Skip to content
Threat Feed

Tag

Anomaly

18 briefs RSS
medium advisory

Ollama Abnormal Network Connectivity Detected

This detection identifies unusual network patterns and connection problems within Ollama, encompassing unauthorized API access attempts beyond localhost and warning-level network errors like DNS lookup failures, TCP connection issues, or host resolution problems, which can signal network-based attacks, unauthorized access, or infrastructure reconnaissance.

Ollama network-connectivity anomaly
2r 1t
medium advisory

Cloud Instance Modified by Previously Unseen User

This analytic identifies cloud instances being modified by users who have not previously modified them, specifically focusing on successful modifications of EC2 instances, potentially indicating unauthorized access and configuration changes.

EC2 +1 cloud aws anomaly
2r 2t
high advisory

Windows System File Execution from Unusual Location

This rule detects the execution of legitimate Windows system binaries from non-standard locations, potentially indicating malicious activity such as malware execution or defense evasion.

Windows defense-evasion anomaly
2r 1t
high advisory

Unusual Process Loading Mozilla NSS/Mozglue Module

Detection of processes loading Mozilla NSS/Mozglue libraries (mozglue.dll, nss3.dll) outside of known Mozilla applications, potentially indicating malware or unauthorized activity.

Firefox +9 defense-evasion anomaly windows
2r 1t
medium advisory

Windows Firewall Rule Modification Detection

This detection identifies instances where a Windows Firewall rule has been modified, potentially indicating an attempt to weaken security policies and allow malicious traffic or prevent legitimate communications.

Windows +3 firewall anomaly
2r
high advisory

Unusual Cloud Security Group Modifications by User

This analytic identifies unusual modifications to cloud security groups by users, such as modifications, deletions, or creations, analyzed over 30-minute intervals, potentially indicating compromised accounts or insider threats leading to resource exposure or service disruption.

AWS +2 cloud security_group anomaly
2r 2t
high threat

Suspicious Bluetooth Service Installation from Uncommon Location

The creation of a Windows service named 'BluetoothService' with a binary path in user-writable directories, such as %AppData%, indicates potential malware persistence, as seen in the Lotus Blossom Chrysalis backdoor campaign.

Windows Lotus Blossom persistence defense-evasion anomaly
2r 2t
medium advisory

Linux Auditd Daemon Abort Detection

Detection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.

Splunk Enterprise +3 auditd linux anomaly endpoint
2r 1t
medium advisory

ESXi Download Error Detection

Detection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.

ESXi +3 vmware syslog anomaly T1601.001 T1685 ESXi Post Compromise Black Basta Ransomware Infrastructure +1
2r 2t
medium advisory

Detection of Failed ESXi File Downloads

This detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in system logs, potentially indicating unauthorized attempts to install malicious components or scripts.

ESXi vmware download-error anomaly black-basta
2r 2t
medium advisory

Cloud Provisioning Activity From Previously Unseen Region

This analytic detects cloud provisioning activities originating from previously unseen regions by identifying resource creation events and cross-referencing them with a baseline of known regions, potentially indicating unauthorized access or misuse of cloud resources.

AWS cloud provisioning anomaly
2r 1t
high advisory

Cloud Compute Instance Created With Previously Unseen Image

This analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.

EC2 cloud aws cloudtrail compute_instance anomaly
2r 2t
medium advisory

AWS ECR Container Upload Anomaly Outside Business Hours

This detection identifies uploads of new containers to AWS Elastic Container Registry (ECR) outside of standard business hours, potentially indicating unauthorized access or malicious deployments.

AWS +1 cloud ecr anomaly
2r 1t
medium advisory

Linux Stdout Redirection to /dev/null Indicates Potential Malware Activity

The redirection of standard output to /dev/null on Linux systems, particularly when observed in conjunction with other suspicious activities, can indicate attempts to hide malicious command execution, as seen in malware like Cyclops Blink, potentially leading to unauthorized system modifications and persistent access.

Splunk Enterprise +2 linux malware cyclopsblink anomaly endpoint
2r
medium advisory

Linux Auditd Daemon (Re)Initialization Detection

Detection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.

Splunk Enterprise +4 linux auditd anomaly
3r 1t
high advisory

Detection of M365 Copilot Jailbreak Attempts via Prompt Injection

This detection identifies attempts to jailbreak M365 Copilot by using prompt injection techniques to bypass safety controls and manipulate system behavior, potentially violating acceptable use policies.

Microsoft 365 Copilot m365 copilot jailbreak prompt-injection anomaly
2r 1t
medium advisory

Cloud API Calls From Previously Unseen User Roles

This analytic identifies anomalous cloud API calls executed by user roles that have not previously performed those commands, potentially indicating malicious activity or unauthorized actions leading to unauthorized access or data breaches.

Amazon Web Services cloud aws anomaly assumedrole
2r 2t
medium advisory

Unusual EC2 Instance Creation with Unseen Instance Type

An attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.

EC2 cloud anomaly cryptomining
2r 1t