaustion Vulnerability (CVE-2026-33756)
2 rules 1 TTP 1 CVEUnauthenticated attackers can exploit a resource exhaustion vulnerability (CVE-2026-33756) in Saleor e-commerce platform versions before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118 by sending a single HTTP request with a large number of GraphQL operations, bypassing query complexity limits and exhausting server resources.
First Time Python Process Creates macOS Launch Agent or Daemon
2 rules 2 TTPsThis rule detects the initial creation or modification of a macOS LaunchAgent or LaunchDaemon plist file by a Python process, a common persistence technique employed by attackers using malicious scripts, compromised dependencies, or model file deserialization.
LORIS Directory Traversal Vulnerability
2 rules 2 TTPs 1 CVELORIS, a neuroimaging research data management web application, is vulnerable to directory traversal (CVE-2026-35446) due to an incorrect order of operations in the FilesDownloadHandler, allowing authenticated attackers to access unauthorized files.
Saleor GraphQL Resource Exhaustion Vulnerability (CVE-2026-35401)
2 rules 1 TTP 1 CVEA remote, unauthenticated attacker can cause resource exhaustion in Saleor e-commerce platforms via maliciously crafted GraphQL API requests, leading to denial of service.
Red Hat Quay Image Upload Interference Vulnerability (CVE-2026-32589)
2 rules 2 TTPs 1 CVECVE-2026-32589 describes a vulnerability in Red Hat Quay's container image upload process where an authenticated user can interfere with other users' uploads, potentially leading to unauthorized access and modification.
Kibana Fleet Plugin Privilege Escalation via CVE-2026-4498
2 rules 1 TTP 1 CVECVE-2026-4498 allows an authenticated Kibana user with Fleet sub-feature privileges to read index data beyond their direct Elasticsearch RBAC scope due to improper privilege handling in debug route handlers.
Dell ECS and ObjectScale Sensitive Information Logging Vulnerability (CVE-2026-28261)
2 rules 1 TTP 1 CVEDell Elastic Cloud Storage and ObjectScale are vulnerable to local privilege escalation due to sensitive information being logged, potentially allowing a low-privileged attacker with local access to expose secrets and gain unauthorized access.
OpenClaw Agent Suspicious Child Process Execution
2 rules 10 TTPs 3 IOCsMalicious actors are exploiting OpenClaw, Moltbot, and Clawdbot AI coding agents via Node.js to execute arbitrary shell commands and download-and-execute commands, potentially targeting cryptocurrency wallets and credentials.
IBM Tivoli Netcool Impact Sensitive Information Leak via Log Files (CVE-2026-4788)
2 rules 1 TTP 1 CVEIBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files, potentially exposing it to unauthorized local users, tracked as CVE-2026-4788.
IBM Verify and Security Verify Access Container Server-Side Request Forgery Vulnerability (CVE-2026-1343)
2 rules 2 TTPs 1 CVECVE-2026-1343 allows an attacker to contact internal authentication endpoints protected by the Reverse Proxy in IBM Verify Identity Access Container and IBM Security Verify Access Container.
OpenSSH GSSAPI Vulnerability Leads to Potential Denial-of-Service
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in OpenSSH GSSAPI and Ubuntu Linux to trigger undefined behavior or a potential denial-of-service attack.
CSRF Vulnerability in WordPress Under Construction Plugin (CVE-2026-34896)
2 rules 2 TTPs 1 CVEA cross-site request forgery (CSRF) vulnerability exists in the Analytify Under Construction, Coming Soon & Maintenance Mode WordPress plugin (versions n/a through 2.1.1), potentially allowing attackers to execute unauthorized actions on behalf of legitimate users.
Brave CMS Insecure Direct Object Reference Vulnerability (CVE-2026-35183)
1 rule 1 TTP 1 CVEBrave CMS versions prior to 2.0.6 are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability allowing authenticated users with edit permissions to delete images attached to articles owned by other users due to missing ownership verification in the deleteImage method.
openFPGALoader Heap-Buffer-Overflow Read Vulnerability
2 rules 1 TTP 1 CVEA heap-buffer-overflow read vulnerability exists in openFPGALoader 1.1.1 and earlier, allowing out-of-bounds heap memory access via a crafted .pof file, potentially leading to denial of service or information disclosure.
Qualcomm Transient Denial-of-Service via FILS Discovery Frames (CVE-2026-21367)
2 rules 2 TTPs 1 CVECVE-2026-21367 describes a transient denial-of-service vulnerability in Qualcomm products that occurs when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans, potentially leading to service disruption.
GLPI Cross-Site Scripting Vulnerability (CVE-2026-25932)
2 rules 1 TTP 1 CVECVE-2026-25932 is a cross-site scripting vulnerability in GLPI versions 0.60 to before 10.0.24, where an authenticated technician user can store a malicious XSS payload within supplier fields, potentially leading to arbitrary code execution in the context of other users' browsers.
Microsoft VPN Browser+ 1.1.0.0 Denial of Service Vulnerability (CVE-2018-25241)
2 rules 1 TTP 1 CVEAn unauthenticated attacker can cause a denial of service by crashing Microsoft VPN Browser+ 1.1.0.0 via oversized input to the search functionality, leading to application termination.
WordPress Widgets for Social Photo Feed Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'feed_data' parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that will execute when a user accesses the injected page.
Piwigo Unauthenticated History Search Access
2 rules 1 TTP 1 CVE 1 IOCPiwigo versions prior to 16.3.0 expose the full browsing history of gallery visitors to unauthenticated users via the pwg.history.search API method due to a missing authorization check.
Suricata Quadratic Complexity Issue in SMTP URL Searching (CVE-2026-31934)
2 rules 1 TTP 1 CVE 1 IOCSuricata versions 8.0.0 to before 8.0.4 exhibit a quadratic complexity vulnerability (CVE-2026-31934) when searching for URLs in MIME-encoded SMTP messages, leading to significant performance degradation and potential denial-of-service conditions; this is fixed in version 8.0.4.
Democratization of Business Email Compromise (BEC) Attacks
2 rules 2 TTPs 1 CVE 6 IOCsAttackers are leveraging AI to rapidly reconnoiter and tailor content for smaller organizations, making it easier to execute business email compromise (BEC) scams and scam smaller sums from many victims, as demonstrated by a recent attack targeting a small community organization.
ManageEngine Exchange Reporter Plus Stored XSS Vulnerability
2 rules 2 TTPs 1 CVEZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in the Distribution Lists report, allowing attackers to inject malicious scripts.
OpenClaw Arbitrary File Read and Credential Exfiltration Vulnerability
2 rules 1 TTPThe openclaw package is vulnerable to arbitrary file read and credential exfiltration due to media local roots self-whitelisting in `appendLocalMediaParentRoots`, allowing a model to initiate arbitrary host file reads, potentially leading to credential exfiltration.
OpenSSH scp Insecure File Permission Vulnerability (CVE-2026-35385)
2 rules 1 TTP 1 CVEOpenSSH versions before 10.3 allow for the potential installation of setuid or setgid files when using scp to download files as root with the -O option (legacy SCP protocol) and without the -p option (preserve mode), contrary to user expectations.
Rack::Static Information Disclosure Vulnerability (CVE-2026-34785)
2 rules 1 TTP 1 CVERack versions prior to 2.2.23, 3.1.21, and 3.2.6 are vulnerable to information disclosure due to improper static file serving via a prefix matching issue in Rack::Static.
Huimeicloud hm_editor Server-Side Request Forgery Vulnerability (CVE-2026-5346)
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability exists in huimeicloud hm_editor up to version 2.2.3, allowing remote attackers to manipulate the 'url' argument in the client.get function of src/mcp-server.js to potentially access internal resources.
Suricata HTTP2 Continuation Frame Flooding Denial of Service (CVE-2026-31935)
2 rules 1 TTP 1 CVEA denial of service vulnerability, CVE-2026-31935, exists in Suricata versions prior to 7.0.15 and 8.0.4, where flooding the system with crafted HTTP2 continuation frames leads to memory exhaustion and process termination.
Suricata DCERPC Buffering Inefficiency Vulnerability (CVE-2026-31937)
2 rules 1 TTP 1 CVESuricata versions prior to 7.0.15 are vulnerable to CVE-2026-31937, where inefficient DCERPC buffering can lead to a denial-of-service condition through performance degradation.
Suricata NULL Dereference Vulnerability
2 rules 2 TTPs 1 CVESuricata versions 8.0.0 to before 8.0.4 are vulnerable to a NULL dereference crash when using the 'tls.alpn' rule keyword, potentially leading to a denial of service.
Suricata KRB5 Buffering Inefficiency Vulnerability (CVE-2026-31932)
2 rules 1 TTP 1 CVEAn unauthenticated attacker can exploit CVE-2026-31932, a vulnerability in Suricata versions prior to 7.0.15 and 8.0.4, to cause performance degradation due to inefficient KRB5 buffering.
Suricata DoS Vulnerability (CVE-2026-31933)
2 rules 1 TTP 1 CVESpecially crafted network traffic can cause Suricata to slow down, leading to a denial-of-service condition in versions prior to 7.0.15 and 8.0.4, as identified by CVE-2026-31933.
Keycloak Redirect URI Bypass Vulnerability (CVE-2026-3872)
2 rules 1 TTP 1 CVECVE-2026-3872 is a vulnerability in Keycloak that allows an attacker controlling a path on the same web server to bypass URI redirect validation using a wildcard, potentially leading to access token theft and information disclosure.
SSH Authorized Key File Modification Inside a Container
2 rules 4 TTPsThe rule detects the creation or modification of an authorized_keys file inside a container, a technique used by adversaries to maintain persistence on a victim host by adding their own public key(s) to enable unauthorized SSH access for lateral movement or privilege escalation.
V-SFT Out-of-Bounds Read Vulnerability (CVE-2026-32929)
2 rules 1 TTP 1 CVEV-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability (CVE-2026-32929) in VS6ComFile!get_macro_mem_COM, where opening a crafted V7 file may lead to information disclosure.
V-SFT Out-of-Bounds Read Vulnerability (CVE-2026-32926)
2 rules 6 TTPs 1 CVE 2 IOCsV-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in the VS6ComFile!load_link_inf function, allowing for potential information disclosure when opening a crafted V7 file.
File Browser EPUB Preview Stored XSS Vulnerability (CVE-2026-34529)
2 rulesFile Browser versions prior to 2.62.2 are vulnerable to stored cross-site scripting (XSS) via the EPUB preview function, allowing attackers to execute arbitrary JavaScript in a user's browser by embedding malicious code in a crafted EPUB file.
Payload CMS Stored XSS Vulnerability (CVE-2026-34748)
2 rules 1 TTP 1 CVEA stored Cross-Site Scripting (XSS) vulnerability exists in Payload CMS versions prior to 3.78.0, allowing authenticated users with write access to inject malicious scripts that execute in the browsers of other users.
Payload CMS SSRF Vulnerability (CVE-2026-34746)
2 rules 1 TTP 1 CVEPayload CMS versions before 3.79.1 are vulnerable to Server-Side Request Forgery (SSRF) allowing authenticated users with upload access to trigger outbound HTTP requests to arbitrary URLs.
Open WebUI Broken Access Control Vulnerability (CVE-2026-34222)
2 rules 3 TTPs 1 CVEA broken access control vulnerability in Open WebUI versions prior to 0.8.11 (CVE-2026-34222) allows authenticated users to potentially access or modify tool values they should not be authorized to, leading to privilege escalation and unauthorized configuration changes.
Unsecured Zoom Meeting Creation
2 rules 2 TTPsThe creation of Zoom meetings without passcodes allows unauthorized access and disruption, known as Zoombombing, potentially leading to the exposure of sensitive information or reputational damage.
Corosync Integer Overflow Vulnerability (CVE-2026-35092) Leads to DoS
2 rules 2 TTPs 1 CVECVE-2026-35092 is an integer overflow vulnerability in Corosync's join message sanity validation, allowing a remote, unauthenticated attacker to send crafted UDP packets, resulting in a denial of service condition.
WebServer Access Logs Deleted
2 rules 1 TTPDetection of web server access log deletion across Windows, Linux, and macOS systems indicates potential defense evasion and destruction of forensic evidence by threat actors.
Dell AppSync 4.6.0 UNIX Symbolic Link Following Vulnerability (CVE-2026-22767)
2 rules 1 TTP 1 CVEDell AppSync version 4.6.0 is vulnerable to a UNIX Symbolic Link (Symlink) Following vulnerability (CVE-2026-22767) that allows a low-privileged local attacker to tamper with information.
HTTP/2 Implementations Vulnerability Enables Denial of Service
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in various HTTP/2 implementations to perform a denial-of-service attack.
7-Zip Vulnerability Allows File Manipulation
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in 7-Zip to manipulate files, leading to potential data integrity issues.
XenForo Path Disclosure via Open-Basedir Restrictions (CVE-2025-71282)
2 rules 1 TTP 1 CVEXenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions, allowing attackers to gain sensitive information about the server's directory structure.
MPPX TypeScript Interface Vulnerability (CVE-2026-34209)
1 rule 1 TTP 1 CVEA vulnerability exists in mppx TypeScript interface before version 0.4.11, allowing attackers to close or grief channels for free by submitting close vouchers equal to the settled amount due to incorrect validation.
Query Monitor WordPress Plugin Vulnerable to Reflected XSS (CVE-2026-4267)
2 rules 1 TTP 1 CVEThe Query Monitor WordPress plugin is vulnerable to reflected cross-site scripting (XSS) due to insufficient input sanitization and output escaping of the '$_SERVER['REQUEST_URI']' parameter, allowing unauthenticated attackers to inject arbitrary web scripts.
OpenClaw Microsoft Teams Plugin Sender Allowlist Bypass (CVE-2026-34506)
2 rules 2 TTPs 1 CVEOpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin, allowing unauthorized senders to bypass intended authorization checks due to improper handling of empty groupAllowFrom parameters, potentially leading to information disclosure.
OpenClaw Information Disclosure via Telegram Bot Token Exposure
2 rules 1 CVEOpenClaw before version 2026.3.13 exposes Telegram bot tokens in error messages due to the fetchRemoteMedia function embedding these tokens in MediaFetchError strings when media downloads fail.
baserCMS DOM-Based Cross-Site Scripting Vulnerability (CVE-2026-32734)
2 rules 1 TTP 1 CVEbaserCMS versions prior to 5.2.3 are vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation, potentially allowing a remote attacker to execute arbitrary JavaScript in a user's browser.
FreeRDP Heap-Buffer-Overflow Vulnerability (CVE-2026-33982)
2 rules 3 TTPs 1 CVEA heap-buffer-overflow read vulnerability exists in FreeRDP versions prior to 3.24.2, specifically in the winpr_aligned_offset_recalloc() function, potentially leading to denial of service or information disclosure.
Symantec DLP Windows Endpoint Elevation of Privilege Vulnerability (CVE-2026-3991)
2 rules 1 TTPCVE-2026-3991 is an elevation of privilege vulnerability in Symantec Data Loss Prevention (DLP) Windows Endpoint that could allow a local attacker to gain elevated access to resources.
Potential Abuse of msDS-ManagedAccountPrecededByLink for Privilege Escalation
2 rules 4 TTPsDetection of PowerShell scripts modifying the msDS-ManagedAccountPrecededByLink attribute, potentially indicating exploitation of the BadSuccessor privilege escalation vulnerability in Windows Server 2025.
CrowdStrike Falcon Cloud Security Advances CNAPP with Adversary-Informed Risk Prioritization
2 rules 5 TTPsCrowdStrike Falcon Cloud Security enhances its CNAPP capabilities, incorporating adversary intelligence to prioritize cloud risks based on threat actor behavior, particularly focusing on groups like LABYRINTH CHOLLIMA and SCATTERED SPIDER, to enable security teams to understand and remediate cloud exposures more effectively.
CrowdStrike Falcon Next-Gen SIEM Supports Third-Party EDR Tools
2 rules 2 TTPsCrowdStrike's Falcon Next-Gen SIEM now supports third-party EDR solutions, starting with Microsoft Defender, to extend AI-native SOC capabilities without replacing existing endpoint agents.
OpenClaw Insufficient File Permissions Vulnerability (CVE-2026-33572)
2 rules 1 TTPOpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local users to read transcript contents and extract sensitive information.
CrowdStrike CNAPP Adds Adversary-Informed Risk Prioritization
2 rules 1 TTPCrowdStrike's CNAPP enhancements prioritize cloud risks based on adversary behavior, application context, and configuration change tracking to reduce breach likelihood.
Securing AI Agents with Falcon AIDR and NVIDIA NeMo Guardrails
3 rules 4 TTPsCrowdStrike Falcon AIDR now supports NVIDIA NeMo Guardrails to protect AI agents by blocking prompt injection attacks, redacting sensitive data, defanging malicious content, and moderating unwanted topics, ensuring compliance and preventing abuse.
CrowdStrike Falcon Next-Gen SIEM Integrates with Microsoft Defender EDR
2 rules 2 TTPsCrowdStrike Falcon Next-Gen SIEM now supports third-party EDR solutions like Microsoft Defender, enabling unified detection and response across diverse environments, addressing the challenges of cross-domain attacks and fragmented security systems.
CrowdStrike CNAPP Enhanced with Adversary-Informed Risk Prioritization
2 rules 3 TTPsCrowdStrike enhances its CNAPP capabilities by incorporating adversary intelligence for improved risk prioritization, addressing limitations in infrastructure visibility, threat actor behavior analysis, and alert triage.
elecV2 elecV2P Server-Side Request Forgery Vulnerability (CVE-2026-5016)
2 rules 2 TTPsA server-side request forgery vulnerability exists in elecV2 elecV2P up to 3.8.3, affecting the eAxios function within the /mock URL handler, allowing remote attackers to manipulate the req argument and potentially conduct internal reconnaissance or other malicious activities.
CrowdStrike Falcon SIEM Integration with Microsoft Defender
2 rules 10 TTPsCrowdStrike's Falcon Next-Gen SIEM expands to support third-party EDR solutions, beginning with Microsoft Defender, to unify detection, investigation, and response without requiring the Falcon sensor and modernize security operations.
CrowdStrike Innovations Secure AI Agents and Govern Shadow AI
2 rules 2 TTPsCrowdStrike is introducing innovations to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud environments by extending AI detection and response (AIDR) capabilities to cover desktop AI applications and provide visibility into AI-related components, helping to prevent prompt attacks, data leaks, and policy violations.
CrowdStrike Falcon SIEM Integrates with Microsoft Defender EDR
2 rules 1 TTPCrowdStrike Falcon Next-Gen SIEM is expanding its capabilities to integrate with third-party EDR solutions, starting with Microsoft Defender, to enable organizations to extend their AI-native SOC across heterogeneous environments without replacing existing endpoint agents.
Securing AI Agents with CrowdStrike Falcon AIDR and NVIDIA NeMo Guardrails
2 rules 2 TTPsCrowdStrike Falcon AIDR integrates with NVIDIA NeMo Guardrails to provide comprehensive protection for AI agents against prompt injection, data leaks, and malicious content.
CrowdStrike CNAPP Enhanced with Adversary-Informed Risk Prioritization
2 rules 2 TTPsCrowdStrike has enhanced its CNAPP capabilities by adding application-layer visibility and prioritizing risks based on known adversary tactics, techniques, and procedures (TTPs).
CrowdStrike Falcon Enhancements for Securing AI Environments
2 rules 2 TTPsCrowdStrike is enhancing its Falcon platform with new features focusing on AI Detection and Response (AIDR) capabilities across endpoints, SaaS, and cloud environments to mitigate risks such as prompt injection attacks, data leaks, and policy violations related to AI agents and shadow AI.
CrowdStrike Falcon Cloud Security CNAPP with Adversary-Informed Risk Prioritization
2 rules 3 TTPsCrowdStrike Falcon Cloud Security enhances CNAPP capabilities with application-layer visibility and adversary-informed risk prioritization, enabling security teams to focus on attacker-aligned risks and known threat actors.
CrowdStrike Falcon Cloud Security Introduces Adversary-Informed Risk Prioritization
2 rules 8 TTPsCrowdStrike's Falcon Cloud Security enhances CNAPP capabilities by introducing adversary-informed risk prioritization, application layer visibility, and root cause analysis of configuration changes, enabling security teams to better understand and remediate cloud risks.
CrowdStrike Agentic MDR and SOC Transformation Services
2 rules 2 TTPsCrowdStrike introduces agentic MDR and SOC Transformation Services to enhance breach prevention through machine-speed execution and expert oversight, while SOC Transformation Services aim to modernize security operations by focusing on SIEM, data pipelines, workflows, talent models, and governance.
CrowdStrike Charlotte AI AgentWorks and Agentic SOAR for Automated Security Operations
2 rulesCrowdStrike introduces Charlotte AI AgentWorks and Agentic SOAR to enhance security operations through AI-driven automation and orchestration, reducing manual workloads and improving decision accuracy.
CrowdStrike Falcon Next-Gen SIEM Supports Third-Party EDR Tools
2 rulesCrowdStrike Falcon Next-Gen SIEM is expanding to support third-party EDR solutions, starting with Microsoft Defender, enabling organizations to extend their AI-native SOC across their ecosystem by unifying detection, investigation, and response.
CrowdStrike Charlotte AI AgentWorks for Agentic SOC Transformation
2 rules 2 TTPsCrowdStrike's Charlotte AI AgentWorks facilitates the development and deployment of AI-driven security agents within the SOC, aiming to enhance analyst capabilities through automated and orchestrated responses to threats.
CrowdStrike Charlotte AI AgentWorks and Agentic SOAR for Agentic Security Operations
2 rulesCrowdStrike's Charlotte AI AgentWorks and Agentic SOAR aim to revolutionize security operations by enabling the creation and orchestration of AI-powered agents, enhancing analyst capabilities and automating tasks to combat AI-accelerated adversaries.
CrowdStrike Agentic MDR and SOC Transformation Services
2 rules 2 TTPsCrowdStrike's Agentic MDR combines machine-speed execution with expert oversight, leveraging deterministic automation and adaptive AI agents to enhance breach prevention and SOC modernization.
CrowdStrike Flex for Services Expands Access to Incident Response Expertise
2 rules 2 TTPsCrowdStrike is expanding its Falcon Flex model to its services offering, providing flexible access to incident response, proactive security services, advisory, platform services, and training.
CrowdStrike Falcon Cloud Security CNAPP with Adversary-Informed Risk Prioritization
3 rules 2 TTPsCrowdStrike's new CNAPP capabilities in Falcon Cloud Security focus on adversary-informed risk prioritization by correlating application-layer visibility with threat actor profiles and techniques, enabling security teams to understand cloud risk, prioritize remediation, and accelerate response.
CrowdStrike Falcon Next-Gen SIEM Integrates with Microsoft Defender
2 rules 1 TTPCrowdStrike Falcon Next-Gen SIEM now supports third-party EDR solutions, beginning with Microsoft Defender, enabling organizations to extend their AI-native SOC and unify detection across heterogeneous environments.
CrowdStrike Falcon Enhancements for Securing AI Agents and Governing Shadow AI
2 rulesCrowdStrike is enhancing its Falcon platform with new AI detection and response capabilities to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud environments, addressing threats like prompt injection and data leaks.
CrowdStrike Falcon Data Security Introduction
2 rules 2 TTPsCrowdStrike's Falcon Data Security aims to protect sensitive data by providing visibility into data movement across various environments and preventing data theft.
CrowdStrike Agentic MDR and SOC Transformation Services
3 rulesCrowdStrike's agentic MDR combines automation, AI agents, and human oversight for rapid breach response, while SOC Transformation Services modernize security operations for an agentic SOC approach.
Incus Image Cache Poisoning Vulnerability
2 rules 1 TTP 3 IOCsA vulnerability exists in Incus where it does not properly verify the combined fingerprint when downloading images from simplestreams servers, allowing an attacker to perform image cache poisoning and potentially expose other tenants to running attacker-controlled images.
ManageSieve AUTHENTICATE Command Denial-of-Service Vulnerability (CVE-2025-59032)
2 rules 1 TTPCVE-2025-59032 describes a vulnerability in ManageSieve's AUTHENTICATE command, where using a literal as a SASL initial response can crash the ManageSieve service, leading to a denial-of-service condition.
EVerest EV Charging Stack Data Race Vulnerability (CVE-2026-26074)
2 rulesEVerest versions prior to 2026.02.0 exhibit a data race vulnerability (CVE-2026-26074) where concurrent network requests and physical events can corrupt the event queue, leading to potential denial of service or other undefined behavior.
GitLab Improper HTML Sanitization Vulnerability (CVE-2026-2995)
2 rules 2 TTPsCVE-2026-2995 is a vulnerability in GitLab EE versions 15.4 to 18.10.1 where an authenticated user can add email addresses to other user accounts due to improper HTML sanitization, potentially leading to account takeover or information disclosure.
GitLab GraphQL Denial of Service Vulnerability (CVE-2026-3988)
2 rules 1 TTPCVE-2026-3988 is a denial of service vulnerability in GitLab CE/EE allowing unauthenticated users to crash instances by sending malformed GraphQL requests, affecting versions 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1.
Blackhole for Bad Bots WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTPThe Blackhole for Bad Bots WordPress plugin through version 3.8 is vulnerable to stored cross-site scripting (XSS) via the User-Agent HTTP header, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the plugin's admin page.
IBM InfoSphere Information Server Plaintext Credential Storage Vulnerability
2 rules 1 TTPIBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 stores user credentials in plaintext, allowing local users to read sensitive information.
CPython Zipfile Module Vulnerability Allows File Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in the zipfile module of CPython to manipulate files on affected systems.
Red Hat OpenShift GitOps Multiple Vulnerabilities
2 rules 1 TTPAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift GitOps to manipulate data, misrepresent information, or cause a denial of service.
Mozilla Firefox and Thunderbird Graphics Text Component Vulnerability (CVE-2026-4719)
2 rules 2 TTPsCVE-2026-4719 describes an incorrect boundary condition in the Graphics: Text component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition in vulnerable versions.
WebRTC Signaling Denial-of-Service Vulnerability (CVE-2026-4704)
2 rules 1 TTPCVE-2026-4704 is a denial-of-service vulnerability in the WebRTC Signaling component affecting Firefox, Firefox ESR, and Thunderbird, potentially disrupting service availability.
Mozilla Firefox and Thunderbird WebCodecs Boundary Condition Vulnerability (CVE-2026-4695)
2 rules 1 TTPAn incorrect boundary condition in the Audio/Video Web Codecs component in Mozilla Firefox and Thunderbird (CVE-2026-4695) could lead to a denial-of-service (DoS) condition due to a vulnerability that affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Mozilla Firefox and Thunderbird Web Codecs Denial-of-Service Vulnerability (CVE-2026-4697)
2 rules 1 TTPCVE-2026-4697 is a denial-of-service vulnerability due to incorrect boundary conditions in the Audio/Video Web Codecs component of Mozilla Firefox and Thunderbird, potentially leading to application crashes.
Mozilla Firefox and Thunderbird Audio/Video Playback Denial-of-Service Vulnerability (CVE-2026-4693)
2 rules 1 TTPCVE-2026-4693 is a vulnerability due to incorrect boundary conditions in the Audio/Video: Playback component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition.
Mozilla Firefox Canvas2D Improper Boundary Condition Vulnerability (CVE-2026-4685)
2 rules 2 TTPsAn improper boundary condition vulnerability in the Canvas2D component of Mozilla Firefox, Firefox ESR, and Thunderbird (CVE-2026-4685) could allow for a denial-of-service condition.
OwnTone Server DAAP Request NULL Pointer Dereference Denial-of-Service (CVE-2026-26828)
2 rules 2 TTPsA NULL pointer dereference vulnerability in the daap_reply_playlists function of owntone-server allows attackers to cause a Denial of Service (DoS) by sending a crafted DAAP request.
Easy Chat Server 3.1 Denial of Service Vulnerability (CVE-2019-25613)
2 rules 1 TTPEasy Chat Server 3.1 is vulnerable to a denial-of-service attack where a remote attacker can crash the application by sending oversized data in the message parameter via a POST request to the body2.ghp endpoint after establishing a session, leading to service unavailability.
DNS Queries to RMM Domains from Non-Browser Processes
2 rules 74 IOCsDetection of DNS queries to known remote monitoring and management (RMM) domains originating from non-browser processes on Windows systems indicates potential abuse of legitimate software for command and control.
CrowdStrike Falcon Flex for Services Expansion
2 rules 2 TTPsCrowdStrike is expanding the Falcon Flex model to its services offering to provide organizations with more flexible access to incident response and proactive security services.
VMware Tanzu Spring Framework and Spring Security Vulnerabilities Allow Security Bypass
2 rules 1 TTPAn anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Security and VMware Tanzu Spring Framework to bypass security measures.
Znuny Cross-Site Scripting Vulnerability
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in Znuny to perform a cross-site scripting attack, potentially leading to information disclosure or session hijacking.
cURL Vulnerability Allows File Manipulation
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in cURL to manipulate files on a vulnerable system.
Apache Commons FileUpload Denial of Service Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Apache Commons FileUpload to perform a denial of service attack.
Apache Commons BeanUtils Security Bypass Vulnerability
1 rule 1 TTPAn authenticated remote attacker can exploit a vulnerability in Apache Commons BeanUtils to bypass security measures, potentially leading to unauthorized access or privilege escalation.
MIT Kerberos Security Bypass Vulnerability
2 rules 1 TTPAn anonymous, remote attacker can exploit a vulnerability in MIT Kerberos to bypass security measures.
Android-ImageMagick7 Memory Leak Vulnerability (CVE-2026-33852)
2 rules 1 TTPA missing release of memory vulnerability (CVE-2026-33852) in MolotovCherry Android-ImageMagick7 before version 7.1.2-11 can lead to a denial-of-service condition due to memory exhaustion.
Ruby on Rails Active Storage DoS Vulnerability (CVE-2026-33174)
2 rules 1 TTPA denial-of-service vulnerability (CVE-2026-33174) exists in Ruby on Rails Active Storage versions prior to 8.1.2.1, 8.0.4.1, and 7.2.3.1 due to unbounded memory allocation when handling large or unbounded Range headers in proxy delivery mode.
Citrix NetScaler ADC and Gateway Vulnerabilities
2 rulesCitrix has released a security advisory addressing multiple vulnerabilities in NetScaler ADC and NetScaler Gateway that could lead to sensitive information disclosure and user session mix-up under specific configurations.
Inner Warden Security Agent Capabilities
2 rules 1 TTPThe open-source Inner Warden project is a security agent leveraging eBPF for kernel-level monitoring and autonomous response actions like IP blocking and process termination, aiming to create a distributed security mesh.
RagaSerpent 'Tax Audit' Campaign Targeting Multiple Countries
2 rules 1 TTPThe RagaSerpent cluster, also known as SideWinder-Adjacent, is conducting targeted attacks across multiple countries between 2025 and 2026, associated with a 'Tax Audit' themed campaign.
StoatWaffle Malware Used by WaterPlum Actor
2 rules 1 TTPStoatWaffle is malware employed by the WaterPlum threat actor, used for an unknown purpose.
