Skip to content
Threat Feed

Tag

Collection

42 briefs RSS
medium advisory

Abuse of AWS EC2 Export APIs for Data Exfiltration

Adversaries with compromised AWS credentials can exploit EC2 export APIs to copy entire virtual machine states or images to external storage for data exfiltration.

Elastic Compute Cloud +1 cloud exfiltration collection aws
1r 2t updated
medium advisory

Unauthenticated AWS S3 Bucket Access via Misconfigured Policies

Adversaries leverage misconfigured S3 bucket policies to perform unauthenticated data collection, discovery, and manipulation using tools like the AWS CLI without authentication.

Amazon S3 +1 cloud aws s3 collection discovery impact
4t updated
medium advisory

Detection of Unauthorized S3 Bucket Public Access Policies

Adversaries may modify Amazon S3 bucket policies to include a wildcard ('*') principal with 'Allow' permissions, effectively making bucket contents publicly accessible for data exfiltration.

S3 +1 cloud aws exfiltration collection
1r 2t updated
medium advisory

Detection of AWS EC2 Deprecated AMI Discovery

Detection of reconnaissance activity where AWS users or roles query the EC2 API for deprecated Amazon Machine Images, a technique used by adversaries to identify vulnerable or outdated system images for potential exploitation.

Amazon EC2 cloud-security discovery aws cloud exfiltration collection persistence defense-evasion
3r 7t updated
medium advisory

Detection of Unauthorized AWS RDS Instance Restoration

Threat actors with compromised AWS credentials may use RDS restoration operations to duplicate sensitive database environments, facilitating unauthorized data access, staging, and exfiltration while bypassing production monitoring controls.

Relational Database Service cloud defense-evasion collection aws
1r 3t
low advisory

Abuse of OpenSSL Utility for Data Encryption

Adversaries leverage the legitimate OpenSSL command-line utility to encrypt sensitive files for ransomware extortion or to obfuscate data prior to exfiltration.

defense-evasion collection openssl ransomware
1r 2t updated
medium advisory

Potential Unauthorized Secret Scanning via Gitleaks

Threat actors may leverage the legitimate open-source tool 'Gitleaks' to perform unauthorized secret scanning on compromised hosts to identify and exfiltrate sensitive credentials from source code repositories.

credential-access collection gitleaks threat-detection
1r 2t
high advisory

Unauthorized GenAI Tool Access to Sensitive Local System Files

Attackers are increasingly leveraging GenAI agent processes to perform unauthorized discovery, harvesting of sensitive credentials, and establishment of persistence via shell configuration modifications.

credential-access collection persistence genai-security
1r 2t
medium advisory

Unauthorized Access to Sensitive Files in AWS S3

This detection brief addresses the risk of unauthorized access to sensitive credential and secret files stored in AWS S3 buckets, a common tactic for credential harvesting and lateral movement.

AWS S3 +1 cloud-security credential-access aws exfiltration s3 cloud discovery impact +1
3r 6t updated
medium advisory

Suspicious PowerShell Reconnaissance and Data Export

Adversaries utilize automated PowerShell reconnaissance commands combined with redirection to temporary files to collect and stage system information for exfiltration.

collection powershell reconnaissance
1r 1t
medium advisory

PowerShell Local Email Collection Techniques

Adversaries use PowerShell scripts leveraging Outlook COM objects to programmatically access and exfiltrate user email data from local systems.

collection powershell outlook
1r 1t
medium advisory

PowerShell-Based Keylogging Detection

Adversaries utilize PowerShell scripts to interface with user32.dll for monitoring user keystrokes to facilitate credential theft.

credential-access collection powershell windows
1r 2t
medium advisory

Windows Screen Capture via PowerShell CopyFromScreen

Adversaries use the .NET CopyFromScreen method within PowerShell scripts to capture desktop screenshots for information gathering during post-compromise operations.

collection reconnaissance powershell endpoint-monitoring
1r 1t
medium advisory

Detection of Automated PowerShell Data Collection

Adversaries utilize automated PowerShell scripts to locate and gather sensitive documents across local file systems for subsequent exfiltration.

collection powershell reconnaissance
1r 1t
medium advisory

Detection of Sensitive Data Aggregation via Compression Utilities

Adversaries frequently use standard compression utilities like tar, zip, or gzip to aggregate sensitive files such as SSH keys, cloud credentials, and configuration files prior to exfiltration.

credential-access collection linux endpoint
1r 2t
medium advisory

Detection of Unusual OAuth Application Access to SharePoint and OneDrive

This brief details a detection strategy for identifying potential OAuth phishing and illicit consent grants by monitoring for first-time application access to Microsoft 365 file storage.

