Skip to content
Threat Feed

Tag

Persistence

501 briefs RSS
medium advisory

Detection of Suspicious Offline Registry Library Usage

Detection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.

defense-impairment persistence windows telemetry-bypass
1r 1t
high advisory

Suspicious Staging of Windows Registry Hive Files

Detection of registry hive files created outside of standard user profile directories, a common indicator of unauthorized hive manipulation for credential access or persistence.

persistence privilege-escalation credential-access
1r 2t
medium advisory

Detection of Unusual AWS IAM Guardrail Policy Deletion

This threat brief identifies a detection strategy for attackers attempting defense evasion or persistence by deleting sensitive AWS IAM managed policies using previously unseen identities.

AWS IAM cloud defense-evasion persistence aws iam
1r 2t
low advisory

Detection of Unusual File Creation by Web Server Processes on Linux

This brief details a behavioral detection strategy for identifying potential web shell deployment and persistence mechanisms by monitoring anomalous file creation activities originating from common web server processes on Linux.

nginx +44 persistence web-shell linux behavioral-detection
1r 4t updated
high advisory

Suspicious Echo or Printf Execution Detected via Defend for Containers

A detection rule for Elastic Defend for Containers identifies threat actors leveraging `echo` or `printf` commands within Linux containers to write data to sensitive files for persistence, decode obfuscated payloads, or establish command and control (C2) communication, impacting system integrity and potentially leading to privilege escalation.

container-security cloud-security persistence privilege-escalation execution defense-evasion linux
1r 9t
medium advisory

SSH Authorized Key File Activity Detected in Containers

Adversaries may modify the Secure Shell (SSH) authorized_keys file inside Linux containers to maintain persistence, achieve lateral movement, or escalate privileges by adding their own public keys, with this activity detected by Elastic Defend for Containers.

container linux persistence lateral-movement privilege-escalation ssh
1r 4t
high advisory

Dynamic Linker Modification for Defense Evasion and Privilege Escalation in Linux Containers

Adversaries modify the dynamic linker preload shared object (`/etc/ld.so.preload`) or configuration files (`/etc/ld.so.conf.d/*`, `/etc/ld.so.conf`) inside Linux containers to hijack the dynamic linker, forcing the system to load malicious libraries at runtime, thereby gaining unauthorized access, maintaining persistence, escalating privileges, and evading detection of malicious processes.

defense-evasion persistence privilege-escalation linux container threat-detection
1r 3t
low advisory

Detection of Unusual Windows Services via Machine Learning

This threat involves the detection of unusual Windows services, which can indicate unauthorized service execution, malware, or persistence mechanisms, with a machine learning job identifying atypical services by comparing them against known legitimate patterns to aid in early threat detection and response.

machine-learning-detection persistence execution windows endpoint
2t
low advisory

Anomalous Windows Process Creation Detected by Machine Learning

Elastic Security's machine learning rule `v3_windows_anomalous_process_creation_ea` detects unusual parent-child process relationships on Windows systems, indicating potential malware execution or persistence mechanisms and allowing for early detection of new or emerging threats that bypass traditional antivirus.

endpoint windows machine-learning persistence execution anomaly-detection
2t
low advisory

Unusual Process Detection for Windows Hosts via Machine Learning

An Elastic Security machine learning rule detects rare and unusual processes on individual Windows hosts, indicating potential unauthorized services, malware execution, or persistence mechanisms.

endpoint windows machine-learning persistence threat-detection
2t
low advisory

Unusual Process For a Linux Host Detection

An Elastic machine learning rule detects rare processes on Linux hosts, indicating potential persistence mechanisms, unauthorized services, or malware execution by an unknown threat actor, impacting system integrity and security.

persistence linux machine-learning endpoint threat-detection
1t
low advisory

Unusual Spike in Concurrent Active Sessions by a User

An Elastic machine learning rule detects an unusual spike in concurrent active Okta sessions initiated by a user, indicating potential adversary abuse of valid credentials for privilege escalation or persistence through the execution of multiple privileged operations.

Okta machine-learning anomaly-detection privilege-escalation persistence cloud-security
3t
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
low advisory

Potential Data Exfiltration Activity to an Unusual Region

Elastic's machine learning job identifies potential data exfiltration activity to unusual geo-locations by detecting anomalies in network traffic patterns, indicating adversaries leveraging command and control channels to transfer data outside normal organizational patterns.

Elastic Stack +5 exfiltration data-exfiltration machine-learning elastic network-detection command-and-control initial-access persistence
4t
high threat

Pocket ID OIDC Refresh Token Flow Bypasses Authorization Revocation, Account Disabling, and Group Restrictions

A vulnerability in the Pocket ID OpenID Connect (OIDC) `createTokenFromRefreshToken` function allows refresh tokens to bypass critical authorization controls, enabling threat actors to maintain perpetual access to client applications even after a user revokes authorization, an administrator disables the user account, or a user is removed from an allowed group.

exploited pocket-id +1 oidc authorization-bypass persistence privilege-escalation identity-and-access-management
2t 1c
medium advisory

Msiexec Quiet Installation for Proxy Execution

Adversaries leverage the Windows Installer utility msiexec.exe to proxy the quiet execution of malicious payloads, bypassing traditional security controls by masquerading as legitimate installation processes.

living-off-the-land proxy-execution persistence execution
1r 1t
medium advisory

Suspicious System Process Names in Unusual File Locations

This brief detects an attacker's attempt to evade detection and maintain persistence by creating executable files with names identical to legitimate Windows system processes in non-standard directories, a tactic associated with stealth and defense evasion.

stealth defense-evasion persistence windows file-event
1r 1t
high advisory

Svchost LOLBAS Execution Process Spawn

This brief details the detection of `svchost.exe` spawning Living Off The Land Binaries and Scripts (LOLBAS) processes, indicating potential malicious code execution, privilege escalation, or persistence attempts by adversaries within a Windows environment.

Windows lolbas execution persistence lateral-movement system-binary-proxy-execution
1r 2t
medium advisory

Windows AppCertDLL Modification for Persistence and Privilege Escalation

Attackers can modify Windows AppCertDLL registry keys via command-line utilities to achieve persistence and privilege escalation by registering malicious DLLs to be loaded early in the system startup process.

persistence privilege-escalation windows
1r 2t
high threat

Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass

A remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.

exploited PoC FortiOS +7 fortinet vulnerability cve exposure persistence
1t 3c 4i updated
low advisory

Anomalous Process For a Linux Population Detection

Elastic has released a machine learning detection rule designed to identify rare and unusual process executions across multiple Linux hosts within an entire fleet, aiming to uncover potential malware or suspicious behaviors indicative of persistence or other malicious activity.

persistence linux machine-learning threat-detection
1t
low advisory

Spike in User Account Management Events

Elastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.

Privileged Access Detection integration +7 privileged-access-detection machine-learning anomaly-detection windows account-management privilege-escalation persistence
5t updated
high advisory

Path Traversal Vulnerability in NitroShare Desktop (CVE-2026-66050)

NitroShare Desktop versions up to and including 0.3.4 are vulnerable to a path traversal flaw in their LAN file transfer server, allowing unauthenticated attackers on the same network to craft malicious filenames containing directory traversal sequences within the JSON item header. Exploiting this, attackers can write arbitrary files outside the intended transfer root to any location the current user has write access, including the Windows Startup folder, leading to persistent code execution upon user login.

NitroShare Desktop <= 0.3.4 path-traversal persistence code-execution vulnerability
1r 1t 1c
medium advisory

Windows Autostart Execution in Startup Folder for Persistence

Adversaries leverage the Windows %startup% folder to establish persistence by creating malicious files that execute automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.

persistence autostart windows detection
1r 1t
high advisory

Detection of Registry Keys Used for Persistence

This brief outlines a detection strategy for identifying modifications to Windows registry keys commonly used for persistence, including Run, Winlogon, and Image File Execution Options, enabling detection engineers to alert on unauthorized system startup entries for malicious code execution to prevent persistent access.

Splunk Enterprise +3 persistence registry windows endpoint malware
1r 1t
high threat

TrickBot Variant Utilizes DNS Tunneling for Command and Control

FortiGuard Labs analyzed a new TrickBot variant that employs DNS tunneling for command and control communications, modular execution, and incorporates persistence and obfuscation techniques to evade detection and maintain presence on infected systems.

TrickBot malware banking-trojan dns-tunneling c2 persistence obfuscation
4t
high advisory

Gitea OAuth Callback Re-enables Administrator-Disabled Accounts

An improper authorization vulnerability in Gitea's OAuth2 sign-in callback mechanism (CVE-2026-58422) allows users with linked external identity providers to unilaterally re-enable their administrator-disabled accounts, regaining full access and bypassing security controls.

Gitea improper-authorization oauth account-takeover persistence vulnerability
2t 1c
critical advisory

Gitea Branch Protection Bypass via Pull Request Retargeting

An attacker with write access to a Gitea repository can bypass branch protection rules by exploiting a logic flaw, obtaining an 'official' approval on a pull request (PR) targeting an unprotected branch, then retargeting the PR to a protected branch, preserving the stale approval and leading to unauthorized code merges and privilege escalation.

Gitea branch-protection-bypass code-repository privilege-escalation persistence web-application vulnerability defense-evasion network +7
1r 7t
high advisory

Gitea Repository Migration SSRF and Internal Git Repository Exfiltration

A critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.

Gitea +1 server-side-request-forgery ssrf vulnerability code-exfiltration data-exfiltration information-disclosure api-vulnerability web-vulnerability +5
2r 9t 1c
critical advisory

Denying the Worm: Detecting SANDWORM_MODE and AI Toolchain Supply Chain Attacks

The SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.

npm +16 supply-chain-attack git ai-toolchain development-workflow code-injection credential-theft persistence evasion
3r 14t 8i updated
medium advisory

Detect Potential Sudo Binary Hijacking on Linux Systems

Attackers may hijack the default sudo binary on Linux systems, located at `/usr/bin/sudo` or `/bin/sudo`, replacing it with a malicious version to capture user passwords for credential access, elevate privileges, or establish persistence on the system every time the sudo binary is executed.

privilege-escalation persistence credential-access linux
1r 3t
medium advisory

Potential Privilege Escalation via SUID/SGID Proxy Execution on Linux

Attackers may exploit SUID/SGID binaries like pkexec, su, or sudo on Linux systems to execute commands with elevated privileges, by identifying instances where a process runs with root privileges (user ID 0 or group ID 0) while the real user or group ID is non-root, allowing a low-privilege foothold to gain full system control.

su +17 privilege-escalation linux-security defense-evasion persistence system-exploitation
1r 4t
high threat

Possible FIN7 DGA Command and Control Behavior

FIN7 threat group utilizes a specific Domain Generation Algorithm (DGA) for command and control (C2), characterized by domains with 4-5 alphabetic characters and specific top-level domains such as .pw, .us, .club, .info, .site, or .top, enabling persistence and continued operations within target networks.

FIN7 +2 command-and-control dga network-traffic persistence
1r 2t
high advisory

Unusual Child Process Execution by Web Servers on Linux

This detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.

Elastic Defend +45 persistence execution command-and-control initial-access linux webserver webshell privilege-escalation +4
2r 5t 13i updated
high advisory

Unusual Command Execution via Linux Web Server Processes

This brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.

Apache HTTP Server +40 linux-threat persistence web-exploitation webshell command-execution detection-rule elastic-security
1r 4t
medium advisory

Suspicious Command Execution via Linux Web Server

This brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.

Apache HTTP Server +45 webserver command-injection web-shell vulnerability-exploitation persistence linux
1r 14t
low advisory

PHP File Creation in WordPress Plugin Directory

Attackers commonly establish persistence on compromised Linux WordPress web servers by creating malicious PHP files, often web shells, within the WordPress plugin directory, enabling remote access and command execution following initial compromise of a public-facing application.

WordPress persistence initial-access execution web-shell linux endpoint threat-detection vulnerability
1r 3t 1c 1i updated
critical threat

Three Chained Zero-Days in Siemens ROX II OT Switches Lead to Root Access

Unit 42 and Siemens collaborated to disclose three critical chained zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) in Siemens ROX II operational technology switches, allowing an attacker to achieve arbitrary file disclosure, privilege escalation to root, and persistent root-level code execution.

exploited ROX II OT switches industrial-control-systems ot-security zero-day privilege-escalation command-injection persistence siemens vulnerability-exploit
3r 4t 3c
high advisory

OpenClaw Vulnerability Allows Untrusted Workspace Plugin Loading (CVE-2026-62222)

A vulnerability, CVE-2026-62222, exists in OpenClaw versions prior to 2026.5.22, where an attacker with lower-trust caller access or control over configured input paths can exploit a flaw in the setup-mode discovery to load untrusted workspace plugins, leading to arbitrary code execution, persistence, and privilege escalation.

OpenClaw vulnerability remote-code-execution privilege-escalation persistence
3t 1c 2i
high advisory

OpenClaw Environment Variable Filtering Vulnerability Allows Execution and Persistence

OpenClaw versions prior to 2026.6.6 contain an environment variable filtering vulnerability in its host exec component that fails to properly sanitize rustup startup variables, allowing attackers with lower-trust caller access or configured input paths to execute or persist actions beyond their intended authorization level.

OpenClaw +1 cve-2026-62203 vulnerability environment-variable code-execution persistence
2t 2c
medium advisory

File Creation in World-Writable Directory by Unusual Process

An Elastic detection rule identifies when an unusual process creates files within world-writable directories on Linux systems, a tactic employed by attackers for defense evasion and lateral movement by staging payloads and hiding malicious activities.

Elastic Defend +5 linux defense-evasion persistence lateral-movement
1r 1t
high advisory

Detect Linux Kernel Module Load via Built-in Utility

This threat involves adversaries with root privileges using the `insmod` or `modprobe` utilities to load malicious Linux kernel object files (.ko), often rootkits, which provides complete system control and evasion capabilities, making detection of this uncommon activity critical.

linux persistence defense-evasion rootkit endpoint-security threat-detection elastic-defend
1r 2t
high advisory

HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery

An unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.

ViPNet Update System apt dll-sideloading persistence proxy c2 reconnaissance data-exfiltration russia +1
3r 11t 1i
critical advisory

ClickLock macOS Stealer Uses Coercive App Killing to Force Password Entry

The ClickLock macOS infostealer employs a unique coercive tactic by repeatedly killing essential macOS applications, such as Finder and Dock, every 210 milliseconds until the victim provides their login password, leading to the exfiltration of sensitive credentials and cryptocurrency wallets.

macos infostealer credential-theft persistence social-engineering data-exfiltration malware
3r 9t 2i
high advisory

Splunk Path Traversal Vulnerability Allows Arbitrary File Writes (CVE-2026-20297)

A path traversal vulnerability (CVE-2026-20297) in Splunk Enterprise and Splunk Cloud Platform allows an authenticated user with `edit_local_apps` and `install_apps` capabilities to write files outside the intended application directory during app installation, specifically into the `$SPLUNK_HOME/etc/` directory and its subdirectories, leading to configuration manipulation, persistence, or privilege escalation.

Splunk Enterprise +1 path-traversal vulnerability splunk rce persistence privilege-escalation
3t 1c
high advisory

AWS EC2 Instance Connect SSH Public Key Upload Detection

Adversaries may upload SSH public keys to AWS EC2 instances via the EC2 Instance Connect service using the `SendSSHPublicKey` or `SendSerialConsoleSSHPublicKey` API actions, which can serve as a mechanism for initial access, persistence, or privilege escalation, particularly if the `SendSerialConsoleSSHPublicKey` action is coupled with unauthorized serial console access.

EC2 Instance Connect +1 cloud aws lateral-movement privilege-escalation persistence
1r 3t
high advisory

AWS Sensitive IAM Operations Performed via CloudShell

Attackers can leverage a compromised AWS console session to perform sensitive AWS IAM operations via AWS CloudShell, establishing persistence or escalating privileges, which can be detected by monitoring CloudTrail logs for specific user agent strings and high-risk IAM actions.

AWS CloudShell +2 cloud aws persistence privilege-escalation
1r 4t
high advisory

Suspicious AWS EC2 Key Pair Creation from Non-Cloud Autonomous System

An Elastic detection rule identifies when a previously unseen AWS IAM principal successfully creates an EC2 key pair from an Autonomous System (AS) organization not associated with common cloud or hyperscaler providers, indicating potential attacker persistence or preparation for unauthorized instance access via SSH.

Amazon EC2 cloud aws persistence identity
1r 3t
high advisory

AWS Lambda Function Policy Updated to Allow Public Invocation

Adversaries may modify AWS Lambda function policies via the AddPermission API call, setting the Principal to '*' to enable public invocation, which establishes persistence and creates a covert execution path within an AWS environment.

AWS Lambda aws cloud persistence defense-evasion cloudtrail
1r 2t
high advisory

AWS IAM SAML Provider Creation for Persistence

Adversaries with administrative access to an AWS account can create rogue SAML Identity Providers (IdPs) to establish persistent, federated access to AWS resources that survives credential rotation, enabling them to assume roles and access resources by forging SAML assertions from an IdP they control.

AWS IAM cloud aws aws-iam identity-and-access-audit persistence
1r 3t
high advisory

AWS IAM Roles Anywhere Profile Creation

Adversaries may create new AWS IAM Roles Anywhere profiles via the 'CreateProfile' API call to establish persistence or escalate privileges within an AWS environment by linking highly privileged roles to a rogue trust anchor, facilitating long-term external access.

IAM Roles Anywhere cloud aws persistence privilege-escalation
1r 2t
high advisory

AWS IAM OpenID Connect Provider Creation by Rare User

Adversaries with administrative access to an AWS account may create rogue OpenID Connect (OIDC) Identity Providers to establish persistent, federated access that bypasses credential rotation and allows them to assume IAM roles using tokens from an attacker-controlled Identity Provider.

IAM cloud-security persistence privilege-escalation defense-evasion aws
1r 3t
high advisory

AWS IAM User Creation via Compromised EC2 Assumed Role

Adversaries leverage a compromised AWS EC2 instance's assumed IAM role to create new, unauthorized IAM users, establishing persistence within the AWS environment by granting themselves persistent access even after the initial compromise is remediated.

AWS Identity and Access Management +2 cloud aws persistence identity-and-access-management ec2 privilege-escalation iam
2r 3t 1i
high advisory

Suspicious AWS IAM API Calls via Temporary Session Tokens

This detection rule identifies suspicious AWS IAM API operations performed using temporary session credentials (access keys starting with ASIA) that are not sourced from console logins, indicating potential credential theft, session hijacking, or abuse of privileged temporary credentials by an attacker for persistence, privilege escalation, or defense evasion within the AWS environment.

AWS IAM +3 cloud aws persistence privilege-escalation defense-evasion
1r 2t
high advisory

AWS IAM Virtual MFA Device Registration Attempt with Session Token

Adversaries are exploiting compromised temporary AWS session credentials (access keys starting with 'ASIA') to register or enable virtual MFA devices, establishing persistence and maintaining access to high-privilege accounts even after credential rotation or password resets.

IAM +3 cloud aws persistence identity-and-access-audit
1r 3t updated
high advisory

AWS IAM Multi-Factor Authentication Device Deactivation

Adversaries or compromised administrators may deactivate Multi-Factor Authentication (MFA) devices in AWS Identity and Access Management (IAM) by executing a successful `DeactivateMFADevice` API call, significantly weakening account security, disabling strong authentication, and paving the way for unauthorized access, privilege escalation, or persistence.

