Tag
Detection of Browser-Spawned Unix Shells with External Connectivity
1 TTPAnomalous execution pattern where Unix-based browser processes spawn shells to initiate outbound external network connections, a TTP indicative of potential drive-by exploitation or browser-based post-exploitation.
Detection of Typosquatted Python Package Installation
2 rules 2 TTPsA detection identifies suspicious installations of Python packages, leveraging Cisco NVM flow telemetry to monitor `pip` or `poetry` commands making outbound connections to public repositories for package names resembling known typosquats, indicating potential malicious software supply chain compromise.
Suspicious Download from File Sharing Website via LOLBins
3 rules 1 TTP 26 IOCsDetection of suspicious downloads from file sharing and content delivery platforms using living-off-the-land binaries (LOLBins) to identify potential initial access, payload staging, or command and control activity.
Suspicious File Download via Headless Browser
2 rules 2 TTPs 26 IOCsAttackers are leveraging Chromium-based browsers in headless mode with the `--dump-dom` argument to download files from file-sharing services and direct IPs, potentially indicative of reconnaissance or malware delivery.