Tag
Network Communication With Crypto Mining Pools
1 rule 1 TTP 315 IOCsCrypto mining malware, often deployed by various threat actors, connects to designated mining pools to perform unauthorized cryptocurrency mining, leading to significant system performance degradation and illicit resource consumption.
Detection of Unauthorized Connections to Dead Drop Resolver Domains
1 rule 1 TTPThis brief details the detection of malicious executables establishing network connections to legitimate popular websites, known as dead drop resolvers, to conduct covert command and control (C2) communications, allowing threat actors to evade traditional security controls and maintain persistent access for data exfiltration or further compromise.
GenAI Process Connection to Unusual Domain on macOS
2 rules 1 TTPThis rule detects GenAI tools on macOS connecting to unusual domains, potentially indicating command and control activity, data exfiltration, or malicious payload retrieval following compromise via prompt injection, malicious MCP servers, or poisoned plugins.
Command Prompt Network Connection Activity
2 rules 2 TTPsDetection of command prompt activity initiating network connections can indicate suspicious or malicious behavior, potentially leading to command and control or data exfiltration.
Suspicious Command Prompt Network Connection
2 rules 4 TTPsThis alert identifies suspicious network connections initiated by the command prompt (cmd.exe) when executed with arguments indicative of script execution, remote resource access, or originating from Microsoft Office applications, which is a common tactic for downloading payloads or establishing command and control.