Tag
Unauthorized Command Execution via Self-Hosted GitHub Actions Runners
1 rule 1 TTPAdversaries gaining unauthorized workflow trigger access can abuse GitHub Actions runners to execute arbitrary system commands, potentially leading to credential harvesting, reconnaissance, and CI/CD supply chain compromise.
Suspicious Reconnaissance Activity via GatherNetworkInfo.VBS
1 rule 2 TTPsAdversaries are utilizing the native Windows script GatherNetworkInfo.vbs to perform system reconnaissance and collect network configuration data.
Abuse of Esentutl.exe for Sensitive Credential File Extraction
1 rule 1 TTPAdversaries are leveraging the legitimate Windows binary 'esentutl.exe' to bypass file locks and perform unauthorized copies of system credential databases such as NTDS.dit and SAM.
Bad Apples: Weaponizing Native macOS Primitives for Lateral Movement and Execution
2 rules 2 TTPsAdversaries are increasingly targeting macOS environments, leveraging native tools like Remote Application Scripting (RAS) and Spotlight metadata to bypass security controls for remote code execution and lateral movement.