AWS Identity and Access Management cloud aws iam impact persistence defense-evasion
1r 3t
high advisory

AWS STS GetFederationToken Abuse for Persistence and Defense Evasion

Adversaries may exploit the AWS Security Token Service (STS) GetFederationToken API call to obtain temporary security credentials, enabling persistence and bypassing IAM API call limitations by gaining console access, with these temporary tokens remaining active for up to 36 hours, even if the initial compromised identity is deleted, and used to create console sign-in tokens.

AWS Security Token Service cloud aws defense-evasion persistence threat-detection
1r 2t
high advisory

CRI-O Environment Variable Injection Vulnerability (CVE-2026-15809)

A critical vulnerability, CVE-2026-15809, in CRI-O allows an attacker with the ability to set container environment variables to bypass a previous fix (CVE-2022-4318), inject a newline character into the HOME environment variable, and add arbitrary lines to /etc/passwd, potentially leading to privilege escalation or persistence within the container.

CRI-O +2 container linux vulnerability privilege-escalation persistence
1r 1t 2c
high advisory

ForgeKeep Nebula-Mesh Certificate Revocation Bypass Vulnerability

A high-severity vulnerability, CVE-2026-61699, in ForgeKeep's nebula-mesh allows compromised or offboarded hosts to bypass certificate revocation, enabling attackers to maintain full mesh network access for up to 365 days despite operator actions.

nebula-mesh certificate-revocation network-overlay defense-evasion persistence network
2t
high advisory

Arbitrary File Write in Yutu's MCP caption-download Tool (CVE-2026-50158)

An arbitrary file write vulnerability (CVE-2026-50158) in the `caption-download` MCP tool of the yutu application allows a local attacker, or any process able to reach the unauthenticated HTTP MCP server, to bypass the `YUTU_ROOT` confinement and write arbitrary content to any path writable by the yutu process, leading to potential persistent code execution, privilege escalation, or denial of service.

yutu arbitrary-file-write cve golang local-privilege-escalation persistence
3t
high threat

CVE-2026-60114 Sustainable Irrigation Platform Path Traversal Vulnerability

A path traversal vulnerability (CVE-2026-60114) in Sustainable Irrigation Platform (SIP) through version 5.2.16 allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files containing unvalidated keys, leading to potential remote code execution, persistence, and privilege escalation.

exploited Sustainable Irrigation Platform path-traversal arbitrary-file-write web-application remote-code-execution persistence privilege-escalation
3t 1c
high advisory

AWS Lambda Function URL Created with Public Access

Adversaries can establish persistent, internet-accessible footholds within AWS environments by configuring AWS Lambda function URLs with an authentication type of NONE, allowing unauthenticated invocation directly from the public internet for command and control, data exfiltration, or on-demand code execution.

AWS Lambda cloud aws aws-lambda threat-detection persistence defense-evasion
1r 2t
high threat

ShinyHunters OAuth Abuse Targeting SaaS Applications

ShinyHunters, and related threat actor Storm-3138, conducted campaigns between mid-2025 and mid-2026 by employing voice phishing, supply chain compromise, and misconfigured guest access to abuse trusted OAuth relationships in SaaS applications like Salesforce, leading to unauthorized access, data exfiltration, and persistence.

Salesforce +4 ShinyHunters oauth-abuse saas supply-chain vishing data-exfiltration persistence cloud
6t
high advisory

OpenClaw Environment Filtering Bypass Vulnerability (CVE-2026-62199)

A critical vulnerability, CVE-2026-62199, in OpenClaw versions prior to 2026.6.6 allows a lower-trust caller to bypass host execution environment filtering by supplying crafted interpreter startup variables, leading to unauthorized code execution and persistence.

OpenClaw vulnerability rce persistence
2t 1c
critical advisory

CVE-2026-58122: Hermes WebUI Authentication Bypass via Spoofed X-Forwarded-For Header

CVE-2026-58122 describes an authentication bypass vulnerability in Hermes WebUI before version 0.51.307, allowing unauthenticated remote attackers to bypass local-origin IP restrictions on onboarding endpoints by spoofing the X-Forwarded-For header with a loopback address, leading to server-side request forgery (SSRF), API key overwrites, and persistent access token acquisition.

Hermes WebUI < 0.51.307 authentication-bypass ssrf web-vulnerability credential-theft persistence cloud network
1r 4t 1c
high threat

CitrixBleed 2 (CVE-2025-5777) Exploitation Leading to Dragonforce Ransomware

Initial Access Brokers are actively exploiting CitrixBleed 2 (CVE-2025-5777) on NetScaler appliances to steal session tokens, achieve local privilege escalation, establish persistence via legitimate remote access tools, and ultimately deploy Dragonforce ransomware.

exploited NetScaler ransomware initial-access privilege-escalation persistence citrix dragonforce
4r 9t 1c 7i
high advisory

Serena Agent Unauthenticated RCE via DNS Rebinding (CVE-2026-49471)

An unspecified attacker can achieve remote code execution in Serena agent versions prior to 1.5.2 by leveraging an unauthenticated Flask dashboard, DNS rebinding, and memory poisoning, enabling persistent attacker-controlled command execution.

serena-agent remote-code-execution dns-rebinding persistence command-and-control python flask agent
1r 6t 1c 1i
critical advisory

Nuclio Controller Vulnerability Leads to Persistent Kubernetes RCE (GHSA-v5px-423j-pf7p)

The Nuclio controller improperly sanitizes user-controlled input (cron trigger event headers and body) before injecting it into `curl` commands executed by Kubernetes CronJobs, allowing remote attackers to perform command injection and achieve remote code execution (RCE) by breaking quoting contexts in header keys or utilizing shell command substitution in event bodies, leading to arbitrary command execution with root privileges and potential persistence within the Kubernetes cluster.

Nuclio <= 1.15.27 remote-code-execution kubernetes cloud-native command-injection persistence critical-vulnerability ghsa
2r 3t 2i
high advisory

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are actively exploiting Microsoft's ClickOnce deployment technology, leveraging its low user interaction, lack of privilege requirements, and built-in update mechanisms to deliver malware, establish persistence, and maintain remote access, often executing payloads within legitimate rundll32.exe and dfsvc.exe processes.

PoC ClickOnce +11 microsoft persistence delivery windows endpoint
2r 7t 26i updated
high advisory

New Abuse of ClickOnce Technology: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are exploiting Microsoft's ClickOnce technology to achieve initial access, execute malicious payloads, and maintain persistence. This abuse leverages ClickOnce's user-friendly deployment, minimal privilege requirements, and built-in update mechanism to bypass traditional security defenses and execute malware stealthily within legitimate Microsoft processes like rundll32.exe. Adversaries achieve persistence by pushing malicious updates, or by placing ClickOnce shortcut files (.appref-ms) in the Windows Startup folder or configuring them as scheduled tasks.

ClickOnce +2 persistence initial-access defense-evasion remote-access microsoft windows
2r 5t
critical advisory

9routers Database Exposure and Takeover via Insecure API

A critical vulnerability (CVE-2026-55500) in 9routers versions <= 0.4.71 allows authenticated attackers with a valid JWT token to export the complete database containing plaintext credentials and secrets, and to import a modified database, leading to full system takeover and credential theft.

9router <= 0.4.71 web-exploitation data-exfiltration credential-access persistence impact
1r 6t 1i
medium advisory

AWS Lambda Event Source Mapping Abuse for Persistence and Data Exfiltration

Adversaries can exploit the creation of AWS Lambda event source mappings to establish stealthy persistence and execution, or to continuously siphon records from event sources like Amazon SQS, Kinesis, DynamoDB, MSK, Kafka, or MQ, by mapping an event source to an attacker-controlled Lambda function, enabling durable execution and data exfiltration without requiring further interactive access.

AWS Lambda +6 cloud aws persistence execution data-exfiltration
1r 3t
high advisory

AWS Lambda Function URL Created with Public Access

Adversaries may establish a persistent, internet-reachable entry point by creating or updating an AWS Lambda function URL with an authentication type of NONE, allowing unauthenticated invocation for command and control, data exfiltration, or on-demand code execution, thereby bypassing the need for valid AWS credentials.

AWS Lambda cloud aws persistence defense-evasion
1r 3t
high advisory

AWS Lambda Function Policy Updated to Allow Cross-Account Invocation

An adversary can establish persistence and defense evasion by modifying an AWS Lambda function's resource policy via the `AddPermission` API to grant `lambda:InvokeFunction` permissions to a principal in an external AWS account, enabling unauthorized function invocation and potential data exfiltration without altering function code.

AWS Lambda cloud aws persistence defense-evasion
1r 2t
medium advisory

Systemd Service Override Configuration File Creation for Persistence

Attackers can leverage the creation or renaming of Systemd override configuration files in standard or user service directories to achieve persistence or privilege escalation on Linux systems, altering service behavior to execute malicious commands during system startup or at predefined intervals via timers, thereby maintaining unauthorized access or evading detection.

persistence privilege-escalation linux endpoint
1r 2t
medium advisory

AWS IAM Inline Policy Added to a Group

Adversaries can escalate privileges and establish persistence within AWS by leveraging the `PutGroupPolicy` API call to attach an inline policy to an IAM group, granting broad permissions to all group members, including themselves.

AWS IAM aws cloud privilege-escalation persistence identity
1r 2t
medium advisory

AWS IAM Login Profile Created or Modified for an IAM User

This rule detects the creation or modification of console login profiles for AWS IAM users via the CreateLoginProfile or UpdateLoginProfile APIs. Adversaries with stolen programmatic credentials can use these actions to establish persistent interactive console access, reset other users' passwords to take over accounts, and maintain access even after original access keys are rotated. Since IAM user console access is increasingly managed through federation or IAM Identity Center, direct use of these APIs, especially by unexpected principals, warrants investigation as a strong indicator of persistence or account compromise.

AWS IAM +1 cloud aws persistence identity
1r 1t
high advisory

AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content

This brief details how attackers can leverage compromised AWS credentials to inject malicious, base64-encoded scripts into Amazon SageMaker notebook lifecycle configurations, which then execute as root on notebook instances, enabling persistence, credential theft, or further compromise of the AWS environment.

Amazon SageMaker cloud aws sagemaker persistence execution backdoor credential-theft
2t
high advisory

Web Server Potential SQL Injection Attempt Detection

This brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.

Apache +5 sql-injection web-attack reconnaissance initial-access data-exfiltration command-execution persistence cross-platform
1r 6t
medium advisory

First Time Seen Remote Monitoring and Management Tool Detection

Adversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.

AA +132 command-and-control persistence execution rmm remote-access windows
1r 3t 5i
medium advisory

Detecting Malicious Kernel Module Loading via Built-in Utilities on Linux

Threat actors with root privileges can leverage built-in Linux utilities like `insmod` or `modprobe` to load kernel object files, often for installing rootkits that grant complete system control and enable evasion of security products, representing a significant persistence and defense evasion technique.

persistence defense-evasion rootkit linux endpoint
1r 1t
high advisory

BITS Transfer Job Downloads from File Sharing Domains

Adversaries leverage the Windows Background Intelligent Transfer Service (BITS) to download malicious payloads from legitimate file-sharing and cloud storage domains, enabling stealthy ingress of tools and malware onto compromised systems, a technique observed in campaigns by ransomware groups and nation-state actors.

persistence execution defense-evasion ingress-tool-transfer windows
1r 3t
medium advisory

Detection of Service Manipulation via WMIC.exe

This brief describes the detection of adversaries leveraging the native Windows Management Instrumentation Command-line (WMIC.exe) utility to start or stop services on compromised Windows systems, a common technique for persistence, privilege escalation, or lateral movement.

lolbin windows persistence execution lateral-movement
1r 1t
medium advisory

Suspicious Service Installation for Defense Evasion

Attackers are installing suspicious services, specifically NalDrv or PROCEXP152, via registry modifications to non-system32 folders to facilitate defense evasion by tools like Ghost-In-The-Logs, aiming to disable or impair security monitoring capabilities.

defense-evasion persistence kernel-driver windows
1r
medium advisory

Suspicious Process Monitor Driver Creation by Non-Sysinternals Binary

This brief details a detection strategy for malicious actors attempting to establish persistence or elevate privileges by creating a Process Monitor driver file (`.sys`) from an unauthorized process, indicating potential kernel-level compromise on Windows systems.

persistence privilege-escalation windows detection
1r 2t
high advisory

Detection of Web Shell via Antivirus Signature

This brief describes the detection of web shells by antivirus solutions, emphasizing the importance of investigating these alerts as they signify a compromised web server and potential post-exploitation activity by an attacker.

webshell antivirus detection persistence
1r 1t
high advisory

Suspicious Legitimate Application Dropping Executable

This brief details a detection method for identifying malicious activity where legitimate Windows applications, including Living-Off-The-Land Binaries (LOLBINs) and common productivity software, are abused to drop executable files onto the disk, often indicating malware staging, persistence mechanisms, or process injection attempts.

living-off-the-land LOLBIN persistence malware-staging process-injection windows
1r 3t
high threat

FortiGate VPN SSL Settings Modified

Detection of FortiGate VPN SSL settings modification, such as authentication rules, linked to observed exploitation campaigns (e.g., CVE-2024-535), which threat actors leverage for persistence and unauthorized access after initial compromise.

exploited FortiGate persistence initial-access network-device
1r 2t
medium advisory

FortiGate User Group Modification Detected

An attacker with initial access to a Fortinet FortiGate firewall may modify existing user groups to establish persistence or elevate privileges, potentially granting unauthorized VPN access to internal networks.

FortiGate fortinet firewall persistence privilege-escalation
1r 2t
medium advisory

FortiGate - New VPN SSL Web Portal Added

This brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.

FortiGate Firewall fortigate vpn configuration-change network-device persistence initial-access
1r 2t
medium advisory

FortiGate - New Local User Creation Detection

This brief details the detection of new local user creation on Fortinet FortiGate firewalls, a behavior often leveraged by adversaries for persistence and unauthorized VPN access, underscoring a critical post-exploitation activity for detection engineers.

FortiGate network detection persistence
1r 1t
medium advisory

Windows Autostart Persistence via Startup Folder

Adversaries commonly leverage file creation in the Windows `%startup%` folder (T1547.001) to establish persistence, ensuring malicious code executes automatically upon system boot or user logon, potentially leading to system compromise and unauthorized access.

persistence execution windows malware
1r 2t
high advisory

Executable or Script Creation in Suspicious Windows Paths

This brief details a detection analytic for the creation of executables or scripts, such as .exe, .dll, or .ps1 files, in suspicious Windows file paths like `\windows\fonts\` or `\users\public\`, a technique frequently employed by adversaries for defense evasion and persistence, potentially leading to unauthorized code execution and privilege escalation.

endpoint windows defense-evasion persistence execution detection
1r 2t
high advisory

OpenClaw Control UI Locality Spoofing Vulnerability

An authentication bypass vulnerability (CVE-2026-53817) in OpenClaw's Control UI pairing mechanism allows an attacker with existing network/authentication foothold in LAN/shared-token deployments to spoof locality information, leading to the acquisition of a durable admin-capable device token that grants persistent administrative access, even after shared gateway tokens are rotated.

openclaw authentication vulnerability admin-access persistence network
2t 1c
high advisory

OpenClaw Device Pairing Vulnerability Allows Unauthorized Device Enrollment

A high-severity vulnerability (affecting OpenClaw versions prior to 2026.5.4) in the bundled device-pair plugin allowed authorized non-owner chat senders to issue device-pairing bootstrap codes, enabling them to enroll devices with operator/node capabilities and gain persistent unauthorized access within the OpenClaw environment.

openclaw vulnerability application privilege-escalation persistence npm
2t
high threat

Agentic AI Used to Conduct Ransomware Attack via Langflow

Threat actor JadePuffer exploited CVE-2025-3248 in Langflow instances, leveraging agentic LLM capabilities for advanced reconnaissance, lateral movement, and ultimately encrypting data on production servers with ransomware.

exploited Langflow +1 JadePuffer ransomware ai agentic-ai vulnerability-exploitation data-encryption lateral-movement persistence
2r 10t 2c
medium advisory

Azure VM Managed Run Command Abuse for Execution and Persistence

Adversaries can abuse the Azure VM Managed Run Command feature (MICROSOFT.COMPUTE/VIRTUALMACHINES/RUNCOMMANDS/WRITE) to achieve code execution as System or root and establish persistence on Azure Virtual Machines or Virtual Machine Scale Sets by an unusual identity, potentially evading detections focused solely on action-based Run Commands.

Azure Virtual Machines +2 cloud azure execution persistence defense-evasion vm iac
2r 1t
high advisory

Azure VM Extension CRUD from Unusual Source ASN

Threat actors are performing create, read, update, or delete (CRUD) operations against Azure VM or VM Scale Set extensions (e.g., CustomScript, DSC) from an anomalous source Autonomous System (AS) number, enabling high-privilege code execution and persistence on guest operating systems (SYSTEM on Windows, root on Linux) by abusing compromised Azure identities.

Azure VM +4 cloud endpoint azure azure-activity-logs threat-detection execution persistence
2r 2t
medium advisory

Entra ID OAuth Application Redirect URI Modified

Adversaries are modifying OAuth application redirect URIs (ReplyUrls) in Microsoft Entra ID to intercept OAuth authorization codes and steal tokens, granting unauthorized access without new application registration or user consent.

Entra ID +1 cloud identity azure persistence credential-access token-theft microsoft-entra-id
2r 2t
medium advisory

Microsoft Entra ID Guest Account Promoted to Member

A sophisticated threat actor, having compromised an existing guest account in Microsoft Entra ID, can establish persistent access and elevate privileges by performing a Guest-to-Member account conversion, which grants full directory read access and bypasses Conditional Access restrictions, enabling stealthy long-term access and reconnaissance.

Microsoft Entra ID cloud identity persistence azure microsoft-entra-id
1r 1t
high advisory

Microsoft Entra ID Temporary Access Pass (TAP) Abuse for MFA Bypass and Persistence

An attacker with elevated privileges abuses the Microsoft Entra ID Temporary Access Pass (TAP) feature to bypass multi-factor authentication (MFA), gain unauthorized access to target user accounts, and establish persistence by registering new authentication methods.

Microsoft Entra ID cloud identity azure entra-id mfa-bypass persistence lateral-movement initial-access
3r 2t
high advisory

Microsoft 365 OAuth Device Code Phishing Exploits Non-Compliant Devices

Attackers are actively exploiting the OAuth device code flow in Microsoft 365 to bypass multi-factor authentication (MFA) and gain initial access, leveraging phishing kits like Kali365 and tradecraft similar to Storm-2372 to harvest MFA-satisfied tokens from non-compliant or attacker-controlled devices, and subsequently establishing persistence through device registration.

Microsoft 365 +4 cloud saas identity microsoft-365 initial-access phishing persistence
2r 3t
medium advisory

Google Workspace Custom Admin Role Created for Persistence

Adversaries may create custom administrative roles in Google Workspace to establish persistence with tailored, elevated permissions, which are then assigned to compromised or attacker-controlled accounts to bypass security controls, grant OAuth access, or modify mail routing.

