Skip to content
Threat Feed

Tag

Detection-Engineering

26 briefs RSS
medium advisory

Detection of SDK-Based AWS Control Plane Discovery from Suspicious Processes

This detection monitors for processes executing from temporary or user-writable directories that perform DNS queries to AWS management endpoints, a pattern frequently utilized by post-exploitation tools to bypass CLI-based security controls.

AWS IAM +5 cloud-security discovery aws credential-theft detection-engineering
2t
high advisory

Detection of Potential Lateral Movement via Alert Correlation

This detection capability monitors for lateral movement by identifying sequences where a host IP address from one security alert subsequently appears as the source IP in alerts from a different host.

lateral-movement threat-detection esql detection-engineering
1t
medium advisory

Monitoring Azure Run Command for Unauthorized Execution

This brief outlines detection strategies for unauthorized guest execution via the Azure Virtual Machine Run Command feature, which attackers may abuse to run arbitrary scripts without interactive access.

Azure Virtual Machine azure cloud execution detection-engineering
1r 2t
medium advisory

Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity

This detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.

PAN-OS +1 command-and-control detection-engineering network-security cross-platform
1t
medium advisory

Detecting Identity Masquerading via Behavioral Clustering

Security researchers have developed a behavioral clustering model using unsupervised machine learning to differentiate between legitimate cloud functional roles and attackers masquerading as authorized identities.

AWS Identity and Access Management +1 cloud-security identity-access-management behavior-analysis detection-engineering
1t
rumour rumour

Linux Local Privilege Escalation Detection Framework

This brief summarizes a detection engineering framework from Elastic Security Labs for identifying post-exploitation activity and system misconfigurations associated with Linux local privilege escalation.

linux detection-engineering privilege-escalation informational
1t
low advisory

Detection of Newly Observed IPSEC NAT Traversal Peers

Detection of potentially unauthorized IPSEC NAT Traversal (NAT-T) tunnels indicates potential command and control (C2) or exfiltration activity masked by encrypted traffic.

command-and-control network-security vpn detection-engineering
1r 3t
medium advisory

Cross-Platform C2 Detection via Suricata and Elastic Defend Correlation

This detection capability correlates network-layer Suricata alerts with host-based process telemetry from Elastic Defend to identify malicious outbound command and control communication.

command-and-control detection-engineering network-security
3t
high advisory

Suspicious PowerShell Invoke-WebRequest Usage for File Downloads

This threat brief details the detection of suspicious PowerShell Invoke-WebRequest activity used to download payloads into high-risk, world-writable directories on Windows systems.

windows powershell command-and-control detection-engineering
1r 1t
high advisory

Detection of Suspicious File Writes by Core Windows Processes

Detection of suspicious file creation events where critical Windows system binaries write files with potentially malicious extensions, indicating potential process masquerading or system compromise.

stealth persistence detection-engineering windows-security
1r 1t
medium advisory

Detecting PowerShell Command Line Obfuscation Techniques

Detection logic for identifying PowerShell execution utilizing excessive special characters for command line obfuscation to bypass security monitoring.

obfuscation powershell detection-engineering
1r 2t
medium advisory

Abuse of PowerShell MSXML COM Objects for Network Interaction

Adversaries leverage the MSXML2 COM object within PowerShell scripts to facilitate network communication and potential code execution.

living-off-the-land execution powershell detection-engineering
1r 1t
low advisory

Detection Capability for Executable File Creation via Sysmon

This brief details a detection capability for monitoring the creation of Portable Executable files using Sysmon Event ID 29 to identify unauthorized binary drops.

windows sysmon detection-engineering defensive-telemetry
1r
high advisory

Detection of Script Interpreter Execution from Suspicious Directories

Adversaries frequently utilize script interpreters such as cscript, wscript, and mshta from non-standard or user-writable directories to execute malicious payloads while evading security controls.

living-off-the-land detection-engineering execution
1r 1t
medium threat

Detection of WinAPI Function Calls via Command Line Interface

Adversaries are leveraging tools like winapiexec to execute Windows API functions directly from the command line to bypass traditional binary-based detection methods.

exploited execution detection-engineering windows-security
1r 1t
medium advisory

Detection of LOLBin Relocation Techniques

Adversaries frequently copy Living-off-the-Land Binaries (LOLBins) from protected system directories to arbitrary locations to evade security controls that rely on path-based allowlisting.

stealth persistence lolbin windows detection-engineering
1r 1t
medium advisory

Detection of PowerShell Base64 Decoding Techniques

This brief documents the use of the 'FromBase64String' method within PowerShell command lines, a common technique for obfuscating malicious payloads to bypass signature-based detection.

stealth obfuscation powershell detection-engineering
1r 2t
high advisory

Detection of Suspicious PowerShell Invocation Patterns

This brief documents detection logic for common PowerShell obfuscation and execution patterns frequently leveraged by attackers to maintain persistence, bypass security policies, and download secondary payloads.

execution powershell detection-engineering windows
1r 1t
medium advisory

Detection of Suspicious Web Request Execution via PowerShell and CLI

This brief documents detection logic for identifying potential malicious file downloads and C2 communication using native Windows command-line tools and PowerShell cmdlets.

detection-engineering windows execution living-off-the-land
1r 1t
high advisory

Detection of Windows Service Binaries in Suspicious Directories

Adversaries often achieve persistence by registering malicious Windows services with binaries located in writeable or temp directories to evade detection.

persistence defense-impairment windows-registry detection-engineering
1r 1t
medium advisory

Detection of Suspicious Web Server Child Processes on Linux

This brief provides detection logic to identify potential webshell activity on Linux systems by monitoring for suspicious child processes spawned by common web server applications.

persistence linux web-server detection-engineering
1r 1t
medium advisory

Detection of Stealthy User Account Creation via ADSI

Adversaries may use Active Directory Service Interfaces (ADSI) within PowerShell to create local or domain accounts, effectively bypassing standard monitoring for typical user-creation commands.

persistence windows powershell adsi detection-engineering
1r 2t
medium advisory

Detection of Destructive NFS File Operations

Detection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.

impact nfs ransomware network-security detection-engineering
2t
critical advisory

Automated LLM-Based User Account Compromise Triage

An automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.

Elastic Stack +1 identity-compromise llm-security detection-engineering automated-triage
3t updated
medium advisory

Detection of Data Exfiltration via Curl Utility

Adversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.

Elastic Agent +1 exfiltration living-off-the-land detection-engineering curl
1r 3t
medium advisory

AI Agents Mimic Adversarial Behavior, Triggering Security Detections

AI coding agents such as Claude Code, Cursor, Codex, and GStack are increasingly exhibiting behaviors on Windows endpoints that mimic adversarial tradecraft, including credential access, LOLBin usage for ingress, command-line obfuscation, and persistence mechanisms, thereby triggering existing security detection rules designed for malicious activity and posing significant false positive challenges for detection engineers.

Claude Code +9 ai detection-engineering false-positive windows behavioral-detection
9t 9i