Skip to content
Threat Feed

Tag

Impact

97 briefs RSS
medium advisory

Detection of Destructive NFS File Operations

Detection logic identifies ransomware-like activity on NFS shares by flagging high-frequency bursts of successful WRITE, REMOVE, and RENAME operations from a single client within a one-minute window.

impact nfs ransomware network-security detection-engineering
2t
high advisory

Detection of Destructive MongoDB Commands

Detection logic for identifying first-time client IP addresses issuing destructive MongoDB administrative commands often used in wipe-and-extort data destruction campaigns.

MongoDB impact network
1r 1t
medium advisory

Unauthorized Memcached Data Manipulation via CVE-2026-29093

Unauthorized actors can leverage the lack of native authentication in Memcached to perform data manipulation or session hijacking, as identified in CVE-2026-29093.

Memcached network-security cve-2026-29093 impact
1r 1t 1c
high advisory

Detection of Common Ransomware File Extension Modifications

This analytic identifies ransomware activity by detecting file creation or modification events on endpoint filesystems where the resulting file extensions match known ransomware patterns, potentially leading to significant data loss and operational disruption.

ransomware endpoint-detection file-modification impact Rhysida Ransomware Prestige Ransomware LockBit Ransomware Medusa Ransomware +7
1r 1t
high advisory

CVE-2026-13440: Stored Cross-Site Scripting in StoreGrowth WooCommerce Plugin

A high-severity Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-13440, exists in the StoreGrowth: Smart Sales Booster for WooCommerce WordPress plugin (versions up to and including 2.1.0) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts via the 'message_popup' parameter that execute when a user accesses an affected page, facilitated by an exposed nonce.

StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin xss wordpress web impact execution
3t 1c
low advisory

Uncommon Process Loading RstrtMgr.DLL for Malicious Purposes

Attackers, including ransomware families like Conti and Cactus, and wipers such as BiBi, abuse the legitimate Windows `RstrtMgr.dll` (Restart Manager) by loading it into uncommon processes to terminate applications, including security software and those holding locks on files, facilitating data encryption or destruction.

Windows defense-evasion impact ransomware wiper
1r 2t
high advisory

Detection of Common Ransomware Notes

This brief details the detection of files commonly associated with ransomware notes on endpoints, indicating active data encryption and potential extortion attempts by various threat actors.

ransomware impact endpoint-security
1r 1t
medium advisory

FFmpeg: Multiple Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in FFmpeg allow an attacker to achieve arbitrary code execution or cause a denial-of-service condition.

ffmpeg vulnerability code-execution dos execution impact
2t
medium advisory

AWS Attempt to Leave Organization

An adversary attempting to remove an AWS member account from its AWS Organization via the LeaveOrganization API constitutes a critical defense evasion maneuver, as it strips the account of security controls and centralized monitoring, requiring immediate investigation by detection engineers.

AWS Organizations cloud aws defense-evasion impact threat-detection
1r 2t
critical threat

AWS Account Closure Detected

Adversaries or malicious insiders may close an AWS account using the `CloseAccount` API, a highly destructive action that suspends all access for 90 days before permanent termination, leading to data destruction and significant business disruption.

exploited AWS account +1 cloud aws impact data-destruction account-access-removal
1r 2t
high advisory

AWS SNS Topic Message Published by Rare User

This high-severity threat involves adversaries publishing messages to an AWS SNS topic using compromised credentials, identified when a user or role performs this action for the first time, potentially facilitating phishing campaigns, data exfiltration, or lateral movement within an AWS environment.

AWS SNS +1 cloud aws lateral-movement exfiltration impact command-and-control
1r 4t
high advisory

AWS IAM Multi-Factor Authentication Device Deactivation

Adversaries or compromised administrators may deactivate Multi-Factor Authentication (MFA) devices in AWS Identity and Access Management (IAM) by executing a successful `DeactivateMFADevice` API call, significantly weakening account security, disabling strong authentication, and paving the way for unauthorized access, privilege escalation, or persistence.

AWS Identity and Access Management cloud aws iam impact persistence defense-evasion
1r 3t
high advisory

AWS CloudTrail Log Updated

Adversaries can modify AWS CloudTrail configurations via the UpdateTrail API to reduce logging visibility, change log destinations, or weaken integrity, aiming to evade detection by preventing critical audit information from being collected or stored properly.