Google Workspace google-workspace cloud-security persistence privilege-escalation iam
1r 2t
high advisory

Google Workspace Admin Role Assigned to a User or Group

Adversaries leverage the assignment of administrative roles within Google Workspace to an existing or new user/group, establishing persistence and escalating privileges to gain broad control over the tenant, including bypassing single sign-on.

Google Workspace cloud-security google-workspace persistence privilege-escalation account-manipulation saas-security
2r 2t
high advisory

Global Stock Exchange Hit by Monthslong Email Campaign

An unknown threat actor gained continuous administrative access to a senior finance executive's Microsoft Outlook mailbox at a global stock exchange for at least five months, deploying custom infostealers via scheduled tasks and exfiltrating sensitive emails through a Dropbox-based command and control channel after an initial lateral movement event.

Microsoft Outlook +2 espionage financial-sector email-exfiltration persistence living-off-the-land windows advanced-persistent-threat
3r 7t
medium threat

Unusual Child Process Execution from Linux Web Servers

This rule detects unusual child process executions originating from web server processes on Linux systems, which attackers may use to maintain persistence on a compromised system by exploiting web server vulnerabilities.

Jira +20 persistence execution command_and_control initial_access linux webserver
2r 4t
medium threat

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.

Elastic Defend +43 persistence initial-access vulnerability linux
2r 3t
medium advisory

Unusual Child Execution via Web Server

This rule detects unusual child process executions originating from web server processes on Linux systems, potentially indicating attackers exploiting web servers for persistence.

Elastic Defend persistence web-shell linux
2r 4t
medium advisory

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.

Elastic Defend endpoint linux persistence initial-access vulnerability
3r 2t
low advisory

Uncommon Destination Port Connection by Linux Web Server

This rule identifies unusual destination port network activity originating from a web server process on Linux systems, indicating potential web shell activity or unauthorized communication from a web server process to external systems by detecting egress connections from web server processes to non-standard ports while excluding common local IP ranges.

Elastic Defend persistence execution command_and_control web_shell linux
2r 4t
low advisory

Unusual Command Execution from Web Server Parent Process on Linux

This rule detects potential command execution from a web server parent process on a Linux host, indicating a possible web shell attack where adversaries exploit web server vulnerabilities to execute arbitrary commands.

Elastic Defend +2 web-shell command-execution persistence linux
2r 3t
low advisory

Unusual Process Spawned from Web Server Parent

This rule detects unusual processes spawned from a web server parent process on Linux systems, potentially indicating an attacker attempting to establish persistence, execute malicious commands, or establish command and control channels.

Elastic Defend persistence execution command and control web server linux
2r 2t
medium advisory

Kubernetes Static Pod Manifest File Access

This rule detects Linux process executions that reference /etc/kubernetes/manifests in process arguments, which may indicate tampering with static pod manifests for persistence or privilege escalation in Kubernetes environments.

Elastic Defend +2 kubernetes container persistence privilege-escalation linux
3r 2t
medium advisory

Kubernetes Admission Webhook Created or Modified by Non-System Identity

The creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities can allow attackers to inject malicious sidecars or block security tooling deployments for persistence and defense evasion.

kubernetes persistence defense_evasion
2r 2t
low advisory

Google Workspace User Organizational Unit Changed

Detects when a Google Workspace user's organizational unit is changed, potentially indicating an adversary attempting to inherit permissions and gain unauthorized access to resources and applications.

Google Workspace cloud google_workspace persistence privilege_escalation
2r 2t
low advisory

Google Workspace Suspended User Account Renewed

Detection of a renewed suspended user account in Google Workspace, potentially indicating an adversary regaining access to the organization.

Google Workspace google_workspace initial_access persistence
2r 2t
medium advisory

External User Added to Google Workspace Group

Detects an external Google Workspace user account being added to an existing group, potentially allowing adversaries to intercept shared files or emails.

Google Workspace google_workspace initial_access persistence cloud
2r 2t
high advisory

Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a suspicious ASN, indicating potential OAuth phishing or adversary-in-the-middle device registration.

Microsoft Entra ID cloud identity azure entra_id sign-in_logs threat_detection initial_access persistence +1
2r 3t
medium advisory

M365 Exchange Inbox Rule with Obfuscated Name

This rule detects when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters, which adversaries may use to evade detection and hide malicious forwarding or deletion rules.

Microsoft 365 +1 cloud saas email exchange defense evasion persistence
2r 2t
medium advisory

Azure VM Extension Deployment by Interactive User

Successful deployment of a high-risk Azure Virtual Machine extension by an interactive user principal can lead to arbitrary code execution, backdoor account creation, credential harvesting, and persistence on Azure-hosted virtual machines.

Azure Virtual Machines +4 azure vm-extension persistence cloud threat-detection
2r 3t
high advisory

Windows AD Domain Root ACL Deletion

The analytic detects ACL deletion on the domain root object in Active Directory by monitoring Windows Event Log Security event ID 5136, identifying significant AD changes with potentially high impact.

Splunk Enterprise +3 active-directory acl privilege-escalation persistence windows
2r 2t
high advisory

Windows AD ServicePrincipalName Added To Domain Account

This Splunk analytic detects the addition of a Service Principal Name (SPN) to a domain account by monitoring Windows Event Code 5136 and changes to the servicePrincipalName attribute, potentially indicating Kerberoasting attempts leading to unauthorized access.

Splunk Enterprise +2 kerberoasting active_directory spn persistence
2r 1t
high advisory

Windows AD sIDHistory Attribute Modification Detection

This analytic detects changes to the sIDHistory attribute of user or computer objects within the same domain using Windows Security Event Codes 4738 and 4742, which can be abused by adversaries to gain unauthorized access, maintain persistence, or escalate privileges by inheriting permissions from another account.

Splunk Enterprise +2 sidhistory active-directory privilege-escalation persistence windows
2r 2t
medium advisory

Windows AD Object Owner Updated

This Splunk search detects when the owner of an Active Directory object is updated, potentially granting full control privileges and enabling object hiding, focusing on Windows Event Log ID 5136, and includes lookups for SID resolution.

Splunk Enterprise +3 active-directory privilege-escalation persistence
2r 2t
high advisory

Windows AD Hidden Organizational Unit Creation

This analytic detects when an ACL is applied to an organizational unit (OU) to deny listing the objects residing in it; this activity, combined with modifying the owner of the OU, can hide Active Directory objects, even from domain administrators.

Splunk Enterprise +2 active-directory persistence privilege-escalation windows t1222.001 t1484
2r 2t
high advisory

Windows AD Domain Root ACL Modification

Modification of Access Control Lists (ACLs) on the Active Directory domain root object can grant attackers persistent and escalated privileges.

Splunk Enterprise +3 active-directory persistence privilege-escalation
2r 2t
high advisory

Windows AD DCShadow Privilege Escalation via ACL Modification

This detection identifies an Active Directory access-control list (ACL) modification event, which applies the minimum required extended rights to perform the DCShadow attack by modifying permissions on the domainDNS object.

Active Directory +3 dcshadow active_directory acl privilege_escalation persistence
2r 3t
high advisory

Azure AD User ImmutableId Attribute Modification for Persistence

The following analytic identifies modifications to the SourceAnchor (ImmutableId) attribute for an Azure Active Directory user, which is a step in setting up an Azure AD identity federation backdoor that allows an attacker to impersonate any user and bypass MFA.

Splunk Enterprise +3 azuread persistence identityfederation backdoor cloud
2r 1t
high advisory

Cisco Privileged Account Creation with Suspicious SSH Activity

This analytic detects a correlation between privileged account creation on Cisco IOS devices and subsequent inbound SSH connections to non-standard ports or sshd_operns, indicating persistence establishment following initial compromise.

IOS +4 network persistence initial-access
3r 2t
medium advisory

Windows Registry Modification Risk Behavior Detection

This analytic identifies instances where three or more distinct registry modification events associated with MITRE ATT&CK Technique T1112 are detected, leveraging Splunk's Risk data model to detect persistence, hiding malicious configurations, or erasing forensic evidence.

Splunk Enterprise +2 registry persistence defense-evasion windows
2r 2t
medium advisory

Living Off The Land Activity Detection

This correlation search identifies multiple risk events associated with 'Living Off The Land' activity, leveraging the Risk data model to aggregate events, focusing on systems with a high count of distinct sources, potentially enabling attackers to execute code, escalate privileges, or persist within the environment using trusted system utilities.

Splunk Enterprise +2 living-off-the-land persistence privilege-escalation execution
2r 5t
high advisory

Linux Persistence and Privilege Escalation Risk Behavior Detected

A Splunk correlation search identifies potential Linux persistence and privilege escalation activities based on risk scores and event counts from various Linux-related data sources, highlighting behaviors that could allow an attacker to maintain access or gain elevated privileges on a Linux system.

Splunk Enterprise +2 persistence privilege-escalation linux
2r 2t
medium advisory

Google Workspace Device Registration Burst for Single User

Detects bursts of Google Workspace device registration events for a single user exceeding three distinct device registrations within one minute, indicative of AiTM phishing or stolen OAuth token replay attacks.

Google Workspace google_workspace device_registration persistence initial_access credential_access
1r 3t
medium advisory

Google Workspace User Sign-in from Atypical Device Type

This rule detects when a Google Workspace user authenticates from a device type that hasn't been observed for that user in the past 14 days, potentially indicating account compromise via AiTM kits or stolen OAuth refresh tokens.

Google Workspace google_workspace persistence account_compromise device_registration
2r 2t
high advisory

GPU Mining Malware Spreads via SEO Poisoning and AI Chatbots

A cryptojacking campaign targets systems with high-performance GPUs using SEO poisoning and manipulated AI chatbot recommendations, distributing malware disguised as legitimate software utilities to establish persistence and evade detection before deploying GPU mining programs.

Microsoft Defender +8 cryptojacking seo-poisoning process-hollowing persistence defense-evasion gpu-mining windows
3r 6t 1i
critical advisory

CVE-2026-6898: Wishlist Member WordPress Plugin Vulnerability Leads to Site Takeover

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check (CVE-2026-6898), allowing authenticated attackers with subscriber-level access or higher to update the REST API Secret Key, create administrator accounts, and achieve complete site takeover.

Wishlist Member plugin wordpress plugin privilege-escalation credential-access persistence initial-access
2r 4t 1c
critical advisory

CVE-2026-6897: Wishlist Member Plugin Vulnerability Leads to WordPress Site Takeover

CVE-2026-6897 is a critical vulnerability in the Wishlist Member plugin for WordPress, allowing authenticated attackers with subscriber-level access to modify plugin settings, including the REST API secret key, ultimately enabling them to create administrator accounts and take over the entire site.

Wishlist Member plugin wordpress plugin privilege-escalation credential-access persistence
2r 3t 1c
high advisory

Boxlite: Permission Bypass Allows Modification of Read-Only Files via virtiofs

Boxlite, a sandbox service, allows malicious code within a container to bypass read-only restrictions on mounted host directories using virtiofs, due to missing hypervisor-level enforcement and unrestricted kernel capabilities, leading to potential code execution on the host and supply chain risks.

Boxlite privilege-escalation persistence sandbox-escape
2r 1t
high threat

Ransomware-as-a-Service (RaaS) Ecosystem: Affiliate Tradecraft and Initial Access Vectors

Ransomware-as-a-service (RaaS) attacks leverage affiliates for initial access, persistence, and exfiltration, using varied techniques like compromised RDP, vulnerable VPNs, and rogue RMM tools, impacting multiple organizations in a single campaign.

Remote Desktop Protocol +7 ransomware raas initial-access persistence
2r 1t
high threat

TeamPCP Multi-Ecosystem Supply Chain Attack

TeamPCP is conducting a multi-ecosystem supply chain attack targeting the open-source ecosystem, specifically NPM packages, GitHub Actions, and VSCode extensions, to harvest credentials, exfiltrate sensitive data, and establish persistent access on infected systems via a Python-based backdoor.

actions-cool/issues-helper +188 TeamPCP supply-chain credential-theft persistence
3r 5t 4i
medium advisory

macOS Finder Sync Plugin Persistence via Pluginkit

This rule detects suspicious Finder Sync plugin registrations on macOS, where adversaries abuse the pluginkit process to establish persistence by repeatedly executing malicious payloads.

OneDrive +5 persistence macos pluginkit finder sync plugin
2r 1t
medium advisory

Kubernetes Static Pod Manifest File Access

This rule detects Linux process executions that access Kubernetes static pod manifest files, potentially indicating malicious tampering for persistence or privilege escalation.

kubernetes persistence privilege_escalation linux
2r 2t
medium advisory

Entra ID Register Device with Unusual User Agent (Azure AD Join)

Detects suspicious Microsoft Entra ID audit events for device registration where details indicate an Azure AD join and the user agent is not a standard registration client, potentially indicating scripted registration, third-party tooling, or malicious device registration for persistence or token abuse.

Entra ID azure entra_id persistence
2r 1t
high advisory

Google Workspace Device Registration After OAuth from Suspicious ASN

Detects a sequence of events in Google Workspace where OAuth authorization from a suspicious ASN is immediately followed by device registration, potentially indicating attacker-controlled device enrollment after user authorization of a sensitive client, possibly related to Tycoon2FA.

Google Workspace cloud google-workspace persistence initial-access tycoon2fa
2r 2t
high advisory

Tiflux RMM Abused in Malspam Campaign

A malspam campaign is leveraging the Tiflux RMM to gain remote access and persistence on victim machines, abusing legitimate remote management software for stealthy access and persistence.

Tiflux +3 remote-access rmm malspam persistence
2r 1t 2i
high advisory

AWS EKS Access Entry Granted Cluster Admin Policy

Detects when the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy is associated with a principal via the EKS Access Entries API, effectively granting full cluster-admin access and enabling potential privilege escalation and persistence.

EKS cloud kubernetes aws privilege-escalation persistence
2r 2t
medium advisory

AWS EKS Access Entry Modification Detected

Successful Amazon EKS Access Entries API operations that create, update, attach, detach, or delete authentication mappings between IAM principals and the cluster, potentially indicating persistence or privilege escalation are detected.

EKS cloud kubernetes aws persistence privilege-escalation
2r 2t
high advisory

EKS Authentication Configuration Modified

This rule detects modifications to the aws-auth ConfigMap in Amazon EKS clusters, enabling attackers to grant cluster-admin access by mapping AWS IAM roles to the system:masters group, achieving persistence and privilege escalation.

EKS kubernetes persistence privilege-escalation
2r 2t
high advisory

Kubernetes Client Certificate Signing Request Created or Approved by Non-System Identity

Detects creation or approval of a Kubernetes CertificateSigningRequest (CSR) by a non-system identity, indicating an attacker attempting to obtain a long-lived client certificate for persistent cluster access with elevated privileges.

kubernetes persistence privilege-escalation
3r 2t
high advisory

CVE-2026-45229: Quark Drive Mass Assignment Vulnerability Allows Credential Overwrite

Quark Drive before version 0.8.5 is vulnerable to a mass assignment vulnerability (CVE-2026-45229) in the POST /update endpoint, where authenticated attackers can overwrite administrator credentials, gaining persistent access to configured tasks, cloud tokens, and notification services.

Quark Drive < 0.8.5 mass-assignment privilege-escalation persistence cve-2026-45229
1r 2t 1c
high threat

Persistence via WMI Standard Registry Provider

The rule identifies the use of Windows Management Instrumentation StdRegProv (registry provider) to modify commonly abused registry locations for persistence by detecting registry changes made by WmiPrvSe.exe in specific registry paths.

Windows Management Instrumentation persistence registry wmi windows
3r 1t
high advisory

TelemetryController Scheduled Task Hijack for Persistence

The rule detects the hijack of the Microsoft Compatibility Appraiser scheduled task to establish persistence with system integrity level, by monitoring CompatTelRunner.exe process execution and detecting unexpected child processes.

Microsoft Compatibility Appraiser +3 persistence scheduled_task telemetry windows
2r 1t
high advisory

Persistence via Hidden Run Key Detected

This rule detects a persistence mechanism that utilizes the NtSetValueKey native API to create a hidden (null terminated) registry key, evading detection from system utilities.

Elastic Defend +4 persistence registry windows
2r 1t
high threat

Suspicious ImagePath Service Creation in Registry

Detection of suspicious ImagePath values written to the registry, indicating potential persistence or privilege escalation via abnormal service creation involving command interpreters or named pipes.

Elastic Endgame +4 persistence registry service_creation
2r 1t
high advisory

AdminSDHolder SDProp Exclusion Added

Modification of the dsHeuristics attribute to exclude groups from SDProp in Active Directory can allow attackers to maintain persistent access to privileged accounts.

Active Directory active-directory persistence adminsdholder sdprop
3r 1t
high advisory

Potential Modification of Accessibility Binaries for Persistence

Adversaries may modify or replace Windows accessibility binaries (e.g., sethc.exe, utilman.exe) to execute malicious commands or establish persistence mechanisms before a user logs in, potentially leading to elevated privileges and unauthorized access.

Windows persistence privilege_escalation accessibility_features
2r 1t
high advisory

KRBTGT Delegation Backdoor via msDS-AllowedToDelegateTo Modification

Attackers can modify the msDS-AllowedToDelegateTo attribute to KRBTGT, enabling persistent domain access by requesting Kerberos tickets for the KRBTGT service.

persistence active-directory windows
2r 1t
high advisory

Persistence via Microsoft Office Add-Ins File Creation

This rule detects attempts to establish persistence on Windows endpoints by abusing Microsoft Office add-ins through the creation of malicious files in Office startup directories.

Microsoft Office AddIns +4 persistence ms-office add-ins windows
2r 1t
high advisory

Suspicious Startup Shell Folder Modification

Detects suspicious modifications to the Windows Startup shell folder, a technique used to bypass detections monitoring file creation in the Windows Startup folder.

Microsoft Defender XDR +4 persistence registry startup
2r 1t
high advisory

Creation of a Hidden Local User Account

Detects the creation of a hidden local user account by appending a dollar sign ($) to the account name, a technique used by attackers to persist on a system and evade standard account listing methods.

Elastic Defend +3 persistence windows local_account hidden_account
2r 1t
high advisory

AdminSDHolder Backdoor via Active Directory Modification

Detects modifications to the AdminSDHolder object in Active Directory, which attackers can abuse via the SDProp process to implement a persistent backdoor by manipulating permissions on protected accounts and groups to regain administrative privileges.

Active Directory persistence adminsdholder
2r 1t
high advisory

Lateral Movement via Remote Startup Folder Modification

Adversaries may achieve lateral movement by creating malicious files in remote Windows startup folders via RDP or SMB, leading to code execution upon system reboot or user logon.

m365_defender +4 lateral-movement persistence windows
2r 3t
high advisory

OpenClaw Improper Access Control Vulnerability (CVE-2026-45006)

OpenClaw before 2026.4.23 contains an improper access control vulnerability (CVE-2026-45006) in the gateway tool's config.apply and config.patch operations, allowing compromised models to write unsafe configuration changes and persist malicious config modifications by bypassing an incomplete denylist.

OpenClaw access-control configuration-management persistence
1r 1t 1c
medium advisory

Service DACL Modification via sc.exe

Detection of service DACL modifications via `sc.exe` using the `sdset` command, potentially leading to defense evasion by denying service access to legitimate users or system accounts.

