Tag
Ollama Abnormal Network Connectivity Detected
2 rules 1 TTPThis detection identifies unusual network patterns and connection problems within Ollama, encompassing unauthorized API access attempts beyond localhost and warning-level network errors like DNS lookup failures, TCP connection issues, or host resolution problems, which can signal network-based attacks, unauthorized access, or infrastructure reconnaissance.
Cloud Instance Modified by Previously Unseen User
2 rules 2 TTPsThis analytic identifies cloud instances being modified by users who have not previously modified them, specifically focusing on successful modifications of EC2 instances, potentially indicating unauthorized access and configuration changes.
Windows System File Execution from Unusual Location
2 rules 1 TTPThis rule detects the execution of legitimate Windows system binaries from non-standard locations, potentially indicating malicious activity such as malware execution or defense evasion.
Unusual Process Loading Mozilla NSS/Mozglue Module
2 rules 1 TTPDetection of processes loading Mozilla NSS/Mozglue libraries (mozglue.dll, nss3.dll) outside of known Mozilla applications, potentially indicating malware or unauthorized activity.
Windows Firewall Rule Modification Detection
2 rulesThis detection identifies instances where a Windows Firewall rule has been modified, potentially indicating an attempt to weaken security policies and allow malicious traffic or prevent legitimate communications.
Unusual Cloud Security Group Modifications by User
2 rules 2 TTPsThis analytic identifies unusual modifications to cloud security groups by users, such as modifications, deletions, or creations, analyzed over 30-minute intervals, potentially indicating compromised accounts or insider threats leading to resource exposure or service disruption.
Suspicious Bluetooth Service Installation from Uncommon Location
2 rules 2 TTPsThe creation of a Windows service named 'BluetoothService' with a binary path in user-writable directories, such as %AppData%, indicates potential malware persistence, as seen in the Lotus Blossom Chrysalis backdoor campaign.
Linux Auditd Daemon Abort Detection
2 rules 1 TTPDetection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.
ESXi Download Error Detection
2 rules 2 TTPsDetection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.
Detection of Failed ESXi File Downloads
2 rules 2 TTPsThis detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in system logs, potentially indicating unauthorized attempts to install malicious components or scripts.
Cloud Provisioning Activity From Previously Unseen Region
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.
Cloud Compute Instance Created With Previously Unseen Image
2 rules 2 TTPsThis analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.
AWS ECR Container Upload Anomaly Outside Business Hours
2 rules 1 TTPThis detection identifies uploads of new containers to AWS Elastic Container Registry (ECR) outside of standard business hours, potentially indicating unauthorized access or malicious deployments.
Linux Stdout Redirection to /dev/null Indicates Potential Malware Activity
2 rulesThe redirection of standard output to /dev/null on Linux systems, particularly when observed in conjunction with other suspicious activities, can indicate attempts to hide malicious command execution, as seen in malware like Cyclops Blink, potentially leading to unauthorized system modifications and persistent access.
Linux Auditd Daemon (Re)Initialization Detection
3 rules 1 TTPDetection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.
Detection of M365 Copilot Jailbreak Attempts via Prompt Injection
2 rules 1 TTPThis detection identifies attempts to jailbreak M365 Copilot by using prompt injection techniques to bypass safety controls and manipulate system behavior, potentially violating acceptable use policies.
Cloud API Calls From Previously Unseen User Roles
2 rules 2 TTPsThis analytic identifies anomalous cloud API calls executed by user roles that have not previously performed those commands, potentially indicating malicious activity or unauthorized actions leading to unauthorized access or data breaches.
Unusual EC2 Instance Creation with Unseen Instance Type
2 rules 1 TTPAn attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.