| elastic |
Azure Storage Account Deletion by Unusual User |
production |
2026-09-18 |
| elastic |
Azure Compute Snapshot Deletions by User |
production |
2026-09-18 |
| elastic |
Rare GCP Audit Failure Event Code |
production |
2026-09-18 |
| elastic |
Entra ID MFA TOTP Brute Force Attempted |
production |
2026-09-18 |
| elastic |
Entra ID Concurrent Sign-in with Suspicious Properties |
production |
2026-09-18 |
| elastic |
Entra ID Sign-in Brute Force Attempted (Microsoft 365) |
production |
2026-09-18 |
| elastic |
Entra ID ROPC Authentication with Unknown Client ID |
production |
2026-09-18 |
| elastic |
Entra ID Device-Bound PRT from Unusual Device IP |
production |
2026-09-18 |
| elastic |
Entra ID Excessive Account Lockouts Detected |
production |
2026-09-18 |
| elastic |
Entra ID User Sign-in Brute Force Attempted |
production |
2026-09-18 |
| elastic |
Entra ID OAuth Device Code Sign-in to Azure AD Graph Enumeration |
production |
2026-09-18 |
| elastic |
Azure VM Boot Diagnostics Retrieved |
production |
2026-09-18 |
| elastic |
Azure Storage Account Keys Accessed by Privileged User |
production |
2026-09-18 |
| elastic |
Azure Service Principal Sign-In Followed by Arc Cluster Credential Access |
production |
2026-09-18 |
| elastic |
Web Application Suspicious Activity: Unauthorized Method |
production |
2026-09-18 |
| elastic |
Web Application Suspicious Activity: sqlmap User Agent |
production |
2026-09-18 |
| elastic |
Potential Secret Scanning via Gitleaks |
production |
2026-09-18 |
| elastic |
Multi-Cloud CLI Token and Credential Access Commands |
production |
2026-09-18 |
| snort |
ET TROJAN AsyncRAT Powershell Payload |
rev 1 |
2026-09-18 |
| snort |
ET TROJAN MakinoLoader CnC Checkin |
rev 1 |
2026-09-18 |
| snort |
ET TROJAN MakinoLoader Victim HeartBeat |
rev 1 |
2026-09-18 |
| suricata |
ET MALWARE AsyncRAT Powershell Payload |
rev 1 |
2026-09-18 |
| suricata |
ET MALWARE MakinoLoader Victim HeartBeat |
rev 1 |
2026-09-18 |
| suricata |
ET MALWARE MakinoLoader CnC Checkin |
rev 1 |
2026-09-18 |
| elastic |
Potential Uninstall Entry Concealment |
production |
2026-09-17 |
| elastic |
Excessive Sudo Authentication Failures via macOS Security Events |
production |
2026-09-17 |
| elastic |
Privilege Escalation via Parallels Appliance Extract Argument Injection |
production |
2026-09-17 |
| sigma |
Potential PowerShell Obfuscation Using Alias Cmdlets |
test |
2026-09-17 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.chanka .com domain |
rev 1 |
2026-09-17 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.chanka .com domain |
rev 1 |
2026-09-17 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.chanka .com domain |
rev 1 |
2026-09-17 |
| snort |
ET TROJAN Observed Exploit Kit Profiler Related Domain in TLS SNI |
rev 1 |
2026-09-17 |
| snort |
ET TROJAN AMOS ClickFix Campaign - Bash Stager M1 |
rev 1 |
2026-09-17 |
| snort |
ET CURRENT_EVENTS Generic Phish Request to RMM M2 2026-09-16 |
rev 1 |
2026-09-17 |
| snort |
ET TROJAN Observed CobaltStrike CnC Related Domain in TLS SNI |
rev 1 |
2026-09-17 |
| snort |
ET TROJAN Observed BlueMoon EK CnC Related Domain in TLS SNI |
rev 1 |
2026-09-17 |
| snort |
ET INFO Zecurit RMM Activity - Agent Inbound Command Recieved for agentDownloadURL |
rev 1 |
2026-09-17 |
| snort |
ET TROJAN Observed Exploit Kit Profiler Related Domain in DNS Query |
rev 1 |
2026-09-17 |
| snort |
ET TROJAN Observed BlueMoon EK CnC Related Domain in TLS SNI |
rev 1 |
2026-09-17 |
| snort |
ET INFO Zecurit RMM Activity - Agent Exfil User Fingerprint |
rev 1 |
2026-09-17 |