Tag
Cross-Telemetry Correlation of Endpoint and Network Security Alerts
3 TTPsDetection engineering logic that correlates Elastic Defend endpoint alerts with network security events from PAN-OS, FortiGate, and Suricata to identify potentially compromised hosts based on multi-source telemetry.
Suspicious Activity Detection from GenAI Coding Utilities
1 rule 1 TTPThis detection rule identifies suspicious endpoint activity, such as malicious file creation or shellcode execution, originating from or triggered by AI-assisted coding and assistant tools indicating potential supply chain or prompt injection abuse.
Detection of Coordinated Malware Infections Across Multiple Hosts
1 TTPThis intelligence brief details a behavioral detection strategy for identifying widespread malware infections by correlating alerts across multiple endpoints to facilitate rapid incident response.
Detecting Data Exfiltration Preparation via GenAI Processes
1 rule 3 TTPsDetection of unauthorized GenAI workflows utilizing local compression or encoding utilities followed by outbound network communication, indicating potential staging and exfiltration of sensitive data.
Information Disclosure Vulnerability in Prisma Access Agent for Linux
2 TTPsAn information disclosure vulnerability in the Prisma Access Agent for Linux allows local, low-privileged users to access sensitive configuration data and stored credentials (CVE-2026-0305).
CrowdStrike Falcon Sensor Local Privilege Escalation (FalconFlank)
1 TTPA local privilege escalation vulnerability known as FalconFlank exists in the CrowdStrike Falcon Sensor Windows agent due to a TOCTOU race condition in the Office macro remediation workflow.
Detection of Unauthorized Local Account Creation on macOS
2 TTPsThis brief details the detection of local account creation on macOS systems, a technique often used by adversaries to establish persistence or facilitate privilege escalation through administrative utilities.
Abuse of Native Windows Utilities to Modify File Permissions
1 rule 1 TTPAdversaries leverage native utilities like icacls.exe to modify file and directory permissions via deny flags, effectively hindering security operations and maintaining persistence.
Detection of Potential Defense Evasion via Endpoint Telemetry Suppression
2 TTPsThis detection identifies adversary attempts to impair security monitoring by detecting a complete cessation of host telemetry immediately following a security alert generated by the Elastic Defend agent.
Detection of Malicious Binfmt Configuration File Creation
1 rule 1 TTPDetection rule monitoring for the creation of binfmt configuration files which can be abused by threat actors to execute arbitrary code or maintain persistence on Linux systems.
Detection of Excessive nslookup.exe Usage for Data Exfiltration
1 rule 1 TTPHigh volumes of nslookup.exe executions detected via dynamic thresholding can indicate DNS tunneling used for data exfiltration or command-and-control communication.
Detection of Unauthorized Clipboard Utility Execution on Linux
1 rule 1 TTPThis brief details a detection strategy for identifying unauthorized collection of clipboard data on Linux systems by monitoring the execution of common clipboard utilities from uncommon parent processes.
Abuse of Python Site-Package Hooks for Persistence
1 rule 2 TTPsAdversaries are abusing the Python site module by planting malicious sitecustomize.py or usercustomize.py files in package directories to ensure persistent code execution during Python initialization.
Citrix Workspace App for macOS Privilege Escalation Vulnerability
1 TTPA local privilege escalation vulnerability in Citrix Workspace App for macOS allows a local attacker to elevate their system permissions.
Local Privilege Escalation in Palo Alto Networks GlobalProtect
2 TTPs 2 CVEsA local privilege escalation vulnerability (CVE-2026-0299) in the Palo Alto Networks GlobalProtect app allows authenticated local users to escalate to SYSTEM or root privileges via untrusted search path exploitation.
Detection of Unauthorized Network Sniffing Tools on Windows
1 rule 1 TTPAdversaries leverage network sniffing utilities such as Wireshark and tcpdump on Windows endpoints to conduct reconnaissance, intercept sensitive traffic, and exfiltrate credentials.
Detection of Suspicious Dir Piped to Findstr Activity
1 rule 1 TTPAdversaries frequently leverage the 'dir' command piped to 'findstr' for reconnaissance to identify sensitive files and credentials on compromised Windows systems.
Host Detected with Suspicious Windows Processes via Machine Learning
2 TTPsElastic's machine learning job, utilizing the ProblemChild supervised model and unsupervised techniques, detects Windows hosts exhibiting clusters of suspicious processes with unusually high malicious probability scores, often indicative of defense evasion through Living Off The Land Binaries (LOLbins) and masquerading techniques.
Unusual Process Writing Data to an External Device Detected by Machine Learning
22 TTPsElastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.
Detection of Local LLM Framework DNS Queries
1 rule 3 TTPs 18 IOCsThis brief details the detection of DNS queries originating from local Large Language Model (LLM) frameworks like Ollama, LM Studio, and GPT4All on Windows endpoints, leveraging Sysmon Event ID 22 to identify potential unauthorized AI tool usage or data exfiltration risks associated with model downloads, updates, and telemetry from repositories such as huggingface.co and ollama.ai.
