| elastic |
Code Signing Policy Modification Through Registry |
production |
2026-09-18 |
| elastic |
Code Signing Policy Modification Through Built-in tools |
production |
2026-09-18 |
| elastic |
Windows Event Logs Cleared |
production |
2026-09-18 |
| elastic |
Clearing Windows Event Logs |
production |
2026-09-18 |
| elastic |
Clearing Windows Console History |
production |
2026-09-18 |
| elastic |
Potential Evasion via Boot Time Removal Tool |
production |
2026-09-18 |
| elastic |
Disabling Windows Defender Security Settings via PowerShell |
production |
2026-09-18 |
| elastic |
Sensitive Audit Policy Sub-Category Disabled |
production |
2026-09-18 |
| elastic |
Modification of AmsiEnable Registry Key |
production |
2026-09-18 |
| elastic |
Potential AMSI Bypass via RPC Runtime Hooking |
production |
2026-09-18 |
| elastic |
Potential EDR-Freeze via WerFaultSecure Abuse |
production |
2026-09-18 |
| elastic |
Potential Antimalware Scan Interface Bypass via PowerShell |
production |
2026-09-18 |
| elastic |
Suspicious Antimalware Scan Interface DLL |
production |
2026-09-18 |
| elastic |
Adding Hidden File Attribute via Attrib |
production |
2026-09-18 |
| elastic |
Wireless Credential Dumping using Netsh Command |
production |
2026-09-18 |
| elastic |
Unusual Web Config File Access |
production |
2026-09-18 |
| elastic |
NTDS Dump via Wbadmin |
production |
2026-09-18 |
| elastic |
Potential LSASS Clone Creation via PssCaptureSnapShot |
production |
2026-09-18 |
| elastic |
Microsoft Build Engine Using an Alternate Name |
production |
2026-09-18 |
| elastic |
Potential Veeam Credential Access Command |
production |
2026-09-18 |
| elastic |
Veeam Backup Library Loaded by Unusual Process |
production |
2026-09-18 |
| elastic |
Symbolic Link to Shadow Copy Created |
production |
2026-09-18 |
| elastic |
Suspicious Process Creation CallTrace |
production |
2026-09-18 |
| elastic |
Suspicious Remote Registry Access via SeBackupPrivilege |
production |
2026-09-18 |
| elastic |
Potential LSASS Memory Dump via PssCaptureSnapShot |
production |
2026-09-18 |
| elastic |
Potential Credential Access via LSASS Memory Dump |
production |
2026-09-18 |
| elastic |
Suspicious Zoom Child Process |
production |
2026-09-18 |
| elastic |
Suspicious Lsass Process Access |
production |
2026-09-18 |
| elastic |
Potential Credential Access via Renamed COM+ Services DLL |
production |
2026-09-18 |
| elastic |
User account exposed to Kerberoasting |
production |
2026-09-18 |
| elastic |
Potential Shadow Credentials added to AD Object |
production |
2026-09-18 |
| elastic |
Sensitive Privilege SeEnableDelegationPrivilege assigned to a Principal |
production |
2026-09-18 |
| elastic |
Searching for Saved Credentials via VaultCmd |
production |
2026-09-18 |
| elastic |
Multiple Vault Web Credentials Read |
production |
2026-09-18 |
| elastic |
Unusual Network Connection via RunDLL32 |
production |
2026-09-18 |
| elastic |
Potential Remote Credential Access via Registry |
production |
2026-09-18 |
| elastic |
Potential Local NTLM Relay via HTTP |
production |
2026-09-18 |
| elastic |
Sensitive Registry Hive Access via RegBack |
production |
2026-09-18 |
| elastic |
WDAC Policy File by an Unusual Process |
production |
2026-09-18 |
| elastic |
Rare Connection to WebDAV Target |
production |
2026-09-18 |