Vendor
high
advisory
Boot Registry Parameter Injection in IGEL OS
1 TTP 1 CVECVE-2026-82017 allows attackers with physical access to inject arbitrary kernel command-line parameters into IGEL OS boot configurations, resulting in privilege escalation while bypassing TPM measurements.
IGEL OS 12 +1
1t
1c
high
advisory
Suspicious Kerberos Authentication Ticket Request
2 rules 2 TTPsThis rule detects suspicious Kerberos authentication ticket requests by correlating network connections to the standard Kerberos port (88) from a source machine with a Kerberos authentication ticket request from the target domain controller, which could indicate lateral movement or credential access attempts within a Windows domain.
Elastic Defend +4
lateral-movement
threat-detection
windows
2r
2t