Tag
Local Privilege Escalation in ieungSoft Ultra RAMDisk Pro URDSCSI.sys
1 TTP 1 CVEThe URDSCSI.sys kernel driver in ieungSoft Ultra RAMDisk Pro 1.82 contains an improper privilege management vulnerability that allows local attackers to achieve privilege escalation.
Local Privilege Escalation in CheckMAL AppCheck Pro via Kernel Driver
1 TTP 1 CVEA local privilege escalation vulnerability in the AppCheckD.sys driver of CheckMAL AppCheck Pro version 3.1.43.10 allows attackers to perform uncontrolled search path manipulation.
Suspicious Service Installation for Defense Evasion
1 ruleAttackers are installing suspicious services, specifically NalDrv or PROCEXP152, via registry modifications to non-system32 folders to facilitate defense evasion by tools like Ghost-In-The-Logs, aiming to disable or impair security monitoring capabilities.
fast16 Cyber Sabotage Framework
3 rules 4 TTPs 4 IOCsThe fast16 framework is a cyber sabotage tool dating back to 2005 that selectively targets high-precision calculation software, patching code in memory to tamper with results, using a Lua virtual machine and propagating across an entire facility to produce inaccurate calculations, with svcmgmt.exe as a carrier and fast16.sys modifying executable code.