| sigma |
Potential Arbitrary File Download Using Office Application |
test |
2026-09-25 |
| elastic |
GitHub OAuth Application Authorized |
production |
2026-09-24 |
| elastic |
Lure-Themed Internet-Delivered RMM Executable |
production |
2026-09-24 |
| suricata |
ET MALWARE Exvicy CnC Panel Checkin |
rev 2 |
2026-09-24 |
| snort |
ET TROJAN Exvicy CnC Panel Checkin |
rev 2 |
2026-09-24 |
| elastic |
Google Workspace Object Copied from External Drive with App Consent |
production |
2026-09-24 |
| suricata |
ET ATTACK_RESPONSE Observed Portuguese JS Dropper Inbound M3 |
rev 1 |
2026-09-24 |
| suricata |
ET MALWARE Exvicy CnC Panel Response |
rev 2 |
2026-09-24 |
| suricata |
ET MALWARE Portuguese JS Dropper Payload Request |
rev 1 |
2026-09-24 |
| snort |
ET ATTACK_RESPONSE Observed Portuguese JS Dropper Inbound M3 |
rev 1 |
2026-09-24 |
| snort |
ET TROJAN Portuguese JS Dropper Payload Request |
rev 1 |
2026-09-24 |
| snort |
ET TROJAN Exvicy CnC Panel Response |
rev 2 |
2026-09-24 |
| splunk |
Azure AD OAuth Application Consent Granted By User |
production |
2026-09-24 |
| splunk |
Azure AD User Consent Blocked for Risky Application |
production |
2026-09-24 |
| sigma |
Potential Netcat Reverse Shell Execution |
test |
2026-09-24 |
| splunk |
Windows AD User Suspicious UPN Change |
production |
2026-09-23 |
| splunk |
Windows Admin Password Changed by Non-Admin |
production |
2026-09-23 |
| splunk |
O365 Email Password and Payroll Compromise Behavior |
production |
2026-09-23 |
| splunk |
O365 Email Send and Hard Delete Exfiltration Behavior |
production |
2026-09-23 |
| splunk |
O365 Email Send Attachments Excessive Volume |
production |
2026-09-23 |
| splunk |
O365 Email Receive and Hard Delete Takeover Behavior |
production |
2026-09-23 |
| elastic |
Curl Download Activity from npm Package Install |
production |
2026-09-23 |
| elastic |
Network Connection to OAST Domain via Script Interpreter |
production |
2026-09-23 |
| elastic |
Linux User Account Creation |
production |
2026-09-22 |
| elastic |
Launch Item Registration with Suspicious Executable Path via macOS Security Events |
production |
2026-09-22 |
| elastic |
Suspicious PowerShell from npm Package Install |
production |
2026-09-22 |
| elastic |
Persistence via a Hidden Plist Filename via macOS Security Events |
production |
2026-09-22 |
| elastic |
Kubernetes Pod Exec Sensitive File or Credential Path Access |
production |
2026-09-22 |
| elastic |
Kubernetes Pod Exec Cloud Instance Metadata Access |
production |
2026-09-22 |
| elastic |
Kubernetes Pod Exec with Curl or Wget to HTTPS |
production |
2026-09-22 |
| elastic |
Newly Observed IPSEC NAT Traversal Peer |
production |
2026-09-22 |
| elastic |
Repeated Stalled TLS Handshakes via ALPN acme-tls/1 Extension |
production |
2026-09-22 |
| elastic |
LSASS Process Access via Windows API |
production |
2026-09-22 |
| elastic |
Entra ID Device-Bound PRT Replay via First-Party App from Unusual IP |
production |
2026-09-22 |
| elastic |
GKE API Request Failure Burst by User |
production |
2026-09-22 |
| elastic |
Kubernetes Pod Exec Potential Reverse Shell |
production |
2026-09-22 |
| elastic |
Potential DNS Tunneling via NULL or Long DNS Queries |
production |
2026-09-21 |
| elastic |
Temporarily Scheduled Task Creation |
production |
2026-09-21 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.cthulhu .li domain |
rev 1 |
2026-09-21 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.brianneburnell .com domain |
rev 1 |
2026-09-21 |