Skip to content
Threat Feed

Tag

Detection-Engineering

6 briefs RSS
medium advisory

Detection of Suspicious Web Server Child Processes on Linux

This brief provides detection logic to identify potential webshell activity on Linux systems by monitoring for suspicious child processes spawned by common web server applications.

persistence linux web-server detection-engineering
1r 1t
medium advisory

Detection of Stealthy User Account Creation via ADSI

Adversaries may use Active Directory Service Interfaces (ADSI) within PowerShell to create local or domain accounts, effectively bypassing standard monitoring for typical user-creation commands.

persistence windows powershell adsi detection-engineering
1r 2t
medium advisory

Detection of Destructive NFS File Operations

Detection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.

impact nfs ransomware network-security detection-engineering
2t
critical advisory

Automated LLM-Based User Account Compromise Triage

An automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.

Elastic Stack identity-compromise llm-security detection-engineering automated-triage
3t
medium advisory

Detection of Data Exfiltration via Curl Utility

Adversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.

Elastic Agent +1 exfiltration living-off-the-land detection-engineering curl
1r 3t
medium advisory

AI Agents Mimic Adversarial Behavior, Triggering Security Detections

AI coding agents such as Claude Code, Cursor, Codex, and GStack are increasingly exhibiting behaviors on Windows endpoints that mimic adversarial tradecraft, including credential access, LOLBin usage for ingress, command-line obfuscation, and persistence mechanisms, thereby triggering existing security detection rules designed for malicious activity and posing significant false positive challenges for detection engineers.

Claude Code +9 ai detection-engineering false-positive windows behavioral-detection
9t 9i