SharePoint Online +1 cloud identity oauth phishing collection
1r 2t
low advisory

Detection of Unauthorized Clipboard Utility Execution on Linux

This brief details a detection strategy for identifying unauthorized collection of clipboard data on Linux systems by monitoring the execution of common clipboard utilities from uncommon parent processes.

collection linux endpoint-security
1r 1t
medium threat

Braodo Stealer Screen Capture Activity

The Braodo stealer malware captures victim desktop screenshots and stages them in temporary directories, facilitating subsequent data exfiltration.

Braodo Stealer stealer information-theft windows collection
1r 1t
medium advisory

Unauthorized NFS Root Access via AUTH_SYS Credentials

Detection of unauthorized NFS client access where a remote system asserts root-equivalent (UID 0) privileges over weak RPC/UNIX authentication, facilitating data collection and traversal.

NFS network collection rpc
1r 2t
medium advisory

AWS S3 Bucket ACL Modification to Public Access by New Identity

Detection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.

AWS S3 +1 cloud aws collection s3
1r 1t updated
low advisory

Unusual Remote File Size Detected by ML

An Elastic machine learning job detects unusually large file transfers by remote hosts, indicating potential lateral movement or data exfiltration by adversaries who consolidate data into single large files to avoid detection.

Elastic Defend +3 lateral-movement collection data-exfiltration machine-learning anomaly-detection elastic-defend
3t
medium advisory

LLM-Based Triage of Wget Activity on Linux Hosts

Elastic has developed a detection rule that monitors non-allowlisted `wget` activity on Linux hosts using Auditd Manager or Auditbeat, leveraging an Elastic LLM to triage `wget` executions for potential ingress tool transfer, command and control, or data exfiltration attempts to untrusted destinations, generating alerts only for high-confidence positive or suspicious verdicts.

Elastic Stack +6 endpoint llm linux threat-detection collection command-and-control exfiltration auditd +1
1r 3t 13i updated
medium advisory

LLM-Based Detection of Suspicious Curl Activity on Linux

Elastic's LLM-based detection rule identifies suspicious `curl` activity on Linux systems, aiming to detect command and control, data exfiltration, or ingress tool transfer by analyzing command-line parameters and network destinations via Auditd Manager or Auditbeat logs, which, if left unaddressed, could lead to system compromise or data breach.

Azure +3 Endpoint LLM Linux Threat Detection Collection Command and Control Exfiltration Auditd Manager
3t updated
low advisory

AWS S3 Rapid Bucket Posture API Calls from a Single Principal

This detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.

S3 +2 aws cloudtrail discovery collection reconnaissance cloud
4t updated
high advisory

Gravity Forms Directory Traversal Vulnerability (CVE-2026-12997)

Unauthenticated attackers can exploit a Directory Traversal vulnerability (CVE-2026-12997) in the Gravity Forms plugin for WordPress, affecting all versions up to and including 2.10.4, to read arbitrary files on the server and receive their contents as an email attachment, potentially exfiltrating sensitive information.

Gravity Forms plugin wordpress plugin web-vulnerability collection network
1r 2t 1c
medium advisory

Devolutions Server: Multiple Vulnerabilities Allow Authenticated Attackers to Manipulate Data, Bypass Security, and Disclose Information

A remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to manipulate data, bypass security measures, and disclose information.

Devolutions Server initial-access defense-evasion collection impact
4t
high advisory

QEMU and libvirt: Multiple Vulnerabilities

Multiple vulnerabilities exist in QEMU and libvirt, which can be exploited by a local attacker to disclose sensitive information and bypass security mechanisms, potentially leading to privilege escalation.

QEMU +1 vulnerability linux virtualization defense-evasion privilege-escalation collection
1t
high advisory

CVE-2026-6854 - WordPress My Calendar Plugin Time-Based Blind SQL Injection

A time-based blind SQL Injection vulnerability exists in the My Calendar - Accessible Event Manager plugin for WordPress, affecting all versions up to and including 3.7.8. This flaw, located in the 'mc_auth' parameter, stems from insufficient input sanitization and improper SQL query preparation, allowing unauthenticated attackers to inject additional SQL queries to extract sensitive information from the underlying database.

