| splunk |
Windows Firewall Rule Added |
production |
2026-06-08 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| suricata |
ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| snort |
ET TROJAN Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| snort |
ET TROJAN Fake Updates Victim Click Confirmation |
rev 1 |
2026-06-05 |
| snort |
ET TROJAN Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| suricata |
ET EXPLOIT Kingdee Cloud Star Deserialization Vulnerability |
rev 2 |
2026-06-05 |
| suricata |
ET MALWARE Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| suricata |
ET MALWARE Fake Updates Victim Click Confirmation |
rev 1 |
2026-06-05 |
| suricata |
ET MALWARE Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| sigma |
Vim GTFOBin Abuse - Linux |
test |
2026-06-05 |
| sigma |
Potential Defense Evasion Via Binary Rename |
test |
2026-06-05 |
| sigma |
7Zip Compressing Dump Files |
test |
2026-06-05 |
| sigma |
Compress Data and Lock With Password for Exfiltration With 7-ZIP |
test |
2026-06-05 |
| sigma |
Password Protected Compressed File Extraction Via 7Zip |
test |
2026-06-05 |
| splunk |
M365 Copilot Impersonation Jailbreak Attack |
production |
2026-06-04 |
| splunk |
Linux Proxy Socks Curl |
production |
2026-06-04 |
| splunk |
Windows Alternate DataStream - Process Execution |
production |
2026-06-04 |
| sigma |
NTLM Hash Leak Via Curl NTLM Authentication |
test |
2026-06-04 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.commwebworks .com domain |
rev 1 |
2026-06-03 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.commwebworks .com domain |
rev 1 |
2026-06-03 |
| suricata |
ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.commwebworks .com domain |
rev 1 |
2026-06-03 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.commwebworks .com domain |
rev 1 |
2026-06-03 |
| sigma |
LSASS Crash Via Netlogon Stack Buffer Overflow - CVE-2026-41089 |
experimental |
2026-06-02 |
| splunk |
Windows AD add Self to Group |
production |
2026-06-01 |
| sigma |
Suspicious Eventlog Clearing or Configuration Change Activity |
stable |
2026-06-01 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.sos .al domain |
rev 1 |
2026-05-30 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.sos .al domain |
rev 1 |
2026-05-30 |
| suricata |
ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.sos .al domain |
rev 1 |
2026-05-30 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.sos .al domain |
rev 1 |
2026-05-30 |
| snort |
ET TROJAN Gh0st RAT Variant CNC Checkin Attempt |
rev 1 |
2026-05-28 |
| suricata |
ET MALWARE Gh0st RAT Variant CNC Checkin Attempt |
rev 1 |
2026-05-28 |
| snort |
ET ATTACK_RESPONSE MacSync Stealer Payload Inbound |
rev 1 |
2026-05-27 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.srivaishnavam .org .au domain |
rev 1 |
2026-05-27 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.srivaishnavam .org .au domain |
rev 1 |
2026-05-27 |
| snort |
ET ATTACK_RESPONSE MacSync Stealer Stage 2 Payload Inbound |
rev 1 |
2026-05-27 |
| snort |
ET INFO Telegram 409 Error Response, Failed Fetch /getUpdates due to Multiple Bot Instances |
rev 1 |
2026-05-27 |
| suricata |
ET ATTACK_RESPONSE MacSync Stealer Payload Inbound |
rev 1 |
2026-05-27 |