Tag
Detection of Unauthorized Hosts File Modifications
1 rule 1 TTPAdversaries manipulate endpoint hosts files to intercept network traffic, enabling malicious infrastructure redirection or the disruption of security services such as MFA.
Detection of Web Server Access Log Deletion
1 rule 1 TTPAdversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.
Detection of Anomalous SOCKS Proxy Traffic via FortiGate Integration
1 TTPThis detection leverages cross-platform correlation between FortiGate network application logs and endpoint telemetry to identify processes acting as SOCKS proxies for potential command and control obfuscation.
Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity
1 TTPThis detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.
Nimbus Manticore Targets Developers with Node.js-based Cross-Platform RATs
1 rule 3 TTPs 3 IOCsThe Iranian threat actor Nimbus Manticore is distributing NodeRabbit and PollCat cross-platform RATs via trojanized coding challenges on LinkedIn to compromise developer systems.
UAT-10147 Deploys SPECTRE Cross-Platform Backdoor
2 rules 6 TTPs 2 IOCsThe threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.
Emerging Threat: QuimaRAT, a Cross-Platform Java-Based Remote Access Trojan
2 TTPsQuimaRAT is a newly identified Java-based Remote Access Trojan (RAT) distributed via a Malware-as-a-Service (MaaS) model, capable of targeting Windows, Linux, and macOS systems with a modular architecture for remote access and dynamic functionality expansion.
Web Server Potential SQL Injection Attempt Detection
1 rule 6 TTPsThis brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.