NetNTLM Hash Phishing via Archive Extraction (CVE-2025-59284)
2 rules 1 TTPA phishing technique, potentially still viable due to incomplete patching, allows attackers to obtain NetNTLM hashes from archive extraction on Windows systems (CVE-2025-59284).
Self-Hosted Email Threat Detection Tool
2 rulesA user created a self-hosted email threat detection tool, named VerdictMail, employing IMAP IDLE for real-time monitoring and multi-stage enrichment via SPF, DKIM, DMARC, DNSBL, WHOIS, URLhaus, and VirusTotal, coupled with an LLM for threat assessment.
Iranian Botnet Operation Exposed via Open Directory
1 rule 1 TTP 1 IOCAn Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.
Azure Service Principal Sign-In Followed by Arc Cluster Credential Access
2 rules 2 TTPsDetects a service principal authenticating to Microsoft Entra ID and then listing credentials for an Azure Arc-connected Kubernetes cluster within a short time window, indicating potential unauthorized access to Kubernetes clusters via stolen service principal secrets.
Persistnux - Linux Persistence Detection Tool
3 rules 3 TTPsPersistnux is a bash-based tool designed to identify known Linux persistence mechanisms used by attackers to maintain access to compromised systems, generating detailed reports for DFIR analysis.
HushSpec: Security Policy Specification for AI Agent Action Boundaries
2 rules 1 TTP 1 IOCHushSpec is an open specification under development to standardize security policies at the action boundary of AI agents, focusing on actions such as file access, network egress, and shell execution, aiming to create a portable and engine-agnostic policy layer.
Stealthy WMI Lateral Movement via StealthyWMIExec.py
2 rules 1 TTPThe StealthyWMIExec.py script facilitates lateral movement via WMI, potentially evading standard detection mechanisms by employing stealthy techniques.
GlassWorm Campaign Deploying Wave 3 Windows Payload
2 rules 2 TTPsThe GlassWorm campaign has been observed deploying a Wave 3 Windows payload, indicating ongoing malicious activity targeting Windows systems.
Maltrail IOC Feed Update for Multiple Threats
3 rules 6 TTPs 40 IOCsThis brief summarizes IOCs extracted from the Maltrail feed on March 15, 2026, covering domains and URLs associated with threats targeting macOS and Android platforms, including OSX_Atomic, FakeApp, Android_Joker, Lummack2, APT_Sidewinder, APT_Kimsuky, and Hak5Cloud_C2.
GlassWorm V2 Infrastructure Rotation and GitHub Injection Analysis
2 rules 2 TTPsAnalysis of GlassWorm V2 reveals infrastructure rotation and GitHub injection techniques.
KRVTZ-NET IDS Alerts Analysis: Network Scanning and Exploitation Attempts
3 rules 4 TTPsMultiple IDS alerts indicate potential network reconnaissance, vulnerability exploitation attempts targeting Fortigate VPN (CVE-2023-27997), and ColdFusion servers originating from various IP addresses on March 13, 2026.
Kubernetes Sensitive Role Creation or Modification
2 rules 2 TTPsThis rule detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs (e.g., bind, escalate, impersonate), potentially leading to privilege escalation or unauthorized access within the cluster.
Kubernetes Endpoint Permission Enumeration
2 rules 1 TTPA single user and source IP attempts to enumerate Kubernetes endpoints, issuing API requests across multiple endpoints to identify accessible resources for further exploitation.
Maltrail IOCs Report: Tracking Multiple Threat Actors
3 rules 5 TTPs 27 IOCsThis brief analyzes IOCs aggregated by Maltrail on February 27, 2026, highlighting network activity associated with diverse threat actors including APT_UNC2465, Lazarus Group, Gorat, APT_Bitter, Android_Joker, PowerShell Injector, SmokeLoader, and FakeApp campaigns targeting various sectors.
Suspicious AWS EC2 Key Pair Import Activity
2 rules 1 TTPThe import of SSH key pairs into AWS EC2, as detected by CloudTrail logs, may indicate unauthorized access attempts, persistence establishment, or privilege escalation by an attacker.
AWS SAML Provider Deletion Activity
2 rules 2 TTPsAn adversary may delete an AWS SAML provider to disrupt administrative access, hindering incident response and potentially escalating privileges within the AWS environment.
AWS S3 Unauthenticated Bucket Access by Rare Source
2 rules 4 TTPsThis rule detects AWS CloudTrail events indicative of unauthenticated sources attempting to access an S3 bucket, potentially exposing sensitive data due to misconfigured bucket policies.
Potential Web Shell ASPX File Creation
2 rules 1 TTPThe creation of ASPX files in web server directories, excluding legitimate processes, indicates potential web shell deployment for persistence on Windows systems.
Azure Entra ID MFA TOTP Brute Force Attempted
3 rules 1 TTPIdentifies brute force attempts against Azure Entra multi-factor authentication (MFA) Time-based One-Time Password (TOTP) verification codes, characterized by high-frequency failed attempts for a single user across numerous distinct sessions, potentially indicating programmatic attempts to bypass MFA.
AWS STS AssumeRoot by Rare User and Member Account
2 rules 3 TTPsThe rule detects when the STS AssumeRoot action is performed by a rare user in AWS, potentially indicating privilege escalation.
Entra ID Sign-in Brute Force Attempt Against Microsoft 365
2 rules 1 TTPA high volume of failed Microsoft Entra ID sign-in attempts against Microsoft 365 services within a short time period indicates a potential brute-force attack, which could lead to unauthorized access to Microsoft 365 services.
Windows SIP Provider Modification for Defense Evasion
1 rule 1 TTPThis brief covers the modification of Subject Interface Package (SIP) providers on Windows systems, a technique used by attackers to bypass signature validation checks and inject malicious code into critical processes, ultimately leading to defense evasion.
M365 Identity Login from Atypical Travel Location
2 rules 1 TTPThis rule detects successful Microsoft 365 portal logins from rare locations, potentially indicating an adversary attempting to access an account from an unusual location or behind a VPN.
Bitbucket Secret Scanning Rule Deleted
2 rules 1 TTPAttackers may delete secret scanning rules in Bitbucket to impair defenses and introduce secrets into the code repository undetected, potentially leading to unauthorized access or data breaches.
ROT Encoded Python Script Execution
2 rules 2 TTPsThis analytic detects the execution of Python scripts employing ROT encoding for letter substitution, a technique used by adversaries to obfuscate malicious code within legitimate Python packages on Windows and macOS systems.
Entra ID Device Code Authentication Abuse via Malicious Broker Client
2 rules 2 TTPs 4 IOCsAdversaries are abusing Entra ID device code authentication using a malicious broker client to bypass MFA and gain unauthorized access to Azure resources by compromising Primary Refresh Tokens (PRTs).
Microsoft 365 Identity Login from Impossible Travel Location
2 rules 1 TTPDetects successful Microsoft 365 portal logins from impossible travel locations, defined as logins originating from two different countries within a short time frame, potentially indicating account compromise or unauthorized access.
AWS RDS DB Snapshot Shared with Another Account
2 rules 1 TTPAn AWS RDS DB snapshot is shared with another AWS account or made public, potentially enabling unauthorized access, offline analysis, or data exfiltration by allowing adversaries to restore the snapshot in their controlled infrastructure.
VScode Remote Tunnel Abuse for Command and Control
2 rules 1 TTPAdversaries are leveraging the VScode remote tunnel feature to establish unauthorized access and control over Windows systems, potentially enabling command and control activities via disguised legitimate software.
Potential Persistence via Linux File Modification
3 rules 6 TTPsThis rule detects potential persistence attempts on Linux systems by monitoring file modifications of files commonly used for persistence, such as cron jobs, systemd services, message-of-the-day (MOTD), SSH configurations, shell configurations, runtime control, init daemon, passwd/sudoers/shadow files, Systemd udevd, and XDG/KDE autostart entries.
Suspicious Pod Creation in Kubernetes System Namespace
2 rules 1 TTPAn attacker may deploy a pod within the kube-system namespace in Kubernetes to mimic legitimate system pods and evade detection.
Powercat PowerShell Implementation Detection
2 rules 2 TTPsAdversaries may leverage Powercat, a PowerShell implementation of Netcat, to establish command and control channels or perform lateral movement within a compromised network.
Active Directory Group Modification by SYSTEM Account
2 rules 2 TTPsDetection of a user being added to an Active Directory group by the SYSTEM account (S-1-5-18) can indicate an attacker with SYSTEM privileges attempting to pivot to a domain account.
First Time AWS CloudFormation Stack Creation
2 rules 2 TTPsThis rule detects the first time a principal calls AWS CloudFormation CreateStack or CreateStackInstances API, potentially indicating malicious resource deployment by an attacker with elevated privileges.
Potential Web Shell ASPX File Creation
2 rules 1 TTPThis rule identifies the creation of ASPX files in web server directories, commonly targeted by attackers to deploy web shells for persistence, by monitoring file creation events and excluding known legitimate processes.
GitHub SSH Certificate Configuration Changed
2 rules 4 TTPsAttackers can modify SSH certificate configurations in GitHub organizations to gain unauthorized access, persist in the environment, escalate privileges, and operate stealthily.
Potential Privilege Escalation via SUID/SGID on Linux
2 rules 2 TTPsAttackers may leverage misconfigured SUID/SGID permissions on Linux systems to escalate privileges to root or establish persistence by executing processes with root privileges initiated by non-root users.
Phoenix Long-Poll Transport Denial-of-Service Vulnerability
2 rules 2 TTPs 1 CVEAn unauthenticated denial-of-service vulnerability in Phoenix's long-poll transport allows a remote client to exhaust server memory by sending a series of crafted HTTP requests, affecting LiveView apps with a public Longpoll socket or Phoenix.Socket with longpoll option.
Microsoft Management Console File Execution from Unusual Path
2 rules 5 TTPsThis rule identifies the execution of Microsoft Management Console (MMC) files from unusual paths, a technique adversaries may use to bypass security controls and execute malicious code.
Micronaut TimeConverterRegistrar Memory Exhaustion via Accept-Language Header
3 rules 2 TTPsMicronaut's `TimeConverterRegistrar` has an unbounded `formattersCache` that allows memory exhaustion via a crafted `Accept-Language` header, where an unauthenticated attacker can crash the JVM by sending requests with novel locale tags to `@Format`-annotated endpoints, growing the cache until heap memory is exhausted, affecting Micronaut applications with `micronaut-context` versions 4.3.0 and above, up to but not including 4.10.22.
Local SxS Shared Module DLL Hijacking
2 rules 2 TTPsAdversaries may abuse shared modules in local Side-by-Side (SxS) folders to execute malicious payloads by instructing the Windows module loader to load DLLs from arbitrary local paths, potentially bypassing security controls.
Kubernetes Admission Controller Modification
2 rules 2 TTPsAn adversary modifies Kubernetes admission controller configurations to achieve persistence, escalate privileges, or gain unauthorized access to credentials within the cluster.
go-zserio Unbounded Memory Allocation Vulnerability
2 rules 1 TTPgo-zserio versions prior to 0.9.1 are vulnerable to unbounded memory allocation when deserializing data, potentially leading to denial of service.
Detect AWS Route Table Modification via CloudTrail
2 rulesAn attacker may add a new route to an AWS route table, potentially redirecting network traffic for malicious purposes such as defense impairment or data exfiltration.
Bitbucket Global SSH Settings Changed
2 rules 2 TTPsAn attacker modifies Bitbucket global SSH settings to potentially enable unauthorized access and lateral movement.
M365 Identity Login from Atypical Region
2 rules 1 TTPDetects successful Microsoft 365 portal logins from a country and region the user has not previously authenticated from in a specific time window, potentially indicating unauthorized access attempts by analyzing login events and user location patterns.
Exchange Mailbox Export via PowerShell
2 rules 4 TTPsAdversaries may use the `New-MailboxExportRequest` PowerShell cmdlet to export mailboxes to PST files for sensitive data collection.
Detection of Suspicious PowerShell Arguments
2 rules 4 TTPsThis rule detects suspicious PowerShell arguments often used during malware installation, including encoded commands, file downloads, and obfuscation techniques.
MsiExec Child Process Spawning Network Connections for Defense Evasion
2 rules 1 TTPDetection of MsiExec spawning child processes that initiate network connections, potentially indicating abuse of Windows Installers for malware delivery and defense evasion.
Entra ID OAuth Device Code Grant by Unusual User
2 rules 3 TTPsAn attacker uses device code authentication in Entra ID to phish users and steal access tokens, leading to unauthorized access and potential defense evasion.
Cryptographic Admission Control Framework for Autonomous Agents
2 rules 2 TTPs 3 IOCsA security framework called ACP employs cryptographic measures, including Ed25519 identities, capability tokens, delegation chains, anti-replay mechanisms, and an immutable audit ledger, to govern autonomous agents and prevent unauthorized system state changes.
Bitbucket Audit Log Configuration Modified
2 rules 1 TTPAn attacker may modify the Bitbucket audit log configuration to impair security monitoring and evade detection.
AWS STS GetFederationToken Request for Defense Evasion and Persistence
2 rules 2 TTPsDetection of the first AWS Security Token Service (STS) GetFederationToken request by a user, which adversaries can abuse to obtain temporary credentials for persistence and to bypass IAM API call limitations by gaining console access.
AWS STS Role Chaining for Privilege Escalation and Persistence
2 rules 3 TTPsAWS STS role chaining, where one assumed role is used to assume another, can lead to privilege escalation or persistence by refreshing session tokens, triggering alerts on the first observed role assumption based on CloudTrail logs.
AWS Secrets Manager Rapid Secrets Retrieval Attempts
2 rules 1 TTPCompromised AWS credentials may be used to rapidly retrieve multiple secrets from AWS Secrets Manager in order to escalate privileges or move laterally within the environment.
Detection of Suspicious VScode Remote Tunnel Usage
2 rules 1 TTPThis brief details the detection of potential command and control activity through the suspicious use of the VScode remote tunnel feature, which allows attackers to establish unauthorized remote access to systems.
Persistence via Windows Installer (Msiexec)
3 rules 3 TTPsAdversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.
M365 Identity Login from Impossible Travel Location
2 rules 1 TTPDetects successful Microsoft 365 portal logins from impossible travel locations, defined as logins originating from two different countries within a short timeframe, potentially indicating account compromise or unauthorized access.
AWS Federated User Console Login without MFA Enforcement
2 rules 1 TTPDetection of successful AWS Management Console logins by federated users, which pose a security risk due to potential lack of enforced MFA as CloudTrail does not reliably record MFA status for federated users.
Service DACL Modification via sc.exe
2 rules 2 TTPsAdversaries modify a service's DACL (Discretionary Access Control List) via `sc.exe` to deny access to key user groups, potentially making the service unstoppable or hiding it from users and the system, in order to evade defenses and persist.
Suspicious Execution via Windows Command Debugging Utility (cdb.exe)
2 rules 2 TTPsAdversaries can abuse the Windows command line debugging utility cdb.exe, specifically when executed from non-standard paths with specific command-line arguments (-cf, -c, -pd), to execute commands or shellcode for defense evasion.
Potential WSUS Abuse for Lateral Movement via PsExec
2 rules 2 TTPsThis rule detects potential abuse of Windows Server Update Services (WSUS) for lateral movement by identifying suspicious processes, specifically PsExec, initiated by WSUS (wuauclt.exe).
AWS S3 Object Versioning Suspended
2 rules 1 TTPDetection of S3 bucket versioning suspension via PutBucketVersioning API call, potentially indicating an attempt to inhibit system recovery by making restoration of deleted or overwritten objects impossible.
AWS S3 Bucket Server Access Logging Disabled
2 rules 1 TTPAn adversary may disable server access logging for an Amazon S3 bucket in order to impair defenses by removing logs that contain evidence of malicious activity.
AWS S3 Bucket Replicated to Another Account
2 rules 2 TTPsDetection of S3 bucket replication configurations sending data to a different AWS account, potentially indicating unauthorized data exfiltration by adversaries abusing replication rules.
Alternate Data Stream Creation/Execution at Volume Root Directory
2 rules 1 TTPDetection of Alternate Data Stream (ADS) creation at a volume root directory, a technique used to hide malware and tools by exploiting how ADSs in root directories are not readily visible to standard system utilities, indicating a defense evasion attempt.
AWS RDS DB Instance or Cluster Deletion Protection Disabled
2 rules 2 TTPsAn adversary may disable deletion protection on an AWS RDS DB instance or cluster as a precursor to destructive actions, such as deleting databases containing sensitive data.
First Time Python Created a LaunchAgent or LaunchDaemon
2 rules 1 TTPDetection of the first-time a Python process creates or modifies a LaunchAgent or LaunchDaemon plist file on a given macOS host, which is indicative of persistence attempts via malicious scripts, compromised dependencies, or model file deserialization.
VMware Tanzu Spring Framework Multiple Vulnerabilities
2 rules 2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Framework to disclose information or circumvent security measures.
Unsigned DLL Loaded by DNS Service
2 rules 3 TTPsThe rule identifies the loading of unusual or unsigned DLLs by the DNS Server process, which can indicate exploitation of the ServerLevelPluginDll functionality, potentially leading to privilege escalation and remote code execution with SYSTEM privileges.
russh Keyboard-Interactive Authentication Denial-of-Service
2 rules 2 TTPsA denial-of-service vulnerability exists in the russh crate, where a malicious client can crash any russh-based server implementing keyboard-interactive authentication by sending a crafted SSH_MSG_USERAUTH_INFO_RESPONSE message with a large response count, leading to excessive memory allocation and an out-of-memory crash without requiring any credentials.
Python .pth File Creation for Persistence
2 rules 3 TTPs 2 IOCsAttackers can establish persistence on Linux systems by creating malicious .pth files in Python package directories, causing arbitrary code execution on interpreter startup.
Potential Veeam Credential Access via SQL Commands
2 rules 5 TTPsAttackers can leverage sqlcmd.exe or PowerShell commands like Invoke-Sqlcmd to access Veeam credentials stored in MSSQL databases, potentially targeting backups for destructive operations such as ransomware attacks.
First Time Python Accessed Sensitive Credential Files on macOS
2 rules 1 TTPThis alert triggers on the first instance of a Python process accessing sensitive credential files on macOS, potentially indicating post-exploitation credential theft.
AWS RDS Snapshot Deletion Detected
3 rules 2 TTPsThe deletion of AWS RDS DB snapshots or disabling backups via configuration changes can inhibit recovery, destroy forensic evidence, and prepare for destructive actions by adversaries.
AWS RDS DB Instance Made Public
2 rules 3 TTPsAn attacker with compromised AWS credentials may modify an Amazon RDS DB instance or cluster to be publicly accessible for persistence, data exfiltration, or to bypass network restrictions.
Potential Windows Session Hijacking via CcmExec
2 rules 1 TTPAdversaries may exploit Microsoft's System Center Configuration Manager by loading malicious DLLs into SCNotification.exe, a process associated with user notifications, potentially leading to Windows session hijacking.
NTDS Dump via Wbadmin
2 rules 2 TTPsAttackers with Backup Operator privileges may abuse wbadmin.exe to access the NTDS.dit file, enabling credential dumping and domain compromise.
Microsoft Management Console File Execution from Unusual Path
2 rules 4 TTPsAdversaries may use Microsoft Management Console (MMC) files from untrusted paths to bypass security controls for initial access and execution on Windows systems.
DNS Global Query Block List Modified or Disabled
2 rules 3 TTPsAttackers with DNSAdmin privileges can modify or disable the DNS Global Query Block List (GQBL) in Windows, allowing exploitation of hosts running WPAD with default settings for privilege escalation and lateral movement.
AWS RDS DB Instance or Cluster Password Modification
2 rules 3 TTPsThe modification of the master password for an AWS RDS DB instance or cluster can indicate malicious activity used for persistence, privilege escalation, or defense evasion.
First Time Python Spawned a Shell on macOS Host
2 rules 1 TTPThis rule detects the first time a Python process spawns a shell on a given macOS host using the `-c` flag, indicating potential malicious activity stemming from compromised Python environments.
Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.
AWS IAM AdministratorAccess Policy Attached to Role
2 rules 2 TTPsAn adversary with compromised AWS credentials may escalate privileges or persist in the environment by attaching the AdministratorAccess AWS managed policy to an existing IAM role.
Unauthorized Modification of Azure Conditional Access Policy
2 rules 2 TTPsAn unauthorized actor modifies an Azure Conditional Access policy, potentially leading to privilege escalation, credential access, persistence, or defense impairment.
Suspicious ScreenConnect Client Child Process Activity
2 rules 11 TTPs 2 CVEsThis rule identifies suspicious child processes spawned by ScreenConnect client processes, potentially indicating unauthorized access and command execution abusing ScreenConnect remote access software to perform malicious activities such as data exfiltration or establishing persistence.
AWS Bedrock Model Invocation Logging Deletion
2 rules 1 TTPDetection of AWS Bedrock model invocation logging configuration deletion via the DeleteModelInvocationLogging API in CloudTrail logs, potentially indicating an adversary attempting to evade detection of malicious AI model usage.
Suspicious Sensitive Key and Password Searches within Linux Containers
2 rules 4 TTPsAdversaries may search for sensitive credentials, such as SSH keys and passwords, within Linux containers using utilities like grep and find, potentially leading to unauthorized access or container escape.
Suspicious Child Processes Spawned by JetBrains TeamCity
2 rules 17 TTPs 1 CVEDetection of suspicious processes spawned by JetBrains TeamCity indicates potential exploitation of remote code execution vulnerabilities, with attackers using command interpreters and system binaries for malicious purposes.
AWS Route 53 Resolver Query Log Configuration Deleted
2 rules 1 TTPDetection of the deletion of an Amazon Route 53 Resolver Query Log Configuration, potentially stopping DNS query and response logging for associated VPCs, which can be used by adversaries to evade detection and suppress forensic evidence.
AWS EC2 EBS Snapshot Shared or Made Public
2 rules 1 TTPAn AWS Elastic Block Store (EBS) snapshot is shared with another AWS account or made public, potentially leading to data exfiltration and persistence operations.
Google Workspace Object Copied from External Drive Followed by OAuth Consent
1 rule 3 TTPsDetects a sequence of events where a user copies a Google Workspace object (spreadsheet, form, document, or script) from an external drive and subsequently grants OAuth permissions to a custom application, potentially indicating a phishing attack leveraging container-bound scripts.
Azure AD Root Certificate Authority Added for Passwordless Authentication
2 rules 4 TTPsAn attacker may add a new root certificate authority to an Azure AD tenant to support certificate-based authentication for persistence, privilege escalation, or defense evasion.
Suspicious JetBrains TeamCity Child Process Activity
2 rules 17 TTPs 1 CVEDetection of suspicious processes spawned by JetBrains TeamCity indicates potential exploitation of remote code execution vulnerabilities.
OpenSSL Vulnerability Allows Denial of Service and Information Disclosure
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in OpenSSL to perform a denial-of-service attack and disclose information.
phpseclib OID Amplification DoS Vulnerability
2 rules 1 TTPA vulnerability exists in phpseclib when loading untrusted ASN1 files, potentially leading to an OID amplification denial-of-service (DoS) in the ASN1::decodeOID() function.
AWS EC2 Instance Connect SSH Public Key Upload
2 rules 3 TTPsThis rule detects the uploading of new SSH public keys to AWS EC2 instances using the EC2 Instance Connect service, which could indicate an adversary attempting to maintain access, escalate privileges, or move laterally within the cloud environment.
Microsoft Defender Tampering via Registry Modification
3 rules 2 TTPsAdversaries may disable or tamper with Microsoft Defender features to evade detection and conceal malicious behavior by modifying specific registry keys and values.
Veeam Backup Library Loaded by Unusual Process
2 rules 3 TTPsDetects potential credential decryption operations by PowerShell or unsigned processes using the Veeam.Backup.Common.dll library, indicating potential credential access attempts to target backups as part of destructive operations.
AWS EC2 AMI Shared with Another Account for Potential Exfiltration
2 rules 1 TTPAn AWS Amazon Machine Image (AMI) being shared with another AWS account could indicate data exfiltration, as AMIs may contain sensitive data, and unauthorized sharing can lead to exposure.
Logback Denial of Service Vulnerability
2 rules 3 TTPsA remote, anonymous attacker can exploit a vulnerability in Logback to perform a denial-of-service (DoS) attack.
Insecure AWS EC2 VPC Security Group Ingress Rule Added
2 rules 2 TTPsAn AWS EC2 VPC security group ingress rule was added to allow traffic from any IP address (0.0.0.0/0 or ::/0) to common remote access ports, potentially exposing instances to unauthorized access and defense evasion.
Potential AWS S3 Bucket Ransomware Note Upload
3 rules 3 TTPsAn adversary may upload a ransomware note to an AWS S3 bucket by abusing compromised credentials or overly permissive bucket policies, potentially leading to data encryption or exfiltration.
GenAI Process Connection to Unusual Domain on macOS
2 rules 1 TTPThis rule detects GenAI tools on macOS connecting to unusual domains, potentially indicating command and control activity, data exfiltration, or malicious payload retrieval following compromise via prompt injection, malicious MCP servers, or poisoned plugins.
AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role
2 rules 2 TTPsThe rule detects the first occurrence of an unauthorized attempt by an AWS role to use `GetPasswordData` to access the administrator password of an EC2 instance, potentially indicating privilege escalation or lateral movement.
Zserio Runtime Unbounded Memory Allocation Vulnerability
2 rules 1 TTPA crafted payload can force memory allocations of up to 16 GB, leading to a denial-of-service condition in applications using the Zserio serialization framework, including those within the automotive Navigation Data Standard (NDS).
Monetr Lunch Flow SSRF Vulnerability
2 rules 1 TTP 1 IOCA server-side request forgery (SSRF) vulnerability in Monetr's Lunch Flow integration allows authenticated users on self-hosted instances to send HTTP GET requests to arbitrary URLs, potentially exposing sensitive information.
Kubernetes Event Deletion for Defense Evasion
2 rules 1 TTPAn adversary may delete Kubernetes events to evade detection and hide malicious activity within a Kubernetes environment by removing audit logs.
AWS Systems Manager SecureString Parameter Request with Decryption Flag
2 rules 1 TTPThis rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true, potentially indicating credential access.
AWS S3 Bucket Policy Modified to Share with External Account
2 rules 3 TTPsAn attacker modifies an Amazon S3 bucket policy to grant access to an external AWS account, potentially leading to unauthorized data access and exfiltration.
AWS IAM Roles Anywhere Trust Anchor Created with External CA
2 rules 2 TTPsThe creation of an AWS IAM Roles Anywhere Trust Anchor using an external Certificate Authority (CA) instead of an AWS-managed CA allows adversaries to establish persistent access by using their own CA to sign certificates for authentication.
Azure AD Certificate-Based Authentication Enabled
2 rules 1 TTPEnabling certificate-based authentication (CBA) in Azure Active Directory can be abused by attackers to establish persistence, escalate privileges, and impair defenses.
Bitbucket Global Secret Scanning Rule Deletion
2 rules 1 TTPAn adversary with administrative privileges may delete global secret scanning rules in Bitbucket to impair defenses and exfiltrate sensitive data without detection.
Potential Abuse of AWS Console GetSigninToken
2 rules 2 TTPsAdversaries may abuse the AWS GetSigninToken API to create temporary federated credentials for obfuscating compromised AWS access keys and pivoting to console sessions without MFA, potentially leading to lateral movement within the AWS environment.
Bitbucket Repository Exempted from Secret Scanning
2 rules 1 TTPAn attacker may attempt to disable or bypass secret scanning on a Bitbucket repository to avoid detection of committed secrets, potentially leading to credential compromise and subsequent unauthorized access.
AWS SSM Session Started to EC2 Instance for Lateral Movement
2 rules 1 TTPAn AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.
AWS EC2 User Data Retrieval for EC2 Instance
2 rules 2 TTPsDetection of the AWS EC2 DescribeInstanceAttribute API call to retrieve the userData attribute, potentially exposing sensitive information like credentials or configuration details.
Bitbucket User Login Failure Detection
2 rules 3 TTPsDetection of Bitbucket user login failures, potentially indicating credential access attempts, initial access attempts, or other malicious activity.
GitHub Repository Deletion Detection
2 rules 1 TTPDetection of unauthorized GitHub repository deletion within an organization, potentially leading to irreversible data loss and indicating compromise.
Autodesk Fusion Stored XSS Vulnerability via Maliciously Crafted Design Name
2 rules 2 TTPs 1 CVE 2 IOCsA stored cross-site scripting (XSS) vulnerability exists in the Autodesk Fusion desktop application, where a maliciously crafted HTML payload stored in a design name and exported to CSV can be triggered, potentially leading to local file reads or arbitrary code execution.
Algolia Admin Keys Exposed in Open Source Documentation
2 rules 2 TTPs 1 IOCA security researcher discovered 39 Algolia admin keys exposed across various open source documentation websites, potentially allowing unauthorized access and modification of search indices.
Google Workspace Application Removed from Blocklist
2 rules 2 TTPsAn adversary with Google Workspace administrative privileges may remove an application from the explicit blocklist to enable its distribution and usage, potentially indicating unauthorized activity and defense evasion.
Remote File Copy to a Hidden Share
2 rules 3 TTPsDetects remote file copy attempts to hidden network shares, indicative of lateral movement or data staging, by monitoring command-line tools like cmd.exe and powershell.exe for hidden share patterns.
Suspicious Child Processes from Communication Applications
3 rules 3 TTPsThe detection rule identifies suspicious child processes spawned from communication applications on Windows systems, potentially indicating masquerading or exploitation of vulnerabilities within these applications.
Potential Account Takeover via Mixed Logon Types
2 rules 1 TTPAtypical logon patterns, where a high-volume account (e.g., service account) exhibits successful logons using an unusual logon type with low frequency, may indicate account takeover or stolen credentials.
Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
2 rules 2 TTPsDetection of unauthorized access to Kubernetes secrets or configmaps via the Azure Arc AAD proxy service account, indicating potential abuse of stolen service principal credentials to read, exfiltrate, or modify sensitive data.
Azure Firewall Rule Collection Modification or Deletion
2 rules 2 TTPsAn attacker may modify or delete Azure Firewall rule collections (Application, NAT, and Network) to impair defenses and potentially enable malicious traffic.
AWS Console Login by User from New Region
2 rules 1 TTPAn AWS account may be compromised if a user logs into the AWS console from a geographic region they have never accessed before, potentially indicating unauthorized access or account takeover.
Suspicious Svchost.exe Spawning Cmd.exe
2 rules 2 TTPsDetects suspicious activity where svchost.exe spawns cmd.exe, potentially indicating malware masquerading or privilege escalation on Windows systems.
Potential Enumeration via Active Directory Web Service
2 rules 3 TTPsAdversaries may abuse the Active Directory Web Service (ADWS) to enumerate network resources and user accounts, by loading AD-related modules followed by a network connection to the ADWS dedicated TCP port.
WinRAR and 7-Zip Encryption Abuse for Data Exfiltration Preparation
3 rules 2 TTPsAdversaries use WinRAR or 7-Zip to create encrypted archives in preparation for data exfiltration, using command-line arguments to enable encryption functionality.
Windows Defender Disabled via Registry Modification
3 rules 3 TTPsAttackers modify Windows Defender registry settings to disable the service or set the service to manual start, evading defenses to operate undetected.