Microsoft Defender XDR +2 defense-evasion persistence windows
2r 2t
medium advisory

Potential Active Directory Replication Account Backdoor

Attackers can modify Active Directory object security descriptors to grant DCSync rights to unauthorized accounts, creating a backdoor to extract credential data.

Active Directory credential-access persistence active-directory dcsync
2r 2t
medium advisory

Local Account TokenFilter Policy Modification for Defense Evasion and Lateral Movement

Adversaries may modify the LocalAccountTokenFilterPolicy registry key to bypass User Account Control (UAC) and gain elevated privileges remotely by granting high-integrity tokens to remote connections from local administrators, facilitating lateral movement and defense evasion.

Elastic Defend +3 defense-evasion lateral-movement persistence registry-modification
2r 4t
high advisory

GenAI Tools Accessing Sensitive Files for Credential Access and Persistence

This threat brief details the detection of GenAI tools accessing sensitive files containing credentials, SSH keys, browser data, and shell configurations, indicating potential credential harvesting and persistence attempts by attackers leveraging GenAI agents.

Elastic Endpoint Security genai credential-access persistence collection
2r 4t
high advisory

AWS IAM Privilege Operations via Lambda Execution Role

Detection of IAM API calls that create or empower IAM users and roles, attach policies, or configure instance profiles when the caller is an assumed role session associated with AWS Lambda, potentially indicating privilege escalation or persistence.

AWS IAM +1 aws iam lambda privilege-escalation persistence
2r 3t
medium advisory

Google Workspace Login Attempt with Government Attack Warning

A Google Workspace login attempt flagged as a potential attack by a government-backed threat actor, indicating potential privilege escalation, defense evasion, persistence, initial access, or impact.

Google Workspace googleworkspace intrusion initial-access persistence privilege-escalation
2r 1t
medium advisory

Linux Persistence via Sudoers.d File Manipulation

Attackers can achieve persistence and privilege escalation on Linux systems by creating or modifying files in the /etc/sudoers.d/ directory to grant unauthorized users or groups sudo privileges.

persistence privilege-escalation linux sudoers
3r 2t
high advisory

GenAI Tool Access to Sensitive Files for Credential Harvesting and Persistence

This brief outlines the threat of attackers leveraging GenAI tools to access sensitive files containing credentials, SSH keys, browser data, and shell configurations for credential access and persistence.

credential-access genai file-access persistence
2r 4t
high advisory

State-Sponsored Actors Leveraging Vulnerabilities and Identity for Persistent Access (2025)

In 2025, state-sponsored actors from China, Russia, North Korea, and Iran leveraged vulnerabilities and identity compromise for initial access, focusing on persistence for long-term espionage or disruption.

state-sponsored apt persistence vulnerability-exploitation
2r 6t
medium advisory

Suspicious Registry Modifications by Scripting Engines

Scripting engines such as WScript, CScript, and MSHTA are being used to make registry modifications, potentially for persistence or defense evasion.

registry-modification persistence defense-evasion scripting-engine
1r 3t
medium advisory

Entra ID ADRS Token Request by Microsoft Authentication Broker

Detects suspicious OAuth 2.0 token requests where the Microsoft Authentication Broker requests access to the Device Registration Service on behalf of a user principal, potentially indicating an attempt to abuse device registration for unauthorized persistence.

azure entra_id persistence oauth
2r 2t 1i
high advisory

AWS IAM Login Profile Added for Root

An adversary with temporary root access in AWS may create a login profile for the root account to establish persistent console access, even if the original access keys are rotated or disabled.

cloud aws iam persistence
2r 2t
medium advisory

First Time Python Process Creates macOS Launch Agent or Daemon

This rule detects the initial creation or modification of a macOS LaunchAgent or LaunchDaemon plist file by a Python process, a common persistence technique employed by attackers using malicious scripts, compromised dependencies, or model file deserialization.

persistence macos python
2r 2t
high advisory

Coder Code-Marketplace Zip Slip Vulnerability

A Zip Slip vulnerability in coder/code-marketplace allows authenticated users to upload malicious VSIX files containing path traversal entries, leading to arbitrary file writes outside the extension directory and potentially enabling persistence.

zip-slip path-traversal code-marketplace persistence
2r 2t
critical threat

BRICKSTORM Malware Targeting VMware vSphere Environments

The BRICKSTORM malware targets VMware vSphere environments, specifically vCenter Server Appliance (VCSA) and ESXi hypervisors, by exploiting weak security configurations to establish persistence at the virtualization layer, leading to administrative control and potential data exfiltration.

BRICKSTORM vsphere virtualization persistence lateral-movement
2r 2t
medium advisory

SSH Authorized Key File Modification Inside a Container

The rule detects the creation or modification of an authorized_keys file inside a container, a technique used by adversaries to maintain persistence on a victim host by adding their own public key(s) to enable unauthorized SSH access for lateral movement or privilege escalation.

container persistence lateral-movement privilege-escalation ssh
2r 4t
medium advisory

Potential Abuse of msDS-ManagedAccountPrecededByLink for Privilege Escalation

Detection of PowerShell scripts modifying the msDS-ManagedAccountPrecededByLink attribute, potentially indicating exploitation of the BadSuccessor privilege escalation vulnerability in Windows Server 2025.

privilege-escalation defense-evasion persistence initial-access active-directory
2r 4t
high advisory

@mobilenext/mobile-mcp Path Traversal Vulnerability

The @mobilenext/mobile-mcp package before version 0.0.49 is vulnerable to a Path Traversal vulnerability in the mobile_save_screenshot and mobile_start_screen_recording tools where the `saveTo` and `output` parameters are passed directly to filesystem operations without validation, potentially allowing an attacker to write files outside the intended workspace, leading to privilege escalation and persistence by overwriting sensitive host files.

path-traversal file-write privilege-escalation persistence
2r 2t
high advisory

OpenClaw Symlink Traversal via IDENTITY.md appendFile in agents.create/update

OpenClaw is vulnerable to symlink traversal via IDENTITY.md appendFile in agents.create/update. An attacker who can place a symlink in the agent workspace can hijack the IDENTITY.md path to append attacker-controlled content to arbitrary files on the system leading to remote code execution, persistent code execution, unauthorized SSH access, or service disruption.

openclaw symlink-traversal vulnerability npm rce persistence
2r 2t
high advisory

RegPwnBOF Registry Symlink Race Condition Exploit

RegPwnBOF exploits a registry symlink race condition in the Windows Accessibility ATConfig mechanism, enabling a normal user to write arbitrary values to protected HKLM registry keys for persistence and privilege escalation.

registry symlink race-condition accessibility privilege-escalation persistence windows
2r 2t
high advisory

Entra ID Federated Identity Credential Issuer Modified

Modification of the issuer URL of a federated identity credential in Entra ID can allow an attacker to authenticate as the application's service principal, granting persistent access to Azure resources by pointing to an attacker-controlled identity provider and bypassing normal authentication.

azure entra_id federated_identity persistence privilege_escalation
2r 2t
medium advisory

Persistnux - Linux Persistence Detection Tool

Persistnux is a bash-based tool designed to identify known Linux persistence mechanisms used by attackers to maintain access to compromised systems, generating detailed reports for DFIR analysis.

persistence linux dfir
3r 3t
medium advisory

Kubernetes Sensitive Role Creation or Modification

This rule detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs (e.g., bind, escalate, impersonate), potentially leading to privilege escalation or unauthorized access within the cluster.

kubernetes rbac privilege-escalation persistence
2r 2t
medium advisory

Suspicious AWS EC2 Key Pair Import Activity

The import of SSH key pairs into AWS EC2, as detected by CloudTrail logs, may indicate unauthorized access attempts, persistence establishment, or privilege escalation by an attacker.

Elastic Compute Cloud aws cloudtrail ec2 keypair initial-access persistence privilege-escalation
2r 1t
medium threat

Potential Web Shell ASPX File Creation

The creation of ASPX files in web server directories, excluding legitimate processes, indicates potential web shell deployment for persistence on Windows systems.

exploited SharePoint web-shell persistence windows
2r 1t
high advisory

Outlook Home Page Registry Modification for Command and Control or Persistence

Attackers abuse the Outlook Home Page functionality by modifying specific registry keys to point to attacker-controlled URLs or file paths, enabling command and control or persistence on compromised Windows systems.

Outlook registry command-and-control persistence windows
2r 2t
medium advisory

Potential Persistence via Linux File Modification

This rule detects potential persistence attempts on Linux systems by monitoring file modifications of files commonly used for persistence, such as cron jobs, systemd services, message-of-the-day (MOTD), SSH configurations, shell configurations, runtime control, init daemon, passwd/sudoers/shadow files, Systemd udevd, and XDG/KDE autostart entries.

Linux persistence file_integrity_monitoring
3r 6t
medium advisory

Active Directory Group Modification by SYSTEM Account

Detection of a user being added to an Active Directory group by the SYSTEM account (S-1-5-18) can indicate an attacker with SYSTEM privileges attempting to pivot to a domain account.

Active Directory persistence privilege-escalation windows
2r 2t
medium threat

Potential Web Shell ASPX File Creation

This rule identifies the creation of ASPX files in web server directories, commonly targeted by attackers to deploy web shells for persistence, by monitoring file creation events and excluding known legitimate processes.

exploited SharePoint web-shell aspx persistence windows
2r 1t
medium advisory

GitHub SSH Certificate Configuration Changed

Attackers can modify SSH certificate configurations in GitHub organizations to gain unauthorized access, persist in the environment, escalate privileges, and operate stealthily.

Github ssh certificate initial-access persistence privilege-escalation stealth t1078.004
2r 4t
medium advisory

Potential Privilege Escalation via SUID/SGID on Linux

Attackers may leverage misconfigured SUID/SGID permissions on Linux systems to escalate privileges to root or establish persistence by executing processes with root privileges initiated by non-root users.

Elastic Defend privilege-escalation persistence defense-evasion suid sgid
2r 2t
high advisory

O365 Admin Consent Bypassed by Service Principal

A service principal in Office 365 Azure Active Directory assigns app roles without standard admin consent, potentially bypassing critical administrative controls and leading to unauthorized access or privilege escalation.

Office 365 +1 azuread office365 serviceprincipal adminconsent persistence
2r 2t
medium advisory

Kubernetes Admission Controller Modification

An adversary modifies Kubernetes admission controller configurations to achieve persistence, escalate privileges, or gain unauthorized access to credentials within the cluster.

Kubernetes admission-controller privilege-escalation persistence credential-access
2r 2t
medium advisory

AWS STS GetFederationToken Request for Defense Evasion and Persistence

Detection of the first AWS Security Token Service (STS) GetFederationToken request by a user, which adversaries can abuse to obtain temporary credentials for persistence and to bypass IAM API call limitations by gaining console access.

AWS Security Token Service aws cloud defense-evasion persistence
2r 2t
low threat

AWS STS AssumeRole with New MFA Device

This rule identifies when a user has assumed a role using a new MFA device in AWS, which can be indicative of persistence and privilege escalation attempts by threat actors.

exploited AWS Security Token Service +1 aws cloudtrail sts assume_role mfa persistence privilege_escalation lateral_movement
2r 4t
medium advisory

AWS STS Role Chaining for Privilege Escalation and Persistence

AWS STS role chaining, where one assumed role is used to assume another, can lead to privilege escalation or persistence by refreshing session tokens, triggering alerts on the first observed role assumption based on CloudTrail logs.

AWS Security Token Service +1 aws sts role-chaining privilege-escalation persistence
2r 3t
medium advisory

Persistence via Windows Installer (Msiexec)

Adversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.

Windows +21 persistence defense-evasion
3r 3t
medium advisory

Service DACL Modification via sc.exe

Adversaries modify a service's DACL (Discretionary Access Control List) via `sc.exe` to deny access to key user groups, potentially making the service unstoppable or hiding it from users and the system, in order to evade defenses and persist.

Windows defense-evasion persistence
2r 2t
medium advisory

First Time Python Created a LaunchAgent or LaunchDaemon

Detection of the first-time a Python process creates or modifies a LaunchAgent or LaunchDaemon plist file on a given macOS host, which is indicative of persistence attempts via malicious scripts, compromised dependencies, or model file deserialization.

macOS +2 persistence python launchagent launchdaemon
2r 1t
medium advisory

Unsigned DLL Loaded by DNS Service

The rule identifies the loading of unusual or unsigned DLLs by the DNS Server process, which can indicate exploitation of the ServerLevelPluginDll functionality, potentially leading to privilege escalation and remote code execution with SYSTEM privileges.

Elastic Defend privilege-escalation execution persistence windows
2r 3t
medium advisory

Python .pth File Creation for Persistence

Attackers can establish persistence on Linux systems by creating malicious .pth files in Python package directories, causing arbitrary code execution on interpreter startup.

Copilot Studio +5 persistence python linux pth file_creation
2r 3t 2i updated
medium advisory

AWS RDS DB Instance Made Public

An attacker with compromised AWS credentials may modify an Amazon RDS DB instance or cluster to be publicly accessible for persistence, data exfiltration, or to bypass network restrictions.

AWS RDS cloud aws rds persistence defense_evasion
2r 3t
medium advisory

AWS RDS DB Instance or Cluster Password Modification

The modification of the master password for an AWS RDS DB instance or cluster can indicate malicious activity used for persistence, privilege escalation, or defense evasion.

RDS cloud aws persistence
2r 3t
medium advisory

AWS IAM AdministratorAccess Policy Attached to Role

An adversary with compromised AWS credentials may escalate privileges or persist in the environment by attaching the AdministratorAccess AWS managed policy to an existing IAM role.

AWS IAM cloud aws iam privilege-escalation persistence
2r 2t
medium advisory

Suspicious ScreenConnect Client Child Process Activity

This rule identifies suspicious child processes spawned by ScreenConnect client processes, potentially indicating unauthorized access and command execution abusing ScreenConnect remote access software to perform malicious activities such as data exfiltration or establishing persistence.

Elastic Defend +3 command-and-control defense-evasion execution persistence screenconnect
2r 11t 2c
medium advisory

Google Workspace Object Copied from External Drive Followed by OAuth Consent

Detects a sequence of events where a user copies a Google Workspace object (spreadsheet, form, document, or script) from an external drive and subsequently grants OAuth permissions to a custom application, potentially indicating a phishing attack leveraging container-bound scripts.

Google Workspace +5 google-workspace oauth phishing initial-access persistence
1r 3t
low advisory

AWS IAM Roles Anywhere Profile Creation

Detection of AWS IAM Roles Anywhere profile creation, potentially indicating an adversary establishing persistence or escalating privileges through rogue trust anchors to gain long-term external access.

IAM Roles Anywhere aws iam rolesanywhere persistence privilege-escalation
2r 2t
medium advisory

AWS EC2 Instance Connect SSH Public Key Upload

This rule detects the uploading of new SSH public keys to AWS EC2 instances using the EC2 Instance Connect service, which could indicate an adversary attempting to maintain access, escalate privileges, or move laterally within the cloud environment.

EC2 +1 cloud aws ssh lateral-movement privilege-escalation persistence
2r 3t
medium advisory

AWS IAM Roles Anywhere Trust Anchor Created with External CA

The creation of an AWS IAM Roles Anywhere Trust Anchor using an external Certificate Authority (CA) instead of an AWS-managed CA allows adversaries to establish persistent access by using their own CA to sign certificates for authentication.

IAM Roles Anywhere aws iam rolesanywhere persistence
2r 2t
high advisory

Okta Admin Console Unusual Behavior Detection

This brief details detection of anomalous activity within the Okta Admin Console, potentially indicating privilege escalation, persistence, defense evasion, or initial access attempts by malicious actors.

Okta Identity Engine okta identity privilege-escalation persistence defense-evasion initial-access
2r 4t
medium advisory

Azure AD Certificate-Based Authentication Enabled

Enabling certificate-based authentication (CBA) in Azure Active Directory can be abused by attackers to establish persistence, escalate privileges, and impair defenses.

Azure Active Directory azure certificate-based-authentication persistence privilege-escalation
2r 1t
high advisory

Detection of System Control Panel Item Load from Uncommon Locations

This brief focuses on detecting the loading of system control panel items (.cpl) from unusual locations, potentially indicating DLL sideloading or other exploitation techniques by threat actors to achieve defense evasion, persistence, and privilege escalation on Windows systems.

Windows defense-evasion persistence privilege-escalation dll-sideloading
2r 3t
medium advisory

Suspicious Child Processes from Communication Applications

The detection rule identifies suspicious child processes spawned from communication applications on Windows systems, potentially indicating masquerading or exploitation of vulnerabilities within these applications.

Elastic Defend +12 defense-evasion persistence windows
3r 3t
high advisory

Persistence via Malicious Microsoft Office Add-ins

Attackers can establish persistence by placing malicious add-ins (e.g., .xll, .xlam) in Microsoft Office startup directories, ensuring execution each time the application launches.

Microsoft Office +2 persistence office-addins windows
2r 1t
low advisory

Netsh Helper DLL Persistence

Attackers may abuse the Netsh Helper DLL functionality by adding malicious DLLs to execute payloads every time the netsh utility is executed via administrators or scheduled tasks, achieving persistence.

Microsoft Defender XDR +3 persistence windows netsh registry
2r 2t
low advisory

Entra ID Service Principal Creation for Persistence

An adversary may create a new service principal in Microsoft Entra ID to establish persistence and potentially impersonate legitimate services or applications, blending in with normal activity.

Microsoft Entra ID +1 azure entra_id service_principal persistence
2r 1t
low advisory

Detection of New GitHub Actions Secrets Creation

This analytic detects the creation of new GitHub Actions secrets at the organization, environment, codespaces, or repository level, potentially indicating malicious persistence or privilege escalation.

GitHub Actions github persistence privilege-escalation initial-access
3r 3t
medium advisory

AWS CreateLoginProfile Activity Detection

Detects the creation of AWS IAM login profiles, which can be indicative of new user creation or modifications by potentially malicious actors for privilege escalation or persistence.

AWS Identity and Access Management aws cloud iam privilege_escalation persistence
2r 2t
medium advisory

Office Test Registry Persistence for Malicious DLL Execution

Attackers can modify the Microsoft Office 'Office Test' Registry key to establish persistence by loading a malicious DLL that executes every time an MS Office application starts.

Microsoft Office persistence registry modification office test
2r 2t
medium advisory

Suspicious Registry Modifications by Scripting Engines

The use of scripting engines like WScript and CScript to modify the Windows registry can indicate an attempt to bypass standard tools and evade defenses, potentially for persistence or other malicious activities.

Windows defense-evasion persistence execution registry-modification
2r 3t
medium advisory

Scheduled Task Created or Deleted via Command Line

Detection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.

Windows persistence privilege_escalation scheduled_task
2r 2t
low advisory

Entra ID External Guest User Invitation

Detection of external guest user invitations in Entra ID, which can be abused for unauthorized access and persistence by creating overlooked accounts.

Entra ID +1 cloud azure initial-access persistence
2r 2t
critical threat

Azure AD Privileged Graph API Permission Assignment

Detection of high-risk Graph API permission assignments (Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All, and RoleManagement.ReadWrite.Directory) in Azure AD, potentially leading to unauthorized modifications and security breaches.