My Calendar - Accessible Event Manager plugin <= 3.7.8 wordpress sql-injection vulnerability web-application collection initial-access
1r 2t 1c
high advisory

Detection of PowerShell Get-Clipboard for Data Collection

This brief describes the detection of adversaries leveraging the `Get-Clipboard` PowerShell commandlet, identified through PowerShell Script Block Logging (EventCode 4104), to steal sensitive information such as credentials or PII from the Windows clipboard during the collection phase of an attack, potentially leading to unauthorized access and further compromise.

collection endpoint powershell data-theft post-exploitation
1r 1t
high advisory

praisonai-platform: Cross-Workspace Label IDOR Vulnerability

Praison AI's praisonai-platform is vulnerable to an insecure direct object reference (IDOR) in the label endpoints (CVE-2026-47414), allowing cross-workspace label modification and information disclosure due to improper validation of label and issue IDs.

praisonai-platform idor vulnerability privilege-escalation collection impact cloud
2r 3t
high advisory

GenAI Tools Accessing Sensitive Files for Credential Access and Persistence

This threat brief details the detection of GenAI tools accessing sensitive files containing credentials, SSH keys, browser data, and shell configurations, indicating potential credential harvesting and persistence attempts by attackers leveraging GenAI agents.

Elastic Endpoint Security genai credential-access persistence collection
2r 4t
medium advisory

AWS S3 Unauthenticated Bucket Access by Rare Source

This rule detects AWS CloudTrail events indicative of unauthenticated sources attempting to access an S3 bucket, potentially exposing sensitive data due to misconfigured bucket policies.

Amazon S3 aws s3 unauthenticated-access cloudtrail collection
2r 4t
low advisory

AWS S3 Bucket Enumeration and Brute Force Attempts

A high number of failed S3 operations (AccessDenied errors) against a single bucket from a single source address within a short timeframe can indicate attempts to enumerate bucket objects, brute-force object keys, or inflate AWS billing.

Amazon S3 cloud aws s3 enumeration brute_force impact discovery collection
2r 4t
medium advisory

Remote File Copy to a Hidden Share

Detects remote file copy attempts to hidden network shares, indicative of lateral movement or data staging, by monitoring command-line tools like cmd.exe and powershell.exe for hidden share patterns.

Windows lateral-movement collection
2r 3t
medium advisory

Kubernetes Secret or ConfigMap Access via Azure Arc Proxy

Detection of unauthorized access to Kubernetes secrets or configmaps via the Azure Arc AAD proxy service account, indicating potential abuse of stolen service principal credentials to read, exfiltrate, or modify sensitive data.

Azure Arc +2 kubernetes azure-arc credential-access collection
2r 2t
medium advisory

Detection of Sensitive LDAP Attribute Access

This rule detects unauthorized access to sensitive Active Directory object attributes such as unixUserPassword, ms-PKI-AccountCredentials, and msPKI-CredentialRoamingTokens, potentially leading to credential theft and privilege escalation.

Active Directory +1 credential-access privilege-escalation collection windows
2r 5t
medium advisory

Linux Clipboard Activity Monitoring

This brief provides detection strategies for monitoring clipboard activity on Linux systems, potentially identifying malicious data exfiltration or command execution attempts.

Linux clipboard data exfiltration collection
3r 1t
medium advisory

OpenSSL Data Encryption Detection

This brief documents detection of OpenSSL being used to encrypt data using command-line arguments specifying input and output files, potentially indicating data exfiltration preparation or ransomware activity by threat actors.

OpenSSL defense-evasion collection data-encryption
2r 2t
medium advisory

Exchange Mailbox Export via PowerShell

Adversaries may use the New-MailboxExportRequest PowerShell cmdlet to export mailboxes in Exchange, potentially leading to sensitive information theft.

Microsoft Defender XDR +2 collection execution powershell exchange mailbox
2r 4t
low advisory

AWS CloudTrail Trail Creation Detected

Detection of new AWS CloudTrail trail creation, potentially indicating malicious activity such as subverting monitoring objectives or capturing sensitive data by adversaries.

CloudTrail aws collection defense_evasion
2r 2t
medium advisory

Linux Sensitive File Compression for Credential Access

Attackers may use compression utilities like zip, tar, and gzip on Linux systems to collect and archive sensitive files containing credentials and system configurations for credential access and data exfiltration.

Elastic Defend +2 credential-access collection linux
2r 3t
high advisory

PowerShell Keylogging Script Detection

This brief documents a high-severity threat involving PowerShell scripts used for keylogging on Windows systems to capture credentials and sensitive user input.

Windows +1 keylogger powershell collection
2r 1t