Windows Console History Clearing
2 rules 2 TTPsAdversaries may clear the command history of a compromised account to conceal the actions undertaken during an intrusion on a Windows system.
System Information Discovery Detection
2 rules 1 TTPThis detection identifies system information discovery techniques by monitoring process execution logs for commands like `wmic qfe`, `systeminfo`, and `hostname`, often used by attackers to gather system configuration details for further exploitation, potentially leading to privilege escalation, persistence, or data exfiltration.
Suspicious Windows Process Cluster from Parent Process via Machine Learning
2 rules 2 TTPsA machine learning model detected a parent process spawning a cluster of suspicious Windows processes with high malicious probability scores, potentially indicating LOLBins usage and defense evasion.
Suspicious Explorer Child Process via DCOM
3 rules 9 TTPsA suspicious Windows Explorer child process is detected, indicating potential exploitation of explorer.exe to launch malicious scripts or executables from a trusted parent process via DCOM.
Suspicious AWS ECR Container Upload by Unknown User
2 rules 1 TTPThis alert detects a container image upload to an AWS Elastic Container Registry (ECR) repository by a user that is not typically associated with such actions, potentially indicating account compromise or insider threat activity.
Service Reconnaissance via WMIC.exe
2 rules 1 TTPAdversaries use WMIC.exe to enumerate running services on remote devices, potentially identifying valuable targets or misconfigured systems.
Remote Management Software Launch After MSI Install
3 rulesAttackers are leveraging MSI installers to deploy remote management software (RMM) such as ScreenConnect, Syncro, and VNC, potentially indicating unauthorized access and control over compromised systems.
Keitaro Tracker Abused in AI-Driven Investment Scams
2 rules 2 TTPs 1 IOCThe Keitaro Tracker advertising platform is being exploited by malicious actors to facilitate AI-driven investment scams.
Fortigate SSL VPN Login Followed by SIEM Alert
2 rulesDetection of initial access via Fortigate SSL VPN login, followed by a SIEM alert, indicating potential malicious activity post-VPN access.
Expired or Revoked Driver Loaded
2 rules 3 TTPsAn expired or revoked driver being loaded on a Windows system may indicate an attempt to gain code execution in kernel mode or abuse revoked certificates for malicious purposes, potentially leading to privilege escalation or defense evasion.
DiceBear SVG Size Capping Bypass Leads to Denial of Service
2 rules 1 TTPA denial-of-service vulnerability exists in DiceBear versions prior to 9.4.2 due to a bypassable regex in the `ensureSize()` function, allowing attackers to craft SVGs that cause out-of-memory crashes during rendering on Node.js.
Detection of Unauthorized GitHub Actions Runner Registration
3 rules 3 TTPsThe configuration of a GitHub Actions self-hosted runner using the Runner.Listener binary can indicate malicious activity aimed at establishing remote code execution via malicious GitHub workflows.
Cisco IOS and IOS XE HTTP Server Denial-of-Service Vulnerability (CVE-2026-20125)
3 rules 1 TTPCVE-2026-20125 allows an authenticated, remote attacker to cause a denial of service by sending malformed HTTP requests to a Cisco IOS or IOS XE device, triggering a device reload.
AWS CreateLoginProfile Activity Detection
2 rules 2 TTPsDetects the creation of AWS IAM login profiles, which can be indicative of new user creation or modifications by potentially malicious actors for privilege escalation or persistence.
Apple's App Translocation Security Mechanism
2 rules 2 CVEsApple's App Translocation in macOS v10.12 mitigates Gatekeeper bypasses (CVE-2015-3715, CVE-2015-7024) by creating a read-only DMG, impacting applications accessing external resources.
AdFind.exe Execution with Reconnaissance Arguments
2 rules 1 TTP 1 IOCThis rule detects the execution of AdFind.exe with specific command-line arguments used for reconnaissance, often associated with threat actors like Wizard Spider, FIN6, and groups linked to SUNBURST, who use it to enumerate domain controllers.
Office Test Registry Persistence for Malicious DLL Execution
2 rules 2 TTPsAttackers can modify the Microsoft Office 'Office Test' Registry key to establish persistence by loading a malicious DLL that executes every time an MS Office application starts.
Node.js Spawning Curl or Wget for Command and Control
2 rules 2 TTPsDetection of Node.js directly or via a shell spawning curl or wget, potentially indicating command and control behavior where adversaries download tools or payloads onto the system.
Encoded Executable Stored in the Registry
2 rules 3 TTPs 1 IOCThis rule detects registry modifications used to hide encoded portable executables, indicating a defense evasion technique where adversaries avoid storing malicious content directly on disk by writing encoded executables to the Windows Registry.
Azure AD Authentication from Unexpected Geo-locations
2 rules 1 TTPDetection of successful authentications originating from geographic locations outside of an organization's expected operational footprint, potentially indicating compromised credentials or unauthorized access.
free5GC PCF Nil Pointer Dereference Vulnerability
2 rules 1 TTP 2 IOCsA nil-pointer dereference vulnerability exists in free5GC's PCF when handling POST requests to `/npcf-smpolicycontrol/v1/sm-policies`. When a downstream UDR lookup returns a 404 error, the handler continues execution instead of returning, leading to a nil response struct dereference and a panic. This results in an HTTP 500 error for the request, but the PCF process continues running. The vulnerability is triggered by sending a POST request with input that causes the downstream UDR lookup to fail, such as an unknown DNN. This issue affects free5GC versions v4.1.0 and v4.2.1.
Zoom Meetings Created Without Passcodes
2 rules 2 TTPsDetection of Zoom meetings created without a passcode, which are susceptible to Zoombombing and potential disruption or exposure of sensitive information.
Web Server Local File Inclusion Activity Detected
3 rules 4 TTPsDetection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.
VaultCmd Usage for Listing Windows Credentials
2 rules 2 TTPsAdversaries may use vaultcmd.exe to list credentials stored in the Windows Credential Manager to gain unauthorized access to saved usernames and passwords, potentially in preparation for lateral movement.
Suspicious Registry Modifications by Scripting Engines
2 rules 3 TTPsThe use of scripting engines like WScript and CScript to modify the Windows registry can indicate an attempt to bypass standard tools and evade defenses, potentially for persistence or other malicious activities.
Scheduled Task Created or Deleted via Command Line
2 rules 2 TTPsDetection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.
Program Files Directory Masquerading
2 rules 1 TTPAdversaries may masquerade malicious executables within directories mimicking the legitimate Windows Program Files directory to evade defenses and execute untrusted code.
Prismatic WordPress Plugin Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Prismatic plugin for WordPress versions 3.7.3 and earlier is vulnerable to stored cross-site scripting (XSS) via the 'prismatic_encoded' pseudo-shortcode, allowing unauthenticated attackers to inject arbitrary web scripts into pages.
Potential LSASS Memory Dump Activity
2 rules 1 TTPThis brief covers the potential for credential access via LSASS memory dumping, a technique used to steal credentials from memory, though specific details are absent from the provided source.
Potential Evasion via Filter Manager
2 rules 1 TTPAdversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, evading defenses like EDR and antivirus.
Okta Policy Rule Modification or Deletion
2 rules 1 TTPAn Okta policy rule was modified or deleted, potentially weakening security controls.
Okta Initial Access via Proxy
2 rules 1 TTPDetection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.
Newly Observed Fortigate Alert
2 rules 7 TTPsThis brief covers a newly observed Fortigate alert rule added to the Elastic detection rules repository, potentially indicating emerging threat activity targeting Fortigate devices.
Kubernetes Cluster Enumeration via Audit Logs
3 rules 2 TTPsAttackers attempt to enumerate and discover sensitive information within a Kubernetes cluster by leveraging common shells, utilities, and specialized tools, as reflected in audit logs.
GCP Storage Bucket Deletion for Impact
2 rules 1 TTPAn adversary may delete a Google Cloud Platform (GCP) storage bucket to disrupt business operations, detected via GCP audit logs.
Enhancing Detection Capabilities Through PowerShell Script Logging
2 rules 6 TTPsThis brief highlights the importance of PowerShell and script logging to improve threat detection capabilities within an organization's environment, focusing on increased visibility into malicious activities.
Discussion of EDR Killers on Reddit
2 rules 2 TTPsA Reddit post on r/blueteamsec references an ESET WeLiveSecurity article discussing EDR killer techniques that extend beyond driver manipulation.
AWS SAML Identity Provider Modification
2 rules 1 TTPAn adversary may attempt to modify the AWS SAML Identity Provider configuration to potentially escalate privileges or disrupt federated access.
AWS KMS Key User Performing S3 Encryption
2 rules 1 TTPDetection of AWS users employing KMS keys for S3 encryption, potentially indicating suspicious data handling within cloud environments.
AWS IAM Group Deletion Failure
2 rules 1 TTPDetection of a failed attempt to delete an AWS IAM group, which could indicate an attempt to remove audit trails or disrupt security policies.
AWS Console Login by User from New City
2 rules 1 TTPDetection of AWS console logins by a user from a previously unseen city, potentially indicating compromised credentials or account takeover.
Admidio SAML Assertion Consumer Service (ACS) URL Validation Bypass
2 rules 2 TTPs 2 IOCsAdmidio's SAML IdP implementation in its SSO module is vulnerable to sending SAML responses to unvalidated Assertion Consumer Service URLs, allowing an attacker to craft a SAML AuthnRequest with an arbitrary AssertionConsumerServiceURL, causing the IdP to send the signed SAML response, containing user identity attributes, to an attacker-controlled URL, enabling impersonation of the victim user on the legitimate SP by replaying the SAML assertion.
Local Account TokenFilter Policy Modification for Defense Evasion
2 rules 3 TTPsModification of the LocalAccountTokenFilterPolicy registry key to enable high-integrity tokens for local administrator accounts is detected, potentially allowing attackers to bypass User Account Control (UAC) and facilitate lateral movement.
AWS IAM AdministratorAccess Policy Attached to User
2 rules 2 TTPsAn adversary with compromised AWS credentials may attempt to escalate privileges or persist access by attaching the AdministratorAccess AWS managed policy to an existing IAM user via the AttachUserPolicy API, granting full access to all AWS services and resources.
Windows Registry Classes Autorun Keys Modification for Persistence
3 rules 1 TTPAdversaries modify Windows Registry Classes keys to establish persistence by executing malicious code when specific file types are opened or actions are performed, potentially leading to privilege escalation and persistent access.
Remote File Download via Script Interpreter
2 rules 3 TTPsAttackers are using Windows script interpreters (cscript.exe or wscript.exe) to download executable files from remote locations to deliver second-stage payloads or download tools.
Kerberos Pre-authentication Disabled for User Account
3 rules 4 TTPsDetection of Kerberos pre-authentication being disabled for a user account, potentially leading to AS-REP roasting and offline password cracking by attackers with GenericWrite or GenericAll rights over the account.
CircleCI Security Step Disabled Detection
2 rules 1 TTPDetection of disabling security steps in CircleCI, potentially indicating an attempt to bypass security controls during the CI/CD process.
Detection of Obfuscated IP Address Usage in Download Commands
2 rules 2 TTPsThis brief details the use of obfuscated IP addresses within download commands, often employed to evade detection by hiding the true destination of malicious downloads.
Suspicious Zoom Child Process Activity
2 rules 5 TTPsThe spawning of command interpreters (cmd.exe, powershell.exe, pwsh.exe) as child processes of Zoom.exe is indicative of potential exploitation or malicious masquerading, allowing attackers to execute arbitrary commands within the context of the Zoom application.
M365 Copilot Impersonation Jailbreak Attempt Detection
2 rules 1 TTPThis detection identifies M365 Copilot impersonation and roleplay jailbreak attempts by analyzing exported eDiscovery prompt logs, searching for users manipulating the AI into adopting alternate personas or bypassing safety controls via roleplay keywords, categorizing specific impersonation types to identify persona injection attacks.
Mozilla Firefox and Thunderbird GMP Component Denial-of-Service Vulnerability (CVE-2026-4709)
2 rules 1 TTPA vulnerability exists in the Audio/Video: GMP component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions, potentially leading to a denial-of-service condition.
Kyverno Controller Denial of Service via forEach Mutation Panic
2 rules 2 TTPsAn unchecked type assertion in Kyverno versions v1.13.0 to v1.17.1 allows a user with permission to create a Policy or ClusterPolicy to crash the cluster-wide background controller into a persistent CrashLoopBackOff, leading to a denial of service, by crafting a malicious policy that triggers a nil pointer dereference in the forEach mutation handler.
CI4MS Improper Sanitization of User Input Leading to XSS
2 rules 1 TTP 1 CVECI4MS versions prior to 0.31.2.0 are vulnerable to stored cross-site scripting due to improper sanitization of user-controlled input within the System Settings – Company Information, allowing attackers to inject arbitrary JavaScript into public-facing pages.
Application Compatibility Shim Database Installation for Persistence
2 rules 1 TTPAttackers abuse Application Compatibility Shims to establish persistence by installing custom shim databases, allowing for stealthy code execution within legitimate Windows processes.
Active Directory msPKIAccountCredentials Modification
2 rules 2 TTPsAttackers can modify the msPKIAccountCredentials attribute in Active Directory user objects to abuse credential roaming, potentially overwriting files for privilege escalation, by injecting malicious credential objects.
Kaspersky Anti-Virus Reverse Engineering for Document Detection
2 rules 1 TTPA blog post details the reverse engineering of the Kaspersky anti-virus engine on macOS to demonstrate the potential for crafting signatures capable of detecting and flagging classified documents, leveraging the product's scanning capabilities and dynamic signature updates, without implying any malicious activity by Kaspersky.
XSL Script Execution via COM Interface in Microsoft Office
2 rules 5 TTPsAdversaries may exploit Microsoft Office applications to execute malicious JScript or VBScript by leveraging the Microsoft.XMLDOM COM interface to process and transform XML documents using XSL scripts, potentially leading to initial access or defense evasion.
System Language Discovery via Reg.Exe
2 rules 1 TTPAdversaries use reg.exe to query system language settings in order to determine the geographic location of victims, customize payloads, or evade detection by avoiding certain locales.
Okta Network Zone Deactivation or Deletion
2 rules 1 TTPAn Okta network zone was deactivated or deleted, potentially indicating malicious activity aimed at bypassing security controls.
Mozilla Firefox and Thunderbird Information Disclosure Vulnerability (CVE-2026-4712)
2 rules 1 TTPCVE-2026-4712 is an information disclosure vulnerability in the Widget: Cocoa component affecting Firefox versions less than 149, Firefox ESR versions less than 140.9, Thunderbird versions less than 149, and Thunderbird versions less than 140.9, potentially allowing a remote attacker to access sensitive information.
macOS Mojave Sandbox Distributed Notification Bypass
2 rules 1 TTPA vulnerability in macOS Mojave allows sandboxed applications to bypass sandbox restrictions and surreptitiously monitor user activities by registering for distributed notifications by name, circumventing intended privacy protections.
Simple Social Media Share Buttons CSRF Vulnerability (CVE-2026-34904)
2 rules 1 TTP 1 CVEA cross-site request forgery (CSRF) vulnerability exists in the Simple Social Media Share Buttons WordPress plugin (versions through 6.2.0), potentially allowing attackers to perform unauthorized actions on behalf of authenticated users.
Potential NetNTLMv1 Downgrade Attack via Registry Modification
2 rules 2 TTPsAttackers modify the Windows registry to weaken NTLM authentication, forcing a downgrade to the less secure NTLMv1 protocol, potentially leading to credential compromise.
WP Statistics Plugin Stored XSS Vulnerability (CVE-2026-5231)
2 rules 1 TTP 1 CVEThe WP Statistics WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'utm_source' parameter, allowing unauthenticated attackers to inject arbitrary web scripts into admin pages.
Windows Scheduled Tasks AT Command Enabled via Registry Modification
2 rules 2 TTPsAttackers may enable the deprecated Windows scheduled tasks AT command via registry modification to achieve local persistence or lateral movement on a compromised system.
LSASS Credential Dumping via Windows Error Reporting (WER) Abuse
2 rules 2 TTPsAttackers can enable full user-mode dumps system-wide via registry modification to facilitate LSASS credential dumping, allowing extraction of credentials from process memory without deploying malware.
Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)
2 rules 1 TTPLangflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.
GCP Logging Sink Deletion for Defense Evasion
2 rules 1 TTPDetection of Google Cloud Platform (GCP) Logging sink deletion, a technique used by adversaries to impair defenses and evade detection by preventing log entries from being exported to designated destinations.
Unusual Network Connection via RunDLL32
2 rules 2 TTPsThe rule detects unusual outbound network connections made by rundll32.exe, specifically when executed with minimal arguments, which may indicate command and control activity or defense evasion tactics on Windows systems.
Persistence via BITS Job Notify Cmdline
2 rules 1 TTPAdversaries can achieve persistence by abusing the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute a program after a job finishes, leading to arbitrary code execution and system compromise.
Google Workspace Suspicious Login Activity
3 rules 1 TTPDetect Google Workspace login activity that Google has classified as suspicious, potentially indicating initial access, privilege escalation, defense evasion, or persistence attempts.
Network-Level Authentication (NLA) Disabled via Registry Modification
2 rules 3 TTPsDetection of attempts to disable Network-Level Authentication (NLA) by modifying the registry on Windows systems, potentially enabling persistence methods and unauthorized access.
Okta Password Spray Attempt Detection
2 rules 1 TTPDetection of Okta password spraying attempts by identifying multiple failed login attempts from different source IPs targeting the same user account.
Okta Identity Provider Creation Detected
3 rules 2 TTPsAn adversary may create a rogue identity provider within Okta to establish persistence and potentially escalate privileges by impersonating legitimate users or bypassing multi-factor authentication.
Cloud Compute Instance Created with Previously Unseen Image
2 rules 1 TTPA cloud compute instance was created with a previously unseen image, potentially indicating malicious activity such as unauthorized deployment or image compromise.
NTDS Dump via Wbadmin Execution
2 rules 3 TTPsAdversaries with Backup Operator privileges can abuse the legitimate Windows utility `wbadmin.exe` to dump the NTDS.dit file, enabling credential access and domain compromise.
Windows Script Execution from Archive File
2 rules 3 TTPsThis rule identifies attempts to execute Jscript/Vbscript files from an archive file, a common delivery method for malicious scripts on Windows systems.
Unusual Process Performing NewCredentials Logon
2 rules 1 TTPAnomalous NewCredentials logon events triggered by uncommon processes may indicate access token manipulation for privilege escalation.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
2 rules 1 TTP 1 CVEA cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) could allow attackers to execute arbitrary JavaScript within a user's session, potentially leading to unauthorized access to sensitive information.
Suspicious File Creation via OpenEDR ITSMService
3 rules 4 TTPsOpenEDR's ITSMService process, used for remote management, is being abused to create suspicious files on compromised systems, potentially leading to unauthorized file uploads, data staging, or malicious file deployment.
Rare SMB Connection to the Internet
2 rules 2 TTPsThis rule detects rare network connections via the SMB protocol to external networks, where SMB is commonly abused to exfiltrate data or leak NTLM credentials via UNC path injection.
Potential Privilege Escalation via SUID/SGID Abuse on Linux
2 rules 3 TTPsThis rule detects potential privilege escalation attempts on Linux systems by identifying processes running with root privileges but initiated by non-root users, indicative of SUID/SGID abuse.
Potential Account Takeover via Logon from New Source IP
2 rules 1 TTPAtypical login activity where a user account, normally logging in from a high-volume, single source IP, suddenly authenticates from a different IP address, potentially indicating account takeover or stolen credentials.
OpenEDR ssh-shellhost.exe Spawning Command Shell or PowerShell with PTY
2 rules 3 TTPsOpenEDR's ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY capabilities may indicate remote command execution and potential abuse of OpenEDR's remote management features by threat actors for lateral movement or command-and-control.
Nimiq Node Panic due to Invalid BLS Key
2 rules 3 TTPsAn unauthenticated peer can crash a Nimiq node by sending a malformed election macro block containing an invalid BLS voting key, leading to a denial of service.
First Time Seen Remote Monitoring and Management Tool Execution
3 rulesDetects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.
Executable File Creation with Multiple Extensions
2 rules 2 TTPsDetection of executable files created with multiple extensions, a masquerading technique to evade defenses.
EntraFalcon Security Posture Assessment Tool
2 rules 3 TTPs 2 IOCsEntraFalcon is a security tool designed to enumerate and assess the security posture of Entra ID tenants, identifying misconfigurations and vulnerabilities related to users, groups, applications, roles, PIM settings, and Conditional Access policies.
Azure Compute VM Command Execution Detected
2 rules 1 TTPSuccessful execution of commands on Azure Virtual Machines, specifically the MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMAND/ACTION operation, may indicate unauthorized activity or lateral movement attempts.
Apache Tomcat Security Bypass Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit an unspecified vulnerability in Apache Tomcat to bypass security measures, potentially leading to unauthorized access or modification of data.
UAC Bypass via Windows Firewall MMC Snap-In Hijack
2 rules 2 TTPsAttackers bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in to execute code with elevated permissions, potentially leading to system compromise.
Process Execution from Unusual Windows Directories
1 rule 1 TTPAdversaries may execute processes from unusual Windows directories to masquerade malware as legitimate software and evade defenses.
Suspicious Microsoft Outlook Child Processes
2 rules 10 TTPsDetects suspicious child processes spawned by Microsoft Outlook, commonly associated with spear phishing attacks and the execution of malicious payloads.
Spoofing AD FS Signing Logs via Azure AD Hybrid Health Service
2 rules 1 TTPA threat actor can create a new, rogue AD Health ADFS service within Azure and then create a fake server instance, which can be leveraged to spoof AD FS signing logs without compromising on-prem AD FS servers.
Okta Security Threat Detected
2 rules 1 TTPThis alert detects when Okta's ThreatInsight identifies a security threat within an Okta environment, potentially indicating command and control activity.
Okta Admin Role Assignment Creation
2 rules 1 TTPDetection of new admin role assignments in Okta, potentially indicating privilege escalation or persistence attempts by malicious actors.
Local Account TokenFilter Policy Modification
2 rules 4 TTPsAn adversary modifies the LocalAccountTokenFilterPolicy registry key to weaken security controls and enable privilege escalation, allowing them to bypass User Account Control (UAC) and gain elevated privileges remotely.
Ech0 OAuth Redirect URI Validation Bypass Vulnerability
2 rules 1 TTPEch0's OAuth redirect URI validation ignores the path component, allowing attackers to craft malicious redirect URIs for exchange-code theft and potential account takeover.
Detection of Persistent Scripts in the Startup Directory
2 rules 2 TTPsThis rule identifies script engines creating files in the Startup folder, or the creation of script files in the Startup folder, enabling adversaries to maintain persistence by placing malicious scripts or shortcuts in the Windows Startup folder, which are then executed during account logon.
Curl or Wget Execution from Container Context
2 rules 2 TTPsThis rule detects the execution of curl or wget from within runc-backed containers on Linux systems monitored by Auditd Manager, indicating potential ingress tool transfer or data exfiltration by attackers who have compromised the container.
Azure Blob Storage Permissions Modified for Defense Evasion
2 rules 1 TTPAn adversary may modify Azure Blob Storage permissions to weaken security controls, leading to potential data exposure or loss; this rule detects such modifications by monitoring Azure activity logs for specific operations related to permission changes on blobs.
Azure Authentication Method Change Detection
2 rules 3 TTPsAn attacker may add an authentication method to a compromised Azure account for persistent access, which can be detected by monitoring changes to authentication methods in Azure audit logs.
AWS CloudTrail Logging Disabled or Modified
3 rules 1 TTPDetection of AWS CloudTrail being disabled, deleted, or updated by an adversary to impair defenses and evade detection.
AWS IAM User Creates Access Keys For Another User
2 rules 2 TTPsAn adversary with access to compromised AWS credentials may attempt to persist or escalate privileges by creating a new set of access keys for an existing IAM user, potentially leading to unauthorized access to resources and data.
AWS KMS Key Policy Updated via PutKeyPolicy
2 rules 2 TTPsDetection of successful PutKeyPolicy calls on AWS KMS keys to identify potential privilege escalation or unauthorized access by adversaries modifying key policies to decrypt or exfiltrate data.
CVE-2026-34293: Unspecified Vulnerability in Microsoft Product
2 rules 1 CVECVE-2026-34293 is an unspecified vulnerability affecting a Microsoft product, for which details are currently unavailable, posing a potential risk to affected systems.
Suspicious WMIC XSL Script Execution
2 rules 3 TTPsThis rule detects suspicious execution of scripts via WMIC, potentially used for allowlist bypass, by identifying WMIC executions with atypical arguments and the loading of specific libraries like jscript.dll or vbscript.dll for defense evasion and execution.
ProblemChild ML Detection of Suspicious Windows Processes
2 rules 2 TTPsThe ProblemChild machine learning model has detected a user with suspicious Windows processes exhibiting unusually high malicious probability scores, potentially indicating defense evasion via masquerading or LOLbins.
Potential Ransomware Behavior - Note Files Dropped via SMB
2 rules 4 TTPsThis rule detects potential ransomware behavior by identifying the creation of multiple files with the same name over SMB by the SYSTEM account, potentially indicating remote execution of ransomware dropping note files.
Detection of User-Reported Phishing or Malware in Office 365
2 rules 1 TTPThis detection identifies potentially malicious emails reported by users within an Office 365 environment through Security & Compliance policies, indicating possible phishing or malware attacks targeting the organization.
CVE-2026-31613 SMB Client Out-of-Bounds Read Vulnerability
2 rules 1 TTP 1 CVECVE-2026-31613 is an out-of-bounds read vulnerability in the SMB client when parsing symlink error responses, requiring patching to prevent potential information disclosure or denial-of-service.
Detection of Sensitive LDAP Attribute Access
2 rules 5 TTPsThis rule detects unauthorized access to sensitive Active Directory object attributes such as unixUserPassword, ms-PKI-AccountCredentials, and msPKI-CredentialRoamingTokens, potentially leading to credential theft and privilege escalation.
Okta End-User Reports Suspicious Account Activity
2 rules 1 TTPAn Okta end-user reports potentially suspicious activity on their account, indicating possible compromise or unauthorized access.
Entra ID Unusual ROPC Login Attempt
2 rules 2 TTPsDetects unusual resource owner password credential (ROPC) login attempts by a user principal in Microsoft Entra ID, potentially indicating account compromise or password spraying.
Detect Suspicious Windows Service Installation
2 rules 1 TTPThis detection identifies the creation of new Windows services with suspicious command values, often used for privilege escalation and persistence by malicious actors.
Azure VNet Full Network Packet Capture Enabled
3 rules 2 TTPsDetection of Azure Network Watcher's Packet Capture feature being enabled, potentially indicating malicious network sniffing for credential access and discovery of sensitive data in unencrypted traffic.
GCP Logging Bucket Deletion for Defense Evasion
2 rules 1 TTPDetection of a Google Cloud Platform (GCP) logging bucket deletion, which can be used by adversaries to impair defenses and evade detection by removing or modifying cloud logs.
Windows Sandbox Abuse with Sensitive Configuration
3 rules 1 TTPThis rule detects the abuse of Windows Sandbox with sensitive configurations to evade detection, where malware may abuse the sandbox feature to gain write access to the host file system, enable network connections, and automatically execute commands via logon, identifying the start of a new container with these sensitive configurations.
PhpSpreadsheet XML Reader Denial of Service via Unbounded Row Index
2 rules 1 TTPPhpSpreadsheet is vulnerable to a denial-of-service attack by crafting a SpreadsheetML XML file with an excessively large row index, which exhausts server CPU resources due to unbounded iteration.
Unsigned DLL Loaded by Svchost for Persistence and Privilege Escalation
2 rules 4 TTPs 5 IOCsAdversaries may load unsigned DLLs into svchost.exe to establish persistence or escalate privileges, leveraging a shared Windows service to execute malicious code with elevated permissions.
Azure Kubernetes Events Deleted
2 rules 1 TTPAdversaries may delete events in Azure Kubernetes to evade detection, which this rule detects via the MICROSOFT.KUBERNETES/CONNECTEDCLUSTERS/EVENTS.K8S.IO/EVENTS/DELETE operation.
AWS EBS Encryption Disabled
2 rules 2 TTPsDetects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region, potentially leading to data exposure and weakening data protection against exfiltration or ransomware.
Suspicious Process Execution via Renamed PsExec Executable
2 rules 3 TTPsThe rule identifies suspicious PsExec activity where the psexec service is executed from a renamed executable, possibly to evade detection and enable lateral movement.
AWS ECR Container Upload Outside Business Hours
2 rules 1 TTPThis analytic detects the upload of a new container image to AWS Elastic Container Registry (ECR) outside of standard business hours, indicating potential unauthorized activity and leveraging AWS CloudTrail logs to identify `PutImage` events during non-business hours.
Web Server Potential Remote File Inclusion Activity
2 rules 2 TTPsThis rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths, potentially leading to information disclosure or further compromise.
Windows Subsystem for Linux Distribution Installation via Registry Modification
2 rules 3 TTPsDetects the installation of a new Windows Subsystem for Linux (WSL) distribution through registry modifications, which can be leveraged by attackers to evade security measures and execute malicious activities on Windows systems.
Netsh Used to Enable Remote Desktop Protocol (RDP) in Windows Firewall
2 rules 2 TTPsAdversaries use the `netsh.exe` utility to enable inbound Remote Desktop Protocol (RDP) connections through the Windows Firewall, potentially for unauthorized remote access and lateral movement.
ESXi System Information Discovery via ESXCLI
2 rules 1 TTPAdversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.
Azure Storage Account Deletion Detection
2 rules 2 TTPsThis brief detects the deletion of Azure Storage Accounts which can indicate malicious activity like data destruction, denial of service, or covering tracks after data exfiltration by adversaries.
macOS Mojave Beta Webcam and Microphone Access Bypass
2 rules 1 TTPmacOS Mojave beta's new privacy controls can be bypassed by exploiting the entitlements of trusted applications like QuickTime Player via AppleScript to access the webcam and microphone without user consent.
Twisted DNS Server Denial of Service via Crafted Compression Pointers
2 rules 1 TTPA denial-of-service vulnerability exists in the twisted.names module, where an unauthenticated attacker can send a crafted TCP DNS packet with deeply chained compression pointers, causing the Twisted reactor to hang while processing recursive lookups and effectively freezing the server.
Microsoft Graph API Email Access by Unusual Client and User
2 rules 1 TTPDetects anomalous access to email resources via Microsoft Graph API, potentially indicating a compromised OAuth refresh token or Primary Refresh Token (PRT) being used by an attacker.
GoBGP Remote Denial of Service via Malformed BGP Update Message
2 rules 1 TTPGoBGP version 4.4.0 is vulnerable to a remote denial-of-service attack where a malformed BGP UPDATE message triggers a nil pointer dereference, crashing the GoBGP process.
Entra ID Service Principal Federated Credential Authentication by Unusual Client
2 rules 3 TTPsDetection of initial Entra ID service principal authentication using a federated identity credential, potentially indicating a rogue identity provider abusing compromised applications.