Azure Active Directory NOBELIUM Group azuread cloud graphapi privilegeescalation persistence
2r 1t
high threat

Azure AD FullAccessAsApp Permission Assignment

Detection of 'full_access_as_app' permission assignment to an application in Office 365 Exchange Online, potentially leading to unauthorized access and data exfiltration.

Office 365 Exchange Online +1 NOBELIUM Group azure azuread office365 persistence nobelium
2r 2t
low advisory

Netsh Helper DLL Persistence via Registry Modification

Attackers may establish persistence by adding a malicious DLL as a Netsh Helper, which executes whenever the Netsh utility is run, often abusing this mechanism to execute malicious payloads.

Windows persistence registry netsh
2r 3t
medium advisory

AWS IAM AdministratorAccess Policy Attached to User

An adversary with compromised AWS credentials may attempt to escalate privileges or persist access by attaching the AdministratorAccess AWS managed policy to an existing IAM user via the AttachUserPolicy API, granting full access to all AWS services and resources.

AWS IAM aws iam privilege-escalation persistence
2r 2t
high advisory

Suspicious Startup Shell Folder Modification

This rule detects suspicious modifications to the startup shell folder registry keys, potentially indicating an attempt to establish persistence by pointing to malicious executables and bypassing traditional defenses.

Windows persistence defense-evasion registry-modification
2r 2t
medium advisory

Application Compatibility Shim Database Installation for Persistence

Attackers abuse Application Compatibility Shims to establish persistence by installing custom shim databases, allowing for stealthy code execution within legitimate Windows processes.

Windows persistence app-compat
2r 1t
low advisory

Detection of Malicious Browser Extension Installation

This rule detects the installation of browser extensions, a persistence mechanism where attackers install malicious extensions via app store downloads, social engineering, or compromised systems, focusing on file creation events in extension directories on Windows.

Firefox +1 persistence browser-extension windows
2r
high advisory

Windows EFI Bootloader File Modification Detection

A process writing to critical EFI bootloader files (bootmgfw.efi or bootx64.efi) within the \EFI\Boot\ directory may indicate a bootkit installation, malicious code persistence at the firmware level, or tampering with the system boot process.

Splunk Enterprise +2 bootkit persistence efi bootloader windows
2r 1t 1c
low advisory

Detection of Malicious Browser Extension Installation

This rule identifies the installation of potentially malicious browser extensions, which adversaries can leverage for persistence and unauthorized activity by monitoring file creation events in common browser extension directories on Windows systems.

Elastic Defend +2 persistence browser-extension windows
2r
medium advisory

Persistence via BITS Job Notify Cmdline

Adversaries can achieve persistence by abusing the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute a program after a job finishes, leading to arbitrary code execution and system compromise.

Defender XDR +2 persistence bits windows
2r 1t
medium advisory

Google Workspace Suspicious Login Activity

Detect Google Workspace login activity that Google has classified as suspicious, potentially indicating initial access, privilege escalation, defense evasion, or persistence attempts.

Google Workspace initial-access privilege-escalation defense-evasion persistence gworkspace
3r 1t
medium advisory

Okta Identity Provider Creation Detected

An adversary may create a rogue identity provider within Okta to establish persistence and potentially escalate privileges by impersonating legitimate users or bypassing multi-factor authentication.

Okta identityprovider persistence
3r 2t
low advisory

Azure Automation Runbook Created or Modified

An adversary may create or modify an Azure Automation runbook to execute malicious code and maintain persistence in their target's environment, detected through Azure activity logs.

Azure Automation azure automation runbook execution persistence
2r 2t
medium advisory

Potential Privilege Escalation via SUID/SGID Abuse on Linux

This rule detects potential privilege escalation attempts on Linux systems by identifying processes running with root privileges but initiated by non-root users, indicative of SUID/SGID abuse.

Elastic Defend privilege-escalation persistence suid sgid
2r 3t
medium advisory

First Time Seen Remote Monitoring and Management Tool Execution

Detects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.

Elastic Defend +101 remote-access rmm command-and-control persistence
3r
medium advisory

Okta Admin Role Assignment Creation

Detection of new admin role assignments in Okta, potentially indicating privilege escalation or persistence attempts by malicious actors.

Okta identity privilege-escalation persistence
2r 1t
high advisory

Entra ID Protection Alert Followed by Device Registration

Detection of a Microsoft Entra ID protection alert followed by a new device registration attempt by the same user, potentially indicating account compromise and unauthorized device registration for persistence.

Microsoft Entra ID +1 azure entra_id persistence device_registration
2r 2t
medium advisory

Detection of Persistent Scripts in the Startup Directory

This rule identifies script engines creating files in the Startup folder, or the creation of script files in the Startup folder, enabling adversaries to maintain persistence by placing malicious scripts or shortcuts in the Windows Startup folder, which are then executed during account logon.

Windows persistence startup-folder malware
2r 2t
medium advisory

Azure Authentication Method Change Detection

An attacker may add an authentication method to a compromised Azure account for persistent access, which can be detected by monitoring changes to authentication methods in Azure audit logs.

Azure persistence privilege-escalation
2r 3t
medium advisory

AWS IAM User Creates Access Keys For Another User

An adversary with access to compromised AWS credentials may attempt to persist or escalate privileges by creating a new set of access keys for an existing IAM user, potentially leading to unauthorized access to resources and data.

AWS Identity and Access Management cloud aws iam persistence privilege-escalation
2r 2t
high advisory

Entra ID Service Principal Federated Issuer Modification

Entra ID (Azure AD) service principal federated issuers can be modified by an attacker to establish persistence within a target environment.

Entra ID azuread persistence federated_identity
2r 1t
medium advisory

Detect Suspicious Windows Service Installation

This detection identifies the creation of new Windows services with suspicious command values, often used for privilege escalation and persistence by malicious actors.

Windows persistence privilege_escalation service_creation
2r 1t
medium advisory

Unsigned DLL Loaded by Svchost for Persistence and Privilege Escalation

Adversaries may load unsigned DLLs into svchost.exe to establish persistence or escalate privileges, leveraging a shared Windows service to execute malicious code with elevated permissions.

Elastic Defend persistence defense-evasion execution windows dll-injection
2r 4t 5i
low advisory

Uncommon Destination Port Connection by Web Server on Linux

The rule identifies unusual outbound network connections on non-standard ports originating from web server processes on Linux systems, indicative of potential web shell activity or unauthorized communication.

Elastic Defend persistence execution command-and-control web shell linux
2r 4t
high advisory

Web Shell Activity Detection via Process Monitoring

This brief focuses on detecting malicious activity related to web shells on Windows systems by identifying the execution of command interpreters and scripting engines as child processes of common web server processes, potentially indicating unauthorized command execution and persistent access.

Windows +3 webshell persistence initial-access execution
2r 4t
low advisory

AWS EC2 Route Table Created for Persistence or Defense Evasion

An EC2 Route Table creation event in AWS can indicate an attacker attempting to disrupt network traffic, reroute communications, or maintain persistence by creating unauthorized routes.

EC2 cloud aws persistence network-security
2r 2t
medium advisory

Entra ID OAuth PRT Issuance to Non-Managed Device Detected

Detection of Entra ID OAuth Primary Refresh Token (PRT) issuance to a non-managed device following a refresh token sign-in via Microsoft Authentication Broker (MAB), potentially indicating device registration abuse (ROADtx) for persistent access.

Entra ID +1 cloud entra_id persistence initial_access credential_access defense_evasion
2r 4t
low advisory

Windows User Account Creation via net.exe

Attackers may create new accounts on Windows systems using `net.exe` to maintain access and establish persistence, which this detection identifies.

Windows persistence account-creation
3r 2t
medium advisory

Windows Persistence via Scheduled Job Creation

Adversaries can abuse the Windows Task Scheduler to establish persistence by creating malicious scheduled jobs, which are detected by monitoring for the creation of '.job' files in the 'Windows\Tasks' directory while excluding known legitimate software.

Windows persistence scheduled-task
2r 1t
medium advisory

Unauthorized Removal of Azure Conditional Access Policy

An unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.

Azure Active Directory azure conditional-access privilege-escalation credential-access persistence defense-impairment
2r 3t
high advisory

Linux Dynamic Linker Copy and Shared Object Creation

This brief outlines detection strategies for Linux systems where the dynamic linker binary is copied and a shared object file is created, a technique used by malware to inject malicious shared objects by patching the dynamic linker.

Linux operating system persistence linux dynamic-linker shared-object
2r 1t
medium advisory

Werfault ReflectDebugger Persistence Abuse

Attackers can achieve persistence by modifying the ReflectDebugger registry key associated with Windows Error Reporting (Werfault) to execute arbitrary code when Werfault is invoked with the `-pr` parameter.

Windows persistence registry
2r 2t
high advisory

WMI Permanent Event Subscription Abuse for Persistence

Attackers use WMI permanent event subscriptions to execute malicious scripts or binaries for persistence by creating event consumers other than the default NTEventLogEventConsumer.

Windows persistence wmi
2r 1t
high advisory

Windows Suspicious Process Execution from Unusual File Paths

Adversaries may execute malicious processes from unusual file paths (e.g., within Windows, Users, or Recycle Bin directories) to evade defenses and potentially compromise systems.

Windows suspicious-process defense-evasion persistence
3r 2t
medium advisory

Unusual Persistence via Services Registry Modification

Adversaries may modify the Windows services registry keys directly to stealthily persist through abnormal service creation or modification of an existing service, bypassing standard APIs, detected by monitoring registry changes related to service DLLs and image paths.

Windows persistence registry services
2r 3t
high advisory

Suspicious Kernel Module Load from Unusual Location (Linux)

This alert detects the loading of Linux kernel modules from non-standard directories, potentially indicating malicious persistence or rootkit activity.

Kernel kernel-module persistence rootkit linux
2r
medium advisory

Potential Application Shimming via Sdbinst

This brief covers the abuse of application shimming in Windows via `sdbinst.exe` to achieve persistence and privilege escalation by executing arbitrary code within legitimate processes.

Windows persistence privilege-escalation application-shimming
3r 2t
medium advisory

Persistence via Scheduled Job Creation

This detection rule identifies attempts to establish persistence on Windows systems by creating scheduled jobs in the Windows Tasks directory, excluding known legitimate jobs.

Microsoft Defender XDR +5 persistence windows
2r 1t
high advisory

Azure AD Service Principal Created

The creation of a Service Principal in an Azure AD environment is detected, which can be used by adversaries to establish persistence and bypass multi-factor authentication.

Azure Active Directory azure cloud persistence service-principal
2r 1t
high advisory

AWS Virtual MFA Device Registration Attempt

An adversary attempts to register a virtual MFA device to an AWS account, potentially leading to account takeover and unauthorized access to resources.

AWS Identity and Access Management aws persistence mfa account_takeover
2r 1t
high advisory

AWS IAM Persistence via User Session Token

This brief covers detection of potential persistence techniques in AWS environments through the use of compromised user session tokens to make IAM API calls, potentially leading to unauthorized privilege escalation or resource access.

IAM aws persistence cloud
2r 1t
medium advisory

AWS EC2 Security Group Configuration Change Detection

Detection of unauthorized changes to AWS EC2 Security Group configurations, potentially leading to persistence, data exfiltration, or lateral movement within the AWS environment.

Elastic Compute Cloud cloud aws security-group persistence
3r 4t
low advisory

AWS EC2 Route Table Modification or Deletion

An attacker modifies or deletes AWS EC2 route tables to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment.

EC2 aws cloudtrail route-table persistence defense-evasion
2r 2t
medium advisory

Suspicious WerFault Child Process Abuse

This rule detects suspicious child processes of WerFault.exe, a Windows error reporting tool, indicating potential abuse of the SilentProcessExit registry key to execute malicious processes stealthily for defense evasion, persistence, and privilege escalation.

Microsoft Defender XDR +2 defense-evasion persistence privilege-escalation masquerading
2r 3t
high advisory

Okta MFA Disabled by User

Detection of Okta multi-factor authentication (MFA) being disabled by a user account, potentially indicating malicious activity or account compromise and leading to unauthorized access.

Okta Identity Cloud okta mfa account-takeover persistence
2r 1t
medium advisory

Entra ID MFA Disabled for User

Detection of multi-factor authentication (MFA) being disabled for an Entra ID user account, potentially weakening account security and leading to compromise.

Entra ID azure entra_id mfa persistence credential_access defense_evasion
2r 3t
medium advisory

Detection of Custom Shim Database Installation for Persistence

Attackers abuse the Application Compatibility Shim functionality in Windows to establish persistence and achieve arbitrary code execution by installing malicious shim databases, which this detection identifies through monitoring registry changes.

Windows +7 persistence app-compat shim
2r 1t
high advisory

Apache Struts CVE-2023-50164 Exploitation Leading to Web Shell Deployment

Exploitation of CVE-2023-50164, a critical path traversal vulnerability in Apache Struts 2, is detected by identifying malicious multipart/form-data POST requests with WebKitFormBoundary targeting Struts .action upload endpoints, followed by JSP web shell creation in Tomcat's webapps directories, indicating remote code execution.

Struts 2 apache-struts webshell cve-2023-50164 initial-access persistence command-and-control
2r 3t 1c
medium advisory

Suspicious Azure Automation Account Creation

An adversary may create an Azure Automation account to maintain persistence in the target environment by automating malicious tasks.

Azure Automation azure persistence cloud
2r 2t
low advisory

GitHub Repository Archive Status Changed

Detection of GitHub repository archiving or unarchiving events, which could indicate malicious activity such as persistence, impact, or defense impairment.

GitHub repository archive unarchive persistence impact defense-impairment
2r 3t
medium advisory

Persistence via Malicious Microsoft Outlook VBA Template

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file, detected by monitoring for unauthorized file modifications.

Outlook persistence vba windows
2r 1t
medium advisory

Kubernetes Sensitive Role Creation or Modification

Detects the creation or modification of Kubernetes Roles or ClusterRoles that grant high-risk permissions, such as wildcard access or RBAC escalation verbs, potentially leading to privilege escalation or unauthorized access within the cluster.

Kubernetes rbac privilege-escalation persistence
2r 2t
high advisory

Entra ID: Global Administrator Role Assigned to PIM User

An adversary may add an account to the Global Administrator role within Azure AD Privileged Identity Management (PIM) to establish persistence and gain privileged access.

Azure Active Directory +1 azure entra_id persistence privilege_escalation
2r 2t
medium advisory

Cisco ASA - New Local User Account Creation

Detection of new user account creations on Cisco ASA devices, potentially indicating unauthorized access or persistence attempts by adversaries.

Cisco ASA cisco-asa account-creation persistence
2r 2t
medium advisory

Azure AD Bitlocker Key Retrieval

An adversary with sufficient privileges in Azure Active Directory may attempt to retrieve BitLocker keys to decrypt drives for lateral movement or data exfiltration.

Azure Active Directory azure bitlocker key-retrieval persistence privilege-escalation
2r 3t
high advisory

Azure PIM Elevation Approved or Denied

Detection of Azure Privileged Identity Management (PIM) elevation approvals or denials, which, if unexpected, may indicate unauthorized privilege escalation or malicious activity within an Azure environment.

Azure pim privilege-escalation persistence
2r 3t
high advisory

Azure AD User Added to Global or Device Admin Role

An attacker may attempt to add a user to a high-privilege Azure AD role, such as Global Administrator or Device Administrator, to establish persistence, gain initial access, escalate privileges, or operate stealthily within the compromised environment.

Azure Active Directory azuread role-assignment privilege-escalation persistence
2r 3t
low advisory

Web Server Potential Command Injection Request

The rule detects potential command injection attempts via web server requests by identifying URLs that contain suspicious patterns commonly associated with command execution payloads.

Nginx +4 web-server command-injection persistence
2r 5t
medium advisory

Potential Port Monitor or Print Processor Registration Abuse

This rule detects potential abuse of port monitors and print processors for privilege escalation and persistence on Windows systems by identifying registry modifications to load malicious DLLs that execute with SYSTEM privileges during system boot, focusing on modifications made by non-SYSTEM users.

Windows privilege-escalation persistence
2r 4t
medium advisory

Kubernetes Admission Webhook Manipulation for Persistence and Defense Evasion

The rule detects creation, modification, or deletion of Kubernetes MutatingWebhookConfigurations or ValidatingWebhookConfigurations by non-system identities, allowing attackers to inject malicious sidecars, block security tooling, or exfiltrate pod specifications.

kubernetes persistence defense-evasion
2r 2t
high advisory

Detection of Windows Defender Service Disabling via Registry Modification

This brief covers the detection of adversaries disabling Windows Defender services by modifying specific registry keys to set the 'Start' value to '0x00000004', indicating an attempt to evade detection and maintain persistence.

Windows Defender +3 defense-evasion persistence windows registry-abuse
2r
medium advisory

Suspicious AWS SAML Activity Detection

This rule identifies suspicious SAML activity in AWS, such as AssumeRoleWithSAML and UpdateSAMLProvider events, which could indicate an attacker gaining backdoor access, escalating privileges, or establishing persistence.

AWS IAM +1 aws saml cloudtrail initial-access lateral-movement persistence privilege-escalation stealth
2r 3t
high advisory

Windows Registry Modification to Disable Registry Tools

This analytic detects modifications to the Windows registry, specifically targeting the 'DisableRegistryTools' key, which is a common tactic used by malware for persistence and defense evasion by preventing the removal of malicious entries.

Windows +3 defense-evasion registry-modification persistence
2r 2t
medium advisory

Outlook Security Settings Registry Modification

Attackers modify Outlook security settings via registry changes to enable malicious mail rules and bypass security controls, potentially leading to persistence and data compromise.

Microsoft Outlook persistence registry_modification outlook email
2r 1t
high advisory

O365 Advanced Audit Disabled

Detection of O365 advanced audit being disabled for a specific user, potentially allowing attackers to operate with reduced risk of detection, leading to unauthorized data access, data exfiltration, or account compromise.

Office 365 +3 cloud o365 audit defense-evasion persistence
2r 1t
high advisory

Coldroot RAT Targeting macOS

The Coldroot RAT is a cross-platform backdoor targeting macOS systems, providing remote attackers persistent access through a launch daemon, masquerading as an Apple audio driver, and beaconing to a command and control server.

macOS rat persistence coldroot
2r 2t 2i
medium advisory

Suspicious Execution via Scheduled Task

This rule identifies execution of suspicious programs via scheduled tasks by looking at process lineage and command line usage, detecting processes such as cscript.exe, powershell.exe, and cmd.exe when executed from suspicious paths like C:\Users\ and C:\ProgramData\.

Windows persistence execution
2r 2t
high advisory

Comprehensive Analysis of Mac Malware in 2017

A comprehensive analysis of Mac malware discovered in 2017, detailing infection vectors, persistence mechanisms, features, and goals, including FruitFly, MacDownloader (iKitten), and others.

Flash Player +2 macos malware backdoor exfiltration persistence
3r 6t
high advisory

CrossRAT Multi-Platform Surveillanceware Analysis

CrossRAT is a Java-based, multi-platform surveillance tool targeting Windows, macOS, and Linux systems, capable of file system manipulation, screenshot capture, and persistence.

Mac OS X crossrat rat persistence surveillanceware
2r 1t
high advisory

SeEnableDelegationPrivilege Assignment Detection

Detection of the assignment of the SeEnableDelegationPrivilege user right to a principal can indicate potential Active Directory compromise and privilege elevation by attackers.

