Tag
medium
advisory
Potential Network Sniffing via Start-NetEventSession
1 rule 1 TTPAdversaries may use the legitimate Windows PowerShell cmdlet Start-NetEventSession to capture network traffic and perform reconnaissance or credential theft.
credential-access
discovery
network-sniffing
powershell
windows
1r
1t
medium
advisory
Sensitive File Compression Detected in Linux Containers for Credential Access
3 rules 8 TTPs 1 IOCElastic Defend for Containers detects the use of compression utilities like tar or zip within Linux containers to collect sensitive files such as SSH keys, AWS credentials, or system configurations, indicating potential credential access and data collection attempts by adversaries.
Defend for Containers
container
linux
credential-access
data-collection
threat-detection
discovery
reconnaissance
network-scanning
+6
3r
8t
1i
medium
advisory
Azure VNet Full Network Packet Capture Enabled
3 rules 2 TTPsDetection of Azure Network Watcher's Packet Capture feature being enabled, potentially indicating malicious network sniffing for credential access and discovery of sensitive data in unencrypted traffic.
Azure +1
network-sniffing
credential-access
3r
2t