| elastic |
Potential PowerShell Obfuscated Script via High Entropy |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via Invalid Escape Sequences |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via Character Array Reconstruction |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via High Numeric Character Proportion |
production |
2026-09-18 |
| elastic |
Potential Dynamic IEX Reconstruction via Environment Variables |
production |
2026-09-18 |
| elastic |
Dynamic IEX Reconstruction via Method String Access |
production |
2026-09-18 |
| elastic |
PowerShell Obfuscation via Negative Index String Reversal |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via String Concatenation |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via String Reordering |
production |
2026-09-18 |
| elastic |
Potential PowerShell Obfuscation via Special Character Overuse |
production |
2026-09-18 |
| elastic |
Potential Process Injection via PowerShell |
production |
2026-09-18 |
| elastic |
Windows Firewall Disabled via PowerShell |
production |
2026-09-18 |
| elastic |
Suspicious Microsoft Diagnostics Wizard Execution |
production |
2026-09-18 |
| elastic |
DNS Global Query Block List Modified or Disabled |
production |
2026-09-18 |
| elastic |
Potential RemoteMonologue Attack |
production |
2026-09-18 |
| elastic |
File with Right-to-Left Override Character (RTLO) Created/Executed |
production |
2026-09-18 |
| elastic |
Alternate Data Stream Creation/Execution at Volume Root Directory |
production |
2026-09-18 |
| elastic |
Windows Sandbox with Sensitive Configuration |
production |
2026-09-18 |
| elastic |
Unusual Child Processes of RunDLL32 |
production |
2026-09-18 |
| elastic |
Service DACL Modification via sc.exe |
production |
2026-09-18 |
| elastic |
Potential Windows Session Hijacking via CcmExec |
production |
2026-09-18 |
| elastic |
Scheduled Tasks AT Command Enabled |
production |
2026-09-18 |
| elastic |
Script Execution via Microsoft HTML Application |
production |
2026-09-18 |
| elastic |
Potential Secure File Deletion via SDelete Utility |
production |
2026-09-18 |
| elastic |
SIP Provider Modification |
production |
2026-09-18 |
| elastic |
SolarWinds Process Disabling Services via Registry |
production |
2026-09-18 |
| elastic |
Suspicious CertUtil Commands |
production |
2026-09-18 |
| elastic |
Suspicious Execution from a Mounted Device |
production |
2026-09-18 |
| elastic |
Unsigned DLL loaded by DNS Service |
production |
2026-09-18 |
| elastic |
First Time Seen Driver Loaded |
production |
2026-09-18 |
| elastic |
Expired or Revoked Driver Loaded |
production |
2026-09-18 |
| elastic |
Potential privilege escalation via CVE-2022-38028 |
production |
2026-09-18 |
| elastic |
Creation or Modification of a new GPO Scheduled Task or Service |
production |
2026-09-18 |
| elastic |
Startup/Logon Script added to Group Policy Object |
production |
2026-09-18 |
| elastic |
Group Policy Abuse for Privilege Addition |
production |
2026-09-18 |
| elastic |
Scheduled Task Execution at Scale via GPO |
production |
2026-09-18 |
| elastic |
Potential Privilege Escalation via InstallerFileTakeOver |
production |
2026-09-18 |
| elastic |
Service Creation via Local Kerberos Authentication |
production |
2026-09-18 |