Tag
SharpView Reconnaissance Tool Execution
1 rule 2 TTPsAdversaries utilize the SharpView C# port of PowerView to perform extensive Active Directory reconnaissance, domain enumeration, and discovery of sensitive network objects.
Detection of BloodHound and SharpHound Enumeration Tools
1 rule 1 TTPAdversaries utilize BloodHound and SharpHound to perform automated reconnaissance and enumeration of Active Directory environments, facilitating lateral movement and privilege escalation.
Detection of Rubeus Kerberos Exploitation Tool
1 rule 2 TTPsThis brief covers detection strategies for the Rubeus hacktool, which is frequently used by attackers to perform Kerberos-based credential theft and lateral movement.
PowerUp DLL Hijacking Tool Usage
1 rule 1 TTPThe PowerUp tool is leveraged by attackers to perform DLL hijacking for privilege escalation by writing malicious batch files to the filesystem.
Detection of XORDump Credential Dumping Activity
1 rule 2 TTPsXORDump is a utility used by attackers to dump process memory, specifically targeting lsass.exe to facilitate credential theft.
Usage of SelectMyParent HackTool for PPID Spoofing
1 rule 1 TTPAdversaries use the SelectMyParent utility to perform Parent Process ID (PPID) spoofing, enabling stealthy process execution by masquerading as legitimate system processes.
HackTool - SysmonEnte Execution for Sysmon Evasion
1 ruleThis brief details the SysmonEnte hacktool, an open-source utility developed by codewhitesec, designed to attack the integrity of Microsoft Sysmon processes to impair endpoint detection and bypass security monitoring on Windows systems.
Antivirus Alert for Hacktools or Attack Tools
1 rule 1 TTPThis brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.
NetExec File Creation Detection
2 rules 3 TTPsThis brief covers the detection of NetExec, a post-exploitation and lateral movement tool, through monitoring for unique file creation patterns associated with its execution and file extraction in Windows environments.