Entra ID OAuth PRT Issuance to Non-Managed Device Detected
2 rules 4 TTPsDetection of Entra ID OAuth Primary Refresh Token (PRT) issuance to a non-managed device following a refresh token sign-in via Microsoft Authentication Broker (MAB), potentially indicating device registration abuse (ROADtx) for persistent access.
BloodHound Suite User-Agent Detected in Entra ID Sign-ins
3 rules 6 TTPsDetection of BloodHound tools like AzureHound and SharpHound being used to enumerate Microsoft Entra ID and Microsoft 365 environments, potentially indicating reconnaissance activity by red teams or malicious actors.
M365 Copilot Impersonation Jailbreak Attack
3 rulesThis detection identifies attempts to jailbreak M365 Copilot by impersonating roles, adopting unrestricted personas, or mimicking malicious AI systems to bypass safety controls, searching exported eDiscovery prompt logs for roleplay keywords and categorizing prompts into impersonation types to detect persona injection attacks.
CustomLoadImage .NET Assembly Loading Technique
2 rules 1 TTP 1 IOCCustomLoadImage enables stealthy reflective loading of .NET assemblies by directly calling AssemblyNative::LoadFromBuffer, bypassing hooks on RuntimeAssembly.nLoadImage for defense evasion.
Unusual Azure Storage Account Key Access by Privileged User
2 rules 2 TTPsDetects unusual access to Azure Storage Account keys by users with Owner, Contributor, Storage Account Contributor, or User Access Administrator roles, potentially indicating compromised identities as seen in STORM-0501 ransomware campaigns.
Windows Persistence via Scheduled Job Creation
2 rules 1 TTPAdversaries can abuse the Windows Task Scheduler to establish persistence by creating malicious scheduled jobs, which are detected by monitoring for the creation of '.job' files in the 'Windows\Tasks' directory while excluding known legitimate software.
Unauthorized Removal of Azure Conditional Access Policy
2 rules 3 TTPsAn unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.
Successful AWS Console Login Without MFA
2 rules 1 TTPSuccessful AWS console logins without multi-factor authentication can indicate compromised credentials, misconfigured security settings, or unauthorized access attempts.
Multiple Remote Management Tool Vendors on Same Host
3 rulesThe presence of multiple remote monitoring and management (RMM) tools from different vendors on a single Windows host within a short time frame may indicate compromise, shadow IT, or attacker staging for redundant access.
GCP Virtual Private Cloud Route Deletion for Defense Evasion
2 rules 2 TTPsAn adversary may delete a Virtual Private Cloud (VPC) route in Google Cloud Platform (GCP) to disrupt network traffic flow and evade defenses.
Execution of Downloaded Windows Script
2 rules 5 TTPsThis rule identifies the creation and execution of a Windows script downloaded from the internet, which adversaries may leverage for initial access and execution by exploiting unusual parent-child process relationships and script attributes.
Entra ID Service Principal Sign-in from Unusual ASN
2 rules 2 TTPsDetection of Entra ID service principal sign-ins originating from a previously unseen combination of workload identity and source autonomous system number (ASN), potentially indicating compromised credentials or malicious activity.
AWS EC2 EBS Snapshot Access Permissions Removed
2 rules 4 TTPsDetection of AWS EC2 EBS snapshot access permissions removal can indicate malicious attempts to disrupt data recovery, evade detection, or maintain exclusive backup access, leading to increased attack impact and incident response complexity.
Werfault ReflectDebugger Persistence Abuse
2 rules 2 TTPsAttackers can achieve persistence by modifying the ReflectDebugger registry key associated with Windows Error Reporting (Werfault) to execute arbitrary code when Werfault is invoked with the `-pr` parameter.
Suspicious Remote File Copy via TeamViewer
2 rules 2 TTPsAttackers may abuse TeamViewer, a legitimate remote access tool, to transfer malware or tools into a compromised environment by creating executable or script files with suspicious extensions.
Potential PowerShell Obfuscated Script via High Entropy
2 rules 3 TTPsThis rule detects potential PowerShell obfuscated scripts by identifying script blocks with high entropy and non-uniform character distributions, which attackers use to evade signature-based detections.
Office 365 User Restricted from Sending Email
2 rules 1 TTPAn Office 365 user account is restricted from sending email, potentially indicating account compromise, policy violation, or administrative action following suspicious activity.
Linux Service Stop and Disable Detection
3 rules 2 TTPsAttackers may halt or disable security services on Linux systems to evade defenses, maintain persistence, or disrupt operations, detected through the use of utilities like 'systemctl', 'service', and 'chkconfig'.
Execution via GitHub Actions Runner
2 rules 8 TTPsCompromised GitHub Actions workflows allow attackers to execute arbitrary commands on self-hosted runners, leading to code execution, file manipulation, and potential data exfiltration.
Azure Resource Group Deletion Detected
2 rules 5 TTPsThis rule detects the deletion of a resource group in Azure. Deleting a resource group permanently removes all resources within it, which adversaries may use to evade defenses or destroy data.
Signed Proxy Execution via MS Work Folders
2 rules 3 TTPs 1 IOCAdversaries may misuse Windows Work Folders to execute a masqueraded 'control.exe' file from a non-standard location, bypassing application controls and potentially escalating privileges.
Microsoft Exchange Server UM Spawning Suspicious Processes
2 rules 2 TTPs 1 CVEThis rule detects suspicious processes spawned by the Microsoft Exchange Server Unified Messaging (UM) service, potentially indicating exploitation of CVE-2021-26857 and leading to unauthorized process execution and system compromise.
Multiple Logon Failure Followed by Logon Success
2 rules 1 TTPThis rule identifies potential password guessing/brute force activity from a single address, followed by a successful logon, indicating that an attacker may have compromised an account by brute-forcing login attempts across multiple users.
Unusual Persistence via Services Registry Modification
2 rules 3 TTPsAdversaries may modify the Windows services registry keys directly to stealthily persist through abnormal service creation or modification of an existing service, bypassing standard APIs, detected by monitoring registry changes related to service DLLs and image paths.
Suspicious WMI Image Load from MS Office
2 rules 1 TTPAdversaries may exploit Windows Management Instrumentation (WMI) to execute code stealthily, bypassing traditional security measures by loading `wmiutils.dll` from Microsoft Office applications, potentially indicating malicious execution.
SUSE Harvester Rancher Integration Vulnerable to MITM and DOS
3 rules 2 TTPsSUSE Harvester's Rancher integration mechanism is vulnerable to a man-in-the-middle attack due to insecure TLS options, potentially leading to denial of service.
rustls-webpki Denial-of-Service Vulnerability via Malformed CRL BIT STRING
2 rules 1 TTPA denial-of-service vulnerability exists in rustls-webpki versions prior to 0.103.13 and between 0.104.0-alpha.1 and 0.104.0-alpha.7 due to a panic in `bit_string_flags()` when processing a malformed CRL BIT STRING, triggered when CRL checking is enabled and an attacker provides a crafted CRL.
rust-zserio Unbounded Memory Allocation Vulnerability
2 rules 1 TTPThe rust-zserio package is vulnerable to unbounded memory allocation when deserializing arrays, strings, or bytes (blob) types, allowing an attacker to cause a denial-of-service by providing a crafted data file with a large size value.
Potential Reverse Shell via Java on Linux
2 rules 2 TTPsThe execution of a Linux shell process from a Java JAR application following an incoming network connection may indicate reverse shell activity.
Potential Application Shimming via Sdbinst
3 rules 2 TTPsThis brief covers the abuse of application shimming in Windows via `sdbinst.exe` to achieve persistence and privilege escalation by executing arbitrary code within legitimate processes.
Persistence via Scheduled Job Creation
2 rules 1 TTPThis detection rule identifies attempts to establish persistence on Windows systems by creating scheduled jobs in the Windows Tasks directory, excluding known legitimate jobs.
Pachno 1.0.6 Stored Cross-Site Scripting Vulnerability
2 rules 1 TTP 1 CVEPachno 1.0.6 is vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious HTML or scripts into POST parameters, which are then stored and executed in user browser sessions due to improper sanitization.
Ollama Abnormal Network Connectivity Detected
2 rules 1 TTPThis detection identifies unusual network patterns and connection problems within Ollama, encompassing unauthorized API access attempts beyond localhost and warning-level network errors like DNS lookup failures, TCP connection issues, or host resolution problems, which can signal network-based attacks, unauthorized access, or infrastructure reconnaissance.
MSBuild Making Network Connections Indicating Potential Defense Evasion
2 rules 2 TTPsMsBuild.exe making outbound network connections may indicate adversarial activity as attackers leverage MsBuild to execute code and evade detection.
Linux Log Clearing Attempts via Common Utilities
3 rules 1 TTPAdversaries attempt to clear Linux system logs using utilities like rm, rmdir, shred, and unlink to conceal malicious activity and evade detection.
Kubernetes Service Account Token Access Followed by API Request
2 rules 5 TTPsDetection of interactive access to a Kubernetes service account token or certificate followed by a Kubernetes API request, potentially indicating credential theft and lateral movement within the cluster.
Kubernetes Potential Endpoint Permission Enumeration by Anonymous User
2 rules 1 TTPAn anonymous user attempts to enumerate Kubernetes API endpoints, resulting in a series of failed API requests across multiple endpoints, potentially revealing the cluster's exposed surface.
Granian WebSocket Subprotocol Header Denial of Service
2 rules 1 TTPGranian versions 1.2.0 through 2.7.3 are vulnerable to an unauthenticated denial of service. Sending a WebSocket upgrade request with a `Sec-WebSocket-Protocol` header containing non-ASCII bytes causes a worker process to abort, leading to a denial of service.
Google Workspace BitLocker Setting Disabled
2 rules 2 TTPsDetection of Google Workspace administrators disabling the BitLocker setting, potentially allowing adversaries with valid account access to decrypt sensitive data on managed Windows devices.
FreeScout Unauthorized Attachment Deletion Vulnerability (CVE-2026-41192)
2 rules 1 CVEFreeScout versions prior to 1.8.215 are vulnerable to unauthorized attachment deletion, allowing a malicious mailbox peer to delete attachments by replaying encrypted attachment IDs in the `save_draft` flow.
Direct Interactive Kubernetes API Request by Common Utilities
2 rules 3 TTPsThis rule detects direct interactive Kubernetes API requests by common utilities from within a container, potentially indicating lateral movement or discovery activities within the cluster.
Defense Evasion via Exchange DLP Policy Removal
2 rules 1 TTPAttackers may remove or modify Exchange Data Loss Prevention (DLP) policies in Microsoft 365 to evade detection and exfiltrate sensitive data without triggering alerts.
Azure Diagnostic Settings Deletion for Defense Evasion
2 rules 2 TTPsAdversaries may delete Azure diagnostic settings to evade defenses by hindering detection and analysis, which this detection identifies by monitoring Azure activity logs for successful deletion operations.
Azure AD Service Principal Enumeration via Microsoft Graph API
2 rules 2 TTPsAn attacker uses Microsoft Graph API to enumerate multiple Azure AD service principals, potentially using tools like AzureHound or ROADtools, to gather information for privilege escalation or lateral movement.
AWS WAF Rule or Rule Group Deletion
2 rules 1 TTPDetection of AWS WAF rule or rule group deletions, which can weaken web application security and expose applications to various attacks.
AWS RDS DB Instance Restored for Defense Evasion or Data Collection
3 rules 3 TTPsDetection of AWS RDS database instance restoration from a snapshot or S3 backup, potentially indicating unauthorized data access, defense evasion, or data collection by adversaries recreating database environments to bypass controls or exfiltrate sensitive data.
AWS KMS Key User Performing S3 Encryption Detection
2 rules 1 TTPDetection of AWS users utilizing KMS keys to perform encryption operations on S3 buckets, indicating potential misuse or malicious activity within the cloud environment.
AWS IAM Long-Term Access Key First Seen from Source IP
2 rules 2 TTPsThe rule identifies the first time a long-term IAM access key ID (prefix AKIA) is used successfully from a given source.ip in AWS CloudTrail, indicating potential credential compromise.
AWS EC2 Security Group Configuration Change Detection
3 rules 4 TTPsDetection of unauthorized changes to AWS EC2 Security Group configurations, potentially leading to persistence, data exfiltration, or lateral movement within the AWS environment.
AWS CLI Activity Detection for Open S3 Bucket Creation
2 rules 1 TTPDetection of S3 bucket creation via AWS CLI which might lead to data exposure and unauthorized access.
AWS Account Login Profile Update
3 rules 1 TTPAn AWS account's login profile has been modified, potentially indicating account compromise, privilege escalation, or malicious user activity.
Windows Subsystem for Linux Enabled via Dism Utility
2 rules 1 TTPAdversaries may enable Windows Subsystem for Linux (WSL) via the Dism utility to evade detection by running Linux tools on Windows.
Suspicious WerFault Child Process Abuse
2 rules 3 TTPsThis rule detects suspicious child processes of WerFault.exe, a Windows error reporting tool, indicating potential abuse of the SilentProcessExit registry key to execute malicious processes stealthily for defense evasion, persistence, and privilege escalation.
Remote Management Access Launch After MSI Install
2 rulesDetects a suspicious sequence of an MSI installer execution immediately followed by the execution of commonly abused Remote Management Software, potentially indicating unauthorized remote access.
PowerShell Script Block Logging Disabled via Registry Modification
2 rules 2 TTPsAttackers may disable PowerShell Script Block Logging by modifying the registry to conceal their activities on the host and evade detection by setting the `EnableScriptBlockLogging` registry value to 0, impacting security monitoring and incident response capabilities.
Potential Timestomping of Executable Files on Windows
2 rules 1 TTPThis rule identifies potential timestomping behavior on Windows systems where the creation time of executable files in sensitive system directories is modified, potentially to blend malicious executables with legitimate system files and evade detection.
Potential Data Exfiltration via Wget on Linux Systems
2 rules 1 TTPThis rule detects the use of wget on Linux systems to upload files to an external server, a tactic commonly used for data exfiltration.
MSBuild Making Network Connections
2 rules 2 TTPsDetection of MsBuild.exe making outbound network connections which may indicate adversarial activity used to execute code and evade detection.
Ingress Transfer via Windows BITS
2 rules 2 TTPsAdversaries leverage the Windows Background Intelligent Transfer Service (BITS) to download executable and archive files, potentially delivering malicious payloads while evading traditional security measures.
IIS AppCmd Tool Used to Dump Service Account Credentials
2 rules 2 TTPsAttackers with access to IIS web servers may use the AppCmd command-line tool to dump sensitive configuration data, including application pool credentials, potentially leading to lateral movement and privilege escalation.
Entra ID OAuth Phishing via First-Party Microsoft Application
2 rules 5 TTPsAttackers are leveraging first-party Microsoft applications in Entra ID to conduct OAuth phishing attacks, bypassing traditional consent prompts and accessing sensitive resources like Microsoft Graph and legacy Azure AD.
Entra ID MFA Disabled for User
2 rules 3 TTPsDetection of multi-factor authentication (MFA) being disabled for an Entra ID user account, potentially weakening account security and leading to compromise.
Disabling Windows Defender Security Settings via PowerShell
2 rules 2 TTPsAttackers use PowerShell commands, including base64-encoded variants, to disable or weaken Windows Defender settings, impairing defenses on compromised systems.
Detection of Custom Shim Database Installation for Persistence
2 rules 1 TTPAttackers abuse the Application Compatibility Shim functionality in Windows to establish persistence and achieve arbitrary code execution by installing malicious shim databases, which this detection identifies through monitoring registry changes.
Cisco ASA Device File Copy Activity
2 rules 2 TTPsAdversaries may copy device files, including configurations and packet captures, from Cisco ASA devices via CLI or ASDM for reconnaissance, credential extraction, or data exfiltration, which can be detected via command execution logs.
Azure Event Hub Deletion for Defense Evasion
2 rules 2 TTPsDetection of Azure Event Hub deletion, indicative of defense evasion by adversaries seeking to disrupt data flow and evade detection by erasing log evidence.
AWS EC2 Network Access Control List Deletion
2 rules 1 TTPThe deletion of an Amazon EC2 network access control list (ACL) or its entries can indicate an attacker attempting to disable security controls for unauthorized access or data exfiltration.
AWS CloudTrail Logging Suspended via StopLogging API
3 rules 2 TTPsAn attacker may suspend AWS CloudTrail logging via the StopLogging API (StopLogging) to eliminate audit visibility and evade defenses.
AppArmor Policy Interface Tampering
3 rules 1 TTPDetection of unauthorized access to AppArmor kernel policy control interfaces, specifically the `.load`, `.replace`, or `.remove` files, indicating potential defense evasion or policy tampering on Linux systems.
Creation of New DMSA Service Account Potentially Exploiting BadSuccessor Vulnerability
2 rules 2 TTPsThe creation of a new Delegated Managed Service Account (DMSA) within specific Organizational Units (OUs) using the New-ADServiceAccount cmdlet is indicative of potential BadSuccessor privilege escalation attempts in Windows Server 2025 Active Directory environments.
AWS EC2 Traffic Mirroring Abuse for Data Exfiltration
2 rules 5 TTPsAn attacker creates an Amazon EC2 Traffic Mirroring session to capture and exfiltrate sensitive network traffic from EC2 instances, potentially including unencrypted data.
CoreDNS DoH GET Query Denial-of-Service
2 rules 1 TTPCoreDNS is vulnerable to a denial-of-service attack where processing oversized DNS-over-HTTPS GET requests exhausts resources prior to returning an error.
AWS IAM Access Denied Discovery Events
2 rules 1 TTPThis detection identifies potential reconnaissance activity by an attacker attempting to discover AWS IAM permissions and configurations by generating a high volume of access denied events.
Google Drive Ownership Transferred via Google Workspace
2 rules 2 TTPsAdversaries may transfer files to an adversary account for potential exfiltration by abusing Google Workspace administration permissions to transfer file ownership within Google Drive.
AWS CloudWatch Log Group Deletion
2 rules 3 TTPsDetection of Amazon CloudWatch Log Group deletion via the 'DeleteLogGroup' API by non-AWS Internal user agents, potentially indicating defense evasion or disruption of logging pipelines.
Detection of Downloaded URL Files Used in Phishing Campaigns
2 rules 3 TTPsThis detection rule identifies downloaded .url shortcut files on Windows systems, often used in phishing campaigns, by monitoring their creation events and flagging those from non-local sources, enabling early threat detection.
Suspicious Azure Automation Account Creation
2 rules 2 TTPsAn adversary may create an Azure Automation account to maintain persistence in the target environment by automating malicious tasks.
Kubectl Secrets Enumeration Across All Namespaces
2 rules 2 TTPsThe use of `kubectl get secrets --all-namespaces` command is detected, which enumerates secret resources across the entire Kubernetes cluster, potentially aiding credential discovery, privilege escalation, or lateral movement.
Process Execution from Suspicious Windows Directories
2 rules 1 TTPAdversaries may execute processes from unusual default Windows directories to masquerade malware and evade defenses by blending in with trusted paths, making malicious activity harder to detect.
Persistence via Malicious Microsoft Outlook VBA Template
2 rules 1 TTPAttackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file, detected by monitoring for unauthorized file modifications.
Kubernetes Sensitive Role Creation or Modification
2 rules 2 TTPsDetects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs, potentially leading to privilege escalation or unauthorized access within the cluster.
GitHub Enterprise Audit Log Streaming Paused
2 rules 2 TTPsDetection of a user pausing audit log event streaming in GitHub Enterprise, potentially indicating an attempt to evade detection by disabling the audit trail.
GCP Virtual Private Cloud Network Deletion
2 rules 2 TTPsDetection of Virtual Private Cloud (VPC) network deletion in Google Cloud Platform (GCP), which can be used by an adversary to disrupt a target's network and business operations.
GCP Service Account Disabled
2 rules 1 TTPDetection of a Google Cloud Platform (GCP) service account being disabled, potentially indicating malicious activity aimed at disrupting business operations by an adversary.
Detection of Command and Control Activity via Commonly Abused Web Services
2 rules 2 TTPsThis rule detects command and control activity using common web services by identifying Windows hosts making DNS requests to a list of commonly abused web services from processes outside of known program locations, potentially indicating adversaries attempting to blend malicious traffic with legitimate network activity.
DCOM Lateral Movement via ShellWindows/ShellBrowserWindow
2 rules 2 TTPsThis analytic identifies the use of Distributed Component Object Model (DCOM) to execute commands on a remote host, specifically when launched via ShellBrowserWindow or ShellWindows Application COM objects, indicating potential lateral movement by an attacker.
Cisco ASA - New Local User Account Creation
2 rules 2 TTPsDetection of new user account creations on Cisco ASA devices, potentially indicating unauthorized access or persistence attempts by adversaries.
AzureHound Reconnaissance Activity in Azure AD
2 rules 2 TTPsDetection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.
AWS CloudTrail Trail Deletion Detected
2 rules 2 TTPsDetection of AWS CloudTrail trail deletion via the DeleteTrail API indicates potential defense evasion and destruction of audit logging.
Executable File Creation with Multiple Extensions
2 rules 2 TTPsThis rule detects the creation of executable files with multiple extensions, a masquerading technique used to evade defenses by disguising malicious executables as benign files to trick users into executing them.
Disable Windows Event and Security Logs Using Built-in Tools
3 rules 3 TTPsAttackers attempt to disable Windows Event and Security Logs using logman, PowerShell, or auditpol to evade detection and cover their tracks.
Incoming Execution via PowerShell Remoting
2 rules 2 TTPsThis rule identifies remote execution via Windows PowerShell remoting, which allows a user to run any Windows PowerShell command on one or more remote computers, potentially indicating lateral movement.
Suspicious Container Runtime CLI Execution
3 rules 2 TTPsThe rule detects execution of container runtime CLI tools (ctr, crictl, nerdctl) with arguments indicating container creation, command execution inside existing containers, image manipulation, or host filesystem mounting, potentially leading to container escape and privilege escalation.
Okta Session Hijacking via Multiple Device Token Hashes
2 rules 2 TTPsDetection of multiple device token hashes and source IPs for a single Okta session, indicating potential session hijacking and unauthorized access to Okta resources.
Linux Clipboard Activity Monitoring
3 rules 1 TTPThis brief provides detection strategies for monitoring clipboard activity on Linux systems, potentially identifying malicious data exfiltration or command execution attempts.
Azure Firewall Modification or Deletion Detected
2 rules 1 TTPAn Azure firewall was created, modified, or deleted, potentially indicating malicious activity aimed at impairing network defenses.
Azure AD Bitlocker Key Retrieval
2 rules 3 TTPsAn adversary with sufficient privileges in Azure Active Directory may attempt to retrieve BitLocker keys to decrypt drives for lateral movement or data exfiltration.
Cloud Instance Modified by Previously Unseen User
2 rules 2 TTPsThis analytic identifies cloud instances being modified by users who have not previously modified them, specifically focusing on successful modifications of EC2 instances, potentially indicating unauthorized access and configuration changes.
Suspicious File Download via Headless Browser
2 rules 2 TTPs 26 IOCsAttackers are leveraging Chromium-based browsers in headless mode with the `--dump-dom` argument to download files from file-sharing services and direct IPs, potentially indicative of reconnaissance or malware delivery.
Potential Port Monitor or Print Processor Registration Abuse
2 rules 4 TTPsThis rule detects potential abuse of port monitors and print processors for privilege escalation and persistence on Windows systems by identifying registry modifications to load malicious DLLs that execute with SYSTEM privileges during system boot, focusing on modifications made by non-SYSTEM users.
External User Added to Google Workspace Group
2 rules 2 TTPsDetection of an external Google Workspace user account being added to an existing group, potentially indicating an adversary attempting to intercept shared files or emails by adding accounts where the domain name of the target doesn't match the Google Workspace domain.
Entra ID Illicit Consent Grant via Registered Application
2 rules 3 TTPsAttackers register malicious applications within Entra ID and deceive users into granting extensive permissions through OAuth consent, enabling unauthorized access to sensitive data like emails and files.
Cisco ASA Logging Message Suppression
2 rules 1 TTPDetection of 'no logging message' command usage on Cisco ASA devices, potentially indicating an adversary suppressing security-critical log events to evade detection.
Cisco 802.1X (dot1x) Disabled on Network Interface
2 rules 2 TTPsDetection of manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface, potentially allowing unauthorized network access and lateral movement.
GenAI Process Performing Encoding/Chunking Prior to Network Activity
2 rules 4 TTPsThis rule detects GenAI processes performing encoding or chunking (base64, gzip, tar, zip) followed by outbound network activity, indicating data preparation for exfiltration.
Kubernetes Admission Webhook Manipulation for Persistence and Defense Evasion
2 rules 2 TTPsThe rule detects creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities, allowing attackers to inject malicious sidecars, block security tooling, or exfiltrate pod specifications.
Detection of Downloaded Shortcut Files
2 rules 3 TTPsThis rule detects potentially malicious .lnk shortcut files downloaded from outside the local network on Windows systems, which are commonly used in phishing campaigns.
Suspicious AWS SAML Activity Detection
2 rules 3 TTPsThis rule identifies suspicious SAML activity in AWS, such as AssumeRoleWithSAML and UpdateSAMLProvider events, which could indicate an attacker gaining backdoor access, escalating privileges, or establishing persistence.
User Added to Group with Conditional Access Policy Modification Access
3 rules 4 TTPsAn attacker adds a user to a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, credential access, persistence, and defense impairment.
Netsh Used to Enable Network Discovery
2 rules 1 TTPAdversaries may use the `netsh.exe` command-line tool to enable Network Discovery via the Windows firewall, weakening host defenses and facilitating lateral movement by identifying other systems on the network.
Kubernetes Secret Access by Node or Pod Service Account
2 rules 1 TTPThis rule detects Kubernetes audit events where a node or pod service account attempts to read secrets directly, which is often a sign of credential access.
Calendar 2 Mac App Store Application Mines Cryptocurrency
3 rules 1 TTPThe 'Calendar 2' application, available on the official Mac App Store, was found to surreptitiously mine cryptocurrency on users' Macs, utilizing the 'xmr-stak' miner to mine Monero (XMR) and report mining operations to calendar.qbix.com.
Outlook Security Settings Registry Modification
2 rules 1 TTPAttackers modify Outlook security settings via registry changes to enable malicious mail rules and bypass security controls, potentially leading to persistence and data compromise.
InstallUtil Process Making Network Connections for Defense Evasion
2 rules 1 TTPDetection of InstallUtil.exe making outbound network connections, which can indicate adversaries leveraging it to execute code and evade detection by proxying execution through a trusted system binary.
Windows Downdate Attack Registry Modification
2 rules 1 TTPThe Windows Downdate attack involves modifying specific registry keys to force a Windows downgrade, enabling exploitation of older, vulnerable versions, which this detection identifies through monitoring for the creation or modification of the pending.xml file in unusual locations.
Third-party Backup Files Deleted via Unexpected Process
2 rules 2 TTPsThis detection identifies the deletion of backup files by processes outside of the backup suite, specifically targeting Veritas and Veeam backups, which may indicate an attempt to prevent recovery from ransomware.
Suspicious File Creation by Microsoft Exchange Unified Messaging Service
2 rules 3 TTPs 1 CVEThis rule detects suspicious file creations by the Microsoft Exchange Server Unified Messaging service, potentially indicative of exploitation of CVE-2021-26858, leading to web shell deployment for initial access, lateral movement, and persistence.
Suspicious Execution via Microsoft Office Add-Ins
3 rules 4 TTPsThis rule identifies suspicious execution patterns where Microsoft Office applications launch add-ins from unusual paths or with atypical parent processes, potentially indicating initial access via a malicious phishing MS Office Add-In.
Potential Command and Control via Internet Explorer COM Abuse
2 rules 4 TTPsThis rule detects potential command and control activity where Internet Explorer (iexplore.exe) is started via the Component Object Model (COM) and makes unusual network connections, indicating adversaries might exploit Internet Explorer via COM to evade detection and bypass host-based firewall restrictions.
Azure Network Firewall Policy Modification or Deletion
3 rulesAn adversary may modify or delete Azure Network Firewall Policies to impair defenses and potentially impact network security.
Suspicious Execution via Scheduled Task
2 rules 2 TTPsThis rule identifies execution of suspicious programs via scheduled tasks by looking at process lineage and command line usage, detecting processes such as cscript.exe, powershell.exe, and cmd.exe when executed from suspicious paths like C:\Users\ and C:\ProgramData\.
AWS RDS Snapshot Export to S3 for Potential Data Exfiltration
2 rules 1 TTPAn adversary may export RDS snapshots to Amazon S3 to exfiltrate sensitive data outside of RDS-managed storage, potentially bypassing database access controls and leading to unauthorized data theft.
Mac Malware of 2018 Retrospective
3 rules 1 TTP 4 IOCsThis brief analyzes Mac malware discovered in 2018, including OSX.Mami, a DNS hijacker distributed via browser popups, and CrossRAT, a cross-platform Java-based backdoor likely spread through phishing, highlighting infection vectors, persistence mechanisms, and capabilities.
Potential Credential Access via LSASS Handle Duplication
2 rules 1 TTPDetection of suspicious LSASS handle access via DuplicateHandle from an unknown call trace module, indicating a potential attempt to bypass the NtOpenProcess API to evade detection and dump LSASS memory for credential access.
AWS Bedrock Knowledge Base Deletion Attempt
2 rules 2 TTPsAn adversary may delete AWS Bedrock Knowledge Bases, which are resources that store and manage domain-specific information for AI models, to disrupt business operations or remove traces of data access by using the DeleteKnowledgeBase API call.
Nginx-UI Unauthenticated Initial Admin Claim Vulnerability
2 rules 1 TTPAn unauthenticated network attacker can claim the initial administrator account on a fresh Nginx-UI instance during the first-run setup window by exploiting the publicly accessible /api/install endpoint.
Suspicious PowerShell TabExpansion Direct Call
2 rules 2 TTPsThis detection identifies PowerShell scripts that directly call the TabExpansion internal function, which is uncommon and may indicate malicious activity, such as TabShell, potentially bypassing sandboxes by loading PowerShell functions via directory traversal.
Network Connection via Compiled HTML File
2 rules 3 TTPsThis rule detects network connections initiated by hh.exe, the HTML Help executable, which may indicate the execution of malicious code embedded in compiled HTML files (.chm) to deliver malicious payloads, bypass security controls, and gain initial access via social engineering.
Windows Subsystem for Linux Distribution Installed via Registry Modification
2 rules 3 TTPsThis rule detects registry modifications indicative of a new Windows Subsystem for Linux (WSL) distribution installation, a technique adversaries may leverage to evade detection by utilizing Linux environments within Windows.
AWS IAM OIDC Provider Created by Rare User
2 rules 3 TTPsAn uncommon user or role creating an OpenID Connect (OIDC) Identity Provider in AWS IAM can indicate an attacker establishing persistent, federated access by creating rogue OIDC providers to assume roles using attacker-controlled IdP tokens.
Zoom High Video Latency Potentially Indicating Remote Employment Fraud
2 rules 1 TTP 1 IOCThis analytic identifies Zoom users exhibiting high video latency, a potential indicator of Remote Employment Fraud (REF), by analyzing Zoom logs for average and overall latency and highlighting users with latency exceeding 300ms.
