Skip to content
Threat Feed

Tag

Post-Exploitation

31 briefs RSS
medium advisory

Detection of Malicious Socat Listener Configurations

Adversaries leverage the socat utility to establish bind shells or facilitate remote command execution by binding executables to network listeners, a technique increasingly observed in macOS post-exploitation scenarios.

macos linux post-exploitation lateral-movement
1r 2t
medium advisory

Abuse of macOS AppleScript Utilities for Execution

Adversaries leverage 'osascript' and 'osacompile' utilities on macOS to execute shell commands or stage malicious AppleScript payloads via the 'do shell script' command.

macos execution post-exploitation scripting
1r 1t
medium advisory

Detection of Windows Private Key Discovery Activity

Adversaries utilize native Windows utilities like cmd.exe and findstr.exe to search for sensitive private key files, a common post-exploitation technique used to facilitate credential theft, privilege escalation, and persistence.

Windows credential-access discovery post-exploitation
1r 1t
high advisory

Detection of Mimikatz Credential Dumping Tool Execution

Adversaries utilize the Mimikatz post-exploitation framework to dump credentials and perform authentication abuse by executing specific command-line modules in Windows environments.

credential-access windows post-exploitation
1r 1t
high advisory

Detection of CrackMapExec Post-Exploitation Execution Patterns

Detection engineering brief covering common command-line execution patterns generated by the CrackMapExec (CME) post-exploitation framework during lateral movement and command execution.

lateral-movement post-exploitation crackmapexec offensive-tooling
1r 3t
high advisory

Detection of PowerView Enumeration Framework Activity

PowerView is an open-source PowerShell module frequently used by threat actors for domain reconnaissance, user enumeration, and identifying lateral movement opportunities.

reconnaissance discovery post-exploitation powershell
1r 1t
high advisory

Detection of Nishang Exploitation Framework PowerShell Cmdlets

This brief documents detection signatures for the Nishang offensive PowerShell framework, a collection of scripts used for post-exploitation, lateral movement, and credential theft.

offensive-tool post-exploitation powershell detection
1r 1t
high advisory

Detection of Malicious PowerShell Framework Commandlets

This brief documents a comprehensive list of commandlet patterns associated with common PowerShell-based exploitation frameworks, privilege escalation tools, and post-exploitation modules used by threat actors.

windows powershell execution discovery post-exploitation
1r
medium advisory

Linux XDG Autostart Persistence Mechanism

Adversaries, including those using the PANIX post-exploitation framework, are abusing XDG autostart directories on Linux to achieve persistence via malicious .desktop files.

persistence linux post-exploitation
1r 2t
high advisory

Suspicious Redis Server Process Execution

Detection of unauthorized system shell and utility execution originating from Redis server processes indicative of post-exploitation activity or sandbox escapes like CVE-2022-0543.

redis-server +1 redis linux post-exploitation cve-2022-0543
1r 1t 1c
medium advisory

Detection of Unauthorized Shell History File Access on Linux

Detection of malicious actors accessing sensitive shell history files using common command-line utilities to harvest credentials or reconnaissance data on compromised Linux hosts.

credential-access linux post-exploitation
1r 1t
low advisory

Detection of Root-Level Execution of the 'id' Command on Linux

This brief addresses the detection of the 'id' command executed by the root user on Linux systems, a behavior frequently utilized by attackers for situational awareness during post-exploitation and privilege escalation verification.

linux post-exploitation discovery privilege-escalation
1r 1t
medium advisory

Detection of Malicious Netcat Usage on Linux

This brief details the detection of suspicious outbound network connections initiated by Netcat (nc, ncat) utilities on Linux systems, which are frequently used by threat actors for C2 communication and data exfiltration.

Splunk Enterprise +2 linux netcat command-and-control exfiltration post-exploitation
1r 1t
medium advisory

Detection of Linux Binary Execution from Shared Memory Directories

Detection of root-level execution of binaries from volatile shared memory directories (/dev/shm/ and /run/shm/) used by threat actors for fileless persistence and forensic evasion.

linux post-exploitation persistence tmpfs
1r 1t
medium advisory

Credential Manager Access By Uncommon Applications

A SigmaHQ detection rule identifies suspicious processes accessing Windows credential manager and vault files, potentially indicating credential theft by tools like Mimikatz, enabling lateral movement and data exfiltration.

credential-theft mimikatz dpapi windows post-exploitation
1r 1t
high advisory

Web Server Outbound Connections to File Sharing Services

Attackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.