Detection of Local LLM Model File Creation on Endpoints
2 rules 5 TTPsThis brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.
Detection of Common Ransomware Notes
1 rule 1 TTPThis brief details the detection of files commonly associated with ransomware notes on endpoints, indicating active data encryption and potential extortion attempts by various threat actors.
Statistical Model Detected Command-and-Control Beaconing Activity
3 TTPsElastic Security's statistical model identifies command-and-control (C2) beaconing activity in network logs on Windows and Linux systems by analyzing network traffic patterns and excluding known benign processes, enabling defenders to detect and respond to stealthy adversary communications for persistence and data exfiltration.
Autonomous AI Agents Pose New Supply Chain and Data Exfiltration Risks
4 TTPs 16 IOCsThis content introduces AI Detection and Response (AIDR) as a new cybersecurity category to address emerging threats from autonomous AI agents, including supply chain attacks and unintended data sharing, highlighting their ability to execute with inherited privileges across endpoints, SaaS, and cloud environments.
Shell Command Execution via Elastic Endpoint Console
1 rule 3 TTPsAttackers who compromise Elastic Endpoint console access can leverage its legitimate remote support feature to execute arbitrary shell commands on Linux endpoints, turning it into a command and control channel for persistence, tool deployment, and data exfiltration.
Detect Linux Kernel Module Load via Built-in Utility
1 rule 2 TTPsThis threat involves adversaries with root privileges using the `insmod` or `modprobe` utilities to load malicious Linux kernel object files (.ko), often rootkits, which provides complete system control and evasion capabilities, making detection of this uncommon activity critical.
Denial-of-Service Vulnerability Affects ESET Endpoint Antivirus and Server Security Products (CVE-2026-6424)
1 TTP 1 CVEA vulnerability, identified as CVE-2026-6424, has been discovered in various ESET Endpoint Antivirus and Server Security product versions, allowing an attacker to cause a denial of service, impacting the availability of the affected systems.
Vulnerability in ESET Inspect Connector Allowing Privilege Escalation
A vulnerability, CVE-2026-6423, in ESET Inspect Connector versions prior to 3.1.6017.0 for Windows allows an attacker to achieve privilege escalation on affected systems.
Shell Execution via Elastic Endpoint on Linux
1 rule 3 TTPsThis brief details the detection of shell command execution initiated by the Elastic Endpoint agent on Linux systems, indicating potential post-exploitation activity such as remote access or command and control via misuse of the endpoint's response capabilities.
Windows Defender Tampering via WMIC for Defense Evasion
1 rule 2 TTPsA technique brief describes how adversaries may use `wmic.exe` to tamper with Windows Defender settings, specifically to add exclusions via the `\root\Microsoft\Windows\Defender` WMI namespace, reducing the host's security posture and enabling further malicious activity.
Threat Brief: Detection of Sysinternals Sysmon Uninstallation
1 rule 1 TTPThis brief describes the detection of attackers uninstalling Sysinternals Sysmon, a critical endpoint monitoring tool, as a defense evasion technique to obscure malicious activities and maintain stealth.
Potential Evasion via Windows Filtering Platform Blocking Security Software
2 rules 2 TTPsAdversaries may add malicious Windows Filtering Platform (WFP) rules to prevent endpoint security solutions from sending telemetry data, impairing defenses, which this rule detects by identifying multiple WFP block events where the process name is associated with endpoint security software.
CrowdStrike Innovations Secure AI Agents and Govern Shadow AI
2 rules 2 TTPsCrowdStrike is introducing innovations to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud environments by extending AI detection and response (AIDR) capabilities to cover desktop AI applications and provide visibility into AI-related components, helping to prevent prompt attacks, data leaks, and policy violations.
CrowdStrike Falcon Enhancements Secure AI Agents and Govern Shadow AI
2 rules 3 TTPsCrowdStrike is enhancing its Falcon platform with AI Detection and Response (AIDR) to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud, addressing threats like prompt injection attacks, data leaks, and policy violations.
CrowdStrike Falcon Enhancements for Securing AI Agents and Governing Shadow AI
2 rulesCrowdStrike is enhancing its Falcon platform with new AI detection and response capabilities to secure AI agents and govern shadow AI across endpoints, SaaS, and cloud environments, addressing threats like prompt injection and data leaks.
macOS File Monitoring via Endpoint Security Framework
2 rules 1 TTPObjective-See details how to create a file monitor for macOS 10.15 using Apple's Endpoint Security Framework to capture file I/O events and process information.
Leveraging Apple's Endpoint Security Framework for Process Monitoring
2 rules 2 TTPsThis brief discusses the use of Apple's Endpoint Security Framework in macOS 10.15 and later for user-mode process monitoring, offering improved capabilities over the older OpenBSM subsystem.