AWS CloudTrail cloud-security aws log-auditing impact defense-evasion
1r 2t
high advisory

Potential Ransomware Note File Dropped via SMB

Elastic has released a detection rule to identify the creation of ransomware note files by the Windows System process (PID 4) via the SMB protocol, indicating a remote ransomware attack often leveraging lateral movement to perform data encryption, destruction, or inhibit system recovery.

Elastic Defend ransomware smb windows impact lateral-movement
1r 4t
high advisory

Suspicious File Renaming via SMB Indicating Remote Ransomware Activity

This threat brief details a high-severity detection rule that identifies remote ransomware activity on Windows systems, leveraging SMB to initiate rapid, high-entropy file renames by the System process (PID 4) on user-owned files, which often signifies data encryption for impact.

ransomware impact lateral-movement windows endpoint
1r 4t
medium advisory

Devolutions Server: Multiple Vulnerabilities Allow Authenticated Attackers to Manipulate Data, Bypass Security, and Disclose Information

A remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to manipulate data, bypass security measures, and disclose information.

Devolutions Server initial-access defense-evasion collection impact
4t
high advisory

Unusual AWS S3 Object Encryption with SSE-C

Adversaries with compromised AWS credentials can exploit Server-Side Encryption with Customer-Provided Keys (SSE-C) in Amazon S3 to encrypt objects, rendering them unreadable and potentially enabling ransomware operations, which detection engineers can identify by monitoring CloudTrail logs for specific `PutObject` or `CopyObject` API calls.

Amazon S3 cloud aws s3 ransomware encryption impact data-loss
1r 2t
medium advisory

Potential AWS S3 Bucket Ransomware Note Uploaded

Adversaries exploit misconfigured AWS S3 buckets or compromised credentials to upload ransomware notes, often after deleting or encrypting data, aiming to extort victims.

Amazon S3 cloud aws s3 ransomware impact data-destruction
1r 3t 2i
high advisory

rclone: Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in rclone to gain unauthorized capabilities, allowing them to read and write arbitrary files on the system, disclose sensitive information, and bypass existing security mechanisms, potentially leading to data compromise or system integrity issues.

rclone vulnerability data-exfiltration impact
5t
high advisory

IBM Operational Decision Manager: Multiple Vulnerabilities Reported

Multiple critical vulnerabilities in IBM Operational Decision Manager allow an attacker to achieve arbitrary code execution, elevate privileges, perform denial of service attacks, disclose information, manipulate files, and bypass security measures.

IBM Operational Decision Manager bsi vulnerability rce privilege-escalation denial-of-service data-exfiltration impact defense-evasion
4t
high advisory

CVE-2026-56246 - Capgo Broken Access Control in Organization Management API

Capgo versions prior to 12.128.2 contain a broken access control vulnerability (CVE-2026-56246) in their organization management API where a scoped API key inherits the full permissions of its owner-user, allowing an attacker to perform destructive operations against unauthorized organizations, bypassing intended scope and leading to privilege escalation and impact.

Capgo < 12.128.2 vulnerability privilege-escalation data-destruction impact cloud
3t 1c
critical advisory

9routers Database Exposure and Takeover via Insecure API

A critical vulnerability (CVE-2026-55500) in 9routers versions <= 0.4.71 allows authenticated attackers with a valid JWT token to export the complete database containing plaintext credentials and secrets, and to import a modified database, leading to full system takeover and credential theft.

9router <= 0.4.71 web-exploitation data-exfiltration credential-access persistence impact
1r 6t 1i
medium advisory

dhcpcd Denial of Service Vulnerability

A vulnerability in the dhcpcd DHCP client daemon allows an attacker from an adjacent network to execute a Denial of Service attack, potentially disrupting network connectivity on affected Linux systems.

dhcpcd denial-of-service linux impact
1t
medium advisory

Potential DHCP Starvation via High Client MAC Cardinality

Attackers utilize DHCP starvation by flooding network segments with DHCP DISCOVER messages containing a high cardinality of distinct client MAC addresses to exhaust the DHCP lease pool, potentially leading to denial of service for legitimate clients and facilitating rogue DHCP server deployment.

network-attack denial-of-service network-security-monitoring impact
1t
medium advisory

AWS Lambda Function Deletion

Adversaries may delete AWS Lambda functions to disrupt business operations, remove evidence of their presence, or impede incident response, an action detectable by monitoring for `DeleteFunction` calls in `aws.cloudtrail` logs and correlating with expected change windows.

