Tag
AWS EC2 EBS Snapshot Exfiltration via ModifySnapshotAttribute
1 TTPAdversaries may exploit the ModifySnapshotAttribute API to share Amazon EBS snapshots with external accounts or the public, facilitating data exfiltration and unauthorized access to sensitive volume data.
Monitoring Malicious Use of SCCM Application Execution
1 TTPThis brief documents the execution mechanics of Microsoft System Center Configuration Manager (SCCM), identifying risks where adversary-controlled software or scripts are deployed through the SCCM client infrastructure.
Correlation of First Seen Network Flow Exporters with Suspicious Source Activity
1 TTPThis detection identifies potential defense evasion where a newly observed network flow exporter subsequently acts as the source of suspicious security alerts within a 30-minute window.
Detection of TeamViewer Desktop Installation
1 ruleThis brief documents the detection of TeamViewer Desktop installation via file system activity, often associated with Remote Access Software usage.
Detection of Suspicious Artifacts and Tools via File Names
1 rule 1 TTPThis brief documents patterns in file naming conventions frequently associated with attacker toolkits, proof-of-concept exploits, and red team frameworks.
Detecting Lateral Movement via Windows Remote Shell
1 rule 1 TTPDetection of child processes spawned by winrshost.exe identifying potential lateral movement and remote command execution via Windows Remote Management (WinRM).
Monitoring Restoration of Quarantined Files in Microsoft Defender
1 ruleThis brief documents the detection of file restoration events from the Microsoft Defender quarantine, a technique that can be leveraged by attackers to re-enable malicious payloads.
Historical Campaign Targeting Centreon IT Monitoring Software
3 TTPsBetween 2017 and 2020, threat actors targeted Centreon environments at IT service providers by deploying the P.A.S. webshell and the Exaramel backdoor.
Veeam ONE Security Bypass Vulnerability
1 TTP 1 CVEA vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.
Detection of Potential Credential Access via AWS SSM SecureString Decryption
1 rule 1 TTPThis detection monitors for the first occurrence of an AWS identity accessing AWS Systems Manager (SSM) SecureString parameters with the decryption flag enabled, indicating potential unauthorized retrieval of stored sensitive credentials.
Detection of Unauthorized Windows Firewall Exception Rule Creation
1 ruleMonitoring for non-standard additions to the Windows Defender Firewall exception list to identify potential defense impairment activity by unauthorized processes.
Nagios Core and XI CSRF Protection Bypass
2 TTPs 2 CVEsNagios Core and XI contain a CSRF protection bypass vulnerability (CVE-2026-48551) that allows unauthenticated attackers to execute commands as an authorized user via manipulated double-submit cookies.
Detection of High-Frequency File Operations in Administrative Network Shares
1 rule 1 TTPAn anomaly-based detection analytic identifying potential insider threats or data exfiltration by monitoring for high-frequency write operations to administrative network shares via Windows Event ID 5145.