Skip to content
Threat Feed

Tag

Initial_access

12 briefs RSS
medium threat

Unusual Child Process Execution from Linux Web Servers

This rule detects unusual child process executions originating from web server processes on Linux systems, which attackers may use to maintain persistence on a compromised system by exploiting web server vulnerabilities.

Jira +20 persistence execution command_and_control initial_access linux webserver
2r 4t
low advisory

Google Workspace Suspended User Account Renewed

Detection of a renewed suspended user account in Google Workspace, potentially indicating an adversary regaining access to the organization.

Google Workspace google_workspace initial_access persistence
2r 2t
medium advisory

External User Added to Google Workspace Group

Detects an external Google Workspace user account being added to an existing group, potentially allowing adversaries to intercept shared files or emails.

Google Workspace google_workspace initial_access persistence cloud
2r 2t
high advisory

Entra ID Microsoft Authentication Broker Sign-In with Non-Standard User Agent

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker authenticates using a non-standard user agent, inconsistent with common browser, mobile, or Windows platforms, potentially indicating adversary-in-the-middle or OAuth phishing attacks.

Entra ID cloud identity azure entra_id initial_access
2r 3t
high advisory

Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a suspicious ASN, indicating potential OAuth phishing or adversary-in-the-middle device registration.

Microsoft Entra ID cloud identity azure entra_id sign-in_logs threat_detection initial_access persistence +1
2r 3t
medium advisory

Google Workspace Device Registration Burst for Single User

Detects bursts of Google Workspace device registration events for a single user exceeding three distinct device registrations within one minute, indicative of AiTM phishing or stolen OAuth token replay attacks.

Google Workspace google_workspace device_registration persistence initial_access credential_access
1r 3t
high advisory

Entra ID Kali365 User-Agent Detected

This brief detects the use of the Kali365 user agent, a phishing-as-a-service platform, within Entra ID or Microsoft 365 logs, indicating potential account compromise through stolen tokens.

Entra ID +1 cloud entra_id o365 initial_access credential_access
2r 4t 4i
high advisory

M365 or Entra ID Identity Sign-in from a Suspicious Source

This rule correlates Entra-ID or Microsoft 365 mail successful sign-in events with network security alerts by source address, indicating potential initial access by adversaries triggering network security alerts before accessing cloud resources.

Microsoft 365 +1 cloud saas azure entra_id microsoft_365 initial_access
2r 1t
medium advisory

Entra ID Microsoft Authentication Broker Sign-In to Unusual Resource

Detects successful Microsoft Entra ID sign-ins where the client application is the Microsoft Authentication Broker (MAB) and the requested resource identifier is outside a short list of commonly observed first-party targets, potentially indicating abuse to obtain tokens for unexpected APIs or enterprise applications.

Entra ID cloud identity azure entra_id microsoft_entra_id sign_in_logs threat_detection initial_access
2r 2t
medium advisory

Suspicious macOS MS Office Child Process

This rule identifies suspicious child processes of Microsoft Office applications on macOS, which often result from exploitation or malicious macros, by detecting unexpected processes like curl, bash, osascript, and python spawned by Office apps, while filtering out false positives related to product version discovery, error reporting, and legitimate software.

Microsoft Word +7 endpoint macos initial_access microsoft_office
2r 6t
high advisory

Malware Spreading Through Fake 'Claude Code' Google Ads

Malware is distributed via malicious advertisements on Google impersonating 'Claude Code', targeting both Windows and macOS operating systems with the goal of infecting users.

malware google_ads initial_access windows macos
2r 1t
medium advisory

Windows Script Interpreter Executing Process via WMI

The rule identifies the use of Windows script interpreters (cscript.exe or wscript.exe) executing a process via Windows Management Instrumentation (WMI), which may indicate malicious activity, especially when initiated by non-system accounts.

Sysmon windows wmi script_execution initial_access execution
2r 4t