Active Directory credential-access persistence windows active-directory
3r 2t
high advisory

Linux Kernel Module Load from Unusual Location

This rule detects the loading of a kernel module from an unusual location, which could indicate a rootkit attempting to maintain persistence on the system by hiding processes, files, or network activity.

Linux Kernel persistence defense-evasion rootkit linux
3r 2t
medium advisory

AWS IAM OIDC Provider Created by Rare User

An uncommon user or role creating an OpenID Connect (OIDC) Identity Provider in AWS IAM can indicate an attacker establishing persistent, federated access by creating rogue OIDC providers to assume roles using attacker-controlled IdP tokens.

IAM aws oidc persistence cloud
2r 3t
medium advisory

Malicious Azure Kubernetes Admission Controller Configuration

An adversary can exploit Kubernetes Admission Controllers in Azure to achieve persistence, privilege escalation, or credential access by manipulating webhook configurations.

Azure Kubernetes Service +1 azure kubernetes admission-controller persistence privilege-escalation credential-access
2r 4t
high advisory

Azure AD Temporary Access Pass Added to Account

Detection of a temporary access pass (TAP) being added to an Azure AD account, which could indicate potential privilege escalation, initial access, persistence, or stealth activity.

Azure Active Directory azuread temporary-access-pass privilege-escalation initial-access persistence
2r 4t
medium advisory

Windows Time-Based Evasion via Choice Exec

Detection of choice.exe used in batch files for time-based evasion, a technique observed in SnakeKeylogger malware, indicating potential stealthy code execution and persistence.

Windows +3 time-based-evasion malware persistence defense-evasion
2r 1t
high advisory

Windows EFI Volume Mount Attempt via Mountvol

Detection of attempts to mount the EFI volume on Windows systems using mountvol.exe, potentially leading to system compromise.

Splunk Enterprise +2 efi mountvol windows persistence defense-evasion
2r 3t
high advisory

Windows Computer Account Changed to Domain Controller

Detects modifications to a Windows computer account's User Account Control flags, specifically the `SERVER_TRUST_ACCOUNT` flag, potentially indicating unauthorized domain controller promotion or privilege escalation within Active Directory.

Splunk Enterprise +3 active-directory privilege-escalation persistence windows
2r 2t
medium advisory

System Shells Launched via Windows Services

Attackers may configure existing Windows services or create new ones to execute system shells (cmd.exe, powershell.exe) to elevate privileges from administrator to SYSTEM for persistence and further malicious activity.

Windows persistence execution privilege-escalation
2r 4t
medium advisory

Suspicious Modification of Sensitive Linux Files

This threat brief covers the detection of suspicious processes modifying sensitive files on Linux systems, potentially indicating malicious attempts to persist, escalate privileges, or disrupt system operations.

file-integrity privilege-escalation persistence linux
3r 1t
high advisory

Microsoft Office for Mac Sandbox Escape via Faulty Regex

A vulnerability in Microsoft Office for Mac allows malicious code to escape the application's sandbox and achieve persistence by abusing a faulty regex for temporary files.

Microsoft Word sandbox-escape persistence office-macro macos
2r 3t
high advisory

Linux SSH Persistence via Backdoored System User

Attackers can maintain unauthorized access to Linux systems by backdooring system user accounts with SSH keys, allowing persistent access even after password changes.

Linux +1 persistence ssh
3r 2t
medium advisory

Execution of Persistent Suspicious Programs via Run Keys

This analytic identifies suspicious programs such as script interpreters, rundll32, or MSBuild being executed shortly after user logon, indicating potential persistence mechanisms abusing the registry run keys.

Elastic Defend persistence windows threat-detection
2r 8t
critical advisory

Detection of ConvertTo-AADIntBackdoor Execution via PowerShell

This brief outlines the detection of the ConvertTo-AADIntBackdoor command execution via PowerShell Script Block Logging, a technique used to create a backdoor in federated Azure AD domains by modifying federation settings and allowing attackers to control the authentication process.

Azure Active Directory azure-ad backdoor powershell persistence privilege-escalation
2r 4t
medium advisory

Detect Windows Entra User Management Via Azure CLI

This analytic detects the usage of the Azure CLI to interact with user accounts, such as creating or deleting a user, potentially indicating malicious activity aimed at maintaining persistence and evading detection within an Entra ID environment.

Azure CLI +3 azure entra-id user-management persistence windows
2r 3t
medium advisory

Azure AD User Password Reset Detection

Detects when a user successfully resets their own password in Azure Active Directory, which may indicate malicious activity or account compromise.

Azure Active Directory azure password-reset privilege-escalation initial-access persistence credential-access stealth
2r 1t
medium advisory

Attrib.exe Used to Hide Files and Directories

Detection of attrib.exe being used with the +h flag to hide files and directories on Windows systems, a technique used by attackers for defense evasion and persistence.

Splunk Enterprise +2 defense-evasion persistence windows
2r 1t
high advisory

TelemetryController Scheduled Task Hijack for Persistence and Privilege Escalation

Adversaries can hijack the Microsoft Compatibility Appraiser scheduled task (TelemetryController) to establish persistence and escalate privileges by executing arbitrary code with system-level permissions.

Windows persistence privilege-escalation scheduled-task
2r 2t
medium advisory

Python Site or User Customize File Creation for Persistence

Attackers can exploit Python's sitecustomize.py and usercustomize.py files for persistence by injecting malicious code, allowing them to execute arbitrary commands upon Python startup.

Python persistence startup-hook linux
2r 2t
medium advisory

MSSQL xp_cmdshell Stored Procedure Abuse for Persistence and Execution

Attackers leverage the MSSQL xp_cmdshell stored procedure to execute arbitrary commands, escalating privileges and establishing persistence on Windows systems.

SQL Server mssql xp_cmdshell persistence execution
2r 2t
medium advisory

Linux Cron File Creation for Persistence

An attacker may create new cron files in cron directories to establish persistence on a Linux system, potentially leading to privilege escalation and arbitrary code execution.

cron persistence privilege-escalation linux
2r 1t
high advisory

Detection of Privileged Identity Management (PIM) Settings Modifications

Detects unauthorized or malicious modifications to Privileged Identity Management (PIM) settings within Azure environments, potentially leading to privilege escalation, persistence, and stealthy access by attackers.

Azure Active Directory azure pim privilege-escalation persistence
2r 4t
medium advisory

Detection of Azure Service Principal Creation

Detects the creation of a service principal in Azure, which could indicate potential attacker activity for lateral movement or persistence.

Azure cloud service principal persistence lateral movement
3r 1t
high advisory

AWS Identity Center Identity Provider Modification

An adversary modifies the AWS Identity Center identity provider configuration, potentially leading to persistent access and privilege escalation through user impersonation.

AWS Identity Center cloud aws identity persistence credential-access defense-evasion
2r 1t
high advisory

AWS IAM User or Access Key Creation via S3 Browser

The use of S3 Browser to create IAM users or access keys in AWS environments indicates a potential privilege escalation, persistence, or initial access attempt by threat actors leveraging a known cloud administration tool.

AWS IAM cloud aws iam privilege-escalation persistence
2r 2t
medium advisory

Registry Persistence via AppCert DLL

Detection of Registry Persistence via AppCert DLL, which involves modifying registry keys to load malicious DLLs upon process creation, enabling persistence and potential privilege escalation.

Windows persistence privilege-escalation
2r 2t
high advisory

Azure Application URI Configuration Modification

Detection of Azure application URI modifications that can be indicative of malicious activity, such as using dangling URIs, non-HTTPS URIs, wildcard domains, or URIs pointing to uncontrolled domains, potentially leading to initial access, stealth, persistence, credential access, and privilege escalation.

Azure Active Directory cloud azure application uri modification persistence credential-access privilege-escalation
3r 4t
low advisory

Windows User Account Creation via Net.exe

This rule identifies attempts to create new users on Windows systems using net.exe, a common tactic used by attackers to increase access or establish persistence.

Microsoft Defender XDR +2 persistence user-account-creation windows
2r 2t
medium advisory

Potential RemoteMonologue Attack via Registry Modification

This rule detects potential RemoteMonologue attacks by identifying attempts to perform session hijacking via COM object registry modification, specifically when the RunAs value is set to Interactive User.

MsMpEng.exe +4 remotemonologue defense-evasion persistence windows
2r 4t
medium advisory

Detecting Remote Windows Service Installation for Lateral Movement

This rule detects a network logon followed by Windows service creation with the same LogonId on a Windows host, which could indicate lateral movement or persistence by adversaries.

Windows +4 lateral-movement persistence
2r 3t
medium advisory

Windows System Restore Disabled via Registry Modification

Attackers disable Windows System Restore by modifying specific registry keys to hinder recovery efforts after malicious activity.

Windows impact t1490 persistence
2r 1t
medium advisory

Windows System File Ownership Change via Takeown or Icacls

Adversaries may modify file or directory ownership to evade access control lists (ACLs) and access protected files by using takeown.exe or icacls.exe to grant excessive permissions to system files.

Windows defense-evasion persistence
2r 2t
medium advisory

Windows Root Certificate Modification Detection

The modification of root certificates on Windows systems by unauthorized processes can allow attackers to masquerade malicious files as valid signed components and intercept/decrypt SSL traffic, leading to defense evasion and data collection.

Elastic Defend +2 defense-evasion persistence root certificate mitm
2r 2t
high advisory

Windows Registry Deletion of Scheduled Task Security Descriptor

Attackers may delete a scheduled task's Security Descriptor (SD) from the registry to remove evidence of the task for defense evasion.

Splunk Enterprise +2 defense-evasion persistence windows
2r 1t
medium advisory

Windows Guest Account Enabled via net.exe

The Windows guest account, typically restricted, can be enabled via `net.exe` for malicious activities like malware installation or data theft, potentially indicating persistence, defense evasion, privilege escalation or initial access.

Splunk Enterprise +2 guest-account persistence windows
2r 1t
medium advisory

Windows Firewall Rule Added via Event ID 4946

This detection identifies instances where a Windows Firewall rule is added by monitoring Event ID 4946 in the Windows Security Event Log, potentially indicating unauthorized changes or malicious activity such as attackers allowing traffic for backdoors or persistence mechanisms.

Splunk Enterprise +2 firewall persistence windows
2r
high advisory

Windows Files and Dirs Access Rights Modification via Icacls

Detection of icacls.exe, cacls.exe, or xcacls.exe being used to modify file or directory permissions, often used by APTs and coinminers for defense evasion and persistence.

Splunk Enterprise +2 defense-evasion persistence windows access-control
2r 1t
high advisory

Windows Defender Enhanced Notification Disabled via Registry Modification

An attacker modifies the Windows Registry to disable Windows Defender's Enhanced Notification feature, preventing users from receiving security alerts and potentially allowing malicious activities to go unnoticed, ultimately enabling persistence and evasion.

Windows Defender +3 registry-modification windows-defender persistence evasion
2r 1t
medium advisory

Windows Application Hotkey Disablement via Registry Modification

Attackers disable Windows application hotkeys by modifying specific registry entries to hinder incident response and evade detection.

Splunk Enterprise +2 registry-modification defense-evasion persistence hotkey-disablement
2r 1t
high advisory

Windows AppCertDLL Registry Modification via Command Line

Attackers modify the AppCertDLL registry key via command-line utilities to load malicious DLLs during system startup, achieving persistence and privilege escalation.

Splunk Enterprise +2 persistence privilege-escalation windows
2r 2t
medium advisory

Windows AD GPO Disabled

Detection of Active Directory Group Policy being disabled using the Group Policy Management Console, potentially indicating malicious attempts to weaken security controls.

Splunk Enterprise +3 active_directory group_policy persistence
3r 1t
critical advisory

Windows AD Domain Replication ACL Addition Detection

This brief details the detection of unauthorized modifications to Active Directory domain replication Access Control Lists (ACLs), specifically targeting permissions that enable DCSync attacks, potentially leading to sensitive data exfiltration and privilege escalation.

Active Directory active-directory dcsync acl windows privilege-escalation persistence
2r 2t
low advisory

Werfault ReflectDebugger Persistence via Registry Modification

Attackers may establish persistence by modifying the ReflectDebugger registry key associated with Windows Error Reporting to execute arbitrary code when Werfault is invoked with the '-pr' parameter.

Elastic Defend +1 persistence registry_modification werfault
2r 2t
medium advisory

Web Server Request Command Injection Attempt

Detection of potential command injection attempts via web server requests by identifying URLs containing suspicious patterns associated with command execution payloads, which attackers exploit to execute arbitrary commands on the server.

Apache +4 command-injection web-server persistence
2r 5t
medium advisory

User Added to Privileged Group in Active Directory

Adversaries may add a user to a privileged group in Active Directory, such as Domain Admins, to maintain persistent access and elevate privileges within the domain.

Active Directory persistence privilege_escalation active_directory
2r 1t
low advisory

Unusual Scheduled Task Update

This rule detects modifications to scheduled tasks by user accounts, excluding system activity and machine accounts, which adversaries can exploit for persistence by modifying them to execute malicious code.

Windows persistence scheduled-task
2r 1t
low advisory

Unusual Persistence via Services Registry Modification

Detection of processes modifying the Windows services registry key directly, potentially indicating stealthy persistence attempts via abnormal service creation or modification.

Microsoft Defender XDR +2 persistence windows registry modification
2r 3t
medium advisory

Uncommon Registry Persistence Change Detection

This rule detects changes to uncommon registry persistence keys on Windows systems that are not commonly used or modified by legitimate programs, which could indicate an adversary's attempt to persist in a stealthy manner by modifying registry keys for persistence, ensuring malicious code executes on startup or during specific events.

Windows persistence registry
2r 2t
medium advisory

Unauthorized Guest User Invitation Attempt in Azure

Detection of a failed attempt to invite an external guest user by an Azure user lacking the necessary permissions, potentially indicating privilege escalation or malicious insider activity.

Azure privilege-escalation initial-access persistence stealth
2r 1t
high advisory

Suspicious Process Execution from Unusual File Paths

Attackers may execute malicious code from unusual file paths such as Windows fonts or debug directories to evade defenses and gain unauthorized access, as detected by endpoint detection and response (EDR) agents.

Splunk Enterprise +2 defense-evasion persistence windows
2r 2t
medium advisory

Suspicious Mofcomp Activity Leading to WMI Abuse

Attackers may leverage the mofcomp.exe utility to compile malicious MOF files, enabling them to manipulate the Windows Management Instrumentation (WMI) repository for persistence or execution of arbitrary code.

Windows execution persistence wmi mofcomp
2r 3t
medium advisory

Suspicious Modifications to Windows Security Support Provider (SSP) Registry

Adversaries may modify the Windows Security Support Provider (SSP) configuration in the registry to establish persistence or evade defenses.

Microsoft Defender XDR +4 persistence defense-evasion registry-modification ssp
2r 2t
high advisory

Suspicious LNK File Creation in Temporary Directories

Detection of processes creating .lnk files in suspicious locations like user directories or temporary folders, often indicative of spear phishing or malware persistence mechanisms.

Windows lnk shortcut persistence phishing
2r 3t
high advisory

Suspicious ImagePath Service Creation

Adversaries may create or modify Windows services with malicious ImagePath values containing command shells or named pipes to establish persistence or escalate privileges, detected through registry modifications.

Windows persistence defense_evasion
2r 2t
low advisory

Suspicious Image Load (taskschd.dll) from MS Office

Detection of taskschd.dll image loads from Microsoft Office applications indicates potential COM-based scheduled task creation for persistence, bypassing traditional schtasks.exe usage.

Word +4 persistence execution windows image_load scheduled_task
2r 2t
high threat

Suspicious Bluetooth Service Installation from Uncommon Location

The creation of a Windows service named 'BluetoothService' with a binary path in user-writable directories, such as %AppData%, indicates potential malware persistence, as seen in the Lotus Blossom Chrysalis backdoor campaign.

Windows Lotus Blossom persistence defense-evasion anomaly
2r 2t
high advisory

Suspicious Azure PowerShell Module Installation via PowerShell Script

Detection of Azure AD and cloud management modules installation via PowerShell Script Block Logging, potentially indicating reconnaissance, privilege escalation, or persistence operations by adversaries.

Azure Active Directory +4 azure powershell module-installation privilege-escalation persistence
2r 5t
medium advisory

Suspicious AWS EC2 Key Pair Creation from Non-Cloud AS

An AWS EC2 CreateKeyPair event triggered by a new principal originating from a network autonomous system (AS) organization not associated with major cloud providers, indicating potential unauthorized access or persistence activity.

Amazon EC2 aws ec2 keypair persistence credential_access lateral_movement
2r 3t
low advisory

Startup or Run Key Registry Modification

Attackers modify registry run keys or startup keys to achieve persistence by referencing a program that executes when a user logs in or the system boots.

Elastic Defend +6 persistence registry runkey
3r 2t
medium advisory

Schtasks Run Task On Demand

Detection of on-demand execution of Windows Scheduled Tasks via the schtasks.exe command-line utility, a common technique for persistence and lateral movement.

Splunk Enterprise +2 schtasks scheduled-task persistence execution
2r 1t
high threat

Scheduled Task Disablement via Schtasks.exe

Detection of the use of schtasks.exe to disable scheduled tasks, a common tactic used by adversaries like IcedID to disable security applications and evade detection, potentially leading to persistence and further system compromise.

Splunk Enterprise +2 IcedID persistence defense_evasion windows
2r
medium advisory

Scheduled Task Creation via Scripting

Detection of scheduled task creation by Windows scripting engines like cscript.exe, wscript.exe, or powershell.exe, used by adversaries to establish persistence on compromised systems.

Elastic Defend +1 persistence scheduled-task windows
3r 3t
medium advisory

Scheduled Task Creation via Group Policy Object

Detects the creation of scheduled tasks within a Group Policy Object (GPO) by monitoring for the creation of the ScheduledTasks.xml file in the SYSVOL share, potentially indicating malicious persistence.

Splunk Enterprise +3 scheduled-task gpo persistence windows
2r 2t
medium advisory

Registry Persistence via AppInit DLL Modification

Modification of the AppInit DLLs registry keys on Windows systems allows attackers to execute code in every process that loads user32.dll, establishing persistence and potentially escalating privileges.

Microsoft Windows +6 persistence defense-evasion appinit-dlls registry windows
2r 2t
high advisory

Privileged Identity Management (PIM) Alerting Disabled

An adversary disables Privileged Identity Management (PIM) alerts in Azure to evade detection and maintain persistent access with escalated privileges.

Azure pim alerts privilege-escalation persistence
2r 1t
high threat

Potential Vcruntime140 DLL Sideloading

Detects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library, often used by threat actors like APT29 (via WinELOADER) to load malicious payloads under the guise of legitimate applications, leading to defense evasion, persistence, and privilege escalation.

Visual C++ Redistributable APT29 +5 dll-sideloading vcruntime140.dll wineloader defense-evasion persistence privilege-escalation
2r 3t
medium advisory

Potential Persistence via Time Provider Modification

The rule detects potential persistence via modification of the Time Provider in Windows by adversaries who register and enable a malicious DLL as a time provider, allowing for persistent code execution.

