Vendor
Multiple Vulnerabilities in Rapid7 Velociraptor
2 TTPs 1 CVERapid7 Velociraptor is affected by multiple vulnerabilities allowing an authenticated remote attacker to perform arbitrary file manipulation, security bypass, remote code execution, and privilege escalation.
Authenticated Identity Spoofing Vulnerability in Velociraptor
1 CVERapid7 Velociraptor versions prior to 0.77.2 are affected by an authenticated identity-spoofing vulnerability, CVE-2026-18972, that may allow unauthorized access or impersonation within the platform.
Multiple Vulnerabilities in Rapid7 Velociraptor
2 rules 2 TTPsMultiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to perform a denial-of-service attack or disclose sensitive information.
Multiple Vulnerabilities in Rapid7 Velociraptor
2 rules 3 TTPsMultiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to disclose information or cause a denial of service.
Kerberos Traffic from Unusual Process
2 rules 2 TTPsDetects network connections to the standard Kerberos port from an unusual process other than lsass.exe, potentially indicating Kerberoasting or Pass-the-Ticket activity on Windows systems.
Rapid7 Velociraptor Improper Input Validation Vulnerability
2 rules 1 TTP 1 CVERapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability allowing authenticated remote attackers to achieve remote code execution on the server.