AWS Lambda cloud aws lambda impact data-destruction service-stop
1r 2t
high advisory

AWS Backup Vault Deleted or Vault Lock Removed

An adversary is detected performing anti-recovery actions in AWS Backup by deleting backup vaults or removing their Vault Lock configurations via the DeleteBackupVault or DeleteBackupVaultLockConfiguration API calls, serving as a strong precursor to ransomware or data destruction, preventing organizations from restoring critical data.

AWS Backup cloud-security aws anti-recovery defense-evasion impact
1r 2t
medium advisory

Application Removal Via Wmic.EXE

Adversaries are leveraging the Windows Management Instrumentation Command-line (WMIC) utility, `wmic.exe`, to uninstall legitimate or security applications as a method of defense evasion and system impact within Windows environments.

defense-evasion impact windows
1r 1t
high advisory

Renamed Sysinternals Sdelete Utility Execution

The execution of a renamed Microsoft Sysinternals Sdelete utility is a highly suspicious technique often employed by adversaries to destroy data on Windows systems, leading to severe impact on system integrity and data availability.

data-destruction living-off-the-land windows impact defense-evasion
1r 2t
high advisory

WatchGuard Firebox: Multiple Critical Vulnerabilities

Multiple vulnerabilities in WatchGuard Firebox appliances allow a remote, unauthenticated attacker to execute arbitrary code, cause a denial of service, manipulate or disclose data, and perform Cross-Site Scripting attacks, necessitating immediate patching to mitigate critical risks.

Firebox network vulnerability execution impact
2t
medium advisory

Google Workspace Admin Role Deletion

Adversaries with elevated privileges within Google Workspace may delete custom administrative roles to impede security operations, remove delegated administrator access, or obfuscate their activities during an active incident, leading to disrupted delegated administration, loss of security team access, or hindrance of incident response efforts.

Google Workspace cloud google-workspace identity-and-access-audit impact defense-evasion admin-role-deletion
2r 2t
high advisory

praisonai-platform: Cross-Workspace Label IDOR Vulnerability

Praison AI's praisonai-platform is vulnerable to an insecure direct object reference (IDOR) in the label endpoints (CVE-2026-47414), allowing cross-workspace label modification and information disclosure due to improper validation of label and issue IDs.

praisonai-platform idor vulnerability privilege-escalation collection impact cloud
2r 3t
critical advisory

Multiple Vulnerabilities in Apple macOS Sequoia, Sonoma, and Tahoe

A remote, anonymous attacker can exploit multiple vulnerabilities in Apple macOS to gain root privileges, execute arbitrary code, cause a denial-of-service condition, disclose confidential information, modify data, or bypass security measures.

macOS Sequoia +2 vulnerability macos privilege-escalation execution impact discovery defense-evasion
2r 5t
high advisory

Budibase Multiple Vulnerabilities

Multiple vulnerabilities in Budibase could be exploited by an attacker to gain administrative privileges, bypass security measures, perform cross-site scripting attacks, manipulate data, or disclose confidential information.

Budibase vulnerability privilege-escalation defense-evasion execution impact discovery cloud
2r 5t
high advisory

Multiple Vulnerabilities in Rsync

Multiple vulnerabilities in Rsync could be exploited by an attacker to elevate privileges, disclose information, bypass security precautions, and perform a denial of service attack.

rsync vulnerability privilege-escalation information-gathering defense-evasion impact
2r 4t
high advisory

Multiple Vulnerabilities in Microsoft Defender and Malware Protection Engine

Multiple vulnerabilities in Microsoft Defender and Microsoft Malware Protection Engine could allow an attacker to elevate privileges, execute arbitrary code, and cause a denial of service condition.

Defender +1 privilege-escalation execution impact windows
2r 3t
critical threat

Multiple Vulnerabilities in Palo Alto Networks GlobalProtect App

Multiple vulnerabilities in the Palo Alto Networks GlobalProtect App could allow an attacker to gain administrator privileges, execute arbitrary code with administrator privileges, disclose sensitive information, manipulate data, and cause a denial-of-service condition.

GlobalProtect App vulnerability privilege-escalation execution credential-access impact
2r 4t
high threat

Multiple Vulnerabilities in F5 BIG-IP Products

Multiple vulnerabilities in F5 BIG-IP products could allow an attacker to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.

