| splunk |
Network Share Discovery Via Dir Command |
production |
2026-08-05 |
| snort |
ET WEB_SPECIFIC_APPS Red Hat Keycloak Unauthenticated Server-side Request Forgery in OIDC Dynamic Client Registration |
rev 1 |
2026-08-04 |
| suricata |
ET WEB_SPECIFIC_APPS Red Hat Keycloak Unauthenticated Server-side Request Forgery in OIDC Dynamic Client Registration |
rev 1 |
2026-08-04 |
| elastic |
Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt |
deprecated |
2026-08-03 |
| snort |
ET INFO HTTP 300-Series Redirect to file URI attempt |
rev 2 |
2026-07-31 |
| snort |
ET WEB_CLIENT PROPFIND Flowbit Set |
rev 6 |
2026-07-31 |
| suricata |
ET WEB_CLIENT PROPFIND Flowbit Set |
rev 8 |
2026-07-31 |
| suricata |
ET HUNTING HTTP 300-Series Redirect to file URI attempt |
rev 8 |
2026-07-31 |
| snort |
ET RETIRED Possible 2015-7547 Malformed Server response |
rev 2 |
2026-07-30 |
| suricata |
ET RETIRED Possible 2015-7547 Malformed Server response |
rev 2 |
2026-07-30 |
| splunk |
Windows Network Sniffing Tool Executed |
production |
2026-07-30 |
| splunk |
Windows Suspicious Child Process of Consent.EXE |
production |
2026-07-30 |
| splunk |
Windows Powershell Commands from DNS TXT |
production |
2026-07-30 |
| splunk |
Windows Dir Piped to Findstr Activity |
production |
2026-07-30 |
| sigma |
Suspicious Machine Account Replication - DcSync Indicator |
test |
2026-07-30 |
| sigma |
Active Directory Replication from Non Machine Account - DcSync Indicator |
test |
2026-07-30 |
| sigma |
ADCS - Certighost Ghost Machine Account Creation |
experimental |
2026-07-30 |
| snort |
ET INFO Server Hello with Downgrade Request to TLS 1.1 or Lower |
rev 1 |
2026-07-28 |
| snort |
ET TROJAN OWAReaper C2 Beacon |
rev 1 |
2026-07-28 |
| suricata |
ET INFO Server Hello with Downgrade Request to TLS 1.1 or Lower |
rev 1 |
2026-07-28 |
| suricata |
ET MALWARE OWAReaper C2 Beacon |
rev 1 |
2026-07-28 |
| elastic |
Multiple Alerts in Different ATT&CK Tactics on a Single Host |
deprecated |
2026-07-28 |
| sigma |
System File Execution Location Anomaly |
test |
2026-07-28 |
| sigma |
Files With System Process Name In Unsuspected Locations |
test |
2026-07-28 |
| sigma |
Credential Manager Access By Uncommon Applications |
test |
2026-07-28 |
| sigma |
Access To Windows DPAPI Master Keys By Uncommon Applications |
test |
2026-07-28 |
| sigma |
PSScriptPolicyTest Creation By Uncommon Process |
test |
2026-07-28 |
| sigma |
PowerShell Core DLL Loaded By Non PowerShell Process |
test |
2026-07-28 |
| sigma |
Suspicious WSMAN Provider Image Loads |
test |
2026-07-28 |
| sigma |
Load Of RstrtMgr.DLL By An Uncommon Process |
test |
2026-07-28 |
| sigma |
Msiexec Quiet Installation |
test |
2026-07-28 |
| snort |
ET TROJAN Suspected Gamaredon APT Related Activity |
rev 5 |
2026-07-27 |
| suricata |
ET MALWARE Suspected Gamaredon APT Related Activity |
rev 6 |
2026-07-27 |
| splunk |
Windows File Without Extension In Critical Folder |
production |
2026-07-27 |
| splunk |
Svchost LOLBAS Execution Process Spawn |
production |
2026-07-27 |
| splunk |
Windows AppCertDLL Modification Via Command Line |
production |
2026-07-27 |
| splunk |
Windows AppCertDLL Modification Via Registry |
production |
2026-07-27 |
| sigma |
ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121) |
experimental |
2026-07-27 |
| sigma |
ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121) |
experimental |
2026-07-27 |
| snort |
ET INFO Adobe Coldfusion POST Request for RDS Services |
rev 1 |
2026-07-24 |