Skip to content
Threat Feed

Tag

Detection

15 briefs RSS
low advisory

Detection of Suspicious Base64 Decoding Activity on Linux

This detection brief monitors Linux hosts for the use of standard system utilities and scripting interpreters to decode Base64 data, a common technique employed by adversaries to obfuscate malicious payloads and command-and-control traffic.

Elastic Defend defense-evasion execution linux detection
2t
medium advisory

PSScriptPolicyTest Creation By Uncommon Process

This brief describes a detection opportunity for the stealthy creation of the 'PSScriptPolicyTest' PowerShell script by processes other than standard PowerShell executables or legitimate Windows components, a behavior potentially indicative of advanced adversaries attempting to bypass PowerShell logging and security policies.

stealth detection powershell
1r 1t
medium advisory

Windows Autostart Execution in Startup Folder for Persistence

Adversaries leverage the Windows %startup% folder to establish persistence by creating malicious files that execute automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.

persistence autostart windows detection
1r 1t
low advisory

DNS Request to Suspicious Top Level Domain

This threat brief details how Linux systems making DNS queries to commonly abused top-level domains may indicate malware-related command and control (C2) communications, data exfiltration, or payload downloads, often blending into normal name resolution, signaling a potential compromise of servers, workstations, or containerized workloads.

command-and-control exfiltration linux endpoint network detection
1r 8t 50i
high advisory

Detection of Accepted Default Telnet Port Connection

This brief details the detection of unencrypted Telnet traffic on its default port 23, a legacy protocol commonly used for remote administration but frequently exploited by threat actors for initial access or as a backdoor due to its plain-text nature, which exposes sensitive information and facilitates unauthorized access.

command-and-control lateral-movement initial-access telnet network-security detection elastic-rule
1r 4t
high advisory

Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location

This brief details a detection strategy for suspicious network connections originating from processes located in uncommon or typically protected Windows file system directories, often indicative of malware establishing command and control or exfiltrating data.

endpoint detection command-and-control malware
1r 1t
medium advisory

Suspicious Process Monitor Driver Creation by Non-Sysinternals Binary

This brief details a detection strategy for malicious actors attempting to establish persistence or elevate privileges by creating a Process Monitor driver file (`.sys`) from an unauthorized process, indicating potential kernel-level compromise on Windows systems.

persistence privilege-escalation windows detection
1r 2t
medium advisory

Potential Privileged System Service Operation - SeLoadDriverPrivilege

This brief details the detection of `SeLoadDriverPrivilege` usage on Windows systems, a critical privilege enabling attackers to load malicious kernel drivers for advanced defense evasion and privilege escalation, leading to full system compromise.

windows defense-evasion privilege-escalation detection
1r 2t
high advisory

Detection of Web Shell via Antivirus Signature

This brief describes the detection of web shells by antivirus solutions, emphasizing the importance of investigating these alerts as they signify a compromised web server and potential post-exploitation activity by an attacker.

webshell antivirus detection persistence
1r 1t
critical advisory

Detection of Malicious Remote Access Tools by Antivirus

This brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.

remote-access-trojan rat antivirus detection malware windows
1r 1t
high advisory

Antivirus Alert for Hacktools or Attack Tools

This brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.

antivirus hacktool post-exploitation detection incident-response malware
1r 1t
critical advisory

Detection of Advanced Persistent Threat (APT) Malware Signatures in Antivirus Logs

This brief details a detection rule for critical antivirus alerts that report Advanced Persistent Threat (APT) malware signatures, enabling detection engineers to identify and investigate sophisticated threats that have reached endpoints.

detection antivirus apt malware endpoint
1r 1t
medium advisory

FortiGate - New Local User Creation Detection

This brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.

FortiGate network detection persistence
1r 1t
high advisory

Executable or Script Creation in Suspicious Windows Paths

This brief details a detection analytic for the creation of executables or scripts, such as .exe, .dll, or .ps1 files, in suspicious Windows file paths like `\windows\fonts\` or `\users\public\`, a technique frequently employed by adversaries for defense evasion and persistence, potentially leading to unauthorized code execution and privilege escalation.

endpoint windows defense-evasion persistence execution detection
1r 2t
medium advisory

Impact of Poor Security Operation Center (SOC) Metrics

Poorly chosen performance metrics can significantly impair a SOC's ability to detect and respond to threats, leading to ineffective security operations and potential compromise.

SharePoint soc metrics threat-hunting detection
2r 2t