Tag
Detection of SDK-Based AWS Control Plane Discovery from Suspicious Processes
2 TTPsThis detection monitors for processes executing from temporary or user-writable directories that perform DNS queries to AWS management endpoints, a pattern frequently utilized by post-exploitation tools to bypass CLI-based security controls.
Detection of Potential Lateral Movement via Alert Correlation
1 TTPThis detection capability monitors for lateral movement by identifying sequences where a host IP address from one security alert subsequently appears as the source IP in alerts from a different host.
Monitoring Azure Run Command for Unauthorized Execution
1 rule 2 TTPsThis brief outlines detection strategies for unauthorized guest execution via the Azure Virtual Machine Run Command feature, which attackers may abuse to run arbitrary scripts without interactive access.
Correlation of Palo Alto Networks C2 Alerts with Endpoint Process Activity
1 TTPThis detection capability correlates Palo Alto Networks (PANW) firewall command and control alerts with Elastic Defend endpoint events to identify the specific process responsible for network traffic flagged as malicious.
Detecting Identity Masquerading via Behavioral Clustering
1 TTPSecurity researchers have developed a behavioral clustering model using unsupervised machine learning to differentiate between legitimate cloud functional roles and attackers masquerading as authorized identities.
Linux Local Privilege Escalation Detection Framework
1 TTPThis brief summarizes a detection engineering framework from Elastic Security Labs for identifying post-exploitation activity and system misconfigurations associated with Linux local privilege escalation.
Detection of Newly Observed IPSEC NAT Traversal Peers
1 rule 3 TTPsDetection of potentially unauthorized IPSEC NAT Traversal (NAT-T) tunnels indicates potential command and control (C2) or exfiltration activity masked by encrypted traffic.
Cross-Platform C2 Detection via Suricata and Elastic Defend Correlation
3 TTPsThis detection capability correlates network-layer Suricata alerts with host-based process telemetry from Elastic Defend to identify malicious outbound command and control communication.
Suspicious PowerShell Invoke-WebRequest Usage for File Downloads
1 rule 1 TTPThis threat brief details the detection of suspicious PowerShell Invoke-WebRequest activity used to download payloads into high-risk, world-writable directories on Windows systems.
Detection of Suspicious File Writes by Core Windows Processes
1 rule 1 TTPDetection of suspicious file creation events where critical Windows system binaries write files with potentially malicious extensions, indicating potential process masquerading or system compromise.
Detecting PowerShell Command Line Obfuscation Techniques
1 rule 2 TTPsDetection logic for identifying PowerShell execution utilizing excessive special characters for command line obfuscation to bypass security monitoring.
Abuse of PowerShell MSXML COM Objects for Network Interaction
1 rule 1 TTPAdversaries leverage the MSXML2 COM object within PowerShell scripts to facilitate network communication and potential code execution.
Detection Capability for Executable File Creation via Sysmon
1 ruleThis brief details a detection capability for monitoring the creation of Portable Executable files using Sysmon Event ID 29 to identify unauthorized binary drops.
Detection of Script Interpreter Execution from Suspicious Directories
1 rule 1 TTPAdversaries frequently utilize script interpreters such as cscript, wscript, and mshta from non-standard or user-writable directories to execute malicious payloads while evading security controls.
Detection of WinAPI Function Calls via Command Line Interface
1 rule 1 TTPAdversaries are leveraging tools like winapiexec to execute Windows API functions directly from the command line to bypass traditional binary-based detection methods.
Detection of LOLBin Relocation Techniques
1 rule 1 TTPAdversaries frequently copy Living-off-the-Land Binaries (LOLBins) from protected system directories to arbitrary locations to evade security controls that rely on path-based allowlisting.
Detection of PowerShell Base64 Decoding Techniques
1 rule 2 TTPsThis brief documents the use of the 'FromBase64String' method within PowerShell command lines, a common technique for obfuscating malicious payloads to bypass signature-based detection.
Detection of Suspicious PowerShell Invocation Patterns
1 rule 1 TTPThis brief documents detection logic for common PowerShell obfuscation and execution patterns frequently leveraged by attackers to maintain persistence, bypass security policies, and download secondary payloads.
Detection of Suspicious Web Request Execution via PowerShell and CLI
1 rule 1 TTPThis brief documents detection logic for identifying potential malicious file downloads and C2 communication using native Windows command-line tools and PowerShell cmdlets.
Detection of Windows Service Binaries in Suspicious Directories
1 rule 1 TTPAdversaries often achieve persistence by registering malicious Windows services with binaries located in writeable or temp directories to evade detection.
Detection of Suspicious Web Server Child Processes on Linux
1 rule 1 TTPThis brief provides detection logic to identify potential webshell activity on Linux systems by monitoring for suspicious child processes spawned by common web server applications.
Detection of Stealthy User Account Creation via ADSI
1 rule 2 TTPsAdversaries may use Active Directory Service Interfaces (ADSI) within PowerShell to create local or domain accounts, effectively bypassing standard monitoring for typical user-creation commands.
Detection of Destructive NFS File Operations
2 TTPsDetection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.
Automated LLM-Based User Account Compromise Triage
3 TTPsAn automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.
Detection of Data Exfiltration via Curl Utility
1 rule 3 TTPsAdversaries frequently abuse the legitimate curl command-line utility to exfiltrate collected sensitive data to external Command and Control (C2) servers via network protocols.
AI Agents Mimic Adversarial Behavior, Triggering Security Detections
9 TTPs 9 IOCsAI coding agents such as Claude Code, Cursor, Codex, and GStack are increasingly exhibiting behaviors on Windows endpoints that mimic adversarial tradecraft, including credential access, LOLBin usage for ingress, command-line obfuscation, and persistence mechanisms, thereby triggering existing security detection rules designed for malicious activity and posing significant false positive challenges for detection engineers.