Tag
Bitdefender Internet and Total Security Vulnerability Allows Privilege Escalation
1 TTPA local attacker can exploit a vulnerability in Bitdefender Internet Security and Bitdefender Total Security to elevate their privileges on the affected system.
Detection of Web Shell via Antivirus Signature
1 rule 1 TTPThis brief describes the detection of web shells by antivirus solutions, emphasizing the importance of investigating these alerts as they signify a compromised web server and potential post-exploitation activity by an attacker.
Detection of Malicious Remote Access Tools by Antivirus
1 rule 1 TTPThis brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.
Antivirus - Ransomware Signature Detection
1 rule 1 TTPThis brief describes a critical Sigma rule designed to detect highly relevant Antivirus alerts reporting known ransomware families, enabling detection engineers to ensure immediate investigation even when the malware has been blocked.
Antivirus Alert for Password Dumper and Stealer Activity
1 rule 4 TTPsThis brief details the detection of highly relevant antivirus alerts indicating the presence of password dumpers and stealers on endpoints, emphasizing the critical need for investigation even if the malware is blocked, to prevent credential compromise and subsequent attacks.
Antivirus Alert for Hacktools or Attack Tools
1 rule 1 TTPThis brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.
Detection of Advanced Persistent Threat (APT) Malware Signatures in Antivirus Logs
1 rule 1 TTPThis brief details a detection rule for critical antivirus alerts that report Advanced Persistent Threat (APT) malware signatures, enabling detection engineers to identify and investigate sophisticated threats that have reached endpoints.
Avast Antivirus Privilege Escalation Vulnerability
2 rules 1 TTPA local attacker can exploit a vulnerability in Avast Antivirus and AVG Technologies Anti-Virus to escalate privileges on a Windows system.
Potential Disabling of Windows Defender Antivirus via Registry Modification
2 rules 1 TTPAn attacker might attempt to disable Windows Defender Antivirus by modifying specific registry keys, potentially leading to a system vulnerable to malware and other threats.
Windows Defender Antivirus Disabled via Registry Modification
2 rules 1 TTPAttackers modify Windows Defender registry settings to disable antivirus and antispyware protections, evading detection and maintaining persistence.