Tag
Script Interpreter Initiating Local Network Connections
1 rule 1 TTPDetection of suspicious network activity where Windows script interpreters (Wscript.exe and Cscript.exe) initiate connections to local IP ranges.
Outbound RDP Connections Initiated by Non-Standard Processes
1 rule 1 TTPDetection of RDP traffic (TCP 3389) initiated by unauthorized or non-standard binaries, which may indicate lateral movement or unauthorized remote access.
Detection of DNS Rebinding via Public-to-Private Resolution Patterns
1 TTPAttackers leverage DNS rebinding to bypass security boundaries by causing a public domain to resolve to internal, loopback, or private IP addresses, enabling unauthorized access to protected internal services.
CVE-2026-38968: ntopng Predictable Session Identifier Vulnerability Leading to Session Hijacking
1 CVECVE-2026-38968 affects ntopng versions up to 6.6, enabling session hijacking through predictable session identifiers generated with weak time-seeded pseudo-randomness in `src/HTTPserver.cpp`, allowing attackers to gain unauthorized access to legitimate user sessions.