Tag
low
advisory
Anomalous Linux Compiler Activity Detection
3 TTPsElastic has developed a machine learning detection rule to identify anomalous compiler activity on Linux systems, which can indicate unauthorized software deployment, ad-hoc changes, or privilege escalation attempts by adversaries.
endpoint
linux
machine-learning
detection-rule
resource-development
defense-evasion
privilege-escalation
3t
low
advisory
AWS SNS Topic Created by Rare User
2 rules 2 TTPsAn AWS SNS topic was created by a user who does not typically perform this action, potentially indicating resource development for data exfiltration or other malicious activities.
Simple Notification Service
cloud
aws
sns
resource-development
impact
2r
2t
high
advisory
AWS Route 53 Domain Transferred to Another Account
2 rules 2 TTPsAn AWS Route 53 domain was transferred to another AWS account, potentially leading to unauthorized control over DNS records and traffic redirection for malicious purposes, such as phishing or establishing persistence.
Route 53
aws
route53
domain-transfer
persistence
resource-development
2r
2t