Windows persistence privilege-escalation
2r 2t
medium advisory

Potential Persistence via Mandatory User Profile Modification

Adversaries may abuse Windows mandatory profiles by dropping a malicious NTUSER.MAN file containing pre-populated persistence-related registry keys to establish persistence, which can evade traditional registry-based monitoring.

Elastic Defend persistence windows mandatory-profile file-modification
2r 2t
medium advisory

Potential LSA Authentication Package Abuse

Adversaries can abuse the Local Security Authority (LSA) authentication packages by modifying the Windows registry to achieve privilege escalation or persistence by executing binaries with SYSTEM privileges.

Microsoft Defender XDR +1 privilege-escalation persistence windows
2r 2t
medium advisory

Potential Adobe Hijack Persistence Mechanism

This brief outlines a potential persistence mechanism involving hijacking Adobe-related processes or components, which could allow attackers to maintain unauthorized access to a system.

Adobe Acrobat Reader +1 persistence process-injection adobe
2r 1t
high advisory

PingID New MFA Method Registered For User

The creation of a new MFA registration in PingID could indicate an attacker attempting to maintain persistence after compromising a user account.

PingID +1 mfa persistence credential-access
2r 3t
medium advisory

Persistence via Visual Studio Tools for Office (VSTO) Add-ins

The Visual Studio Tools for Office (VSTO) add-ins can be abused by attackers to establish persistence in Microsoft Office applications by modifying registry keys.

Microsoft Office +1 persistence office vsto
2r 1t
high advisory

Persistence via Update Orchestrator Service Hijack

Detection of potential hijacking of the Microsoft Update Orchestrator Service to establish persistence and privilege escalation by monitoring uncommon processes spawned by `svchost.exe` with `UsoSvc` as command-line parameters.

Windows 10 +1 persistence privilege-escalation windows
2r 3t 1c
high advisory

OpenClaw Matrix Profile Config Persistence Vulnerability

A vulnerability in the openclaw npm package before version 2026.4.10 allows unauthorized modification of Matrix profile configurations via the `operator.write` message tool.

openclaw npm vulnerability persistence
2r 1t
medium advisory

Okta MFA Reset or Deactivation Attempt

An attacker attempts to disable or reset multi-factor authentication (MFA) for a user account in Okta, potentially leading to unauthorized access and account compromise.

Okta Identity Cloud okta mfa credential-access persistence
2r 1t
high advisory

Okta API Token Creation Detection

Detection of new Okta API token creation, potentially indicating account compromise or unauthorized access leading to persistence and administrative control.

Okta Identity Cloud okta api_token account_takeover persistence
2r 1t
medium advisory

Okta API Token Creation

Detection of Okta API token creation events which can indicate malicious persistence activity.

Okta Identity Cloud persistence okta
2r 1t
high threat

O365 Service Principal Creation Detection

Detection of new service principal creation in O365 tenants, which can be abused by attackers for unauthorized access, API interaction, and data compromise.

Office 365 +5 NOBELIUM Group cloud o365 service_principal persistence azuread
2r 1t
high advisory

O365 Security Feature Modification

Attackers modify or disable Office 365 advanced security settings, such as AntiPhish, SafeLink, SafeAttachment, or Malware policies, to evade detection and operate with reduced risk within the target tenant.

Office 365 +3 o365 email_security defense_evasion persistence
2r 1t
critical threat

O365 ApplicationImpersonation Role Assigned

Detection of the ApplicationImpersonation role being assigned in Office 365, potentially leading to unauthorized mailbox access and impersonation.

Microsoft 365 +1 NOBELIUM Group cloud o365 applicationimpersonation persistence
2r 2t
medium threat

O365 Application Registration Owner Added

A new owner added to an O365 application registration can grant significant control, potentially leading to unauthorized data access, privilege escalation, or malicious behavior.

Azure Active Directory +1 NOBELIUM Group azuread o365 persistence
3r 1t
medium advisory

O365 Advanced Audit Disabled

The O365 Advanced Audit feature provides critical logging and insights into user and administrator activities, and this analytic detects instances where it is disabled for a specific user, potentially blinding security teams to malicious actions.

Microsoft 365 +1 o365 audit defense-evasion persistence
2r 1t
medium advisory

New ActiveSync Allowed Device Added via PowerShell

The rule detects the use of the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially allowing attackers to gain persistent access to sensitive email data by adding unauthorized devices.

Microsoft Defender XDR +4 exchange activesync powershell persistence
2r 3t
medium advisory

Network Logon Provider Registry Modification

Adversaries may modify the network logon provider registry to register a rogue network logon provider module for persistence and credential access by intercepting authentication credentials in clear text during user logon.

Defender XDR +3 credential-access persistence registry-modification
2r 2t
medium threat

MSSQL xp_cmdshell Stored Procedure Abuse for Persistence

Attackers may leverage the xp_cmdshell stored procedure in Microsoft SQL Server to execute arbitrary commands for privilege escalation and persistence, often bypassing default security configurations.

SQL Server persistence sql-server xp_cmdshell windows
2r 2t
medium advisory

Microsoft 365 SharePoint Site Administrator Added

Detection of a new SharePoint Site Administrator added in Microsoft 365, which adversaries may leverage after compromising a privileged account to maintain persistent, high-privilege access, as seen in the 0mega ransomware campaign.

Microsoft 365 +1 privilege-escalation persistence cloud
2r 2t
high advisory

Linux BPF Program or Map Load for Persistence

Attackers can leverage Linux's Berkeley Packet Filter (BPF) functionality to establish persistence by loading malicious programs or maps, allowing for stealthy and persistent code execution within the kernel.

Linux Kernel persistence linux bpf
3r 1t
medium advisory

Kubernetes DaemonSet Deployment Detected

The creation of a Kubernetes DaemonSet is detected via Kubernetes Audit logs, indicating a potential attempt to maintain persistent access and control within the cluster by ensuring a specific pod runs on every node.

Kubernetes +1 daemonset persistence
2r 1t 2i
high advisory

Hiding User Account from Sign-In Screen via Registry Modification

An attacker modifies the Windows registry to hide a user account from the login screen, potentially establishing a hidden admin account for persistence and evading detection.

Splunk Enterprise +2 persistence defense-evasion windows
2r
high advisory

Hidden Local Account Creation via Registry Modification

Attackers may create hidden local accounts, appending a dollar sign ($) to the username, to maintain persistence and evade detection by standard enumeration tools by modifying specific registry keys.

Windows persistence defense-evasion
2r 2t
medium advisory

GPO Scheduled Task or Service Creation/Modification

Detection of the creation or modification of new Group Policy based scheduled tasks or services, which can be abused by attackers with domain admin permissions to execute malicious payloads remotely on domain-joined machines, leading to privilege escalation and persistence.

Elastic Defend +2 group-policy privilege-escalation persistence windows
2r 3t
medium advisory

GPO Modification to Add Startup/Logon Scripts

This rule detects the modification of Group Policy Objects (GPO) to add a startup or logon script to user or computer objects, enabling attackers to achieve privilege escalation and persistence by executing arbitrary commands at scale.

Active Directory +1 group-policy privilege-escalation persistence windows
2r 3t
low advisory

Google Workspace Suspended User Account Renewed

Detection of a renewed, previously suspended user account in Google Workspace, potentially indicating unauthorized access or persistence by an adversary.

Google Workspace google_workspace initial_access persistence
2r 3t
medium advisory

GitHub Owner Role Granted to User

Detection of a member being granted the organization owner role in GitHub, potentially indicating unauthorized privilege escalation and persistence by an attacker.

GitHub persistence privilege-escalation
2r 2t
high advisory

Get-Variable.exe Hijacking for Persistence

Attackers can establish persistence by placing a malicious Get-Variable.exe in the WindowsApps folder, hijacking the legitimate PowerShell cmdlet and executing upon PowerShell window initialization, as seen with the Colibri malware.

Splunk Enterprise +2 persistence powershell windowsapps colibri
2r 1t
low advisory

GCP Service Account Key Creation for Persistence

An adversary may create a new key for a service account in Google Cloud Platform (GCP) to abuse the permissions assigned to that account and evade detection, potentially leading to persistent access.

Google Cloud Platform cloud gcp persistence account-manipulation
2r 1t
medium advisory

First Time Seen Driver Loaded

The rule identifies the load of previously unseen drivers, which may indicate attackers exploiting vulnerable drivers for privilege escalation and persistence.

Elastic Defend privilege-escalation persistence windows
2r 3t
high advisory

Executable or Script Creation in Temporary Paths

Adversaries may create executables or scripts in temporary directories to evade detection, maintain persistence, and execute unauthorized code on Windows systems.

defense-evasion persistence privilege-escalation execution temp-directory file-creation
2r 1t
low advisory

Entra ID User Added as Registered Application Owner

An adversary may add a user account as an owner for an Azure application in order to grant additional permissions and modify the application's configuration using another account, potentially leading to persistence, credential access, or privilege escalation.

Azure +1 cloud persistence credential access privilege escalation
2r 3t
medium advisory

Entra ID Service Principal Credentials Created by Unusual User

Anomalous addition of credentials to an Entra ID service principal by a user not typically performing this action can indicate potential persistence and privilege escalation by an attacker.

Entra ID +1 azure entra_id service_principal persistence privilege_escalation
2r 2t
medium advisory

Entra ID Privileged Identity Management (PIM) Role Modified

Attackers may modify Entra ID Privileged Identity Management (PIM) roles to persist in the environment and weaken security controls, potentially leading to privilege escalation and unauthorized access.

Entra ID Privileged Identity Management azure persistence privileged-identity-management
2r 3t
medium advisory

Entra ID External Authentication Methods (EAM) Modified

Modification of Entra ID external authentication methods (EAM) via the Microsoft Graph API can allow attackers to bypass multi-factor authentication (MFA) and establish persistence or gain unauthorized access via bring-your-own IdP (BYOIDP) methods.

Entra ID azure entra-id persistence authentication
2r 2t
medium advisory

Detection of WMI Temporary Event Subscription Creation

Detection of WMI temporary event subscriptions via Windows Event Logs can identify potential attacker command execution, information gathering, or persistence attempts.

Windows wmi persistence execution
2r 2t
high advisory

Detection of Vulnerable Windows Driver Installation

This analytic detects the installation of known vulnerable Windows drivers, potentially indicating persistence or privilege escalation attempts by threat actors exploiting these drivers for elevated privileges and system compromise.

Windows vulnerable-driver privilege-escalation persistence
2r 1t
high threat

Detection of Processes Launching netsh.exe for Malicious Purposes

Detection of netsh.exe execution by unusual processes indicative of potential malicious activity, including persistence and network configuration changes by threat actors.

exploited Splunk Enterprise +3 netsh living-off-the-land persistence network-configuration
2r
high advisory

Detection of Privileged Azure AD Role Assignment

Detection of privileged Azure AD role assignments to users, which can indicate persistence and privilege escalation by threat actors.

Azure Active Directory +2 azuread privilege-escalation persistence cloud
2r 2t
medium advisory

Detection of Privileged Account Creation in Azure

Detects the creation of new privileged accounts in Azure environments, potentially indicating initial access, persistence, privilege escalation, or stealth activities by malicious actors.

Azure privileged-account initial-access persistence privilege-escalation
2r 3t
medium advisory

Detection of Okta Administrator Role Assignment to User or Group

Detects the assignment of an Okta administrator role to a user or group, potentially indicating privilege escalation or persistence attempts by malicious actors.

Okta privilege-escalation persistence
2r 1t
medium advisory

Detecting Spikes in Active Directory Object Modifications

This detection identifies a spike in Active Directory group or object modifications, potentially indicating unauthorized access, defense impairment, or persistence establishment by threat actors.

Splunk Enterprise +2 active-directory persistence privilege-escalation windows
2r 1t
medium advisory

Detecting Persistence via Parsing macOS Login Item Files

This brief details a method for parsing macOS login item files to detect persistence mechanisms employed by malware or threat actors.

persistence macos
2r 1t
high advisory

Detect Windows Downdate Registry Activity

This detection identifies registry modifications associated with the Windows Downdate attack, specifically focusing on pending.xml file modifications outside standard locations, which could force a Windows downgrade for exploitation.

Splunk Enterprise +2 windows-downgrade registry-modification defense-evasion persistence
2r 2t
medium advisory

Detect Suspicious WMI Event Subscription Creation for Persistence

This threat brief details the detection of malicious Windows Management Instrumentation (WMI) event subscriptions, a technique used by attackers for persistence and privilege escalation on Windows systems.

Elastic Defend persistence wmi windows event-subscription
2r 1t
medium advisory

Detect AWS Access Key Creation

This brief outlines how to detect the creation of AWS Access Keys, a common tactic used by attackers to establish persistence and escalate privileges within compromised AWS environments.

Amazon Web Services cloud aws iam accesskey persistence
2r 1t
low advisory

Component Object Model (COM) Hijacking via Registry Modification

Adversaries may establish persistence by executing malicious content triggered by hijacked references to COM objects through Component Object Model (COM) hijacking via registry modification on Windows systems.

Elastic Defend +9 persistence com-hijacking windows registry defense-evasion privilege-escalation
2r 4t
medium advisory

Chmod Activity Targeting Sensitive Linux Directories

Attackers may use chmod to modify file permissions within sensitive Linux directories such as /tmp/, /etc/, and /opt/ to maintain persistence, escalate privileges, or disrupt system operations.

defense-evasion privilege-escalation persistence linux
2r 1t
medium advisory

BITS Job Notify Command Persistence

Adversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.

Windows persistence bits
2r 1t
high advisory

Azure Subscription Permission Elevation via Activity Logs

An attacker elevates their Azure subscription permissions to manage all subscriptions, potentially leading to unauthorized access and control over the environment.

Azure privilege-escalation persistence initial-access stealth
2r 1t
high advisory

Azure Runbook Webhook Creation Detected

Detection of a new Azure Automation Runbook Webhook creation, potentially leading to unauthorized access and control over Azure resources by enabling unauthenticated URL triggers.

Azure Automation azure runbook webhook persistence
2r 1t
high advisory

Azure RBAC Built-In Administrator Role Assignment

Detection of a user being assigned a built-in administrator role in Azure RBAC, which can be abused for privilege escalation, lateral movement, or persistence.

Azure rbac privilege-escalation persistence
2r 2t
medium advisory

Azure Event Hub Authorization Rule Created or Updated

Creation or modification of Azure Event Hub authorization rules can indicate unauthorized access or privilege escalation by adversaries using cryptographic keys to manage access to event hubs.

Azure Event Hub cloud azure persistence account-manipulation
2r 2t
high advisory

Azure Automation Runbook Creation for Persistence

This analytic detects the creation of a new Azure Automation Runbook within an Azure tenant using Azure Audit events, which adversaries with privileged access can abuse to maintain persistence, escalate privileges, or execute malicious code, potentially leading to unauthorized actions and compromise of the Azure environment.

Azure Automation azure persistence automation cloud
2r 1t
high advisory

Azure Automation Account Creation

Detect the creation of new Azure Automation accounts, which can be used by attackers for persistence, privilege escalation, and malicious runbook execution within Azure environments.

Azure Automation azure automation persistence
2r 1t
critical advisory

Azure AD User ImmutableId Attribute Modification for Persistence

Attackers modify the ImmutableID attribute of an Azure AD user to establish a federation backdoor, bypassing MFA and enabling persistent access.

Azure Active Directory azuread persistence federation immutabilid
2r 1t
high threat

Azure AD Tenant Wide Admin Consent Granted

Detection of admin consent granted to an application within an Azure AD tenant which could lead to data exfiltration and persistence.

Azure AD NOBELIUM Group azure persistence cloud
2r 1t
high advisory

Azure AD Service Principal Credential Addition

Detection of new credentials added to Azure AD Service Principals and Applications via monitoring of the 'Update application*Certificates and secrets management' operation, potentially indicating persistence or privilege escalation attempts.

Azure Active Directory azuread persistence privilege-escalation cloud
2r 2t
high advisory

Azure AD PIM Role Activation Detection

Detection of Azure AD Privileged Identity Management (PIM) role activation, indicating potential privilege escalation or unauthorized access.

Azure Active Directory +1 azure pim privilege-escalation persistence
2r 2t
high advisory

Azure AD New MFA Method Registered For User

An adversary may register a new MFA method in Azure AD on a compromised account to maintain persistence and bypass existing security controls.

Azure AD azure mfa persistence account-takeover
2r 2t
medium advisory

Azure AD MFA Disabled to Bypass Authentication

An adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.

Azure Active Directory azure mfa credential-access persistence defense-impairment
2r 1t
high advisory

Azure AD Federated Domain Added

This analytic detects the addition of a new federated domain within an Azure Active Directory tenant, potentially indicating the establishment of an Azure AD identity federation backdoor for persistence and unauthorized access.

Azure Active Directory azuread persistence cloud
2r 1t
high advisory

Azure AD Custom Domain Addition for Persistence

Detection of a new custom domain addition in Azure AD audit logs, potentially indicating an attacker establishing persistence via identity federation backdoors for unauthorized access and privilege escalation.

Azure Active Directory +1 azuread persistence cloud
2r 1t
high advisory

Azure AD Account Enabled and Password Reset for Backdoor

Detection of an Azure AD user enabling a disabled account and immediately resetting the password, indicating a potential backdoor being established by an adversary with administrative access.

Azure Active Directory azuread persistence backdoor
2r 1t
high advisory

AWS Route 53 Domain Transfer Lock Disabled

The disabling of the transfer lock on an AWS Route 53 domain is detected, potentially indicating unauthorized domain transfer, takeover, or service disruption by an adversary gaining domain-management permissions.

Route 53 aws route53 domain-hijacking persistence
2r 3t
high advisory

AWS Multi-Factor Authentication Disabled

Detection of AWS Multi-Factor Authentication (MFA) being disabled for an IAM user, indicating potential weakening of account security and persistence attempts.

AWS Identity and Access Management aws cloudtrail mfa iam persistence
2r 3t
high advisory

AWS Login Profile Creation Followed by Console Login

Detection of an AWS user creating a login profile for another user, followed by a console login from the same source IP, potentially indicating privilege escalation.

AWS CloudTrail +2 aws privilege-escalation persistence
2r 2t
medium advisory

AWS IAM Virtual MFA Device Registration Attempt with Session Token

An adversary with compromised temporary AWS credentials attempts to establish persistence by creating or enabling a virtual MFA device, bypassing expected session token usage.

IAM cloud aws persistence
2r 3t
low advisory

AWS IAM API Calls via Temporary Session Tokens

Detection of AWS IAM API operations using temporary session credentials, indicating potential credential theft, session hijacking, or privileged role abuse for persistence and defense evasion.

AWS Identity and Access Management +2 cloud aws iam session-token persistence privilege-escalation
3r 2t
high advisory

AWS EC2 Stop, Start, and User Data Modification Correlation

Detection of a sequence of AWS EC2 management API calls indicative of malicious modification of instance user data to execute arbitrary code upon instance restart, potentially leading to privilege escalation and persistence.

EC2 aws user-data privilege-escalation persistence execution
3r 2t
high advisory

AWS Account Compromise via New MFA Registration

An adversary may register a new Multi-Factor Authentication (MFA) method for an AWS account using the `CreateVirtualMFADevice` event in AWS CloudTrail logs to maintain persistence and evade detection in a compromised AWS account.

