{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/offensive-tooling/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["detection","offensive-tooling","monitoring"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eDefenders frequently encounter indicators of adversary activity where tools, payloads, or exploit scripts utilize predictable, default, or descriptive file names. These patterns often arise from the use of publicly available offensive security frameworks, proof-of-concept (PoC) code released in security advisories, or common testing artifacts used during red team engagements. By monitoring for specific file paths and naming conventions, security teams can detect the presence of staging, execution, or testing activities that deviate from standard environment behavior. This detection logic focuses on common naming patterns, such as references to CVE identifiers, various iterations of 'artifact' binaries, and script filenames suggestive of offensive capabilities like beaconing, shellcode execution, or credential dumping.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful identification of these artifacts allows security operations teams to detect early-stage attacker staging or unauthorized red team activity. If left unmonitored, these predictable naming conventions provide a simple indicator that an actor is utilizing standardized tooling, potentially indicating a higher likelihood of automated or template-driven exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy detection coverage for process creation events to identify the execution of files matching common offensive naming conventions. Prioritize tuning these rules based on internal legitimate development and security testing activities.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to identify common offensive tool and artifact naming conventions within the environment.\u003c/li\u003e\n\u003cli\u003eBaseline existing automated maintenance scripts and administrative tools to ensure they do not trigger these detection patterns.\u003c/li\u003e\n\u003cli\u003eIntegrate these detection rules with Sysmon Event ID 1 (Process Creation) logs to capture the full command line and image path for forensic analysis.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:45:40Z","date_published":"2026-09-03T12:45:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-suspicious-program-names/","summary":"This brief documents patterns in file naming conventions frequently associated with attacker toolkits, proof-of-concept exploits, and red team frameworks.","title":"Detection of Suspicious Artifacts and Tools via File Names","url":"https://feed.craftedsignal.io/briefs/2026-09-suspicious-program-names/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["lateral-movement","post-exploitation","crackmapexec","offensive-tooling"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCrackMapExec (CME) is a widely used post-exploitation tool primarily employed by penetration testers and adversaries to assess and exploit Active Directory environments. The tool automates lateral movement and credential harvesting by leveraging native Windows protocols such as SMB, WMI, and WinRM. A key characteristic of CME is its use of specific, predictable command-line execution patterns when executing commands on remote targets. These patterns often involve redirected output via administrative shares or the invocation of PowerShell with specific evasion flags to bypass security policies. Defenders can monitor for these standardized command line arguments to identify unauthorized use of the framework within their environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access and establishes a presence on a compromised host.\u003c/li\u003e\n\u003cli\u003eAttacker deploys CrackMapExec to enumerate network segments or target specific domain controllers.\u003c/li\u003e\n\u003cli\u003eAttacker uses the SMB or WMI module within CME to trigger remote command execution on a target system.\u003c/li\u003e\n\u003cli\u003eCME executes commands via 'cmd.exe' using standardized redirection syntax to capture output into temporary files or administrative shares.\u003c/li\u003e\n\u003cli\u003eAttacker executes PowerShell scripts via CME, typically using 'bypass', 'noni', and 'nop' flags to circumvent execution policies.\u003c/li\u003e\n\u003cli\u003ePowerShell commands are often obfuscated or encoded via 'enc' parameters to minimize detection footprint.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved, such as credential dumping (e.g., Mimikatz modules), persistence establishment, or further lateral movement.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of CrackMapExec by unauthorized actors can lead to rapid lateral movement, privilege escalation, and full domain compromise. The framework's ability to automate complex attacks at scale significantly increases the speed at which an environment can be compromised, often leading to large-scale data exfiltration or ransomware deployment if left undetected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the deployment of process-creation telemetry logging across all domain-joined endpoints. Enable Sysmon Event ID 1 to capture 'CommandLine' and 'ParentImage' metadata. Deploy the Sigma rules below to your SIEM/XDR platform and monitor for these specific command patterns. Because CME is commonly used in testing, triage findings by validating the source of the activity against known scheduled internal red team operations.\u003c/p\u003e\n","date_modified":"2026-09-03T12:39:35Z","date_published":"2026-09-03T12:39:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-crackmapexec-patterns/","summary":"Detection engineering brief covering common command-line execution patterns generated by the CrackMapExec (CME) post-exploitation framework during lateral movement and command execution.","title":"Detection of CrackMapExec Post-Exploitation Execution Patterns","url":"https://feed.craftedsignal.io/briefs/2026-09-crackmapexec-patterns/"}],"language":"en","title":"CraftedSignal Threat Feed - Offensive-Tooling","version":"https://jsonfeed.org/version/1.1"}