BIG-IP f5 vulnerability privilege-escalation execution defense-evasion impact discovery credential-access
3r 5t
medium advisory

Multiple Vulnerabilities in AMD EPYC, Athlon, and Ryzen Processors

Multiple vulnerabilities in AMD EPYC, Athlon, and Ryzen processors can be exploited by an attacker to execute arbitrary code, escalate privileges, bypass security measures, cause a denial-of-service condition, disclose sensitive information, or manipulate data.

EPYC processors +2 amd processor vulnerability privilege-escalation defense-evasion execution denial-of-service information-disclosure +1
2r 7t
high advisory

Kubernetes CoreDNS or Kube-DNS Configuration Modified

Modification of the CoreDNS or kube-dns ConfigMap in the kube-system namespace can lead to cluster-wide DNS poisoning, enabling man-in-the-middle attacks against internal services and the Kubernetes API server.

kubernetes +2 dns man-in-the-middle impact
2r 1t
high advisory

Multiple Vulnerabilities in Kiali for Red Hat OpenShift Service Mesh

An anonymous remote attacker can exploit multiple vulnerabilities in Kiali for Red Hat OpenShift Service Mesh to gain extended privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.

OpenShift Service Mesh +1 kiali openshift servicemesh vulnerability privilege-escalation defense-evasion impact discovery +1
2r 4t
high advisory

CVE-2026-8449: Linux ksmbd Remote Memory Corruption Vulnerability

A remote memory corruption vulnerability exists in Linux ksmbd that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID, potentially leading to kernel instability, denial of service, or privilege escalation.

ksmbd privilege-escalation defense-evasion impact memory corruption
2r 3t 1c
high advisory

Volume Shadow Copy Deletion via WMIC

The rule detects the use of wmic.exe for shadow copy deletion on Windows endpoints, a common tactic used in ransomware or other destructive attacks to inhibit system recovery.

Windows Management Instrumentation +3 impact windows threat-detection
3r 2t
high advisory

Volume Shadow Copy Deletion via PowerShell

Detects the use of PowerShell to delete volume shadow copies, a tactic commonly employed by ransomware and other destructive attacks to hinder data recovery efforts.

Windows impact powershell volume shadow copy ransomware
2r 1t
high advisory

Potential Ransomware Note File Dropped via SMB

The rule identifies the creation of files resembling ransomware notes via SMB, potentially indicating a remote ransomware attack on Windows systems.

Elastic Defend ransomware smb impact windows
2r 4t
high advisory

Potential System Tampering via File Modification

Detection of attempts to delete or modify critical Windows boot files indicating a potential destructive attack to prevent system startup.

Elastic Defend +2 impact destructive-attack windows
2r 1t
low advisory

Potential Secure File Deletion via SDelete Utility

This rule detects file name patterns generated by the use of Sysinternals SDelete utility, potentially used by attackers to delete forensic indicators and hinder data recovery efforts.

Microsoft Defender XDR +3 defense evasion impact windows
2r 2t
medium advisory

Detection of Github Delete Actions in Audit Logs

This brief focuses on detecting deletion actions within GitHub audit logs, specifically targeting the deletion of codespaces, environments, projects, and repositories, potentially indicating malicious activity or insider threats.

Github audit data-loss impact
2r 1t
critical advisory

Multiple Vulnerabilities in Dell PowerProtect Data Domain OS

Multiple vulnerabilities in Dell PowerProtect Data Domain OS allow an attacker to execute arbitrary code with root privileges, escalate privileges to administrator, bypass security measures, manipulate data, disclose sensitive information, or conduct unspecified attacks.

dell powerprotect datadomain vulnerability privilege-escalation defense-evasion credential-access impact
2r 4t
medium advisory

AWS SAML Provider Deletion Activity

An adversary may delete an AWS SAML provider to disrupt administrative access, hindering incident response and potentially escalating privileges within the AWS environment.

aws cloudtrail saml iam deletion impact
2r 2t
medium advisory

AWS S3 Object Versioning Suspended

Detection of S3 bucket versioning suspension via PutBucketVersioning API call, potentially indicating an attempt to inhibit system recovery by making restoration of deleted or overwritten objects impossible.

S3 aws versioning impact
2r 1t
high advisory

Azure Compute Restore Point Collections Mass Deletion

A single user deleting multiple Azure Restore Point Collections in a short time period can indicate a ransomware attack or destructive operation, preventing victim recovery by inhibiting system recovery.