Apache HTTP Server +3 post-exploitation ingress-tool-transfer webshell web-server c2 windows
1r 2t 26i
high advisory

Detection of Attacker Tools on Endpoints

This analytic detects the execution of tools commonly used by attackers for activities such as unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, leveraging process activity data from Endpoint Detection and Response (EDR) agents to identify known attacker tool names.

Sysmon +6 attacker-tools endpoint-detection post-exploitation EDR windows
1r 3t
high advisory

Potential Linux Privilege Escalation via Parent/Child UID Change

This brief details a high-severity Linux privilege escalation technique where an attacker, having gained initial access, drops an exploit in a user- or world-writable directory, executes it as a non-root user, and the resulting child process changes its effective user ID to root (UID 0), thereby achieving full system compromise.

privilege-escalation linux endpoint post-exploitation
1t
low advisory

Local Account and System Owner Discovery via Native Utilities

Threat actors utilize built-in Windows utilities like whoami, wmic, and net to perform local account and system owner discovery, a common post-exploitation reconnaissance technique facilitating privilege escalation and lateral movement.

discovery reconnaissance post-exploitation windows
1r 2t
high advisory

Detection of Renamed Sysinternals Tool Usage via Registry EULA Key

This brief details a detection strategy for identifying the use of renamed Sysinternals utilities by monitoring for suspicious modifications to the 'EulaAccepted' registry key, indicating potential post-exploitation activity or defense evasion on Windows systems.

defense-evasion post-exploitation sysinternals registry windows
1r 1t
medium advisory

Detecting Suspicious GrantedAccess Flags on LSASS

This brief details a detection for potentially suspicious `GrantedAccess` flags when a process attempts to access `LSASS.exe`, indicating possible credential dumping attempts by adversaries, which can lead to lateral movement and privilege escalation on Windows systems.

credential-dumping windows post-exploitation
1r 2t
high advisory

Potential Credential Dumping Activity via LSASS Process Access

Adversaries frequently target the Local Security Authority Subsystem Service (LSASS) process on Windows systems to dump credentials, employing tools like Mimikatz, NanoDump, or Procdump to extract sensitive authentication material for lateral movement and persistence.

credential-access post-exploitation windows
1r 1t
medium advisory

Potentially Suspicious AccessMask Requested From LSASS

This brief describes the detection of suspicious access mask requests to the Local Security Authority Subsystem Service (LSASS) process, a common post-exploitation technique used by threat actors for credential dumping on Windows systems.

credential-dumping post-exploitation windows security-event
1r 1t
high advisory

Antivirus Alert for Hacktools or Attack Tools

This brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.

antivirus hacktool post-exploitation detection incident-response malware
1r 1t
high advisory

Detection of PowerShell Get-Clipboard for Data Collection

This brief describes the detection of adversaries leveraging the `Get-Clipboard` PowerShell commandlet, identified through PowerShell Script Block Logging (EventCode 4104), to steal sensitive information such as credentials or PII from the Windows clipboard during the collection phase of an attack, potentially leading to unauthorized access and further compromise.

collection endpoint powershell data-theft post-exploitation
1r 1t
high advisory

Windows Post Exploitation Risk Behavior Detection

This analytic identifies potential post-exploitation behaviors on a Windows system by monitoring multiple risk events and their associated MITRE ATT&CK tactics, indicating potential malicious actions following an initial compromise.

Splunk Enterprise +2 post-exploitation windows splunk
2r 8t
high advisory

NetExec File Creation Detection

This brief covers the detection of NetExec, a post-exploitation and lateral movement tool, through monitoring for unique file creation patterns associated with its execution and file extraction in Windows environments.

Windows +1 netexec crackmapexec lateral-movement post-exploitation hacktool
2r 3t
high threat

Detection of NetExec Hacktool Execution

The threat brief details the detection of NetExec (formerly CrackMapExec), a post-exploitation tool used for Active Directory penetration testing and network enumeration, often employed by threat actors for lateral movement and credential harvesting.

Active Directory +1 pentest post-exploitation lateral-movement active-directory
2r 2t
medium advisory

WinPEAS PowerShell Script Execution Detection

This brief documents the detection of the WinPEAS PowerShell script execution on Windows systems, a tool commonly used for identifying privilege escalation paths by identifying specific function names used within the script.

Splunk Enterprise +2 privilege-escalation post-exploitation windows
2r 8t
medium advisory

Windows WMI Reconnaissance Activity Detection

Detection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.

Windows wmic reconnaissance post-exploitation
2r 1t
medium advisory

Detection of System Information Discovery Techniques

This brief covers the detection of adversaries using native Windows commands like `wmic qfe`, `systeminfo`, and `hostname` to gather system information for further exploitation.

Windows system-discovery post-exploitation
1r 1t