| snort |
ET INFO DYNAMIC_DNS Query to a *.kandla .com domain |
rev 1 |
2026-06-30 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.kandla .com domain |
rev 1 |
2026-06-30 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.joeseitz .com domain |
rev 1 |
2026-06-30 |
| suricata |
ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.joeseitz .com domain |
rev 1 |
2026-06-30 |
| suricata |
ET WEB_SPECIFIC_APPS [aretiq.ai] Apache OFBiz requirePasswordChange Authentication Bypass Attempt |
rev 1 |
2026-06-30 |
| splunk |
Linux Apparmor Bypass Via Aaexec |
production |
2026-06-30 |
| suricata |
ET MALWARE Observed LMTeamRAT SSL Cert |
rev 1 |
2026-06-29 |
| suricata |
ET MALWARE Observed AlfaRedFox RAT SSL Cert |
rev 1 |
2026-06-29 |
| suricata |
ET MALWARE Observed DarkRAT SSL Cert |
rev 1 |
2026-06-29 |
| splunk |
Rundll32 Create Remote Thread To A Process |
production |
2026-06-29 |
| splunk |
Windows Uncommon Remote Thread Creation In Browser Process |
production |
2026-06-29 |
| splunk |
Windows Powershell Logoff User via Quser |
production |
2026-06-29 |
| splunk |
Windows Powershell Import Applocker Policy |
production |
2026-06-29 |
| splunk |
Windows ClipBoard Data via Get-ClipBoard |
production |
2026-06-29 |
| splunk |
Powershell Processing Stream Of Data |
production |
2026-06-29 |
| splunk |
Create Remote Thread into LSASS |
production |
2026-06-29 |
| splunk |
PowerShell Environment Variable Execution |
production |
2026-06-29 |
| splunk |
Create Remote Thread In Shell Application |
production |
2026-06-29 |
| splunk |
Powershell Windows Defender Exclusion Commands |
production |
2026-06-29 |
| splunk |
PowerShell Loading DotNET into Memory via Reflection |
production |
2026-06-29 |
| splunk |
Powershell Remove Windows Defender Directory |
production |
2026-06-29 |
| sigma |
Process Monitor Driver Creation By Non-Sysinternals Binary |
test |
2026-06-29 |
| sigma |
Sysinternals PsService Execution |
test |
2026-06-29 |
| sigma |
Suspicious Use of PsLogList |
test |
2026-06-29 |
| sigma |
Permission Check Via Accesschk.EXE |
test |
2026-06-29 |
| sigma |
Procdump Execution |
test |
2026-06-29 |
| sigma |
Sysinternals PsSuspend Execution |
test |
2026-06-29 |
| sigma |
Sysinternals PsSuspend Suspicious Execution |
test |
2026-06-29 |
| sigma |
Sysmon Configuration Update |
test |
2026-06-29 |
| sigma |
Suspicious Execution Of Renamed Sysinternals Tools - Registry |
test |
2026-06-29 |
| sigma |
Process Explorer Driver Creation By Non-Sysinternals Binary |
test |
2026-06-29 |
| sigma |
Potential Defense Evasion Via Rename Of Highly Relevant Binaries |
test |
2026-06-29 |
| sigma |
Potential Privileged System Service Operation - SeLoadDriverPrivilege |
test |
2026-06-29 |
| sigma |
Antivirus - Relevant File Paths Alerts Signature |
test |
2026-06-29 |
| sigma |
Suspicious Service Installed |
test |
2026-06-29 |
| sigma |
Potentially Suspicious AccessMask Requested From LSASS |
test |
2026-06-29 |
| sigma |
Suspicious PROCEXP152.sys File Created In TMP |
test |
2026-06-29 |
| sigma |
Antivirus - Web Shell Detection Signature |
test |
2026-06-29 |
| sigma |
Renamed Sysinternals Sdelete Execution |
test |
2026-06-29 |
| sigma |
CredUI.DLL Loaded By Uncommon Process |
test |
2026-06-29 |