Skip to content
Threat Feed

Tag

Monitoring

13 briefs RSS
medium advisory

AWS EC2 EBS Snapshot Exfiltration via ModifySnapshotAttribute

Adversaries may exploit the ModifySnapshotAttribute API to share Amazon EBS snapshots with external accounts or the public, facilitating data exfiltration and unauthorized access to sensitive volume data.

Amazon Web Services +1 cloud exfiltration aws monitoring
1t
rumour rumour

Monitoring Malicious Use of SCCM Application Execution

This brief documents the execution mechanics of Microsoft System Center Configuration Manager (SCCM), identifying risks where adversary-controlled software or scripts are deployed through the SCCM client infrastructure.

System Center Configuration Manager execution enterprise-management windows monitoring
1t
high advisory

Correlation of First Seen Network Flow Exporters with Suspicious Source Activity

This detection identifies potential defense evasion where a newly observed network flow exporter subsequently acts as the source of suspicious security alerts within a 30-minute window.

defense-evasion network-security netflow monitoring
1t
medium advisory

Detection of TeamViewer Desktop Installation

This brief documents the detection of TeamViewer Desktop installation via file system activity, often associated with Remote Access Software usage.

remote-access monitoring
1r
medium advisory

Detection of Suspicious Artifacts and Tools via File Names

This brief documents patterns in file naming conventions frequently associated with attacker toolkits, proof-of-concept exploits, and red team frameworks.

detection offensive-tooling monitoring
1r 1t
medium advisory

Detecting Lateral Movement via Windows Remote Shell

Detection of child processes spawned by winrshost.exe identifying potential lateral movement and remote command execution via Windows Remote Management (WinRM).

lateral-movement windows monitoring
1r 1t
medium advisory

Monitoring Restoration of Quarantined Files in Microsoft Defender

This brief documents the detection of file restoration events from the Microsoft Defender quarantine, a technique that can be leveraged by attackers to re-enable malicious payloads.

defense-impairment windows monitoring
1r
high advisory

Historical Campaign Targeting Centreon IT Monitoring Software

Between 2017 and 2020, threat actors targeted Centreon environments at IT service providers by deploying the P.A.S. webshell and the Exaramel backdoor.

Centreon webshell backdoor persistence monitoring
3t
high advisory

Veeam ONE Security Bypass Vulnerability

A vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.

PoC Veeam ONE vulnerability remote-access monitoring
1t 1c updated
medium advisory

Detection of Potential Credential Access via AWS SSM SecureString Decryption

This detection monitors for the first occurrence of an AWS identity accessing AWS Systems Manager (SSM) SecureString parameters with the decryption flag enabled, indicating potential unauthorized retrieval of stored sensitive credentials.

AWS Systems Manager credential-access cloud aws monitoring
1r 1t
medium advisory

Detection of Unauthorized Windows Firewall Exception Rule Creation

Monitoring for non-standard additions to the Windows Defender Firewall exception list to identify potential defense impairment activity by unauthorized processes.

defense-impairment windows-firewall monitoring
1r
high advisory

Nagios Core and XI CSRF Protection Bypass

Nagios Core and XI contain a CSRF protection bypass vulnerability (CVE-2026-48551) that allows unauthenticated attackers to execute commands as an authorized user via manipulated double-submit cookies.

Nagios Core +1 vulnerability rce monitoring
2t 2c updated
medium advisory

Detection of High-Frequency File Operations in Administrative Network Shares

An anomaly-based detection analytic identifying potential insider threats or data exfiltration by monitoring for high-frequency write operations to administrative network shares via Windows Event ID 5145.

Windows insider-threat data-exfiltration monitoring
1r 1t