Windows Hosts Querying Abused Web Services
2 rules 1 TTP 34 IOCsAdversaries may use abused web services such as paste sites, VoIP, and file hosting to host malicious payloads or facilitate command and control, detected via DNS queries from Windows hosts to these services.
Potential Data Exfiltration via Rclone
3 rules 1 TTPThe rule detects the abuse of rclone, a legitimate file synchronization tool, potentially renamed to evade detection, to exfiltrate data to cloud storage or remote endpoints, using copy/sync commands and specific file filters.
OpenSSL Data Encryption Detection
2 rules 2 TTPsThis brief documents detection of OpenSSL being used to encrypt data using command-line arguments specifying input and output files, potentially indicating data exfiltration preparation or ransomware activity by threat actors.
Multiple Logon Failures from Single Source Indicate Brute Force Attempt
2 rules 2 TTPsDetection of multiple consecutive logon failures from a single source IP within a short time interval indicates a potential brute force or password guessing attack targeting Windows systems.
MSBuild запускает необычные процессы
2 rules 3 TTPsAdversaries may exploit MSBuild to execute malicious scripts or compile code, bypassing security controls; this rule detects unusual processes initiated by MSBuild, such as PowerShell or C# compiler, signaling potential misuse for executing unauthorized or harmful actions.
Malicious Azure Kubernetes Admission Controller Configuration
2 rules 4 TTPsAn adversary can exploit Kubernetes Admission Controllers in Azure to achieve persistence, privilege escalation, or credential access by manipulating webhook configurations.
Detection of Bcdedit Boot Configuration Modification
2 rules 1 TTPThis rule identifies the use of bcdedit.exe to modify boot configuration data, which may be indicative of a destructive attack or ransomware activity aimed at inhibiting system recovery by disabling error recovery or ignoring boot failures.
Azure AD Authentication to Important Apps Using Single-Factor Authentication
2 rules 3 TTPsDetection of successful Azure AD authentications to critical applications that only required single-factor authentication, potentially indicating a security lapse or policy violation leading to unauthorized access.
AWS ECR Container Scanning Reveals Low Severity Vulnerabilities
2 rules 1 TTP 1 CVEThis analytic identifies low, informational, or unknown severity findings from AWS Elastic Container Registry (ECR) image scans using AWS CloudTrail logs, indicating potential vulnerabilities or misconfigurations in container images that could lead to unauthorized access or data breaches.
Detection of Azure Application Deletion
2 rules 1 TTPThis alert identifies when an application is deleted within an Azure environment, which could indicate malicious activity or unintended misconfiguration leading to service disruption.
Gsuite Email with Suspicious Subject and Attachments
2 rules 1 TTP 1 IOCDetection of Gsuite emails with suspicious subjects and attachments (e.g., DHL, UPS, invoice, DOC, ZIP) indicative of spear phishing, excluding internal test domains, which could lead to initial compromise and further malicious activity.
Windows TOR Client Execution Detection
2 rules 1 TTPDetects the execution of the TOR Browser and related components on Windows endpoints, indicating potential anonymization of traffic for command and control, data exfiltration, or policy evasion by adversaries or insider threats.
Windows Time-Based Evasion via Choice Exec
2 rules 1 TTPDetection of choice.exe used in batch files for time-based evasion, a technique observed in SnakeKeylogger malware, indicating potential stealthy code execution and persistence.
Windows Theme File Creation in Unusual Location
2 rules 3 TTPsDetects the creation of Windows theme files in unusual locations, such as Desktop, Documents, Downloads, or Temp directories, which can be indicative of remote code execution or NTLM coercion attacks.
Windows Processes Gathering Network Information via IP Check Web Services
2 rules 1 TTP 26 IOCsDetection of Windows processes using IP check web services for reconnaissance, a behavior commonly associated with malware like Trickbot, by monitoring DNS queries.
Windows Folder Options Disabled via Registry Modification
2 rulesAttackers modify the Windows registry to disable the Folder Options feature, preventing users from showing hidden files and file extensions, commonly used by malware to conceal malicious files and deceive users with fake file extensions.
Windows EventLog Reconnaissance Activity Detection
3 rules 1 TTPThis detection identifies potential reconnaissance activities on Windows systems by adversaries using tools like `wevtutil.exe`, `wmic.exe`, and PowerShell cmdlets to query event logs for sensitive information.
Unusual Network Activity from Windows System Binaries
3 rules 5 TTPsDetection of network connections initiated by unusual Windows system binaries, often leveraged by adversaries to proxy execution of malicious code and evade detection, indicating potential defense evasion and command and control activity.
Unusual Modification of GenAI Tool Configuration File
3 rules 4 TTPsThis rule detects unusual modifications to GenAI tool configuration files, potentially indicating an attacker injecting malicious MCP server configurations to hijack AI agents for persistence, command and control, or data exfiltration.
System Shells Launched via Windows Services
2 rules 4 TTPsAttackers may configure existing Windows services or create new ones to execute system shells (cmd.exe, powershell.exe) to elevate privileges from administrator to SYSTEM for persistence and further malicious activity.
Suspicious WMI Reconnaissance via PowerShell
2 rules 2 TTPsThis analytic detects suspicious PowerShell activity leveraging WMI to gather system information, potentially indicating reconnaissance by an attacker.
Suspicious Modification of Sensitive Linux Files
3 rules 1 TTPThis threat brief covers the detection of suspicious processes modifying sensitive files on Linux systems, potentially indicating malicious attempts to persist, escalate privileges, or disrupt system operations.
Suspicious .NET Code Compilation via Unusual Parent Processes
2 rules 9 TTPsThe execution of .NET compilers (csc.exe, vbc.exe) with suspicious parent processes (wscript.exe, mshta.exe, etc.) indicates potential attempts to compile code after delivery for defense evasion and execution.
Remote File Download via PowerShell
2 rules 2 TTPsDetects PowerShell being used to download executable files from untrusted remote destinations, often used by attackers to transfer malware into a compromised environment.
Rare Connection to WebDAV Target for Credential Access
2 rules 2 TTPsAdversaries may inject WebDAV paths into files or features opened by a user to leak NTLM credentials via forced authentication, and this detection identifies rare connections to WebDAV resources using rundll32.exe.
Potential Lateral Tool Transfer via SMB Share
3 rules 2 TTPsThis rule identifies the creation or change of a Windows executable file over network shares (SMB), indicating adversaries may transfer tools or other files between systems in a compromised environment.
Mounting Hidden or WebDav Remote Shares via Net.exe
2 rules 4 TTPsAdversaries may use net.exe to mount WebDav or hidden remote shares, indicating lateral movement or preparation for data exfiltration within a Windows environment.
Malware Leveraging Large Language Model Endpoints for Command and Control
3 rules 1 TTP 35 IOCsThis rule detects DNS queries to known Large Language Model (LLM) domains originating from unsigned binaries or common Windows scripting utilities, indicating potential malware command and control activity.
Generic Ransomware Detection on macOS
2 rules 1 TTPThis brief outlines a method for generically detecting ransomware on macOS by monitoring file I/O events and identifying the rapid creation of encrypted files by untrusted processes, as proposed by Objective-See.
Execution of Persistent Suspicious Programs via Run Keys
2 rules 8 TTPsThis analytic identifies suspicious programs such as script interpreters, rundll32, or MSBuild being executed shortly after user logon, indicating potential persistence mechanisms abusing the registry run keys.
Entra ID User Sign-in with Unusual Client Application
2 rules 3 TTPsAdversaries with stolen credentials or OAuth tokens may abuse Entra ID-managed or first-party client IDs to perform on-behalf-of (OBO) authentication, blending into legitimate cloud traffic and evading detection by using a rare application ID for principal authentication.
Detect Windows Entra User Management Via Azure CLI
2 rules 3 TTPsThis analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.
Bandit WebSocket Memory Exhaustion Vulnerability
2 rules 2 TTPsAn unauthenticated attacker can exhaust server memory by sending unbounded WebSocket continuation frames in Bandit-fronted applications, leading to a denial of service.
Azure Network Watcher Deletion for Defense Evasion
2 rules 2 TTPsAn adversary may delete an Azure Network Watcher to impair defenses by disabling network monitoring and logging capabilities, as detected by monitoring Azure activity logs for Network Watcher deletion events.
Azure Key Vault Excessive Secret or Key Retrieval
2 rules 2 TTPsDetects excessive secret or key retrieval operations from Azure Key Vault, indicating potential unauthorized access attempts or credential harvesting.
Azure AD User Password Reset Detection
2 rules 1 TTPDetects when a user successfully resets their own password in Azure Active Directory, which may indicate malicious activity or account compromise.
Azure AD Guest to Member User Type Conversion
2 rules 1 TTPAn adversary may convert a guest user account to a member account in Azure Active Directory to elevate privileges and gain persistent access to resources.
AWS User Login Profile Update by Different User
2 rules 1 TTPA user updating the login profile of another user in AWS CloudTrail logs may indicate privilege escalation attempts.
AWS STS Role Assumption by Service for Privilege Escalation
2 rules 2 TTPsDetection of AWS services assuming roles within AWS Security Token Service (STS) to gain temporary credentials and potentially escalate privileges or move laterally within the AWS environment.
AWS SES Identity Deletion
2 rules 1 TTPDetection of an AWS Simple Email Service (SES) identity deletion event, potentially indicating an adversary attempting to cover their tracks after malicious activity.
AWS KMS Customer Managed Key Disabled or Scheduled for Deletion
2 rules 1 TTPAn adversary may disable or schedule the deletion of an AWS customer-managed KMS Key to cause irreversible data loss, disrupt business operations, impede incident response, or hide evidence of prior activity.
AWS IAM SAML Provider Updated Detection
2 rules 2 TTPsDetection of unauthorized updates to AWS IAM SAML providers, potentially leading to privilege escalation and persistent access via trust manipulation.
AWS GuardDuty Member Account Manipulation
2 rules 1 TTPAdversaries may attempt to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization to break centralized visibility, allowing them to operate undetected in member accounts.
AWS Console Login from New Country
2 rules 3 TTPsDetects AWS console logins by a user from a previously unseen country, potentially indicating compromised credentials.
Attrib.exe Used to Hide Files and Directories
2 rules 1 TTPDetection of attrib.exe being used with the +h flag to hide files and directories on Windows systems, a technique used by attackers for defense evasion and persistence.
Apple Security Framework Crash due to Uninitialized Pointer
2 rulesA crash was identified in Apple's Security framework due to an uninitialized pointer in the SecError function, leading to the dereference of an invalid memory address.
Entra ID User Reported Suspicious Activity
2 rules 2 TTPsThis rule detects suspicious activity reported by users in Microsoft Entra ID, indicating potential account compromise or unauthorized access attempts via social engineering during authentication.
Windows Netsh Tool Used for Firewall Discovery
2 rules 1 TTPThe native Windows `netsh.exe` tool is being abused to discover firewall configurations, potentially to weaken defenses before lateral movement and data exfiltration.
Windows Firewall Disabled via Netsh
2 rules 1 TTPDetection of adversaries disabling Windows Firewall rules using the `netsh.exe` command-line tool to weaken defenses and facilitate unauthorized network activity.
Symbolic Link Creation to Shadow Copies for Credential Access
2 rules 3 TTPsThe creation of symbolic links to shadow copies on Windows systems by processes such as cmd.exe or powershell.exe can indicate an attempt to access sensitive files for credential theft.
Suspicious PowerShell Execution via Windows Script Host
2 rules 4 TTPsDetection of PowerShell processes launched by cscript.exe or wscript.exe, indicative of potential malicious initial access or execution attempts.
Suspicious MS Office Child Process
2 rules 18 TTPs 1 CVEThis rule detects suspicious child processes spawned by Microsoft Office applications, indicating potential exploitation or malicious macros used for initial access, command execution, defense evasion, and discovery activities.
Suspicious Module Loaded by LSASS for Credential Access
2 rules 2 TTPsDetection of unsigned or untrusted DLLs being loaded into the LSASS process, which is indicative of credential access attempts by adversaries aiming to steal sensitive information such as user passwords.
RDP (Remote Desktop Protocol) from the Internet
2 rules 3 TTPs 1 CVEThis rule detects network events indicative of RDP traffic originating from the internet, which poses a significant security risk due to its frequent exploitation as an initial access or backdoor vector.
Python Site or User Customize File Creation for Persistence
2 rules 2 TTPsAttackers can exploit Python's sitecustomize.py and usercustomize.py files for persistence by injecting malicious code, allowing them to execute arbitrary commands upon Python startup.
Potential Defense Evasion via Symbolic Link of Common Linux Binaries to Writable Directories
2 rules 1 TTPAn adversary may create symbolic links of legitimate system binaries in world-writable directories to potentially bypass security restrictions or execute malicious code with elevated privileges by masquerading as a trusted process.
MSSQL xp_cmdshell Stored Procedure Abuse for Persistence and Execution
2 rules 2 TTPsAttackers leverage the MSSQL xp_cmdshell stored procedure to execute arbitrary commands, escalating privileges and establishing persistence on Windows systems.
MSIExec Spawning Discovery Commands
2 rules 1 TTPDetection of msiexec.exe spawning discovery commands indicating potential reconnaissance activity by attackers for system information gathering and lateral movement.
MpCmdRun Used for Remote File Download
2 rules 1 TTPAttackers are abusing the Windows Defender command-line utility, MpCmdRun.exe, to download malicious files from remote URLs, enabling them to introduce malware or offensive tooling into compromised environments.
Linux Cron File Creation for Persistence
2 rules 1 TTPAn attacker may create new cron files in cron directories to establish persistence on a Linux system, potentially leading to privilege escalation and arbitrary code execution.
Kubelet API Connection Attempt to Internal IP
2 rules 2 TTPsThe rule detects network connection attempts to the Kubernetes Kubelet API ports 10250 and 10255 on internal IP ranges from Linux hosts, indicating potential lateral movement within container and cluster environments.
Entra ID Service Principal Sign-in from Unusual Source ASN
2 rules 2 TTPsDetects Entra ID service principal sign-ins from a source ASN that is unusual based on a history window, potentially indicating compromised credentials or a rogue application.
Entra ID OAuth User Impersonation to Microsoft Graph
2 rules 2 TTPsDetects potential session hijacking or token replay in Microsoft Entra ID, where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, indicating a successful OAuth phishing attack, session hijacking, or token replay attack.
Detection of Azure Service Principal Creation
3 rules 1 TTPDetects the creation of a service principal in Azure, which could indicate potential attacker activity for lateral movement or persistence.
Azure AD Successful Authentication Increase
2 rules 1 TTPThis detection identifies a statistically significant (10% or greater) increase in successful sign-ins to Azure Active Directory, potentially indicating credential compromise or account takeover attempts.
Azure AD Hybrid Health AD FS Service Deletion for Defense Evasion
2 rules 1 TTPThreat actors may delete Azure AD Hybrid Health AD FS service instances after using them to spoof AD FS signing logs for defense evasion.
UAC Bypass via DiskCleanup Scheduled Task Hijack
2 rules 3 TTPsAttackers bypass User Account Control (UAC) to stealthily execute code with elevated permissions by hijacking the DiskCleanup Scheduled Task, leveraging specific arguments with non-standard executables.
Container Runtime CLI Execution with Suspicious Arguments
2 rules 2 TTPsDetects execution of container runtime CLI tools (ctr, crictl, nerdctl) with arguments indicating container creation, command execution inside existing containers, image manipulation, or host filesystem mounting, potentially leading to privileged container creation and unauthorized access to sensitive data.
Azure Service Principal Removal Detection
2 rules 1 TTPDetection of a service principal removal in Azure, potentially indicating malicious activity or an attempt to remove evidence of a compromise.
Unsecured Elasticsearch Node Inbound Connection
2 rules 2 TTPsThis rule identifies potentially unsecured Elasticsearch nodes that lack TLS and/or authentication and are accepting inbound network connections, which could allow adversaries to gain initial access, exfiltrate data, or disrupt services.
Potential Database Dumping Activity on Linux
2 rules 1 TTPThis rule detects the use of database dumping utilities to exfiltrate data from a database on Linux systems, where attackers may attempt to dump the database to a file and then exfiltrate the file to a remote server.
Suspicious Non-Interactive PowerShell Process Creation
2 rules 1 TTPDetects PowerShell processes spawned by non-interactive parent processes, potentially indicating malicious script execution or automation bypassing user interaction.
Registry Persistence via AppCert DLL
2 rules 2 TTPsDetection of Registry Persistence via AppCert DLL, which involves modifying registry keys to load malicious DLLs upon process creation, enabling persistence and potential privilege escalation.
Kubernetes Multi-Resource Discovery Reconnaissance
2 rules 1 TTPAdversaries may perform reconnaissance in a Kubernetes environment by rapidly querying multiple resource types to map the environment and identify potential privilege escalation paths.
Unusual Network Connection via DllHost
2 rules 2 TTPsThe rule identifies unusual instances of dllhost.exe making outbound network connections to non-local IPs, which may indicate adversarial Command and Control activity and defense evasion.
Unsigned DLL Side-Loading from Suspicious Folders by Trusted Processes
2 rules 2 TTPsThis detection identifies a Windows trusted program running from locations often abused by adversaries to masquerade as a trusted program and loading a recently dropped unsigned DLL, which indicates an attempt to evade defenses via side-loading a malicious DLL within the memory space of a signed process.
Suspicious PowerShell Engine ImageLoad
2 rules 1 TTPThis rule identifies instances where the PowerShell engine is loaded by processes other than powershell.exe, potentially indicating attackers attempting to use PowerShell functionality stealthily by using the underlying System.Management.Automation namespace and bypassing PowerShell security features.
Suspicious MSBuild Execution from Scripting Processes
2 rules 6 TTPsAdversaries may use MSBuild, a legitimate Microsoft tool, to execute malicious code through script interpreters for defense evasion and execution on Windows systems.
Suspicious Execution from a Mounted Device
2 rules 9 TTPsAttackers may use mounted devices as a non-standard working directory to execute signed binaries or script interpreters, evading traditional defense mechanisms, particularly when launched via explorer.exe.
Suspicious CertUtil Commands Used for Defense Evasion
2 rules 3 TTPsAttackers abuse certutil.exe, a native Windows utility, to download/deobfuscate malware for command and control or data exfiltration, evading defenses.
Remote Execution via File Shares
2 rules 2 TTPsThis rule identifies the execution of a file that was created by the virtual system process, potentially indicating lateral movement via network file shares in Windows environments.
Potential RemoteMonologue Attack via Registry Modification
2 rules 4 TTPsThis rule detects potential RemoteMonologue attacks by identifying attempts to perform session hijacking via COM object registry modification, specifically when the RunAs value is set to Interactive User.
Potential Defense Evasion via Filter Manager (fltMC.exe)
2 rules 1 TTPAdversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, thereby evading security software defenses such as malware detection and file system monitoring.
Kerberos Traffic from Unusual Process
2 rules 2 TTPsDetects network connections to the standard Kerberos port from an unusual process other than lsass.exe, potentially indicating Kerberoasting or Pass-the-Ticket activity on Windows systems.
Execution from Unusual Directory - Command Line
2 rules 2 TTPsThis rule identifies process execution from suspicious default Windows directories, which adversaries may abuse to hide malware in trusted paths to evade defenses.
Detecting Remote Windows Service Installation for Lateral Movement
2 rules 3 TTPsThis rule detects a network logon followed by Windows service creation with the same LogonId on a Windows host, which could indicate lateral movement or persistence by adversaries.
WMI Incoming Lateral Movement
3 rules 2 TTPsDetection of processes executed via Windows Management Instrumentation (WMI) on a remote host indicating potential adversary lateral movement.
WinPEAS PowerShell Script Execution Detection
2 rules 8 TTPsThis brief documents the detection of the WinPEAS PowerShell script execution on Windows systems, a tool commonly used for identifying privilege escalation paths by identifying specific function names used within the script.
Windows System Restore Disabled via Registry Modification
2 rules 1 TTPAttackers disable Windows System Restore by modifying specific registry keys to hinder recovery efforts after malicious activity.
Windows System File Ownership Change via Takeown or Icacls
2 rules 2 TTPsAdversaries may modify file or directory ownership to evade access control lists (ACLs) and access protected files by using takeown.exe or icacls.exe to grant excessive permissions to system files.
Windows Subsystem for Linux Enabled via Dism Utility
2 rules 1 TTPAdversaries may enable and use Windows Subsystem for Linux (WSL) using the Microsoft Dism utility to evade detection on Windows systems by running Linux applications and tools.
Windows Software Discovery via PowerShell Registry Queries
2 rules 3 TTPsAttackers use PowerShell to query the Windows registry's Uninstall key to discover installed software and identify potential vulnerabilities for exploitation.
Windows Script Interpreter Executing Process via WMI
2 rules 4 TTPsThe rule identifies the use of Windows script interpreters (cscript.exe or wscript.exe) executing a process via Windows Management Instrumentation (WMI), which may indicate malicious activity, especially when initiated by non-system accounts.
Windows Root Certificate Modification Detection
2 rules 2 TTPsThe modification of root certificates on Windows systems by unauthorized processes can allow attackers to masquerade malicious files as valid signed components and intercept/decrypt SSL traffic, leading to defense evasion and data collection.
Windows Host Network Discovery Enabled via Netsh
2 rules 1 TTPAttackers can enable host network discovery via netsh.exe to weaken host firewall settings, facilitating lateral movement by identifying other systems on the network.
Windows Guest Account Enabled via net.exe
2 rules 1 TTPThe Windows guest account, typically restricted, can be enabled via `net.exe` for malicious activities like malware installation or data theft, potentially indicating persistence, defense evasion, privilege escalation or initial access.
Windows Firewall Rule Modification Detection
2 rulesThis detection identifies instances where a Windows Firewall rule has been modified, potentially indicating an attempt to weaken security policies and allow malicious traffic or prevent legitimate communications.
Windows Firewall Rule Deletion Detection
2 rules 1 TTPDetection of Windows Firewall rule deletion events (Event ID 4948) indicating potential attacker attempts to bypass security controls or malware disabling protections for persistence and command-and-control.
Windows Firewall Rule Added via Event ID 4946
2 rulesThis detection identifies instances where a Windows Firewall rule is added by monitoring Event ID 4946 in the Windows Security Event Log, potentially indicating unauthorized changes or malicious activity such as attackers allowing traffic for backdoors or persistence mechanisms.
Windows Firewall Disabled via PowerShell
2 rules 2 TTPsAttackers may disable the Windows firewall or its rules using the `Set-NetFirewallProfile` PowerShell cmdlet to enable lateral movement and command and control activity.
Windows Firewall Disabled via Netsh
2 rules 1 TTPAttackers use the `netsh.exe` command-line tool to disable or weaken the local Windows firewall, facilitating lateral movement and command and control by bypassing host-based network traffic filtering.
Windows Defender Tracing Level Modification
2 rulesThe following analytic detects modifications to the Windows registry specifically targeting the 'WppTracingLevel' setting within Windows Defender, potentially impairing its diagnostic capabilities and allowing attackers to evade detection.
Windows Defender Throttle Rate Modification
2 rules 1 TTPAn attacker modifies the Windows Defender ThrottleDetectionEventsRate registry setting to reduce the frequency of logged detection events, potentially evading detection.
Windows Defender Signature Retirement Disabled via Registry Modification
2 rules 1 TTPAn attacker disables Windows Defender's signature retirement feature by modifying a registry key, potentially reducing its effectiveness in detecting threats by allowing older, less relevant signatures to persist.
Windows Defender Scan On Update Disabled via Registry Modification
2 rules 1 TTPAn attacker modifies the Windows registry to disable the Windows Defender Scan On Update feature, potentially evading detection and establishing persistence.
Windows Defender Reporting Disabled via Registry Modification
2 rules 1 TTPAttackers modify the Windows registry to disable Windows Defender generic reports, preventing error reports and potentially hiding malicious activity.
Windows Defender Exclusions Added via PowerShell
2 rules 3 TTPsAdversaries may attempt to bypass Windows Defender's capabilities by using PowerShell to add exclusions for folders or processes, and this activity can be detected by monitoring PowerShell command lines that use `Add-MpPreference` or `Set-MpPreference` with exclusion parameters.
Windows Auditpol ResourceSACL Clearing for Defense Evasion
2 rulesAdversaries may clear the global object access auditing policy using `auditpol.exe` with the `/resourceSACL` flag and either `/clear` or `/remove` arguments to evade detection by removing audit configurations.
Windows Audit Policy Sub-Category Disabled
2 rules 3 TTPsThis rule detects attempts to disable auditing for security-sensitive audit policy sub-categories on Windows systems, often done by attackers to evade detection and forensic analysis.
Windows Application Hotkey Disablement via Registry Modification
2 rules 1 TTPAttackers disable Windows application hotkeys by modifying specific registry entries to hinder incident response and evade detection.
Windows AD GPO Disabled
3 rules 1 TTPDetection of Active Directory Group Policy being disabled using the Group Policy Management Console, potentially indicating malicious attempts to weaken security controls.
Web Server Request Command Injection Attempt
2 rules 5 TTPsDetection of potential command injection attempts via web server requests by identifying URLs containing suspicious patterns associated with command execution payloads, which attackers exploit to execute arbitrary commands on the server.
User Removed from Group with Conditional Access Policy Modification Access
2 rules 3 TTPsAn attacker removes a user from a privileged Azure Active Directory group with permissions to modify Conditional Access policies, potentially leading to privilege escalation, persistence, or defense evasion.
User Added to Privileged Group in Active Directory
2 rules 1 TTPAdversaries may add a user to a privileged group in Active Directory, such as Domain Admins, to maintain persistent access and elevate privileges within the domain.
Unusual Volume of File Deletion in Microsoft 365
2 rules 1 TTPAn attacker may delete an unusual volume of files in Microsoft 365 to cause disruption or hide malicious activity.
Unusual Source IP for Azure Arc Cluster Credential Access
2 rules 2 TTPsDetects when a service principal or user performs an Azure Arc cluster credential listing operation from a source IP not previously associated with that identity, potentially indicating compromised credentials.
Unusual Process Connecting to Docker or Containerd Socket
2 rules 3 TTPsAn unusual process connecting to a container runtime Unix socket like Docker or Containerd can indicate an attacker attempting to bypass Kubernetes security measures for container manipulation.
Unused Privileged Identity Management (PIM) Roles in Azure
2 rules 1 TTPDetection of assigned but unused privileged roles in Azure's Privileged Identity Management (PIM) service, indicating potential misconfiguration, license overuse, or dormant privileged access that could be exploited.
Uncommon Registry Persistence Change Detection
2 rules 2 TTPsThis rule detects changes to uncommon registry persistence keys on Windows systems that are not commonly used or modified by legitimate programs, which could indicate an adversary's attempt to persist in a stealthy manner by modifying registry keys for persistence, ensuring malicious code executes on startup or during specific events.
Unauthorized Guest User Invitation Attempt in Azure
2 rules 1 TTPDetection of a failed attempt to invite an external guest user by an Azure user lacking the necessary permissions, potentially indicating privilege escalation or malicious insider activity.
Unauthorized Conditional Access Policy Creation in Azure AD
2 rules 1 TTPAn unauthorized actor created a new Conditional Access policy in Azure AD, potentially leading to privilege escalation and unauthorized access.
UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer
2 rules 3 TTPsThis threat brief details a UAC bypass technique leveraging the Internet Explorer Add-On Installer (ieinstal.exe) and Component Object Model (COM) to execute arbitrary code with elevated privileges.
TeamFiltration Tool User-Agent Detected in Entra ID Sign-ins
2 rules 7 TTPs 1 IOCThe TeamFiltration tool, used for Entra ID and Microsoft 365 enumeration and password spraying, is detected via specific user-agent strings in sign-in logs.
System Process Executables Created in Unusual Locations
3 rules 1 TTPThe creation of executable files masquerading as legitimate Windows system processes in non-standard directories indicates potential malware installation or defense evasion tactics by threat actors.
Suspicious SolarWinds Child Process Execution
2 rules 2 TTPsDetection of unusual child processes spawned by SolarWinds processes may indicate malicious program execution, potentially bypassing security controls.
Suspicious SMB Connections via LOLBin or Untrusted Process
3 rules 1 TTPThis rule identifies potentially suspicious processes, excluding those signed by Microsoft, making Server Message Block (SMB) network connections over port 445, which could indicate lateral movement attempts.
Suspicious Script Object Execution via scrobj.dll
2 rules 2 TTPsDetection of scrobj.dll loaded into unusual Microsoft processes indicates potential malicious scriptlet execution for defense evasion and execution by abusing legitimate system binaries.
Suspicious PowerShell Module DLL Creation
2 rules 3 TTPsThe creation of a DLL file within PowerShell module directories can indicate malicious PowerShell activity, such as installing new modules or attempts at ScriptBlock smuggling, and this activity is detected using Sysmon Event ID 11.
Suspicious PDF Reader Child Process Execution
3 rules 4 TTPsAdversaries may exploit vulnerabilities in PDF reader applications or use social engineering to execute malicious commands, often spawning system utilities for discovery or defense evasion purposes.
Suspicious Network Connection via Registration Utility
2 rules 4 TTPsThe native Windows tools regsvr32.exe, regsvr64.exe, RegSvcs.exe, or RegAsm.exe making a network connection may indicate an attacker bypassing allowlists or running arbitrary scripts via a signed Microsoft binary.
Suspicious MS Office Child Process
2 rules 18 TTPsDetects suspicious child processes of Microsoft Office applications, indicating potential exploitation or malicious macros for initial access, defense evasion, and execution.
Suspicious Mofcomp Activity Leading to WMI Abuse
2 rules 3 TTPsAttackers may leverage the mofcomp.exe utility to compile malicious MOF files, enabling them to manipulate the Windows Management Instrumentation (WMI) repository for persistence or execution of arbitrary code.
Suspicious Modifications to Windows Security Support Provider (SSP) Registry
2 rules 2 TTPsAdversaries may modify the Windows Security Support Provider (SSP) configuration in the registry to establish persistence or evade defenses.
Suspicious Microsoft Workflow Compiler Usage
2 rules 1 TTPThe use of Microsoft Workflow Compiler (microsoft.workflow.compiler.exe), a rarely utilized executable typically found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319, can indicate malicious intent such as code execution or persistence mechanisms, potentially leading to unauthorized access.
Suspicious LSASS Process Access
3 rules 1 TTPThis rule identifies suspicious access attempts to the LSASS process, potentially indicating credential dumping attempts by filtering out legitimate processes and access patterns to focus on anomalies.
Suspicious HTML File Creation Leading to Potential Payload Delivery
3 rules 3 TTPsThis detection identifies the creation of HTML files with high entropy and large size, followed by execution via a browser process, indicating potential HTML smuggling and malicious payload delivery on Windows systems.
Suspicious Execution from VS Code Extension
2 rules 9 TTPsMalicious VS Code extensions can execute arbitrary commands, leading to initial access and subsequent payload deployment on Windows systems.
Suspicious Endpoint Security Parent Process Detected
2 rules 2 TTPsThis rule detects suspicious parent processes of endpoint security solutions such as Elastic Defend, Microsoft Defender, and SentinelOne, indicating potential process hollowing or code injection attempts to evade detection.
