Skip to content
Threat Feed

Tag

Hacktool

9 briefs RSS
high advisory

SharpView Reconnaissance Tool Execution

Adversaries utilize the SharpView C# port of PowerView to perform extensive Active Directory reconnaissance, domain enumeration, and discovery of sensitive network objects.

discovery active-directory windows hacktool
1r 2t
high advisory

Detection of BloodHound and SharpHound Enumeration Tools

Adversaries utilize BloodHound and SharpHound to perform automated reconnaissance and enumeration of Active Directory environments, facilitating lateral movement and privilege escalation.

reconnaissance active-directory windows hacktool
1r 1t
high advisory

Detection of Rubeus Kerberos Exploitation Tool

This brief covers detection strategies for the Rubeus hacktool, which is frequently used by attackers to perform Kerberos-based credential theft and lateral movement.

credential-access lateral-movement kerberos hacktool
1r 2t
high advisory

PowerUp DLL Hijacking Tool Usage

The PowerUp tool is leveraged by attackers to perform DLL hijacking for privilege escalation by writing malicious batch files to the filesystem.

hacktool privilege-escalation persistence
1r 1t
high advisory

Detection of XORDump Credential Dumping Activity

XORDump is a utility used by attackers to dump process memory, specifically targeting lsass.exe to facilitate credential theft.

credential-access stealth hacktool
1r 2t
high advisory

Usage of SelectMyParent HackTool for PPID Spoofing

Adversaries use the SelectMyParent utility to perform Parent Process ID (PPID) spoofing, enabling stealthy process execution by masquerading as legitimate system processes.

hacktool evasion defense-evasion
1r 1t
high advisory

HackTool - SysmonEnte Execution for Sysmon Evasion

This brief details the SysmonEnte hacktool, an open-source utility developed by codewhitesec, designed to attack the integrity of Microsoft Sysmon processes to impair endpoint detection and bypass security monitoring on Windows systems.

Microsoft Sysmon defense-evasion endpoint windows hacktool
1r
high advisory

Antivirus Alert for Hacktools or Attack Tools

This brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.

antivirus hacktool post-exploitation detection incident-response malware
1r 1t
high advisory

NetExec File Creation Detection

This brief covers the detection of NetExec, a post-exploitation and lateral movement tool, through monitoring for unique file creation patterns associated with its execution and file extraction in Windows environments.

Windows +1 netexec crackmapexec lateral-movement post-exploitation hacktool
2r 3t