AWS +1 cloudtrail mfa persistence
2r 2t
medium advisory

Account Configured with Never-Expiring Password

Detects the creation and modification of an account with the 'Don't Expire Password' option enabled, which attackers can abuse to persist in the domain and maintain long-term access.

Active Directory persistence windows account-manipulation
2r 1t
high advisory

Abuse of dnscmd.exe to Modify DNS ServerLevelPluginDLL

Attackers can use dnscmd.exe with administrative privileges to configure the Microsoft DNS ServerLevelPluginDll setting, allowing them to load arbitrary DLLs and execute code within the DNS service context for persistence and privilege escalation.

Splunk Enterprise +3 persistence privilege-escalation windows
2r 1t
high advisory

Windows File Association Modification via Ftype Command

Adversaries can use the `ftype` command to modify Windows file associations, potentially redirecting legitimate file execution to malicious payloads for persistence, execution, and defense evasion.

Splunk Enterprise +2 file-association persistence execution windows
2r 3t
high advisory

Suspicious QEMU Execution on Windows

Detects the execution of QEMU with the -nographic flag and an image file on Windows systems, a technique used for persistence and initial access by installing a rogue Linux virtual machine.

Splunk Enterprise +3 qemu virtualization persistence linux windows
2r 2t
medium advisory

Spike in Active Directory User Modification Activity

Detects an increase in modifications to AD user objects, which may indicate unauthorized access, impaired defenses, or persistence establishment.

Splunk Enterprise +2 account-manipulation persistence windows
2r 1t
medium advisory

Potential Persistence via Time Provider Modification

Adversaries may establish persistence by registering and enabling a malicious DLL as a time provider by modifying registry keys associated with the W32Time service.

Windows +1 persistence privilege-escalation time-provider
2r 2t
high advisory

Potential Modification of Accessibility Binaries for Persistence and Privilege Escalation

Adversaries can modify accessibility binaries to execute malicious code before user login, establishing persistence and potentially escalating privileges by replacing legitimate accessibility tools with backdoored executables.

Windows persistence privilege-escalation
2r 2t
medium advisory

Potential Application Shimming via Sdbinst

Attackers abuse the Application Shim functionality in Windows by using `sdbinst.exe` with malicious arguments to achieve persistence and execute arbitrary code within legitimate Windows processes.

Windows +1 persistence privilege-escalation application-shimming
2r 2t
medium advisory

Persistence via LSA Security Support Provider Registry Modification

Adversaries may establish persistence by modifying the Windows Security Support Provider (SSP) configuration in the registry, allowing malicious code to load during system startup.

Windows persistence registry
2r 2t
high advisory

Logon Script Registry Modification for Persistence and Privilege Escalation

This brief details the detection of UserInitMprLogonScript registry entry modifications, a technique employed by threat actors for persistence and privilege escalation by ensuring payloads execute automatically at system startup.

Splunk Enterprise +2 persistence privilege-escalation windows
2r 2t
high advisory

Linux Auditd Detects Firewall Modification or Disabling

The analytic detects suspicious disabling or modification of the system firewall on Linux systems, which can indicate unauthorized access or attempts to maintain control over a system by disabling host protections.

Splunk Enterprise +3 defense-evasion persistence privilege-escalation firewall
3r 1t
high advisory

Executable or Script Creation in Suspicious Paths

This analytic identifies the creation of executables or scripts in suspicious file paths on Windows systems, where adversaries often use these paths to evade detection and maintain persistence, potentially leading to unauthorized code execution, privilege escalation, or persistence within the environment.

Windows defense-evasion persistence privilege-escalation execution
2r 1t
high advisory

ESXi Account Modification Detection

Detection of local user account creation, deletion, or modification on an ESXi host, potentially indicating unauthorized access, persistence attempts, or defense evasion.

ESXi vmware account-management persistence privilege-escalation
2r 7t
medium advisory

Entra ID Application Credential Modification

An adversary may add unauthorized credentials to an Azure application, enabling persistent access, evading defenses, and escalating privileges by modifying certificates or secrets.

Azure +1 persistence entra_id account_manipulation
3r 2t
high advisory

Cisco ASA User Privilege Level Change Detection

Detection of unauthorized privilege level changes on Cisco ASA devices, potentially indicating privilege escalation or persistence attempts by threat actors.

Cisco ASA cisco-asa privilege-escalation persistence network
2r 2t
critical advisory

Azure AD Global Administrator Role Assigned

Detection of Azure AD Global Administrator role assignment to a user, potentially leading to privilege escalation and control over Azure resources.

Azure Active Directory azuread privilege-escalation persistence
2r 2t
medium threat

Azure AD External Guest User Invitation

Detection of an external guest user invitation in Azure AD through monitoring Azure AD AuditLogs, which, if malicious, can lead to unauthorized access, data breaches, or further exploitation by abusing external identities.

exploited Azure Active Directory azuread cloud persistence
2r 1t
low advisory

AWS IAM Group Creation for Persistence

An adversary with compromised IAM write privileges creates a new group in AWS IAM and grants it excessive permissions to establish a persistence mechanism.

AWS Identity and Access Management aws iam persistence cloud
2r 1t
low advisory

Adding Hidden File Attribute via Attrib.exe

Adversaries can use attrib.exe to add the 'hidden' attribute to files to hide them from users and evade detection, which can be detected by monitoring process executions related to attrib.exe.

M365 Defender +4 defense-evasion persistence windows attrib.exe
2r 2t
high advisory

O365 MFA Disabled by User

Detection of Multi-Factor Authentication (MFA) being disabled for a user account in Office 365, potentially indicating malicious activity or an insider threat.

Office 365 o365 mfa persistence
2r 1t
low advisory

Adobe Acrobat Reader Hijack for Persistence

Attackers can maintain persistence by replacing the legitimate RdrCEF.exe file, used by Adobe Acrobat Reader, with a malicious executable that will be launched upon execution of Adobe Acrobat Reader.

Adobe Acrobat Reader persistence adobe file-replacement
2r 2t
high advisory

Azure AD Account Created and Deleted Within a Close Time Frame

Detection of Azure Active Directory accounts that are created and deleted within a short timeframe, potentially indicating malicious activity such as privilege escalation or persistence attempts.

Azure Active Directory privilege-escalation persistence initial-access stealth account-manipulation
2r 3t
medium advisory

Account Password Reset Remotely

The rule detects attempts to reset potentially privileged account passwords remotely, a tactic used by adversaries to maintain access, evade password policies, and preserve compromised credentials.

Windows persistence impact
2r 2t
medium advisory

Unusual Process For a Windows Host via Machine Learning

This rule detects rare processes running on Windows hosts, potentially indicating unauthorized services, malware, or persistence mechanisms by using machine learning to identify processes that run infrequently compared to other processes on the same host.

Windows persistence execution
2r 2t
medium advisory

Startup Folder Persistence by Suspicious Processes

This rule identifies files written to or modified in the startup folder by commonly abused processes on Windows systems, a technique adversaries use to maintain persistence by automatically executing malicious programs upon user login or system startup.

Windows +2 persistence startup-folder
2r 1t
medium advisory

Persistence via PowerShell Profile Modification

Attackers can establish persistence by creating or modifying PowerShell profiles to execute malicious code each time PowerShell is launched, customizing the user environment.

PowerShell persistence windows
2r 2t
high advisory

Persistence via Hidden Run Key

Adversaries achieve persistence by creating hidden, null-terminated registry keys within common Run key locations, evading standard system utilities.

Windows persistence registry defense-evasion
2r 4t
medium advisory

GCP IAM Custom Role Creation

Detection of Identity and Access Management (IAM) custom role creation in Google Cloud Platform (GCP), which can indicate potential privilege escalation or persistence by adversaries creating roles with excessive permissions.

Google Cloud Platform gcp iam custom-role initial-access persistence privilege-escalation
3r 3t
medium threat

Exchange PowerShell Used to Add New ActiveSync Allowed Device

An adversary may use the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially gaining persistent access to a user's email and sensitive information.

exploited Microsoft Exchange Server exchange powershell activesync persistence
2r 3t
medium advisory

AWS Root Account Usage Detected

The AWS root account, which grants unrestricted access to all resources within an AWS account, was used, potentially indicating unauthorized activity, privilege escalation, or a breach of security best practices.

AWS CloudTrail cloud aws privilege-escalation initial-access persistence stealth
3r 3t
medium advisory

Windows Temporarily Scheduled Task Creation and Deletion

Detection of rapid creation and deletion of scheduled tasks on Windows, indicating potential malicious activity abusing the task scheduler for execution and cleanup.

Windows persistence execution
2r 2t
high advisory

Windows Service Creation via Registry Modification

Detection of registry modifications to create Windows services, a common persistence technique used by attackers to maintain access, escalate privileges, or move laterally within a network.

Windows persistence privilege-escalation
2r 1t
low advisory

Windows Scheduled Task Creation for Persistence

Adversaries may create scheduled tasks on Windows systems to establish persistence, move laterally, or escalate privileges, and this detection identifies such activity by monitoring Windows event logs for scheduled task creation events, excluding known benign tasks and those created by system accounts.

OneDrive +5 persistence scheduled-task windows
3r 1t
medium advisory

Unauthorized Guest User Invitations in Azure AD

Detection of unauthorized guest user invitations within an Azure Active Directory tenant, indicating potential privilege escalation, persistence, or initial access attempts.

azure azuread guest-user privilege-escalation persistence initial-access
2r 3t
low advisory

Suspicious Local Scheduled Task Creation

This rule detects the creation of scheduled tasks on Windows systems by non-system accounts, a common technique used by adversaries for persistence, lateral movement, and privilege escalation.

Elastic Defend persistence windows scheduled_task attack.persistence
2r 1t
high advisory

Suspicious Executable or Script Creation in Uncommon Paths

Detection of executables or scripts being created in unusual directories on Windows systems, which can be indicative of malware installation or persistence attempts.

Windows file-creation persistence
3r 1t
high advisory

S3 Browser Used to Create IAM Login Profiles

The S3 Browser utility is being used to enumerate IAM users lacking login profiles and subsequently create them, potentially for reconnaissance, persistence, and privilege escalation within AWS environments.

AWS IAM aws cloud iam s3browser privilege-escalation persistence
2r 2t
high advisory

Remote Registry Lateral Movement via RPC Firewall

This brief details detection of lateral movement attempts using remote RPC calls to modify the registry, potentially leading to code execution, detected via RPC Firewall logs.

lateral-movement defense-impairment persistence rpc
2r 3t
medium advisory

Okta New Device Enrollment Detection

Detection of new device enrollments in Okta, potentially indicating account takeover or unauthorized access by an adversary.

Okta Identity Cloud okta account-takeover persistence cloud
2r 1t
high advisory

O365 Cross-Tenant Access Policy Changes

Adversaries modify Azure Active Directory cross-tenant access policies for lateral movement or persistence within compromised Microsoft 365 environments.

Azure Active Directory +1 azuread office365 cross-tenant persistence
2r 2t
medium advisory

Microsoft Outlook VBA Template Persistence

Attackers establish persistence by installing a malicious VBA template in Microsoft Outlook, triggering scripts upon application startup by modifying the VBAProject.OTM file.

Outlook persistence vba windows
2r 1t
high advisory

Malicious MSC File Creation in Mock Trusted Directory

The creation of MSC files within a 'C:\Windows \System32' directory can be exploited to execute malicious files due to path parsing vulnerabilities in Windows, potentially leading to privilege escalation, persistence, and defense evasion.

Splunk Enterprise +2 defense-evasion privilege-escalation persistence windows
2r 3t
medium advisory

Mac File Opener Adware Persists via Document Handler Registration

The 'Mac File Opener' adware achieves persistence by registering itself as a document handler for numerous file types, leveraging the Launch Services Daemon (lsd) to automatically parse the application's Info.plist and register the handlers.

macOS adware persistence
2r 1t
high advisory

Lateral Movement via Startup Folder File Creation

Adversaries may move laterally by dropping malicious scripts or executables into a remote system's startup folder via RDP or SMB, enabling execution upon reboot or user logon.

Windows lateral-movement persistence
2r 4t
medium advisory

Image File Execution Options (IFEO) Injection for Persistence and Defense Evasion

Adversaries abuse Image File Execution Options (IFEO) in the Windows Registry by modifying Debugger or MonitorProcess keys to intercept legitimate file executions, enabling persistence and defense evasion.

Windows persistence defense-evasion registry
2r 3t
medium advisory

Google Workspace 2SV Policy Disabled

An adversary may disable 2-Step Verification (2SV) in Google Workspace to weaken account security and facilitate unauthorized access.

Google Workspace google-workspace 2sv persistence
2r 1t
low advisory

GCP Service Account Creation for Persistence

Successful creation of a new service account in Google Cloud Platform (GCP) can indicate malicious persistence, as adversaries may create these accounts to evade detection by avoiding standard user accounts.

Google Cloud Platform cloud gcp persistence iam
2r 1t
high advisory

GCP Multi-Factor Authentication Disabled

Detection of disabled multi-factor authentication (MFA) for a Google Cloud Platform (GCP) user, potentially leading to unauthorized access and data exfiltration.

Google Cloud Platform +1 cloud gcp mfa persistence defense-evasion
2r 2t
low advisory

GCP IAM Service Account Key Deletion

Detection of Identity and Access Management (IAM) service account key deletion in Google Cloud Platform (GCP), potentially indicating malicious activity such as disrupting services or covering tracks after unauthorized access.

Google Cloud Platform cloud gcp iam persistence impact
2r 2t
low advisory

Entra ID User Sign-in with Unusual Non-Managed Device

Detects Microsoft Entra ID user sign-ins from devices not typically used or managed, indicating potential account compromise or unauthorized access via device registration for persistence.

Microsoft Entra ID azure entra-id persistence device-registration
2r 2t
medium advisory

Entra ID User Added as Service Principal Owner for Persistence

An adversary may add a user account as an owner for an Azure service principal to define what an application can do in the Azure AD tenant, potentially leading to persistence and privilege escalation.

Entra ID +1 azure service-principal persistence privilege-escalation
2r 4t
medium advisory

Entra ID Conditional Access Policy (CAP) Modified

An adversary may modify existing Conditional Access Policies (CAPs) in Microsoft Entra ID to weaken access controls and maintain persistence in the environment with a compromised identity.

Microsoft Entra ID azure entra_id conditional_access_policy persistence defense_evasion
2r 2t
medium advisory

Detection of Level RMM Watchdog Task Creation

The creation of the 'Level Watchdog' task, indicative of the Level remote management tool installation, is detected, highlighting the potential abuse of legitimate RMM tools for persistence and execution by threat actors on Windows systems.

Level remote management tool +3 rmm remote-access persistence
2r 2t
low advisory

Component Object Model (COM) Hijacking via Registry Modification

This rule detects Component Object Model (COM) hijacking via registry modification, where adversaries establish persistence by executing malicious content triggered by hijacked references to COM objects.

Windows persistence defense-evasion privilege-escalation com-hijacking
2r 4t
high advisory

Cisco ASA AAA Policy Tampering

Unauthorized modifications to Cisco ASA AAA policies via CLI or ASDM can weaken authentication mechanisms, potentially enabling brute-force attacks, privilege escalation, and persistent access by malicious actors.

Cisco Adaptive Security Appliance cisco-asa aaa-policy privilege-escalation persistence
2r 3t
medium advisory

Azure Domain Federation Settings Modified

An attacker may modify Azure domain federation settings to establish persistence, escalate privileges, or gain unauthorized access to resources.

Azure Active Directory azure federation privilege-escalation persistence initial-access
2r 2t
low advisory

Azure Automation Webhook Created for Persistence

Adversaries may create Azure Automation webhooks to trigger malicious runbooks for persistence in cloud environments.

Azure Automation azure persistence cloud
2r 2t
high threat

Azure AD Service Principal Owner Added

Detection of a new owner being added to an Azure AD Service Principal, potentially indicating persistence or privilege escalation by an attacker exploiting the lack of multi-factor authentication on service principals.

Azure Active Directory NOBELIUM Group azure cloud persistence privilege-escalation
2r 1t
medium advisory

AWS Route 53 Private Hosted Zone Associated With Unauthorized VPC

An adversary with sufficient permissions may associate unauthorized VPCs to intercept, observe, or reroute internal traffic, establish persistence, or expand their visibility within an AWS environment by associating a Route 53 private hosted zone with a new Virtual Private Cloud (VPC).

Route 53 cloud aws route53 persistence
2r 3t
high advisory

AWS Route 53 Domain Transferred to Another Account

An AWS Route 53 domain was transferred to another AWS account, potentially leading to unauthorized control over DNS records and traffic redirection for malicious purposes, such as phishing or establishing persistence.

Route 53 aws route53 domain-transfer persistence resource-development
2r 2t
medium advisory

AWS IAM SAML Provider Creation for Persistence

Detects the creation of a new SAML Identity Provider (IdP) in AWS IAM, potentially indicating an adversary establishing persistent, federated access to AWS accounts by forging SAML assertions from an IdP they control.

IAM aws saml persistence cloud
3r 3t
medium advisory

AWS IAM Operations via Compromised CloudShell

Compromised AWS console sessions can lead to attackers performing sensitive IAM operations via CloudShell to establish persistence or escalate privileges.

AWS CloudShell +2 cloudshell aws iam persistence privilege-escalation
2r 4t
low advisory

AWS EC2 Network Access Control List Creation

The rule detects the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number, which adversaries may exploit to establish persistence or defense evasion by creating permissive rules.

Amazon EC2 cloud aws ec2 network-acl persistence defense-evasion
2r 3t
medium advisory

AppInit DLL Registry Persistence Detected

Modification of the AppInit DLLs registry keys can be used for persistence and defense evasion on Windows systems.

Windows persistence defense-evasion
2r 2t
high advisory

CyberArk PAS Recommended Monitor Events

This rule identifies CyberArk Privileged Access Security (PAS) events recommended for monitoring, focusing on non-error level audit events to detect potential privilege escalation, initial access, credential access, and persistence activities.

CyberArk Privileged Access Security cyberarkpas privilege-escalation initial-access credential-access persistence
3r 4t
high threat

Bitdefender Submission Wizard DLL Sideloading

Detection of potential DLL side-loading of Bitdefender Submission Wizard (BDSubmit.exe, bdsw.exe, or renamed BluetoothService.exe) via loading a malicious log.dll from a non-standard path.

Bitdefender Submission Wizard Lotus Blossom dll-sideloading persistence privilege-escalation lotus-blossom sysmon
2r 2t
high advisory

Azure AD Multi-Factor Authentication Disabled

Detection of attempts to disable multi-factor authentication (MFA) for an Azure AD user by identifying the 'Disable Strong Authentication' operation in Azure Active Directory AuditLogs, which allows adversaries to maintain persistence.

Azure Active Directory azure mfa persistence credential-access
2r 2t
low advisory

AWS IAM Assume Role Policy Update

An attacker modifies an AWS IAM role's trust policy to gain the privileges of the role, potentially leading to privilege escalation and persistence within the AWS environment.

AWS IAM cloud aws iam privilege-escalation persistence
2r 3t
low advisory

Adding Hidden File Attribute via Attrib.exe

Adversaries can use attrib.exe to add the 'hidden' attribute to files and directories to evade detection and persist on a system by hiding artifacts.

Windows defense-evasion persistence
2r 2t