Suspicious Dynamic .NET Compilation via Csc.exe
2 rules 1 TTPAttackers may use csc.exe to compile .NET code on the fly to evade detection, often placing the compiler and source code in suspicious locations, which can be detected by monitoring process creation events.
Suspicious DNS Queries to RMM Domains from Non-Browser Processes
2 rulesDetection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.
Suspicious Copy from or to System Directory
3 rules 1 TTPThis threat involves the suspicious copying of files from or to Windows system directories (System32, SysWOW64, WinSxS) using command-line tools, often employed by attackers to relocate LOLBINs for defense evasion.
Suspicious AWS STS GetSessionToken Usage
2 rules 2 TTPsThe AWS STS GetSessionToken API is being misused to create temporary tokens for lateral movement and privilege escalation within AWS environments by potentially compromised IAM users.
Suspicious AWS EC2 Key Pair Creation from Non-Cloud AS
2 rules 3 TTPsAn AWS EC2 CreateKeyPair event triggered by a new principal originating from a network autonomous system (AS) organization not associated with major cloud providers, indicating potential unauthorized access or persistence activity.
Suspicious Access to Windows Product Key Registry
2 rules 1 TTPDetection of processes attempting to access the Windows registry to recover product keys, potentially indicating malware activity, unauthorized security bypass, or data exfiltration.
Successful AWS IAM Group Deletion Detection
2 rules 1 TTPSuccessful deletion of an AWS IAM group, while not inherently malicious, can indicate insider threat activity, account compromise, or attempts to remove audit trails, and should be monitored.
Spike in AWS Security Hub Alerts for EC2 Instance
2 rules 6 TTPsDetects a sudden increase in security alerts generated by AWS Security Hub related to a specific EC2 instance, potentially indicating active compromise or misconfiguration.
SolarWinds Process Disabling Services via Registry Modification
2 rules 3 TTPsA SolarWinds binary is modifying the start type of a service to be disabled via registry modification, potentially to disable or impair security services.
Signed Proxy Execution via MS Work Folders
2 rules 3 TTPsAttackers can abuse Windows Work Folders to execute a masqueraded control.exe file from untrusted locations, potentially bypassing application controls for defense evasion and privilege escalation.
SharePoint Sensitive Term Discovery via O365 Logs
2 rules 1 TTPAdversaries may search for sensitive terms within SharePoint to identify valuable data for exfiltration or further compromise, leaving traces in O365 audit logs.
Service Startup Type Modification via WMIC
2 rules 2 TTPsAdversaries use the Windows Management Instrumentation Command-line (WMIC) utility to modify the startup type of services, setting them to 'Manual' or 'Disabled' to impair defenses or disrupt system operations.
SeDebugPrivilege Enabled by a Suspicious Process
2 rules 1 TTPThe rule identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege, which can be used by adversaries to debug and modify other processes to escalate privileges and bypass access controls.
Schtasks Run Task On Demand
2 rules 1 TTPDetection of on-demand execution of Windows Scheduled Tasks via the schtasks.exe command-line utility, a common technique for persistence and lateral movement.
Scheduled Task Creation via Scripting
3 rules 3 TTPsDetection of scheduled task creation by Windows scripting engines like cscript.exe, wscript.exe, or powershell.exe, used by adversaries to establish persistence on compromised systems.
Scheduled Task Creation via Group Policy Object
2 rules 2 TTPsDetects the creation of scheduled tasks within a Group Policy Object (GPO) by monitoring for the creation of the ScheduledTasks.xml file in the SYSVOL share, potentially indicating malicious persistence.
RMM Domain DNS Queries from Non-Browser Processes
2 rules 75 IOCsDetects DNS queries to commonly abused remote monitoring and management (RMM) or remote access software domains from non-browser processes, potentially indicating unauthorized remote access or command and control activity.
Right-to-Left Override (RTLO) Masquerading
3 rules 2 TTPsAdversaries use the Right-to-Left Override (RTLO) character in filenames to disguise malicious files and trick users into executing them, leading to potential malware infection and system compromise.
Renamed Utility Executed with Short Program Name
2 rules 1 TTPThis rule detects the execution of renamed utilities with a single-character process name, differing from the original filename, a common technique used by adversaries for staging, executing temporary utilities, or bypassing security detections.
Remote Scheduled Task Creation via RPC
2 rules 2 TTPsThe creation of scheduled tasks from a remote source via RPC, where the RpcCallClientLocality and ClientProcessId are 0, indicates potential adversary lateral movement within a Windows environment.
Remote File Download via Desktopimgdownldr Utility
3 rules 1 TTPThe desktopimgdownldr utility can be abused to download remote files, potentially bypassing standard download restrictions and acting as an alternative to certutil for malware or tool deployment.
Remote File Copy to a Hidden Share
2 rules 3 TTPsThis rule detects remote file copy attempts to hidden network shares, which may indicate lateral movement or data staging activity, by identifying suspicious file copy operations using command-line tools like cmd.exe and powershell.exe focused on hidden share patterns.
Registry Persistence via AppInit DLL Modification
2 rules 2 TTPsModification of the AppInit DLLs registry keys on Windows systems allows attackers to execute code in every process that loads user32.dll, establishing persistence and potentially escalating privileges.
Regasm.exe Making External Network Connection
2 rules 2 TTPsThe detection of regasm.exe, a Microsoft-signed binary, establishing a network connection to a public IP address (excluding private ranges) may indicate command and control activity or attempts to bypass application control.
RDP Enabled via Registry Modification
2 rules 2 TTPsAn adversary may enable Remote Desktop Protocol (RDP) access by modifying the `fDenyTSConnections` registry key, potentially indicating lateral movement preparation or defense evasion.
Process Created with a Duplicated Token
2 rules 2 TTPsThis rule identifies the creation of a process impersonating the token of another user logon session on Windows, potentially indicating privilege escalation.
Privileged Account Brute Force Detection
2 rules 2 TTPsMultiple consecutive logon failures targeting admin accounts from the same source IP address within a short timeframe indicates potential brute-force activity targeting privileged accounts on Windows systems.
PowerShell Script with Encryption/Decryption Capabilities
2 rules 3 TTPsPowerShell scripts employing .NET cryptography APIs are used to encrypt data for impact or decrypt payloads for defense evasion.
PowerShell Get-DomainPolicy Usage for Reconnaissance
2 rules 1 TTPAdversaries use the PowerShell `Get-DomainPolicy` commandlet to enumerate domain password policies for situational awareness and Active Directory discovery, logged via PowerShell Script Block Logging.
Potential Windows Error Manager Masquerading
2 rules 1 TTPAdversaries may masquerade malicious processes as legitimate Windows Error Reporting processes (WerFault.exe or Wermgr.exe) to evade detection by establishing network connections without arguments, thus blending into normal system activity.
Potential Protocol Tunneling via Yuze
2 rules 3 TTPsThis brief describes the detection of Yuze, an open-source tunneling tool often executed via rundll32 to proxy C2 or pivot traffic within a compromised network.
Potential PowerShell Obfuscation via Special Character Overuse
2 rules 3 TTPsThis rule detects PowerShell scripts heavily obfuscated with whitespace and special characters, often used to evade static analysis and AMSI, by identifying scripts with low symbol diversity and a high proportion of whitespace and special characters.
Potential Persistence via Time Provider Modification
2 rules 2 TTPsThe rule detects potential persistence via modification of the Time Provider in Windows by adversaries who register and enable a malicious DLL as a time provider, allowing for persistent code execution.
Potential Persistence via Mandatory User Profile Modification
2 rules 2 TTPsAdversaries may abuse Windows mandatory profiles by dropping a malicious NTUSER.MAN file containing pre-populated persistence-related registry keys to establish persistence, which can evade traditional registry-based monitoring.
Potential Masquerading as Communication Apps
2 rules 3 TTPsAttackers may attempt to evade defenses by masquerading malicious processes as legitimate communication applications such as Slack, WebEx, Teams, Discord, RocketChat, Mattermost, WhatsApp, Zoom, Outlook and Thunderbird.
Potential LSA Authentication Package Abuse
2 rules 2 TTPsAdversaries can abuse the Local Security Authority (LSA) authentication packages by modifying the Windows registry to achieve privilege escalation or persistence by executing binaries with SYSTEM privileges.
Potential DNS Tunneling via NsLookup
2 rules 2 TTPsDetection of multiple nslookup.exe executions with explicit query types from a single host, potentially indicating command and control activity via DNS tunneling, where attackers abuse DNS for data infiltration or exfiltration.
Potential DLL Side-Loading via Trusted Microsoft Programs
2 rules 2 TTPsThis rule detects potential DLL side-loading attempts by identifying trusted Microsoft programs (WinWord.exe, EXPLORER.EXE, w3wp.exe, DISM.EXE) running from non-standard paths or after being renamed to evade defenses.
Potential Defense Evasion via WSL Child Processes
2 rules 2 TTPsAdversaries may attempt to evade detection by executing malicious commands or scripts through child processes spawned from the Windows Subsystem for Linux (WSL), potentially bypassing traditional Windows-based security monitoring.
Potential Cloudflared Network Tunnel Detection
2 rules 1 TTPThis brief detects network connection events associated with the Cloudflared tool, used to create tunnels via Cloudflare, potentially for unauthorized access or exfiltration, by establishing outbound connections to Cloudflare Edge Servers.
Potential Adobe Hijack Persistence Mechanism
2 rules 1 TTPThis brief outlines a potential persistence mechanism involving hijacking Adobe-related processes or components, which could allow attackers to maintain unauthorized access to a system.
PhpSpreadsheet CPU Denial of Service via Unbounded Row Number
2 rules 1 TTPA vulnerability in PhpSpreadsheet exists where a crafted XLSX file containing a large row number can cause excessive CPU consumption due to unbounded loop iterations, leading to a denial of service.
phpMyFAQ Unauthenticated FAQ Permission Bypass via Solution ID Enumeration
2 rules 1 TTPphpMyFAQ version 4.1.1 and earlier is vulnerable to an unauthenticated FAQ permission bypass, allowing attackers to enumerate solution IDs and discover restricted FAQ titles due to missing permission filters in key functions.
Persistence via Visual Studio Tools for Office (VSTO) Add-ins
2 rules 1 TTPThe Visual Studio Tools for Office (VSTO) add-ins can be abused by attackers to establish persistence in Microsoft Office applications by modifying registry keys.
OpenEMR Stored XSS Vulnerability in CCDA Document Preview (CVE-2026-33932)
2 rules 1 TTPA stored cross-site scripting (XSS) vulnerability in OpenEMR's CCDA document preview (CVE-2026-33932) allows an attacker to execute arbitrary JavaScript in a clinician's browser session by uploading a malicious CCDA document.
OpenEMR Authentication Brute Force Vulnerability (CVE-2023-54347)
2 rules 1 TTP 1 CVEOpenEMR version 7.0.1 is vulnerable to an authentication brute force attack where attackers can bypass rate limiting by sending repeated login attempts, leading to potential unauthorized access.
OneDrive Share Mounted via Net Utility for Potential Data Exfiltration
2 rules 1 TTPAdversaries may mount OneDrive shares as network drives using net.exe or net1.exe to stage, access, or exfiltrate data through cloud-hosted WebDAV paths, potentially bypassing traditional file share monitoring.
Ollama API Endpoint Scan Reconnaissance
1 rule 1 TTPDetects potential reconnaissance activity against Ollama servers by identifying sources probing multiple API endpoints within short timeframes, indicative of attackers mapping the API surface for vulnerabilities.
Okta Unauthorized Application Access Attempt
3 rulesThis brief describes a detection for unauthorized application access attempts within an Okta environment, indicating a potential security breach or misconfiguration.
Okta Unauthorized Access to Application
2 rules 2 TTPsAnomalous activity indicating a user is attempting to access Okta applications they have not been assigned, potentially leading to data exposure or service disruption.
Okta Successful Single Factor Authentication Attempt
2 rules 3 TTPs 2 IOCsSuccessful single-factor authentication events against the Okta Dashboard for accounts without Multi-Factor Authentication (MFA) enabled, potentially indicating account takeover attempts.
Okta MFA Reset or Deactivation Attempt
2 rules 1 TTPAn attacker attempts to disable or reset multi-factor authentication (MFA) for a user account in Okta, potentially leading to unauthorized access and account compromise.
Okta Group Privilege Change Spike via ML Detection
2 rules 4 TTPsA machine learning job has identified an unusual spike in Okta group privilege change events, indicating potential privileged access activity where attackers might be elevating privileges by adding themselves or compromised accounts to high-privilege groups, enabling further access or persistence.
Okta Authentication Failed During MFA Challenge
2 rules 3 TTPsDetection of failed authentication attempts during Okta MFA challenges, potentially indicating compromised credentials and attempts to bypass MFA.
Okta Application Sign-On Policy Modified or Deleted
2 rules 1 TTPAttackers may modify or delete Okta application sign-on policies to weaken security controls, potentially leading to unauthorized access and data breaches.
Okta Application Modified or Deleted
2 rules 1 TTPDetects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.
Okta API Token Revoked
2 rules 1 TTPDetection of Okta API token revocation events, indicating potential unauthorized access or compromise.
Okta API Token Creation
2 rules 1 TTPDetection of Okta API token creation events which can indicate malicious persistence activity.
Office Application Autorun Registry Key Modification
2 rules 1 TTPAdversaries modify Office application autostart extensibility point (ASEP) registry keys to achieve persistence and execute malicious code when Office applications are launched.
Office 365 MFA Notification Email Deletion for Defense Evasion
2 rules 1 TTPAttackers may delete multi-factor authentication (MFA) notification emails in Office 365 to evade detection and maintain unauthorized access after compromising an account.
O365 Email Access By Security Administrator
2 rules 2 TTPsAtypical access to O365 mailboxes is detected when a security administrator uses Threat Explorer features to directly view email, potentially indicating reconnaissance or data exfiltration by a compromised or malicious insider.
O365 Data Loss Prevention Rule Triggered
2 rules 2 TTPsDetection of triggered Microsoft Office 365 Data Loss Prevention (DLP) rules, which can indicate potential data exfiltration or policy violations, dependent on upstream DLP configuration.
O365 Compliance Content Search Activity Detected
2 rules 1 TTPDetection of content search initiation within the Office 365 Security and Compliance Center using the SearchCreated operation, which may signal unauthorized access to sensitive organizational data such as emails and documents, potentially leading to data exfiltration and compliance breaches.
O365 Application Registration Owner Added
3 rules 1 TTPA new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.
O365 Advanced Audit Disabled
2 rules 1 TTPThe O365 Advanced Audit feature provides critical logging and insights into user and administrator activities, and this analytic detects instances where it is disabled for a specific user, potentially blinding security teams to malicious actions.
NullSessionPipe Registry Modification for Lateral Movement
3 rules 2 TTPsAttackers modify the NullSessionPipe registry setting in Windows to enable anonymous access to named pipes, potentially facilitating lateral movement and unauthorized access to network resources.
Notepad++ Updater Querying Uncommon Domains
2 rules 2 TTPsThe Notepad++ updater, gup.exe, makes DNS queries to domains not part of the legitimate update infrastructure, potentially indicating updater mechanism exploitation or suspicious network activity.
New ActiveSync Allowed Device Added via PowerShell
2 rules 3 TTPsThe rule detects the use of the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially allowing attackers to gain persistent access to sensitive email data by adding unauthorized devices.
Network Logon Provider Registry Modification
2 rules 2 TTPsAdversaries may modify the network logon provider registry to register a rogue network logon provider module for persistence and credential access by intercepting authentication credentials in clear text during user logon.
Netty HTTP/3 QPACK Literal Unbounded Allocation Vulnerability
3 rules 1 TTPA vulnerability in Netty's HTTP/3 QPACK decoder allows an attacker to cause a denial of service by sending a crafted HTTP/3 header that triggers excessive memory allocation, leading to a server crash.
Mustang Panda USB-Borne Tool Execution
2 rules 3 TTPsThis brief details detection of executables associated with Mustang Panda being launched from non-standard locations, potentially indicating compromise via USB or other removable media.
Multiple Remote Management Tool Vendors on Same Host
2 rulesThis rule identifies Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.
MSSQL xp_cmdshell Stored Procedure Abuse for Persistence
2 rules 2 TTPsAttackers may leverage the xp_cmdshell stored procedure in Microsoft SQL Server to execute arbitrary commands for privilege escalation and persistence, often bypassing default security configurations.
Mshta Making Network Connections Indicative of Defense Evasion
2 rules 1 TTPMshta.exe making outbound network connections may indicate adversarial activity, as it is often used to execute malicious scripts and evade detection by proxying execution of untrusted code.
Mozilla Firefox and Thunderbird Improper Boundary Condition Vulnerability (CVE-2026-4699)
2 rules 1 TTPCVE-2026-4699 describes an improper check for unusual or exceptional conditions in the Layout: Text and Fonts component of Mozilla Firefox and Thunderbird leading to a potential denial-of-service.
Microsoft Defender Tampering via Registry Modification
2 rules 2 TTPsAdversaries may disable or tamper with Microsoft Defender features via registry modifications to evade detection and conceal malicious behavior on Windows systems.
Microsoft Defender 'Block at First Seen' Feature Disabled
2 rules 1 TTPAn attacker disables the Microsoft Defender 'Block at First Seen' feature to allow potentially malicious files to execute without initial scrutiny, increasing the risk of malware infection and data compromise.
Microsoft CVE-2017-3736 Vulnerability
2 rulesCVE-2017-3736 is a vulnerability tracked by Microsoft, potentially leading to exploitation of affected systems.
Microsoft Build Engine Executed After Renaming
2 rules 2 TTPsAttackers may rename the Microsoft Build Engine (MSBuild) executable to evade detection and proxy execution of malicious code.
Microsoft 365 Suspicious Email Delivery
2 rules 2 TTPsThis brief outlines a threat where Microsoft Defender for Office 365 identifies an email as malicious or suspicious but still delivers it to a user's inbox or junk folder, potentially bypassing initial security measures.
Microsoft 365 SharePoint Site Administrator Added
2 rules 2 TTPsDetection of a new SharePoint Site Administrator added in Microsoft 365, which adversaries may leverage after compromising a privileged account to maintain persistent, high-privilege access, as seen in the 0mega ransomware campaign.
Microsoft 365 Risk-Based Step-Up Consent Disabled
2 rules 1 TTPThe Microsoft 365 'risk-based step-up consent' security setting is disabled by an adversary to allow users to grant consent to malicious applications, potentially leading to unauthorized access and data breaches.
Mass Azure Compute Snapshot Deletion
2 rules 2 TTPsThe rule detects mass deletion of Azure disk snapshots, which could indicate an adversary attempting to inhibit system recovery capabilities, destroy backup evidence, or prepare for a ransomware attack.
macOS QuickLook Thumbnail Cache Leak
2 rules 1 TTPmacOS QuickLook caches thumbnails and file paths of files, even those stored within encrypted containers or on removable USB devices, potentially revealing sensitive data to attackers with access to the running system.
macOS Kernel-to-Userland Process Creation Notification via undocumented kev_msg_post
2 rulesThe kev_msg_post function can be abused by malware to broadcast process creation notifications from a kernel extension (kext) to a user-mode application, potentially bypassing security tools that rely on standard APIs and leading to undetected malicious activity.
M365 SharePoint/OneDrive File Access via PowerShell
2 rules 4 TTPsDetects file downloads and access from OneDrive or SharePoint using PowerShell-based user agents, which adversaries leverage with compromised OAuth tokens to exfiltrate data.
M365 Identity OAuth Illicit Consent Grant by Rare Client and User
2 rules 3 TTPsAdversaries may register a malicious application in Microsoft Entra ID and trick users into granting excessive permissions via OAuth consent, allowing the malicious application to access resources in Microsoft 365 on behalf of the user, potentially leading to data exfiltration.
M365 Exchange Inbox Forwarding Rule Creation
2 rules 1 TTPDetection of new Microsoft 365 Exchange inbox forwarding rules indicating potential unauthorized email interception and exfiltration by attackers.
M365 Copilot Application Usage Pattern Anomalies
2 rules 1 TTPThis detection identifies anomalous M365 Copilot usage patterns indicative of potential account compromise or automated abuse by flagging users accessing Copilot from multiple locations, generating excessive daily activity, or utilizing multiple Copilot applications.
M365 Copilot Access from Non-Compliant Devices
2 rules 1 TTPDetects Microsoft 365 (M365) Copilot access from non-compliant or unmanaged devices, potentially indicating shadow IT, BYOD policy violations, or compromised endpoints accessing sensitive data.
LSASS Process Access via Windows API
2 rules 1 TTPDetects suspicious access to the LSASS process via Windows API calls, potentially indicating credential dumping and subsequent lateral movement.
LSA PPL Protection Setting Modification via CommandLine
2 rules 1 TTPAttackers modify LSA PPL protection settings via command-line tools like reg.exe and PowerShell to weaken system security and enable credential dumping.
Linux System Network Discovery via Multiple Utilities
2 rules 1 TTPAdversaries may attempt to enumerate local network configurations on Linux systems using common utilities like arp, ifconfig, ip, netstat, firewall-cmd, ufw, iptables, ss, and route to gather information for reconnaissance and subsequent attacks, leading to network mapping and vulnerability identification.
Linux Auditd Daemon Abort Detection
2 rules 1 TTPDetection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.
LatePoint WordPress Plugin Stored XSS Vulnerability
2 rules 1 CVEThe LatePoint WordPress plugin is vulnerable to stored XSS via the booking_form_page_url parameter, allowing unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user accesses the injected page.
Kubernetes Nginx Ingress Remote File Inclusion Attempt
2 rules 1 TTPThis analytic detects remote file inclusion (RFI) attacks targeting Kubernetes Nginx ingress controllers by analyzing Kubernetes logs from the Nginx ingress controller and identifying suspicious URL requests, potentially leading to arbitrary code execution or sensitive data access.
Kubernetes Forbidden Request from Unusual User Agent
2 rules 1 TTPDetection of forbidden requests originating from unusual user agents within a Kubernetes environment, potentially indicating adversary attempts to exploit vulnerabilities or evade detection by using non-standard user agents to interact with the Kubernetes API.
Kubernetes DaemonSet Deployment Detected
2 rules 1 TTP 2 IOCsThe creation of a Kubernetes DaemonSet is detected via Kubernetes Audit logs, indicating a potential attempt to maintain persistent access and control within the cluster by ensuring a specific pod runs on every node.
Kiteworks Secure Data Forms Stored XSS Vulnerability (CVE-2026-24750)
2 rules 1 TTP 1 IOCAn authenticated attacker can exploit a stored XSS vulnerability (CVE-2026-24750) in Kiteworks Secure Data Forms before version 9.2.1 due to improper neutralization of input, leading to arbitrary script execution in the context of other users.
Keras Model Loader Vulnerable to Denial-of-Service via Malicious HDF5 Shape Bombs
2 rules 1 TTP 1 CVE 1 IOCKeras model loader is vulnerable to denial-of-service by loading specially crafted .keras files containing HDF5-based weight files with maliciously oversized dataset metadata, leading to immediate memory exhaustion during model loading.
Katalyst Koi Session Cookies Replayable After Logout
2 rules 1 TTPKatalyst Koi versions before 4.20.0 and between 5.0.0 and 5.6.0 fail to invalidate admin session cookies upon logout, allowing attackers with a valid cookie to maintain unauthorized access.
IOBit Unlocker Extension DLL Registration via Regsvr32
2 rules 1 TTPThe IOBit Unlocker Extension DLL is being registered via regsvr32.exe, a Windows utility used to unlock files or folders by terminating locking processes, which could be abused for malicious purposes.
Incoming Execution via WinRM Remote Shell
2 rules 1 TTPThis rule detects incoming execution via Windows Remote Management (WinRM) remote shell on a target host, which could be an indication of lateral movement by monitoring network traffic on ports 5985 or 5986 and processes initiated by WinRM.
i18next-http-middleware HTTP Response Splitting and DoS Vulnerability
2 rules 1 TTPi18next-http-middleware versions before 3.9.3 are vulnerable to HTTP response splitting and denial-of-service attacks due to unsanitized Content-Language headers, potentially leading to session fixation, cache poisoning, reflected XSS, or complete service disruption depending on the Node.js version.
Host File System Changes via Windows Subsystem for Linux
2 rules 2 TTPsThis rule detects file creation and modification on the host system from the Windows Subsystem for Linux (WSL), potentially indicating defense evasion by adversaries.
Hickory DNS NSEC3 Validation Vulnerability Leads to DoS
2 rules 1 TTPA vulnerability in Hickory DNS's NSEC3 closest-encloser proof validation allows a remote attacker to cause a denial of service by exhausting memory when processing crafted DNS responses with mismatched SOA records.
GSuite Suspicious File Share with Phishing Filenames
2 rules 1 TTPThis analytic detects suspicious file sharing activity in Google Workspace where files are shared with names commonly associated with phishing campaigns, such as 'invoice,' 'shipment,' or 'delivery', potentially leading to credential theft or malware infection.
GSuite Email with Suspicious Attachment
2 rules 1 TTPThis analytic detects GSuite emails with suspicious file attachments (e.g., .exe, .bat, .js) which may indicate a spear-phishing attack leading to malware deployment and potential system compromise.
GSuite Email with Known Abuse Web Service Links
2 rules 1 TTP 2 IOCsThis analytic detects emails in Gsuite containing links to known abuse web services such as Pastebin, Telegram, and Discord, commonly used by attackers to deliver malicious payloads leading to malware, phishing, or other harmful activities.
Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Gravity Forms plugin for WordPress is vulnerable to unauthenticated stored cross-site scripting (XSS) in versions up to 2.10.0, allowing attackers to inject arbitrary JavaScript code into the product name field within repeater fields, which executes when an administrator views the affected entry.
GPO Scheduled Task or Service Creation/Modification
2 rules 3 TTPsDetection of the creation or modification of new Group Policy based scheduled tasks or services, which can be abused by attackers with domain admin permissions to execute malicious payloads remotely on domain-joined machines, leading to privilege escalation and persistence.
GPO Scheduled Task Abuse for Privilege Escalation and Lateral Movement
2 rules 3 TTPsAttackers abuse Group Policy Objects by modifying scheduled task attributes to execute malicious commands across objects controlled by the GPO, potentially leading to privilege escalation and lateral movement.
GPO Modification to Add Startup/Logon Scripts
2 rules 3 TTPsThis rule detects the modification of Group Policy Objects (GPO) to add a startup or logon script to user or computer objects, enabling attackers to achieve privilege escalation and persistence by executing arbitrary commands at scale.
Gotenberg Denial of Service via Context Pool Reuse
2 rules 2 TTPsGotenberg versions 8.31.0 and earlier are vulnerable to an unauthenticated denial-of-service attack where a race condition in the webhook middleware causes a panic and process termination when handling concurrent requests.
GoBGP Remote Denial of Service via Malformed BGP UPDATE Message
2 rules 1 TTPA remote Denial of Service (DoS) vulnerability exists in GoBGP version 4.2.0 and earlier, where a malformed BGP UPDATE message can trigger a runtime error (index out of range panic), crashing the GoBGP process. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. A single malicious peer or a malformed route propagated through a transit provider can consistently crash the BGP daemon, leading to a complete loss of routing capabilities.
GitHub Repository Archived in Organization
2 rules 2 TTPsThis analytic detects the archival of a repository within a GitHub Organization, potentially indicating malicious activity such as attempts to make code inaccessible, insider threats, or account compromise.
GitHub Owner Role Granted to User
2 rules 2 TTPsDetection of a member being granted the organization owner role in GitHub, potentially indicating unauthorized privilege escalation and persistence by an attacker.
GitHub Organizations 2FA Disabled
3 rules 3 TTPsThe disabling of two-factor authentication (2FA) in GitHub Organizations is detected through audit log monitoring, potentially indicating an attacker's attempt to weaken account security and facilitate unauthorized access.
GitHub Enterprise Self-Hosted Runner Registration
2 rules 1 TTPA self-hosted runner was created in GitHub Enterprise, which could be exploited by attackers to execute malicious code, access sensitive data, or pivot to other systems.
GitHub Enterprise Audit Log Streaming Disabled
2 rules 1 TTPAn attacker disables audit log event streaming in GitHub Enterprise to evade detection by preventing security monitoring platforms from receiving audit events.
GitHub Classic Branch Protection Rule Disabled
2 rules 2 TTPsThis analytic detects when classic branch protection rules are disabled in GitHub Organizations, potentially allowing malicious actors to bypass code review and security controls.
GCP Storage Bucket Configuration Modification
2 rules 1 TTPThis rule detects modifications to Google Cloud Platform (GCP) storage bucket configurations, potentially indicating an adversary attempting to weaken security controls for unauthorized access or data exfiltration.
GCP Service Account Deletion
2 rules 1 TTPDetection of Google Cloud Platform (GCP) service account deletion, which adversaries may perform to disrupt business operations.
GCP Authentication Failure During MFA Challenge
2 rules 2 TTPs 1 IOCDetection of failed MFA challenges in Google Cloud Platform (GCP) using Google Workspace login failure events, potentially indicating credential compromise and unauthorized access attempts.
FortiGate SSL VPN Login Followed by SIEM Alert
2 rules 1 TTPDetects FortiGate SSL VPN logins followed by a SIEM detection alert for the same user within a short timeframe, potentially indicating VPN abuse, credential compromise, or initial access followed by post-compromise activity.
Forbidden Direct Interactive Kubernetes API Request
3 rules 3 TTPsThis rule detects forbidden direct interactive Kubernetes API requests by correlating interactive command execution inside a container with explicitly forbidden Kubernetes API requests, indicating potential enumeration and privilege testing for lateral movement.
Flax Typhoon Masquerading SoftEther VPN as Legitimate Windows Binaries
2 rules 2 TTPsThe Flax Typhoon group uses SoftEther VPN, masquerading the VPN client as legitimate Windows binaries like conhost.exe and dllhost.exe, to obfuscate their network activity within compromised Taiwanese organizations.
First Time Seen Driver Loaded
2 rules 3 TTPsThe rule identifies the load of previously unseen drivers, which may indicate attackers exploiting vulnerable drivers for privilege escalation and persistence.
Execution via Windows Subsystem for Linux
2 rules 2 TTPsThis detection identifies attempts to execute programs from the Windows Subsystem for Linux (WSL) to evade detection by flagging suspicious executions initiated by WSL processes and excluding known safe executables.
Execution via Local SxS Shared Module
2 rules 2 TTPsThis rule detects the creation, modification, or deletion of DLL files within Windows SxS local folders, which could indicate an attempt to execute malicious payloads by abusing shared module loading.
Exchange Mailbox Export via PowerShell
2 rules 4 TTPsAdversaries may use the New-MailboxExportRequest PowerShell cmdlet to export mailboxes in Exchange, potentially leading to sensitive information theft.
Excessive Usage of SC Service Utility
2 rules 3 TTPsDetection of anomalous usage of sc.exe, often abused by ransomware and malware to manipulate services for privilege escalation or disabling security measures.
ESXi SSH Enabled Detection
2 rules 1 TTPThe enabling of SSH on ESXi hosts, as detected in ESXi Syslog, can signal malicious lateral movement by threat actors aiming for persistent access.