Azure cloud ransomware impact
2r 1t
medium advisory

Potential AWS S3 Bucket Ransomware Note Upload

An adversary may upload a ransomware note to an AWS S3 bucket by abusing compromised credentials or overly permissive bucket policies, potentially leading to data encryption or exfiltration.

S3 aws ransomware impact
3r 3t
low advisory

AWS S3 Bucket Enumeration and Brute Force Attempts

A high number of failed S3 operations (AccessDenied errors) against a single bucket from a single source address within a short timeframe can indicate attempts to enumerate bucket objects, brute-force object keys, or inflate AWS billing.

Amazon S3 cloud aws s3 enumeration brute_force impact discovery collection
2r 4t
medium advisory

GitHub Repository Deletion Detection

Detection of unauthorized GitHub repository deletion within an organization, potentially leading to irreversible data loss and indicating compromise.

GitHub repository deletion impact
2r 1t
medium advisory

GCP Storage Bucket Deletion for Impact

An adversary may delete a Google Cloud Platform (GCP) storage bucket to disrupt business operations, detected via GCP audit logs.

Google Cloud Platform +1 cloud gcp impact
2r 1t
medium advisory

Okta Network Zone Deactivation or Deletion

An Okta network zone was deactivated or deleted, potentially indicating malicious activity aimed at bypassing security controls.

Okta Identity Engine okta network-zone impact
2r 1t
medium advisory

Potential Ransomware Behavior - Note Files Dropped via SMB

This rule detects potential ransomware behavior by identifying the creation of multiple files with the same name over SMB by the SYSTEM account, potentially indicating remote execution of ransomware dropping note files.

Elastic Defend ransomware impact lateral-movement windows
2r 4t
low advisory

Azure Automation Runbook Deleted

Detection of Azure Automation runbook deletion, potentially indicating defense evasion or disruption of automated business processes by an adversary removing malicious or critical runbooks.

Azure Automation cloud azure defense-evasion impact
2r 2t
medium advisory

Azure Storage Account Deletion Detection

This brief detects the deletion of Azure Storage Accounts which can indicate malicious activity like data destruction, denial of service, or covering tracks after data exfiltration by adversaries.

Azure Storage Account azure storage deletion impact
2r 2t
medium advisory

AWS EC2 EBS Snapshot Access Permissions Removed

Detection of AWS EC2 EBS snapshot access permissions removal can indicate malicious attempts to disrupt data recovery, evade detection, or maintain exclusive backup access, leading to increased attack impact and incident response complexity.

EC2 +1 aws ebs snapshot impact
2r 4t
medium advisory

Azure Resource Group Deletion Detected

This rule detects the deletion of a resource group in Azure. Deleting a resource group permanently removes all resources within it, which adversaries may use to evade defenses or destroy data.

Microsoft Azure azure resource-group deletion impact
2r 5t
high advisory

Potential System Tampering via File Modification

Attackers may attempt to modify or delete critical Windows boot files such as 'winload.exe' or 'ntoskrnl.exe' to inhibit system recovery and cause data destruction, leading to a denial-of-service condition.

Windows impact defense-evasion
2r 2t
low advisory

GitHub Repository Archive Status Changed

Detection of GitHub repository archiving or unarchiving events, which could indicate malicious activity such as persistence, impact, or defense impairment.

GitHub repository archive unarchive persistence impact defense-impairment
2r 3t
high advisory

VssAdmin Shadow Copy Deletion or Resize

The rule identifies the use of vssadmin.exe to delete or resize shadow copies on Windows endpoints, which is a common tactic used in ransomware attacks to prevent system recovery.

Windows volume-shadow-copy ransomware impact
2r 1t
medium advisory

GCP Virtual Private Cloud Network Deletion

Detection of Virtual Private Cloud (VPC) network deletion in Google Cloud Platform (GCP), which can be used by an adversary to disrupt a target's network and business operations.

Virtual Private Cloud cloud gcp defense-evasion impact
2r 2t
medium advisory

GCP Service Account Disabled

Detection of a Google Cloud Platform (GCP) service account being disabled, potentially indicating malicious activity aimed at disrupting business operations by an adversary.

