Vendor
Local Privilege Escalation Vulnerability in HP Software
1 TTPA local privilege escalation vulnerability in HP software allows a local attacker to elevate their privileges on affected systems.
Arbitrary File Manipulation Vulnerability in HP Web JetAdmin
1 CVEA remote unauthenticated attacker can exploit CVE-2024-4171 in HP Web JetAdmin to perform unauthorized file manipulation on the underlying host system.
HP Security Advisory for Poly Voice Vulnerability
2 rulesHP released a security advisory addressing a critical vulnerability in Poly VVX, Trio 8300, Trio 8500, and Trio 8800 devices, potentially allowing remote control.
Persistence via Windows Installer (Msiexec)
3 rules 3 TTPsAdversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.
WMI Incoming Lateral Movement
3 rules 2 TTPsDetection of processes executed via Windows Management Instrumentation (WMI) on a remote host indicating potential adversary lateral movement.
Suspicious Microsoft HTML Application Child Process
2 rules 1 TTPMshta.exe spawning a suspicious child process, such as cmd.exe or powershell.exe, indicates potential adversarial activity leveraging Mshta to execute malicious scripts and evade detection on Windows systems.