ESXi Shell Enabled Detection
2 rules 1 TTPThe ESXi Shell being enabled on a host may indicate malicious activity like preparing to execute commands locally or establishing persistent access.
ESXi Download Error Detection
2 rules 2 TTPsDetection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.
Enumeration of Privileged Local Groups Membership
2 rules 1 TTPAn unusual process is enumerating built-in Windows privileged local groups membership, such as Administrators or Remote Desktop users, potentially revealing targets for credential compromise and post-exploitation activities.
Entra ID Sharepoint or OneDrive Accessed by Unusual Client
2 rules 4 TTPsAn application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.
Entra ID Service Principal Credentials Created by Unusual User
2 rules 2 TTPsAnomalous addition of credentials to an Entra ID service principal by a user not typically performing this action can indicate potential persistence and privilege escalation by an attacker.
Entra ID Privileged Identity Management (PIM) Role Modified
2 rules 3 TTPsAttackers may modify Entra ID Privileged Identity Management (PIM) roles to persist in the environment and weaken security controls, potentially leading to privilege escalation and unauthorized access.
Entra ID OAuth User Impersonation Scope for Unusual User and Client
2 rules 3 TTPsAdversaries may abuse the user_impersonation OAuth scope in Entra ID to gain unauthorized access to user accounts, especially when combined with single-factor authentication and unbound sign-in sessions, potentially indicating account compromise for users not seen in the last 10 days.
Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
2 rules 3 TTPsDetects the first-time use of an OAuth 2.0 authorization code grant flow for a specific combination of user, application, and resource in Microsoft Entra ID, potentially indicating OAuth phishing attacks like ConsentFix, where attackers steal authorization codes.
Entra ID External Authentication Methods (EAM) Modified
2 rules 2 TTPsModification of Entra ID external authentication methods (EAM) via the Microsoft Graph API can allow attackers to bypass multi-factor authentication (MFA) and establish persistence or gain unauthorized access via bring-your-own IdP (BYOIDP) methods.
Encoded Executable Stored in the Registry
2 rules 3 TTPs 1 IOCThis rule detects registry write modifications hiding encoded portable executables, indicative of adversary defense evasion by avoiding storing malicious content directly on disk.
DivvyDrive Open Redirect Vulnerability
2 rules 1 TTP 1 CVEDivvyDrive versions 4.8.2.9 before 4.8.3.2 are vulnerable to an open redirect vulnerability due to allowing Parameter Injection, potentially leading to phishing attacks.
Detection of WMI Temporary Event Subscription Creation
2 rules 2 TTPsDetection of WMI temporary event subscriptions via Windows Event Logs can identify potential attacker command execution, information gathering, or persistence attempts.
Detection of Windows RMM Tool Execution
3 rules 1 TTPDetects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.
Detection of Suspicious CrowdStrike Agent Registry Key Removal
2 rules 1 TTP 1 CVEThis detection identifies delete events on CrowdStrike registry keys, which typically occur during agent uninstallation, so any unplanned or unexpected removal of these keys should be investigated for malicious activity such as defense evasion or exploits like CVE-2022-44721.
Detection of PuTTY Suite Utility Execution
3 rules 2 TTPsThis analytic detects the execution of programs associated with the PuTTY SSH client suite, including putty.exe, pscp.exe, plink.exe, psftp.exe, and puttygen.exe, which can be used to establish unauthorized remote connections, transfer files, or execute commands on remote systems potentially leading to network compromise.
Detection of Privileged Account Creation in Azure
2 rules 3 TTPsDetects the creation of new privileged accounts in Azure environments, potentially indicating initial access, persistence, privilege escalation, or stealth activities by malicious actors.
Detection of Out-of-Domain Email Forwarding in Google Workspace
2 rules 1 TTPDetects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse by malicious insiders or compromised accounts.
Detection of Okta Administrator Role Assignment to User or Group
2 rules 1 TTPDetects the assignment of an Okta administrator role to a user or group, potentially indicating privilege escalation or persistence attempts by malicious actors.
Detection of Obfuscated IP Addresses via Command Line Tools
3 rules 1 TTPThe use of command-line tools like ping.exe or arp.exe with obfuscated IP addresses (hex, octal, etc.) in the command line can indicate reconnaissance activity or attempts to evade security controls by masking the true destination.
Detection of Failed ESXi File Downloads
2 rules 2 TTPsThis detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in system logs, potentially indicating unauthorized attempts to install malicious components or scripts.
Detection of Azure Storage Utility Execution via Command Line Interface
2 rules 1 TTPAdversaries may leverage Azure Storage utilities like AzCopy and Storage Explorer post-compromise to stage or extract sensitive data from endpoints, blending malicious activity with legitimate cloud traffic.
Detection of Abnormally Large DNS Responses Indicative of CVE-2020-1350 Exploitation
2 rules 2 TTPsThis rule detects abnormally large DNS responses indicative of exploitation attempts targeting a known overflow vulnerability (CVE-2020-1350) in Windows DNS servers, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS).
Detecting WMIC Systeminfo Discovery Activity
2 rules 1 TTPThis brief covers detection of adversaries using Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically the `computersystem` class, a technique used for reconnaissance.
Detecting Spikes in Active Directory Object Modifications
2 rules 1 TTPThis detection identifies a spike in Active Directory group or object modifications, potentially indicating unauthorized access, defense impairment, or persistence establishment by threat actors.
Detecting Persistence via Parsing macOS Login Item Files
2 rules 1 TTPThis brief details a method for parsing macOS login item files to detect persistence mechanisms employed by malware or threat actors.
Detect Windows Netspy Network Scanner Execution
2 rules 2 TTPsThe Netspy network scanner, a tool for internal network discovery, is executed on a Windows endpoint to enumerate active hosts and services, potentially for reconnaissance purposes.
Detect Suspicious WMI Event Subscription Creation for Persistence
2 rules 1 TTPThis threat brief details the detection of malicious Windows Management Instrumentation (WMI) event subscriptions, a technique used by attackers for persistence and privilege escalation on Windows systems.
Detect AWS Access Key Creation
2 rules 1 TTPThis brief outlines how to detect the creation of AWS Access Keys, a common tactic used by attackers to establish persistence and escalate privileges within compromised AWS environments.
Denial of Service Vulnerability in marked via Infinite Recursion
2 rules 1 TTPA denial of service vulnerability exists in marked version 18.0.0 due to infinite recursion when processing a specific 3-byte sequence (tab, vertical tab, and newline), leading to unbounded memory allocation and application crash.
CVE-2026-28390 NULL Dereference in CMS KeyTransportRecipientInfo Processing
2 rules 1 CVECVE-2026-28390 is a vulnerability related to a possible NULL pointer dereference when processing CMS KeyTransportRecipientInfo, potentially leading to a denial-of-service condition.
CVE-2019-1547 ECDSA Remote Timing Attack Vulnerability
2 rulesCVE-2019-1547 is a security vulnerability that could allow a remote timing attack.
Command Prompt Network Connection Activity
2 rules 2 TTPsDetection of command prompt activity initiating network connections can indicate suspicious or malicious behavior, potentially leading to command and control or data exfiltration.
Command Execution via ForFiles Utility for Defense Evasion
2 rules 1 TTPAdversaries are leveraging the Windows `forfiles` utility to proxy command execution, potentially bypassing security controls by using a trusted process, for defense evasion.
Command Execution via ForFiles Utility
2 rules 1 TTPAdversaries may use the Windows forfiles utility to proxy command execution via a trusted parent process, potentially evading detection.
Code Signing Policy Modification Through Registry
2 rules 2 TTPsAttackers modify the Windows Registry to disable code signing enforcement, allowing the execution of unsigned or self-signed malicious code.
Cloudflare Tunnel (cloudflared) Abuse for Protocol Tunneling
3 rules 2 TTPs 1 IOCAdversaries are abusing Cloudflare Tunnel (cloudflared) to create outbound tunnels and proxy command and control traffic, or exfiltrate data, evading direct connection blocking by routing traffic through Cloudflare's edge.
Cloud Provisioning Activity From Previously Unseen Region
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.
Cloud Provisioning Activity From Previously Unseen IP Address
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.
Cloud Provisioning Activity From Previously Unseen City
2 rules 1 TTPThe analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.
Cisco Duo Admin Login from Unusual Browser
2 rules 1 TTPDetects Cisco Duo admin logins from browsers other than Chrome, potentially indicating compromised credentials, session hijacking, or unauthorized device usage.
Cisco ASA User Account Lockout Detection
2 rules 2 TTPsDetection of user account lockouts on Cisco ASA devices due to excessive failed authentication attempts, potentially indicating brute-force attacks, password spraying, or credential stuffing.
Cisco ASA Reconnaissance Command Activity
2 rules 3 TTPsThis analytic detects potential reconnaissance on Cisco ASA devices by identifying execution of multiple information-gathering 'show' commands within a short timeframe, indicating potential enumeration by an attacker.
Cisco ASA Logging Message Suppression
2 rules 2 TTPsAdversaries may suppress specific log message IDs on Cisco ASA devices using the 'no logging message' command to selectively disable logging of security-critical events and evade detection.
Cisco ASA Logging Filters Configuration Tampering
2 rules 1 TTPTampering with logging filter configurations on Cisco ASA devices can allow attackers to evade detection by reducing logging levels or disabling specific log categories.
CircleCI Security Step Disabled
2 rules 1 TTPAn attacker disables security steps within CircleCI to potentially bypass security controls and introduce malicious code into the build pipeline.
Chmod Activity Targeting Sensitive Linux Directories
2 rules 1 TTPAttackers may use chmod to modify file permissions within sensitive Linux directories such as /tmp/, /etc/, and /opt/ to maintain persistence, escalate privileges, or disrupt system operations.
ChatGPTNextWeb NextChat Improper Authorization Vulnerability (CVE-2026-7644)
1 rule 1 TTP 1 CVECVE-2026-7644 is an improper authorization vulnerability in the addMcpServer function of ChatGPTNextWeb NextChat version 2.16.1 and earlier, allowing for potential remote exploitation following public disclosure of the exploit.
changedetection.io Arbitrary Local File Read via Crafted Backup Restore
2 rules 1 TTPchangedetection.io is vulnerable to arbitrary local file read due to insufficient validation of snapshot paths restored from backup files, allowing attackers to read sensitive files by crafting a malicious backup archive containing a manipulated `history.txt` file.
Certreq HTTP POST Abuse for File Transfer
2 rules 4 TTPsAdversaries may abuse the Windows Certreq utility to download files or upload data to a remote URL by making an HTTP POST request, potentially for command and control, defense evasion, or exfiltration.
blueprintUE Password Reset Token Vulnerability (CVE-2026-40585)
2 rules 1 TTP 1 CVEblueprintUE versions before 4.2.0 generate password reset tokens that remain valid indefinitely due to the absence of a timestamp validation, allowing attackers to potentially gain unauthorized access via token reuse.
BITS Job Notify Command Persistence
2 rules 1 TTPAdversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.
Azure Storage Account Blob Public Access Enabled
2 rules 1 TTPDetection of Azure Storage Account Blob public access being enabled, potentially allowing external access to blob containers for data exfiltration, as abused by threat actors modifying storage account settings.
Azure Owner Removed from Application or Service Principal
2 rules 1 TTPAn adversary may remove an owner from an Azure application or service principal to weaken access controls, persist in the environment, or escalate privileges.
Azure Kubernetes Services (AKS) Kubernetes Events Deleted
2 rules 2 TTPsAdversaries may delete Kubernetes events in Azure Kubernetes Services (AKS) to evade detection by removing logs of state changes, container creations, image pulls, and pod scheduling.
Azure Key Vault Unusual Secret Key Usage
2 rules 1 TTPDetects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.
Azure Event Hub Authorization Rule Created or Updated
2 rules 2 TTPsCreation or modification of Azure Event Hub authorization rules can indicate unauthorized access or privilege escalation by adversaries using cryptographic keys to manage access to event hubs.
Azure Compute Restore Point Collection Deleted by Unusual User
2 rules 1 TTPThe deletion of Azure Restore Point Collections, which contain recovery points for virtual machines, by a user who has not previously performed this activity, indicates a potential attempt to prevent recovery during ransomware attacks or cover tracks during malicious operations.
Azure AD User Consent Blocked for Risky Application
2 rules 1 TTPAzure AD blocked a user's attempt to grant consent to a risky application, indicating potential OAuth abuse and requiring investigation of the user and application involved.
Azure AD User Added to Administrator Role
2 rules 4 TTPsAn adversary adds a user to an Azure Active Directory administrative role to gain initial access, persist in the environment, escalate privileges, and potentially operate stealthily.
Azure AD Successful Single-Factor Authentication
2 rules 2 TTPsSuccessful single-factor authentication events against Azure Active Directory are identified using Azure SignInLogs data, which may indicate misconfiguration, policy violation, or potential account takeover leading to data breaches and privilege escalation.
Azure AD Risk-Based Consent Disabled
2 rules 1 TTPThe analytic detects when the risk-based step-up consent security setting in Azure AD is disabled by monitoring Azure Active Directory logs for the 'Update authorization policy' operation and changes to the 'AllowUserConsentForRiskyApps' setting, potentially exposing organizations to OAuth phishing attacks.
Azure AD MFA Disabled to Bypass Authentication
2 rules 1 TTPAn adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.
AzuraCast Account Takeover via X-Forwarded-Host Poisoning
2 rules 3 TTPs 2 IOCsAzuraCast is vulnerable to password reset poisoning due to unconditionally trusting the X-Forwarded-Host header, allowing an attacker to inject a malicious host into the password reset URL, exfiltrate the reset token, reset the victim's password, and disable 2FA, leading to account takeover.
AWS User Performing S3 Encryption with KMS Keys
2 rules 1 TTPA user with KMS keys is performing encryption operations on S3 buckets, potentially masking exfiltration or tampering efforts by encrypting sensitive data to evade detection or preparing it for exfiltration.
AWS STS AssumeRole Misuse for Lateral Movement and Privilege Escalation
1 rule 2 TTPsAbuse of AWS STS AssumeRole can allow attackers to move laterally within an AWS environment and escalate privileges, potentially leading to unauthorized access to sensitive resources and data.
AWS SQS Queue Purge Detection
2 rules 2 TTPsDetection of AWS Simple Queue Service (SQS) queue purging, which adversaries may leverage to disrupt application workflows, destroy operational data, or impair monitoring and alerting systems by removing critical evidence of malicious activity.
AWS SNS Topic Message Publish by Rare User
2 rules 4 TTPsThis rule identifies when an SNS topic message is published by a rare user in AWS, which may indicate lateral movement, data exfiltration, or phishing campaigns, potentially leading to resource hijacking and impact on cloud services.
AWS RDS DB Instance or Cluster Deleted
2 rules 1 TTPAn adversary with sufficient permissions may delete RDS resources such as DB instances or clusters to impede recovery, destroy evidence, or inflict operational impact on the environment.
AWS Network ACL Deletion Detection
2 rules 1 TTPDetection of AWS Network Access Control List (ACL) deletion via CloudTrail logs, potentially indicating malicious attempts to bypass network security controls and gain unauthorized access.
AWS Login Profile Creation Activity
2 rules 2 TTPsMonitoring AWS login profile creation events can help identify potentially malicious user or role creation activities within an AWS environment.
AWS IAM Virtual MFA Device Registration Attempt with Session Token
2 rules 3 TTPsAn adversary with compromised temporary AWS credentials attempts to establish persistence by creating or enabling a virtual MFA device, bypassing expected session token usage.
AWS IAM Session Token Used From Multiple Addresses
2 rules 1 TTPCompromised AWS IAM session tokens are used from multiple IP addresses, networks, cities, and user agents within a short timeframe, indicating potential credential theft and abuse.
AWS IAM Principal Enumeration via UpdateAssumeRolePolicy
2 rules 3 TTPsDetects repeated failed attempts to update an IAM role's trust policy in an AWS account, consistent with role and user enumeration techniques, potentially indicating attacker-controlled infrastructure or offensive tooling.
AWS IAM Policy Deletion Detection
2 rules 1 TTPDetection of AWS IAM policy deletion events, which could indicate malicious activity by a compromised account or insider threat.
AWS IAM MFA Device Deactivation
2 rules 3 TTPsDetection of AWS IAM MFA device deactivation via the `DeactivateMFADevice` API call, which could indicate an attempt to weaken account protections for privilege escalation or persistence.
AWS IAM Default Policy Version Modification
2 rules 1 TTPAn adversary modifies the default version of an AWS IAM policy, potentially downgrading security or disrupting access control.
AWS IAM Customer Managed Policy Version Manipulation for Privilege Escalation
2 rules 2 TTPsSuccessful creation of new or setting default versions of customer-managed IAM policies can indicate privilege escalation attempts by attackers modifying policy permissions.
AWS IAM AccessDenied Discovery Events
2 rules 1 TTPDetection of excessive AccessDenied events within an hour for AWS IAM users, indicating a potential compromised access key used for unauthorized discovery actions.
AWS Excessive Security Scanning Detection
2 rules 1 TTPDetection of excessive AWS API calls indicative of reconnaissance by an attacker attempting to map an AWS environment.
AWS EFS File System Deletion Detected
2 rules 1 TTPAn adversary with sufficient permissions deletes an Amazon EFS file system using the 'DeleteFileSystem' API operation to destroy evidence, disrupt workloads, or impede recovery efforts.
AWS ECR Container Upload Anomaly Outside Business Hours
2 rules 1 TTPThis detection identifies uploads of new containers to AWS Elastic Container Registry (ECR) outside of standard business hours, potentially indicating unauthorized access or malicious deployments.
AWS ECR Container Scanning Reveals Medium Severity Vulnerabilities
2 rules 1 TTP 1 CVEAWS Elastic Container Registry (ECR) image scans reveal medium-severity vulnerabilities, potentially leading to unauthorized access and data breaches if exploited within containerized applications.
AWS Console Login from New City
2 rules 1 TTPA user logging into the AWS console from a previously unseen city could indicate compromised credentials or an insider threat.
AWS Console Login Failed During MFA Challenge
2 rules 2 TTPsDetection of failed AWS console login attempts despite successful MFA usage, indicating potential account compromise attempts.
AWS Console Login by User from New Country
2 rules 1 TTPThis detection identifies AWS console logins by a user originating from a country not previously associated with that user, potentially indicating account compromise.
AWS Console Login by New User
2 rules 1 TTPDetects first-time AWS console login, which can indicate compromised credentials or malicious account creation.
AWS CloudWatch Log Stream Deletion
2 rules 3 TTPsDetection of Amazon CloudWatch log stream deletion via the 'DeleteLogStream' API, potentially indicating defense evasion or impact by adversaries aiming to conceal activity and disrupt security monitoring.
AWS CloudWatch Alarm Deletion for Defense Evasion
2 rules 2 TTPsSuccessful deletion of Amazon CloudWatch alarms via the `DeleteAlarms` API, potentially indicating an adversary attempting to impair visibility, silence alerts, and evade detection after malicious activity within an AWS environment.
AWS Bedrock Invoke Model Access Denied Attempt
2 rules 2 TTPsDetection of AccessDenied errors when attempting to invoke AWS Bedrock models via the InvokeModel API indicates potential reconnaissance or privilege escalation attempts by an adversary with compromised credentials.
AppArmor Profile Compilation via apparmor_parser
2 rules 1 TTPAdversaries may abuse `apparmor_parser` to compile custom AppArmor profiles, potentially weakening security controls and facilitating privilege escalation on Linux systems.
Active Directory Group Policy Deletion Detected
2 rules 2 TTPsDetection of Active Directory Group Policy deletion using event ID 5136, indicating potential malicious activity or misconfiguration.
Account Configured with Never-Expiring Password
2 rules 1 TTPDetects the creation and modification of an account with the 'Don't Expire Password' option enabled, which attackers can abuse to persist in the domain and maintain long-term access.
Abnormally High Number of Cloud Infrastructure API Calls
2 rules 2 TTPsDetection of an abnormally high number of cloud infrastructure API calls, indicating potential malicious activity or misconfiguration in a cloud environment.
Windows Universal Data Link File Creation Detection
2 rules 2 TTPsThe creation of Universal Data Link (UDL) files on Windows systems can indicate a phishing technique where attackers bypass email filters and capture user credentials by tricking victims into testing a connection to a malicious server.
Windows Port Forwarding Rule Addition via Registry Modification
2 rules 3 TTPsThis alert detects the creation of a new port forwarding rule in the Windows Registry, a technique used by attackers to bypass network segmentation and establish internal proxies for command and control or lateral movement.
Unusual Parent-Child Relationship Detection
3 rules 4 TTPsThis rule identifies Windows programs run from unexpected parent processes, which could indicate masquerading or other strange activity on a system, potentially indicating process injection, masquerading, access token manipulation, or parent PID spoofing.
Unusual Microsoft Graph Email Access via OAuth Application
2 rules 2 TTPsAn adversary might use a phished OAuth refresh token or Primary Refresh Token (PRT) with a first-party application to access email resources via Microsoft Graph API, particularly focusing on unusual application and user combinations.
Suspicious Process Execution via Renamed PsExec Executable
2 rules 3 TTPsDetects suspicious PsExec activity where the PsExec service component is executed using a custom name, indicating an attempt to evade detections that look for the default PsExec service component name.
Suspicious Process Creation Followed by Memory Access from Unknown Region
2 rules 1 TTPThe rule identifies suspicious process creation where a process is created and immediately accessed from an unknown memory code region by the same parent process, indicating a potential code injection attempt, specifically process hollowing, commonly targeting processes spawned by Microsoft Office applications, scripting engines, and command-line tools for defense evasion.
Suspicious Outbound Scheduled Task Activity via PowerShell
2 rules 3 TTPsThis rule detects PowerShell loading the Task Scheduler COM DLL followed by an outbound RPC network connection, potentially indicating lateral movement or remote discovery via scheduled tasks.
Spike in Active Directory User Modification Activity
2 rules 1 TTPDetects an increase in modifications to AD user objects, which may indicate unauthorized access, impaired defenses, or persistence establishment.
Remote File Copy via TeamViewer
2 rules 2 TTPsAttackers may abuse legitimate utilities such as TeamViewer to deploy malware interactively by remotely copying executable or script files during a TeamViewer session.
Potential Persistence via Time Provider Modification
2 rules 2 TTPsAdversaries may establish persistence by registering and enabling a malicious DLL as a time provider by modifying registry keys associated with the W32Time service.
Potential Application Shimming via Sdbinst
2 rules 2 TTPsAttackers abuse the Application Shim functionality in Windows by using `sdbinst.exe` with malicious arguments to achieve persistence and execute arbitrary code within legitimate Windows processes.
Persistence via LSA Security Support Provider Registry Modification
2 rules 2 TTPsAdversaries may establish persistence by modifying the Windows Security Support Provider (SSP) configuration in the registry, allowing malicious code to load during system startup.
MpCmdRun.exe Used for Remote File Download
2 rules 1 TTPAttackers are abusing the Windows Defender MpCmdRun.exe utility to download remote files, potentially delivering malware or offensive tools into compromised systems.
LSASS Loading Suspicious DLL
2 rules 2 TTPs 9 IOCsDetection of LSASS loading an unsigned or untrusted DLL, which can indicate credential access attempts by malicious actors targeting sensitive information stored in the LSASS process.
Linux Stdout Redirection to /dev/null Indicates Potential Malware Activity
2 rulesThe redirection of standard output to /dev/null on Linux systems, particularly when observed in conjunction with other suspicious activities, can indicate attempts to hide malicious command execution, as seen in malware like Cyclops Blink, potentially leading to unauthorized system modifications and persistent access.
Kubernetes Scanning by Unauthenticated IP Address
2 rules 1 TTPDetects potential scanning activities within a Kubernetes environment by identifying multiple unauthorized access attempts (HTTP 403 responses) from unauthenticated IP addresses in Kubernetes audit logs, potentially indicating vulnerability probing or exploitation attempts.
Gravity Forms Plugin Unauthenticated Stored XSS Vulnerability
2 rules 1 CVEThe Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.10.0, allowing unauthenticated attackers to inject arbitrary web scripts via form submissions that execute when an administrator views the entry detail page.
Entra ID Application Credential Modification
3 rules 2 TTPsAn adversary may add unauthorized credentials to an Azure application, enabling persistent access, evading defenses, and escalating privileges by modifying certificates or secrets.
Detecting Remote Scheduled Task Creation for Lateral Movement
2 rules 2 TTPsThis rule identifies remote scheduled task creations on a target Windows host, potentially indicating lateral movement by adversaries, by monitoring network connections and registry modifications related to task scheduling.
Cisco ASA User Account Deletion
2 rules 2 TTPsDetection of user account deletion on Cisco ASA devices, potentially indicating adversary attempts to cover tracks, disrupt incident response, or deny administrator access.
Azure AD User Consent Denied for OAuth Application
2 rules 1 TTPThis analytic identifies instances where a user has denied consent to an OAuth application seeking permissions within the Azure AD environment, potentially indicating malicious OAuth application activity.
Azure AD External Guest User Invitation
2 rules 1 TTPDetection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.
AWS Suspicious User Agent Detected in CloudTrail
2 rules 2 TTPsSuccessful AWS API calls with CloudTrail user agents indicating offensive tooling (Kali Linux) or credential verification (TruffleHog) can indicate compromised credentials or unauthorized access.
macOS File Monitoring via Endpoint Security Framework
2 rules 1 TTPObjective-See details how to create a file monitor for macOS 10.15 using Apple's Endpoint Security Framework to capture file I/O events and process information.
Suspicious SUID Binary Execution Sequence on Linux
2 rules 2 TTPsThis rule detects suspicious sequences where a non-root user launches a high-risk parent process and then executes a common privilege elevation helper gaining an effective UID of 0 while the real UID remains non-root, potentially indicating misuse of SUID/SGID helpers or privilege escalation attempts.
Entra ID User Sign-in with Unusual Authentication Type
2 rules 4 TTPsDetects rare authentication requirements for Azure Entra ID principal users, potentially indicating an adversary attempting to bypass conditional access policies and MFA using stolen credentials.
Remote File Download via Script Interpreter
2 rules 2 TTPsThe rule identifies built-in Windows script interpreters, specifically cscript.exe or wscript.exe, being used to download an executable file from a remote destination, often employed by attackers for initial access or to deploy secondary payloads.
Account Password Reset Remotely
2 rules 2 TTPsThe rule detects attempts to reset potentially privileged account passwords remotely, a tactic used by adversaries to maintain access, evade password policies, and preserve compromised credentials.
Unusual Process For a Windows Host via Machine Learning
2 rules 2 TTPsThis rule detects rare processes running on Windows hosts, potentially indicating unauthorized services, malware, or persistence mechanisms by using machine learning to identify processes that run infrequently compared to other processes on the same host.
Startup Folder Persistence by Suspicious Processes
2 rules 1 TTPThis rule identifies files written to or modified in the startup folder by commonly abused processes on Windows systems, a technique adversaries use to maintain persistence by automatically executing malicious programs upon user login or system startup.
Remote File Download via Desktopimgdownldr Utility
2 rules 1 TTPThe rule detects the use of desktopimgdownldr.exe to download remote files, which is an abuse of a signed utility often used as an alternative to certutil for transferring malicious tools or malware into a compromised environment.
Persistence via PowerShell Profile Modification
2 rules 2 TTPsAttackers can establish persistence by creating or modifying PowerShell profiles to execute malicious code each time PowerShell is launched, customizing the user environment.
High Number of AWS Bedrock List Foundation Model Failures
2 rules 1 TTPDetection of a high number of AccessDenied errors when attempting to list AWS Bedrock foundation models, indicating potential reconnaissance activity after credential compromise to discover accessible AI models.
GCP IAM Custom Role Creation
3 rules 3 TTPsDetection of Identity and Access Management (IAM) custom role creation in Google Cloud Platform (GCP), which can indicate potential privilege escalation or persistence by adversaries creating roles with excessive permissions.
Exchange PowerShell Used to Add New ActiveSync Allowed Device
2 rules 3 TTPsAn adversary may use the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially gaining persistent access to a user's email and sensitive information.
Azure Storage Account Data Exfiltration via AzCopy and SAS Token Abuse
2 rules 2 TTPsSuccessful GetBlob operations on Azure Storage Accounts using the AzCopy user agent with SAS token authentication can indicate data exfiltration by adversaries abusing compromised SAS tokens.
Azure AD Failed Authentication Increase
2 rules 1 TTPDetects a significant increase (10% or greater) in failed Azure AD sign-in attempts, potentially indicating brute-force attacks, credential stuffing, or other unauthorized access attempts.
Suspicious dMSA Service Account Creation Attempting BadSuccessor Abuse
2 rules 4 TTPsThe creation of a delegated managed service account (dMSA) in specific Active Directory organizational units (OUs) via PowerShell, especially when the initiating user lacks proper permissions, indicates a potential attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025 environments.
Detection of New User AWS Console Login
2 rules 2 TTPsA new AWS user logging into the console could indicate malicious activity, such as an attacker creating a new identity for persistence or lateral movement within the AWS environment.
AWS Root Account Usage Detected
3 rules 3 TTPsThe AWS root account, which grants unrestricted access to all resources within an AWS account, was used, potentially indicating unauthorized activity, privilege escalation, or a breach of security best practices.
AWS EC2 Instance Export for Potential Exfiltration
2 rules 5 TTPsAn attacker with compromised AWS credentials or EC2 instance access can leverage EC2 export functionalities (CreateInstanceExportTask, ExportImage, or CreateStoreImageTask) to exfiltrate sensitive data by exporting EC2 instances or their images to external storage.
AWS S3 Bucket Deletion Detected via CloudTrail
3 rules 1 TTPAn AWS S3 bucket deletion event was detected via CloudTrail logs, potentially indicating data loss or unauthorized access attempts.
Linux Sensitive File Compression for Credential Access
2 rules 3 TTPsAttackers may use compression utilities like zip, tar, and gzip on Linux systems to collect and archive sensitive files containing credentials and system configurations for credential access and data exfiltration.
Windows Script Execution from Archive File
2 rules 3 TTPsThis rule detects attempts to execute Jscript/Vbscript files from archive files, a common method for delivering malicious scripts by identifying unusual parent-child process relationships where scripting utilities are launched from archive programs, indicating potential exploitation.
Execution via Compiled HTML File
2 rules 6 TTPsAdversaries may abuse compiled HTML files (.chm) to execute malicious code by proxying execution via hh.exe, often leading to command execution via scripting interpreters.
SMB (Windows File Sharing) Activity to the Internet
2 rules 2 TTPsThis rule detects network events indicating the use of Windows file sharing (SMB or CIFS) traffic to the Internet, which is commonly exploited for initial access, backdoor deployment, or data exfiltration.
MikroTik RouterOS SCEP Endpoint Out-of-Bounds Read Vulnerability (CVE-2026-7668)
2 rules 1 TTP 1 CVEMikroTik RouterOS 6.49.8 is vulnerable to an out-of-bounds read in the SCEP endpoint component, triggered by remote manipulation of the transactionID/messageType argument, potentially leading to denial of service or information disclosure.
Windows WMI Reconnaissance Activity Detection
2 rules 1 TTPDetection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.