Google Cloud Platform gcp cloud iam impact
2r 1t
medium advisory

Third-party Backup Files Deleted via Unexpected Process

This detection identifies the deletion of backup files by processes outside of the backup suite, specifically targeting Veritas and Veeam backups, which may indicate an attempt to prevent recovery from ransomware.

Elastic Defend +5 impact backup deletion ransomware
2r 2t
medium advisory

Detection of Bcdedit Boot Configuration Modification

This rule identifies the use of bcdedit.exe to modify boot configuration data, which may be indicative of a destructive attack or ransomware activity aimed at inhibiting system recovery by disabling error recovery or ignoring boot failures.

Microsoft Defender XDR +2 boot-configuration bcdedit impact windows
2r 1t
medium advisory

Detection of Azure Application Deletion

This alert identifies when an application is deleted within an Azure environment, which could indicate malicious activity or unintended misconfiguration leading to service disruption.

Azure application deletion impact t1489
2r 1t
high advisory

GitHub Enterprise Organization Removal

Detection of a user removing an organization from GitHub Enterprise, potentially indicating account compromise, insider threats, or malicious attempts to disrupt business operations by deleting critical business resources.

GitHub Enterprise github cloud impact
2r 2t
low advisory

AWS S3 Bucket Configuration Deletion

Detection of Amazon S3 bucket configuration deletions, such as bucket policies or encryption settings, indicating potential defense evasion or impact attempts by adversaries who may delete logging or policy configurations to disrupt forensic visibility and inhibit recovery.

Amazon S3 aws s3 defense_evasion impact
2r 5t
high advisory

Volume Shadow Copy Deletion via WMIC

Attackers use Windows Management Instrumentation Command-line (WMIC) to delete volume shadow copies, inhibiting system recovery in ransomware and destructive attacks.

Windows volume-shadow-copy wmic ransomware impact
2r 2t
low advisory

Modification of Boot Configuration using Bcdedit

Adversaries may modify the Boot Configuration Data (BCD) store using bcdedit.exe to disable recovery options, which is often associated with ransomware or destructive attacks, preventing system recovery.

Windows impact boot-configuration
2r 1t
medium advisory

Windows System Restore Disabled via Registry Modification

Attackers disable Windows System Restore by modifying specific registry keys to hinder recovery efforts after malicious activity.

Windows impact t1490 persistence
2r 1t
medium advisory

Unusual Volume of File Deletion in Microsoft 365

An attacker may delete an unusual volume of files in Microsoft 365 to cause disruption or hide malicious activity.

Microsoft 365 +3 microsoft365 file_deletion data_loss impact
2r 1t
medium advisory

Mass Azure Compute Snapshot Deletion

The rule detects mass deletion of Azure disk snapshots, which could indicate an adversary attempting to inhibit system recovery capabilities, destroy backup evidence, or prepare for a ransomware attack.

Azure snapshot data-destruction impact
2r 2t
low advisory

GitHub Activity on Private Repository from Unusual IP

Detection of activity on a private GitHub repository from an unusual IP address, potentially indicating unauthorized access or exfiltration attempts.

GitHub cloud supply-chain impact
2r 4t
medium advisory

GCP Service Account Deletion

Detection of Google Cloud Platform (GCP) service account deletion, which adversaries may perform to disrupt business operations.

Google Cloud Platform gcp iam impact
2r 1t
high advisory

Excessive AWS S3 Object Encryption with SSE-C

Compromised AWS credentials can be used to encrypt a large number of S3 objects with SSE-C, rendering them unreadable without the attacker's keys, potentially leading to a ransomware-like extortion scenario.

Amazon S3 aws s3 sse-c ransomware impact
2r 1t
low advisory

Azure Key Vault Modified by Unusual User

This rule identifies modifications to Azure Key Vaults by unusual users, potentially leading to data breaches or service disruptions through defense evasion or impact operations.

Azure Key Vault azure keyvault configuration-audit impact defense-evasion
2r 2t
medium advisory

Azure Compute Restore Point Collection Deleted by Unusual User

The deletion of Azure Restore Point Collections, which contain recovery points for virtual machines, by a user who has not previously performed this activity, indicates a potential attempt to prevent recovery during ransomware attacks or cover tracks during malicious operations.

Azure Compute cloud azure impact
2r 1t
medium advisory

AWS SQS Queue Purge Detection

Detection of AWS Simple Queue Service (SQS) queue purging, which adversaries may leverage to disrupt application workflows, destroy operational data, or impair monitoring and alerting systems by removing critical evidence of malicious activity.