Windows Temporarily Scheduled Task Creation and Deletion
2 rules 2 TTPsDetection of rapid creation and deletion of scheduled tasks on Windows, indicating potential malicious activity abusing the task scheduler for execution and cleanup.
Windows Script Host Executing PowerShell
2 rules 4 TTPsDetects PowerShell execution initiated by cscript.exe or wscript.exe, commonly used by attackers for initial access or payload delivery.
Windows Sandbox Abuse for Defense Evasion
3 rules 1 TTPThe execution of Windows Sandbox processes with sensitive configurations (write access to the host file system, network connection, automatic execution via logon command) is identified, as malware may abuse this sandbox feature to evade detection.
Windows Registry Modification to Disable Run Application
2 rules 1 TTPThe following analytic detects modification of the Windows registry to disable the Run application in the Start menu by monitoring changes to the registry path '*\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun' with a value of '0x00000001', potentially hindering system cleaning and aiding malware persistence.
Windows Defender SmartScreen Level Downgrade to 'Warn'
2 rules 1 TTPThis analytic detects modifications to the Windows Registry to set Windows Defender SmartScreen level to 'Warn', which can reduce user suspicion and increase the risk of malware execution.
Windows Defender Quick Scan Interval Modification
2 rules 1 TTPDetection of modifications to the Windows registry that change the Windows Defender Quick Scan Interval, potentially impairing its ability to detect malware promptly.
Windows Defender PUA Protection Disabled via Registry Modification
2 rulesAn attacker modifies the Windows Registry to disable Windows Defender Potentially Unwanted Application (PUA) protection, increasing the risk of malware installation and system compromise.
Windows Credential Manager Abuse via VaultCmd
2 rules 2 TTPsAdversaries may abuse VaultCmd to list or dump credentials stored in the Windows Credential Manager to obtain saved usernames and passwords, potentially for lateral movement.
Windows Command Obfuscation via Environment Variable Substrings
2 rules 1 TTPAttackers obfuscate commands in Windows by dynamically constructing them using substrings extracted from environment variables, a technique observed in malware families such as Cobalt Strike and Meterpreter.
Windows Admin Account Brute Force Detection
2 rules 2 TTPsThis rule identifies potential password guessing/brute force activity from a single source IP targeting multiple Windows accounts with 'admin' in the username, indicating an attempt to compromise privileged accounts.
Web Server Local File Inclusion Activity
2 rules 1 TTPThis rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.
Wbadmin Backup Catalog Deletion
2 rules 2 TTPsAdversaries may delete Windows backup catalogs using wbadmin.exe to inhibit system recovery, often as part of ransomware or other destructive attacks.
User Account ServicePrincipalName Attribute Modified
2 rules 2 TTPsDetection of modifications to the servicePrincipalName attribute on user accounts, potentially exposing them to Kerberoasting attacks by allowing attackers to request Kerberos tickets for the account.
Unusual Service Host Child Process - Childless Service
2 rules 2 TTPsThe rule identifies unusual child processes of Service Host (svchost.exe) instances hosting services that do not traditionally spawn child processes, potentially indicating code injection or exploitation leading to privilege escalation and defense evasion.
Unusual Process Execution via Alternate Data Streams
2 rules 1 TTPAdversaries may use Alternate Data Streams (ADS) to hide malicious executables and execute them, evading traditional detection methods by concealing the file's true nature.
Unusual Parent Process for cmd.exe
1 rule 1 TTPAtypical parent processes spawning cmd.exe indicate potential malicious command execution on Windows systems, where adversaries leverage cmd.exe from unusual parent processes to execute malicious commands stealthily.
Unauthorized Guest User Invitations in Azure AD
2 rules 3 TTPsDetection of unauthorized guest user invitations within an Azure Active Directory tenant, indicating potential privilege escalation, persistence, or initial access attempts.
Suspicious Unshare Usage for Namespace Manipulation
2 rules 2 TTPs 1 CVEThe `unshare` command is used to create new namespaces in Linux, which can be exploited to break out of containers or elevate privileges by creating namespaces that bypass security controls.
Suspicious Unshare Usage for Container Escape and Privilege Escalation
2 rules 2 TTPsThe rule identifies suspicious usage of unshare to manipulate system namespaces, which can be utilized to escalate privileges or escape container security boundaries.
Suspicious Svchost.exe Child Process: cmd.exe
2 rules 2 TTPsDetection of cmd.exe being spawned by svchost.exe, which is an unusual behavior indicative of potential masquerading or privilege escalation attempts on Windows systems.
Suspicious Shell Execution via Velociraptor
2 rules 2 TTPsAttackers are abusing the Velociraptor endpoint visibility and response tool to execute shell commands (cmd, PowerShell, rundll32) on compromised Windows systems, blending in with legitimate system processes.
Suspicious Remote Registry Access via SeBackupPrivilege
2 rules 3 TTPsDetection of remote registry access by an account with SeBackupPrivilege, potentially indicating credential exfiltration attempts via SAM registry hive dumping.
Suspicious RDP Client Image Load
2 rules 1 TTPThe rule detects suspicious loading of the Remote Desktop Services ActiveX Client (mstscax.dll) from unusual locations, potentially indicating RDP lateral movement on Windows systems.
Suspicious JavaScript File Upload to AWS S3 Static Website
2 rules 2 TTPsDetection of a JavaScript file upload to an AWS S3 static website directory by an IAM user or assumed role, potentially indicating malicious web content modification and frontend compromise.
Suspicious Inter-Process Communication via Outlook COM
2 rules 2 TTPsAdversaries may target user email to collect sensitive information or send email on their behalf via API by abusing Outlook's Component Object Model (COM) interface from unusual processes.
Suspicious Explorer Child Process via DCOM
2 rules 9 TTPsAdversaries abuse the trusted status of explorer.exe to launch malicious scripts or executables, often using DCOM to start processes like PowerShell or cmd.exe, achieving initial access, defense evasion, and execution.
Suspicious Enumeration Commands Spawned via WMIPrvSE
2 rules 13 TTPsThis rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.
Suspicious Command Execution via SolarWinds Process
2 rules 3 TTPsThis brief covers the detection of suspicious command execution, specifically Cmd.exe or PowerShell.exe, as child processes of legitimate SolarWinds executables, indicative of potential supply chain compromise and unauthorized command execution on Windows systems.
Suspicious AWS ECR Container Upload Outside Business Hours
2 rules 1 TTPAn AWS Elastic Container Registry (ECR) container image upload occurring outside of normal business hours can indicate suspicious or malicious activity, such as an attacker attempting to deploy compromised containers.
Suspicious .NET Code Compilation via Unusual Parent Processes
2 rules 3 TTPsAdversaries may use unusual parent processes to execute .NET compilers for compiling malicious code after delivery, evading security mechanisms, and this activity is detected by monitoring compiler executions initiated by scripting engines or system utilities.
SMB Registry Hive Exfiltration
2 rules 3 TTPsDetection of medium-sized registry hive files being created or modified on Server Message Block (SMB) shares, potentially indicating exfiltration of Security Account Manager (SAM) data for credential extraction.
Signal 'Disappearing' Messages Persist in macOS Notification Center
2 rulesmacOS stores Signal message notifications in an unencrypted SQLite database, potentially exposing 'disappearing' messages even after they are deleted from the Signal application.
Python-Multipart Denial of Service Vulnerability
2 rules 1 TTPA denial-of-service vulnerability exists in python-multipart versions prior to 0.0.27 due to unbounded multipart part header parsing, allowing attackers to exhaust CPU resources by sending requests with many repeated headers or a single oversized header value.
PowerShell Script Block Logging Disabled via Registry Modification
2 rules 2 TTPsAttackers may disable PowerShell Script Block Logging by modifying the registry to evade detection and conceal their activities on the host, detected by monitoring changes to the `EnableScriptBlockLogging` registry value.
Potential Kubeletctl Execution on Linux Hosts
2 rules 3 TTPsThis rule detects the execution of kubeletctl, a command-line tool used to interact with the Kubelet API, on Linux hosts, potentially leading to discovery and lateral movement within Kubernetes environments.
Potential Data Exfiltration Through Curl
2 rules 1 TTPThis rule detects potential data exfiltration attempts on Linux systems using the curl command-line tool to upload files to external servers, potentially indicating unauthorized data transfer.
Potential Credential Access via DCSync
2 rules 3 TTPsThis rule identifies when a User Account starts the Active Directory Replication Process, potentially indicating a DCSync attack, which allows attackers to steal credential information compromising the entire domain.
Okta User Account Lockout Detection
2 rules 1 TTPDetection of an Okta user account lockout, which may indicate brute-force attempts or other malicious activity targeting user accounts.
Okta New Device Enrollment Detection
2 rules 1 TTPDetection of new device enrollments in Okta, potentially indicating account takeover or unauthorized access by an adversary.
Okta Credential Stuffing Attempt Detection
2 rules 1 TTPThis brief focuses on detecting credential stuffing attacks against Okta, characterized by multiple failed login attempts from a single source, potentially indicating automated attempts to compromise user accounts.
Nimiq Block Skip Block Quorum Bypass Vulnerability
2 rules 1 TTPA vulnerability exists in Nimiq Block's SkipBlockProof verification process, allowing attackers to bypass quorum checks by manipulating MultiSignature signers with out-of-range indices, potentially compromising blockchain integrity, and affecting rust/nimiq-block versions 0.2.0 and earlier.
New GitHub App Installation Detection
2 rules 3 TTPsThe installation of a new GitHub application within an organization's account may indicate malicious activity by granting unauthorized access to repositories and organizational data.
Netsh Used to Enable Remote Desktop Protocol (RDP) in Windows Firewall
2 rules 2 TTPsAdversaries may use the `netsh.exe` utility to enable inbound Remote Desktop Protocol (RDP) connections in the Windows Firewall, potentially allowing unauthorized remote access to compromised systems.
n8n Unauthenticated Denial of Service via MCP Client Registration
2 rules 1 TTPn8n is vulnerable to an unauthenticated denial of service (DoS) attack due to missing resource controls in the MCP OAuth client registration endpoint, allowing an attacker to exhaust server memory by sending large registration payloads, leading to service unavailability; this is resolved in versions 1.123.32, 2.17.4, and 2.18.1 and tracked as CVE-2026-42236.
MyBB Recent Threads 17.0 Persistent Cross-Site Scripting Vulnerability (CVE-2018-25309)
2 rules 1 TTP 1 CVEMyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability (CVE-2018-25309) that allows attackers to inject malicious scripts by creating threads with crafted subject lines, leading to arbitrary JavaScript execution in the browsers of users viewing the index page.
Multiple Remote Management Tool Vendors on Same Host
3 rulesThis detection identifies a Windows host where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.
Msiexec Arbitrary DLL Execution
2 rules 1 TTPAdversaries may abuse the msiexec.exe utility to proxy the execution of malicious DLL payloads, bypassing application control and other defenses.
MSBuild Started by System Process
2 rules 2 TTPsDetects instances of MSBuild, the Microsoft Build Engine, started by Explorer or the WMI (Windows Management Instrumentation) subsystem, which is unusual and often used by malicious payloads to evade defenses.
MS Office Macro Security Registry Modifications
2 rules 2 TTPsAttackers may modify Microsoft Office registry settings related to macro security (AccessVBOM, VbaWarnings) to disable security warnings, enabling malicious macros for persistence and further compromise.
Mounting of Hidden or WebDav Remote Shares via Net Utility
2 rules 4 TTPsAdversaries may leverage the `net.exe` utility to mount WebDav or hidden remote shares, potentially indicating lateral movement, data exfiltration preparation, or initial access via discovery of accessible shares.
Mod_gnutls Certificate Chain Overflow Vulnerability (CVE-2026-33307)
2 rules 3 TTPsMod_gnutls versions prior to 0.12.3 and 0.13.0 are vulnerable to a certificate chain overflow when verifying client certificates, potentially leading to a segfault or stack corruption.
Microsoft Outlook VBA Template Persistence
2 rules 1 TTPAttackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file.
Microsoft IIS Service Account Password Dump via AppCmd
2 rules 2 TTPsAn attacker with IIS web server access via a web shell can extract service account passwords by requesting full configuration output or targeting credential-related fields using the AppCmd tool.
Microsoft Devtunnels Image Load Detection
2 rules 2 TTPsThis detection identifies potential misuse of Microsoft Devtunnels within Visual Studio by detecting image load events, indicating that an attacker could expose a compromised system or service to the internet for covert communication and data exfiltration.
Microsoft Defender ATP Alert Aggregation and Correlation
2 rulesThis analytic aggregates and summarizes alerts from Microsoft Defender ATP, enriching them with MITRE ATT&CK context and risk scoring for improved correlation and risk-based alerting.
Masquerading Business Application Installers
2 rules 4 TTPsAttackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.
macOS DNS Request for IP Lookup Service via Unsigned Binary
2 rules 1 TTP 42 IOCsAn unsigned or untrusted binary on macOS is performing DNS requests for IP lookup services to determine the system's external IP address, which is commonly used by malware for reconnaissance before establishing C2 connections.
Mac File Opener Adware Persists via Document Handler Registration
2 rules 1 TTPThe 'Mac File Opener' adware achieves persistence by registering itself as a document handler for numerous file types, leveraging the Launch Services Daemon (lsd) to automatically parse the application's Info.plist and register the handlers.
LSASS Shtinkering Detection via Full User-Mode Dump Configuration
2 rules 2 TTPsDetection of the enabling of full user-mode dumps system-wide, a setting change leveraged in LSASS Shtinkering attacks to dump LSASS process memory and steal credentials.
LSASS Memory Dump Creation Detection
2 rules 1 TTPThis rule identifies the creation of LSASS memory dump files, often indicative of credential access attempts using tools like Task Manager, SQLDumper, Dumpert, or AndrewSpecial, by monitoring for specific filenames and excluding legitimate dump locations.
Linux Auditd Daemon (Re)Initialization Detection
3 rules 1 TTPDetection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.
Lanman NullSessionPipe Registry Modification for Lateral Movement
2 rules 2 TTPsAdversaries may modify the NullSessionPipe registry key to enable anonymous access to named pipes, facilitating lateral movement and defense evasion by allowing unauthorized access to network resources.
Kubernetes Anonymous Request Authorized by Unusual User Agent
2 rules 1 TTPThis rule detects when an unauthenticated user request is authorized within a Kubernetes cluster via an unusual user agent, potentially indicating an attacker attempting to gain initial access or avoid attribution by exploiting anonymous accounts.
Kubernetes Access Scanning Detection
2 rules 1 TTPThis analytic detects potential reconnaissance activities within a Kubernetes environment by identifying repeated failed access attempts or unusual API requests from unauthenticated users based on Kubernetes audit logs, indicating a potential attacker's preliminary reconnaissance.
Image File Execution Options (IFEO) Injection for Persistence and Defense Evasion
2 rules 3 TTPsAdversaries abuse Image File Execution Options (IFEO) in the Windows Registry by modifying Debugger or MonitorProcess keys to intercept legitimate file executions, enabling persistence and defense evasion.
Hysteria Server Out-of-Memory Vulnerability via Malformed QUIC Packet
2 rules 1 TTPA specially constructed QUIC package can crash the Hysteria server due to an out-of-memory (OOM) condition when the 'sniff' option is enabled, leading to a denial of service.
High Number of Process and/or Service Terminations Detected
2 rules 2 TTPsA high number of process terminations (stop, delete, or suspend) from the same Windows host within a short time period may indicate malicious activity such as an attacker attempting to disable security measures or prepare for ransomware deployment.
Google Workspace MFA Enforcement Disabled
2 rules 3 TTPsDetection of multi-factor authentication (MFA) enforcement being disabled for Google Workspace users, potentially weakening security controls and leading to account compromise.
Google Workspace 2SV Policy Disabled
2 rules 1 TTPAn adversary may disable 2-Step Verification (2SV) in Google Workspace to weaken account security and facilitate unauthorized access.
GCP Firewall Rule Deletion for Defense Evasion
2 rules 1 TTPThe deletion of firewall rules in Google Cloud Platform (GCP) for Virtual Private Cloud (VPC) or App Engine is detected, potentially weakening security controls and enabling unauthorized access or data exfiltration by adversaries.
First Time Seen AWS Secret Value Accessed in Secrets Manager
2 rules 1 TTPThis rule detects the first time a specific user identity has programmatically retrieved a secret value from AWS Secrets Manager using the GetSecretValue action, which may indicate a compromised AWS service attempting to access secrets.
Firebird Database Server Denial-of-Service Vulnerability (CVE-2026-28212)
2 rules 1 TTP 1 CVEAn unauthenticated attacker can cause a denial-of-service condition on vulnerable Firebird database servers by sending a specially crafted network packet that triggers a null pointer dereference.
File with Right-to-Left Override Character (RTLO) Created/Executed
2 rules 2 TTPsThis rule detects the creation or execution of files or processes with names containing the Right-to-Left Override (RTLO) character, which can be used to disguise the file extension and trick users into executing malicious files on Windows systems.
Excessive OneDrive File Downloads Detection
2 rules 1 TTPDetection of unusual high-volume file downloads from Microsoft OneDrive, potentially indicating data exfiltration by a compromised account or insider threat.
ESXi VM Discovery via ESXCLI Commands
2 rulesAdversaries may use ESXCLI commands to discover virtual machines on an ESXi host, potentially indicating reconnaissance for high-value targets, environment mapping, or preparation for data theft or destructive operations.
ericc-ch copilot-api Permissive Cross-Domain Policy Vulnerability (CVE-2026-6662)
2 rules 1 TTP 1 CVE 2 IOCsCVE-2026-6662 is a vulnerability in ericc-ch copilot-api up to 0.7.0, specifically in the cors function of src/server.ts, leading to a permissive cross-domain policy that can be remotely exploited for cross-domain attacks.
Entra ID User Added as Service Principal Owner for Persistence
2 rules 4 TTPsAn adversary may add a user account as an owner for an Azure service principal to define what an application can do in the Azure AD tenant, potentially leading to persistence and privilege escalation.
Entra ID High Risk User Sign-in Detection
2 rules 1 TTPThis rule identifies high-risk Azure Active Directory (AD) sign-ins by leveraging Microsoft Identity Protection machine learning and heuristics, specifically focusing on events with a risk state of `confirmedCompromised` or `atRisk`, indicating potential initial access attempts.
Entra ID Conditional Access Policy (CAP) Modified
2 rules 2 TTPsAn adversary may modify existing Conditional Access Policies (CAPs) in Microsoft Entra ID to weaken access controls and maintain persistence in the environment with a compromised identity.
Elastic Agent Service Termination Attempt
3 rules 1 TTPThis rule detects attempts to stop the Elastic endpoint agent service, which may indicate a defense evasion tactic employed by adversaries to disable security monitoring and evade detection.
Disabling Windows Defender Security Settings via PowerShell
3 rules 2 TTPsAttackers use PowerShell commands like Set-MpPreference or Add-MpPreference, often with base64 encoding, to disable or weaken Windows Defender security settings in order to evade detection and execute malicious payloads.
Disabling User Account Control via Registry Modification
2 rules 3 TTPsAttackers may disable User Account Control (UAC) by modifying specific registry values, allowing them to execute code with elevated privileges, bypass security restrictions, and potentially escalate privileges on Windows systems.
Disable Windows Event and Security Logs Using Built-in Tools
3 rules 3 TTPsAttackers may attempt to disable Windows event logging to evade detection by using built-in tools like logman, PowerShell, and auditpol.
Detection of WMIC System Information Discovery
2 rules 1 TTPAdversaries may use Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically using the `computersystem` alias to retrieve details about the system's configuration, which aids in reconnaissance.
Detection of System Information Discovery Techniques
1 rule 1 TTPThis brief covers the detection of adversaries using native Windows commands like `wmic qfe`, `systeminfo`, and `hostname` to gather system information for further exploitation.
Detection of Office Macro File Creation
2 rules 1 TTPThis brief outlines a threat involving the creation of new Office macro files, potentially indicating malicious activity such as phishing or malware distribution, targeting Windows systems.
Detection of Level RMM Watchdog Task Creation
2 rules 2 TTPsThe creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.
Detection of Level RMM PowerShell Script Installer
2 rules 1 TTP 1 IOCThis brief details the detection of the Level remote management tool PowerShell installer on Windows endpoints, which can be exploited by threat actors for malicious purposes to maintain persistence and execute commands, although it's a legitimate IT tool.
Detecting Execution from Alternate Data Streams
2 rules 1 TTPAdversaries may execute malicious code from Alternate Data Streams (ADS) on Windows to evade defenses by hiding malware within legitimate files, which this detection identifies by monitoring process execution paths and arguments.
Decidim Amendment Manipulation Vulnerability (CVE-2026-40869)
2 rules 1 TTP 1 CVECVE-2026-40869 allows authenticated users to manipulate amendments in Decidim versions 0.19.0 prior to 0.30.5 and 0.31.1, potentially hijacking authorship and impacting proposal integrity.
CVE-2017-3735 Vulnerability Targeting Microsoft Products
2 rules 1 TTP 1 CVECVE-2017-3735 is a vulnerability impacting Microsoft products, potentially allowing unauthorized access or code execution.
Cloud API Calls From Previously Unseen User Roles
2 rules 2 TTPsThis analytic identifies anomalous cloud API calls executed by user roles that have not previously performed those commands, potentially indicating malicious activity or unauthorized actions leading to unauthorized access or data breaches.
Cisco Duo Policy Change to Allow Devices Without Screen Lock
2 rules 1 TTPA Splunk detection analytic identifies when a Duo policy is created or updated to allow devices without a screen lock, potentially weakening device security controls and increasing the risk of unauthorized access and data breaches.
Cisco Duo Policy Allowing Outdated Flash Usage
2 rules 1 TTPA Cisco Duo administrator may create or update a policy to allow the use of outdated Flash components, potentially increasing the attack surface by allowing exploitation of Flash vulnerabilities.
CircleCI Security Job Disablement Detection
2 rules 1 TTPDetection of activity related to disabling security jobs within CircleCI, potentially indicating an attempt to bypass security controls in a CI/CD pipeline.
Brizy WordPress Plugin Unauthenticated Stored XSS Vulnerability
2 rules 1 TTP 1 CVEThe Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.8.11, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page due to missing nonce verification and improper handling of file upload fields.
BITS Transfer Job With Uncommon or Suspicious Remote TLD
2 rules 2 TTPsAdversaries abuse Background Intelligent Transfer Service (BITS) to download malicious payloads from unusual top-level domains, bypassing traditional security measures and establishing persistence on compromised systems.
Azure Kubernetes Services (AKS) Kubernetes Pod Deletion
2 rules 2 TTPsThe deletion of Azure Kubernetes Pods can indicate malicious activity aimed at disrupting the environment's normal behavior.
Azure Domain Federation Settings Modified
2 rules 2 TTPsAn attacker may modify Azure domain federation settings to establish persistence, escalate privileges, or gain unauthorized access to resources.
Azure Blob Storage Container Access Level Modified
2 rules 3 TTPsThe rule identifies modifications to Azure Blob Storage container access levels, which, if unauthorized, may lead to data exposure and exfiltration.
AWS SSM Inventory Reconnaissance by Rare User
2 rules 3 TTPsDetection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.
AWS S3 Data Exfiltration via Uncommon Client Applications
3 rules 2 TTPsThis rule detects AWS API activity originating from uncommon desktop client applications based on the user agent string, specifically S3 Browser and Cyberduck, which provide bulk upload/download capabilities and have been observed in use by threat actors for data exfiltration, warranting validation against authorized data transfer workflows.
AWS S3 Bucket Policy Added to Allow Public Access
2 rules 2 TTPsAn AWS S3 bucket policy was modified to grant public access using a wildcard (Principal:"*") statement, potentially allowing data exfiltration or malicious content hosting.
AWS Route 53 Private Hosted Zone Associated With Unauthorized VPC
2 rules 3 TTPsAn adversary with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment by associating a Route 53 private hosted zone with a new Virtual Private Cloud (VPC).
AWS Network Access Control List Deletion Detected
2 rules 1 TTPDetection of AWS Network Access Control List (ACL) deletion using AWS CloudTrail logs, which can remove critical access restrictions, potentially allowing unauthorized access to cloud instances and leading to data exfiltration or further compromise.
AWS Management Console Root Login Detected
2 rules 2 TTPsDetection of a successful AWS Management Console login by the Root user, which is an original identity with unrestricted privileges, indicates a potential security breach requiring immediate investigation.
AWS IAM SAML Provider Creation for Persistence
3 rules 3 TTPsDetects the creation of a new SAML Identity Provider (IdP) in AWS IAM, potentially indicating an adversary establishing persistent, federated access to AWS accounts by forging SAML assertions from an IdP they control.
AWS IAM Operations via Compromised CloudShell
2 rules 4 TTPsCompromised AWS console sessions can lead to attackers performing sensitive IAM operations via CloudShell to establish persistence or escalate privileges.
AWS IAM Key Creation with Encryption Policy but Without MFA
2 rules 2 TTPsDetection of AWS IAM users creating access keys with encryption policies applied while failing to use multi-factor authentication, potentially indicating compromised accounts or malicious privilege escalation.
AWS Config Service Disabling Detection
2 rules 1 TTPDetection of AWS Config Service disabling, potentially indicating an attempt to impair defenses by stopping configuration recording and delivery.
AWS Config Resource Deletion for Defense Evasion
2 rules 2 TTPsAn adversary may delete AWS Config resources to evade detection, hide prior activity, or weaken governance controls, which reduces security visibility and auditability within an AWS environment.
AWS CloudTrail Logging Evasion via Oversized IAM Policies
2 rules 1 TTPAttackers evade AWS CloudTrail logging by padding IAM policy documents with whitespace, exceeding logging size limits and obscuring unauthorized changes to IAM policies.
AppInit DLL Registry Persistence Detected
2 rules 2 TTPsModification of the AppInit DLLs registry keys can be used for persistence and defense evasion on Windows systems.
Android-ImageMagick7 Memory Leak Vulnerability (CVE-2026-33856)
2 rules 1 TTPA missing release of memory after effective lifetime vulnerability exists in MolotovCherry Android-ImageMagick7 before version 7.1.2-11, potentially leading to denial of service.
Algovate xhs-mcp Server-Side Request Forgery Vulnerability
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability exists in Algovate xhs-mcp 0.8.11 within the xhs_publish_content function, allowing a remote attacker to manipulate the media_paths argument and potentially access internal resources.
Abuse of Predefined BIOCs in Palo Alto Cortex XDR
2 rules 1 TTPAttackers may decrypt and abuse predefined Behavioral Indicators of Compromise (BIOCs) in Palo Alto Cortex XDR to evade detection or manipulate the system.
Abnormal Cloud Security Group API Call Activity
2 rules 2 TTPsDetection of an abnormally high number of cloud security group API calls which can indicate malicious activity such as reconnaissance, privilege escalation, or lateral movement within a cloud environment.
Zebra Block Discovery Denial-of-Service via Gossip Queue Saturation and Syncer Poisoning
2 rules 1 TTP 1 CVEA denial-of-service vulnerability exists in Zebra's block discovery pipeline, allowing an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node by exploiting weaknesses in the gossip, syncer, and download subsystems.
Windows Update Client DLL Loading Abuse
2 rules 2 TTPsAdversaries abuse the Windows Update Auto Update Client (wuauclt.exe) to load arbitrary DLLs from user-writable locations, achieving defense evasion and execution of malicious code.
Windows Privilege Escalation via Secondary Logon Service
2 rules 2 TTPsThe rule identifies process creation with alternate credentials, which can be used for privilege escalation, by detecting successful logins via the Secondary Logon service (seclogon) from a local source IP address (::1), followed by process creation using the same TargetLogonId.
Unusual EC2 Instance Creation with Unseen Instance Type
2 rules 1 TTPAn attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.
Suspicious MS Outlook Child Process
2 rules 3 TTPsDetection of suspicious child processes spawned by Microsoft Outlook, indicative of spear phishing and malicious file execution leading to potential initial access and further exploitation.
Suspicious Execution via Windows Subsystem for Linux
2 rules 3 TTPsThis rule detects suspicious execution via the Windows Subsystem for Linux (WSL), which adversaries may leverage to execute Linux commands and bypass traditional Windows security measures.
Suspicious CertUtil Commands for Defense Evasion and Lateral Movement
2 rules 3 TTPsThis rule detects suspicious use of certutil.exe, a native Windows utility often abused by attackers for downloading/deobfuscating malware and exfiltrating data, by identifying commands involving decoding, encoding, URL caching, CTL verification, and PFX exporting, which are frequently used for command and control and defense evasion.
Remote Execution via File Shares
2 rules 1 TTPThis rule identifies potential lateral movement via network file shares by detecting the execution of a file that was created by the virtual system process.
Remote Execution of Windows Services via RPC
2 rules 2 TTPsDetection of remote execution of Windows services over RPC by correlating `services.exe` network connections and spawned child processes, potentially indicating lateral movement.
Potential Exploitation of Unquoted Service Path Vulnerability
2 rules 1 TTPThis rule detects potential exploitation of unquoted service paths on Windows systems, which can lead to privilege escalation by identifying suspicious processes starting from common unquoted paths, indicating a potential attempt to execute malicious code.
Leveraging Apple's Endpoint Security Framework for Process Monitoring
2 rules 2 TTPsThis brief discusses the use of Apple's Endpoint Security Framework in macOS 10.15 and later for user-mode process monitoring, offering improved capabilities over the older OpenBSM subsystem.
Large ICMP Traffic Detection
2 rules 1 TTPThis analytic identifies excessive ICMP traffic to external IP addresses exceeding 1,000 bytes, potentially indicating command and control activity, data exfiltration, or covert communication channels.
Impact of Poor Security Operation Center (SOC) Metrics
2 rules 2 TTPsPoorly chosen performance metrics can significantly impair a SOC's ability to detect and respond to threats, leading to ineffective security operations and potential compromise.
Google Workspace Marketplace Restrictions Modified to Allow Any App
2 rules 2 TTPsAn adversary may modify Google Workspace Marketplace restrictions to allow installation of any application, potentially enabling the deployment of malicious APKs to end users within the Google Workspace environment, bypassing security restrictions.
Execution via GitHub Actions Runner
3 rules 3 TTPsAdversaries compromising GitHub Actions workflows can execute arbitrary commands on runner hosts, leading to code execution, reconnaissance, credential harvesting, or network exfiltration.
Execution of COM object via Xwizard
2 rules 2 TTPsAdversaries can abuse the legitimate system binary Xwizard to execute Component Object Model (COM) objects, evading defensive countermeasures by running COM objects created in the registry.
Execution from Unusual Directory - Command Line
2 rules 3 TTPsAdversaries may execute commands and scripts from unusual Windows directories to masquerade malware and evade detection, impacting system integrity and security operations.
Disabling Windows Defender Security Settings via PowerShell
2 rules 2 TTPsThis rule detects the use of the Set-MpPreference PowerShell command to disable or weaken Windows Defender settings, a common defense evasion tactic.
AWS WAF Access Control List Deletion
2 rules 1 TTPDetection of AWS Web Application Firewall (WAF) Web ACL deletion, which adversaries may perform to disable security controls, evade detection, and prepare for subsequent attacks, potentially leading to web-application compromise, data theft, or resource abuse.