Simple Queue Service cloud aws sqs defense-evasion impact
2r 2t
medium advisory

AWS SNS Topic Message Publish by Rare User

This rule identifies when an SNS topic message is published by a rare user in AWS, which may indicate lateral movement, data exfiltration, or phishing campaigns, potentially leading to resource hijacking and impact on cloud services.

Amazon Simple Notification Service aws sns lateral-movement exfiltration impact
2r 4t
medium advisory

AWS EFS File System Deletion Detected

An adversary with sufficient permissions deletes an Amazon EFS file system using the 'DeleteFileSystem' API operation to destroy evidence, disrupt workloads, or impede recovery efforts.

Elastic File System aws efs data-destruction impact
2r 1t
high advisory

Windows Event Log Cleared

Detection of cleared Windows event logs (Security Event ID 1102 or System log event 104) indicates potential defense evasion and obfuscation by threat actors attempting to remove evidence of their activities.

Splunk Enterprise +2 defense-evasion impact windows
2r 1t
critical advisory

Microsoft Intune Bulk Device Wipe Detection

A high volume of 'wipe ManagedDevice' events from the Intune admin portal within a short period (5+ per hour) indicates a potential large-scale data wiping attack against managed endpoints.

Intune cloud microsoft-intune data-wipe impact
2r 1t
medium advisory

Account Password Reset Remotely

The rule detects attempts to reset potentially privileged account passwords remotely, a tactic used by adversaries to maintain access, evade password policies, and preserve compromised credentials.

Windows persistence impact
2r 2t
medium advisory

Wbadmin Backup Catalog Deletion

Adversaries may delete Windows backup catalogs using wbadmin.exe to inhibit system recovery, often as part of ransomware or other destructive attacks.

Windows impact backup-deletion ransomware
2r 2t
low advisory

Potential Secure File Deletion via SDelete Utility

This rule detects file name patterns generated by the use of Sysinternals SDelete utility, which attackers may abuse to delete forensic indicators and hinder recovery efforts after ransomware or data theft.

SDelete defense-evasion impact windows
2r 2t
medium advisory

High Number of Process and/or Service Terminations Detected

A high number of process terminations (stop, delete, or suspend) from the same Windows host within a short time period may indicate malicious activity such as an attacker attempting to disable security measures or prepare for ransomware deployment.

Elastic Defend impact defense-evasion windows
2r 2t
high advisory

GitHub Organization Repository Deletion

Anomalous deletion of a GitHub organization repository can indicate malicious activity aimed at destroying source code, intellectual property, or evidence of compromise, potentially stemming from account compromise, insider threats, or business disruption attempts.

GitHub Organizations github repository deletion impact
1r 2t
low advisory

GCP IAM Service Account Key Deletion

Detection of Identity and Access Management (IAM) service account key deletion in Google Cloud Platform (GCP), potentially indicating malicious activity such as disrupting services or covering tracks after unauthorized access.

Google Cloud Platform cloud gcp iam persistence impact
2r 2t
medium advisory

Azure Kubernetes Services (AKS) Kubernetes Pod Deletion

The deletion of Azure Kubernetes Pods can indicate malicious activity aimed at disrupting the environment's normal behavior.

Azure Kubernetes Services azure kubernetes impact cloud
2r 2t
low advisory

AWS SNS Topic Created by Rare User

An AWS SNS topic was created by a user who does not typically perform this action, potentially indicating resource development for data exfiltration or other malicious activities.

Simple Notification Service cloud aws sns resource-development impact
2r 2t
low advisory

AWS IAM Group Deletion Detected

Detection of AWS IAM group deletion via the DeleteGroup API call, which may indicate an attacker removing audit trails, disrupting operations, or concealing privileged access activity.

IAM aws cloudtrail impact account-access-removal
2r 1t
low advisory

AWS EventBridge Rule Disabled or Deleted

Detection of Amazon EventBridge rule disabling or deletion events, which can disrupt operational workflows and security monitoring.

EventBridge aws impact defense-evasion
2r 2t
high advisory

Multiple Azure Storage Account Deletions by User

A single user or service principal deleting multiple Azure Storage Accounts within a short time period may indicate malicious activity such as data destruction, service disruption, or a ransomware attack.

Azure +1 cloud storage impact
2r 2t