| splunk |
PTC Windchill GW READY OK Probe |
production |
2026-06-14 |
| sigma |
Potential CVE-2023-36884 URL Request Pattern Traffic |
test |
2026-06-14 |
| splunk |
Windows EDRSilencer Execution |
production |
2026-06-13 |
| suricata |
ET EXPLOIT_KIT Clearfake Set-Cookie Inbound M2 |
rev 1 |
2026-06-12 |
| suricata |
ET EXPLOIT_KIT Clearfake Set-Cookie Inbound M1 |
rev 1 |
2026-06-12 |
| splunk |
Splunk Secure Application Alerts for Runtime Security |
experimental |
2026-06-12 |
| sigma |
Suspicious User-Agents Related To Recon Tools |
test |
2026-06-11 |
| snort |
ET TROJAN ClickFix Landing Page Observed |
rev 1 |
2026-06-09 |
| snort |
ET EXPLOIT Kingdee Cloud Star Deserialization Vulnerability |
rev 3 |
2026-06-09 |
| suricata |
ET MALWARE ClickFix Landing Page Observed |
rev 1 |
2026-06-09 |
| splunk |
Cisco SA - Access to Anonymizer Services |
production |
2026-06-09 |
| splunk |
Regsvr32 Silent and Install Param Dll Loading |
production |
2026-06-09 |
| splunk |
Cisco SA - Automated Web Reconnaissance via HTTP Access Errors |
production |
2026-06-09 |
| splunk |
Cisco SD-WAN Multiple SSH key Authentication from Same Source |
production |
2026-06-09 |
| splunk |
Cisco SD-WAN Multiple Source IP vManage Admin SSH Authentication |
production |
2026-06-09 |
| splunk |
Disable Defender AntiVirus Registry |
production |
2026-06-08 |
| splunk |
Windows Event Log Cleared |
production |
2026-06-08 |
| splunk |
Windows Defender Exclusion Registry Entry |
production |
2026-06-08 |
| splunk |
Disable Defender Submit Samples Consent Feature |
production |
2026-06-08 |
| splunk |
Disable Windows Behavior Monitoring |
production |
2026-06-08 |
| splunk |
Windows Firewall Rule Added |
production |
2026-06-08 |
| splunk |
Firewall Allowed Program Enable |
production |
2026-06-08 |
| splunk |
Powershell Disable Security Monitoring |
production |
2026-06-08 |
| splunk |
Windows Obfuscated Files or Information via RAR SFX |
production |
2026-06-08 |
| splunk |
Windows Process Execution From ProgramData |
production |
2026-06-08 |
| splunk |
Powershell Using memory As Backing Store |
production |
2026-06-08 |
| splunk |
Disable Windows SmartScreen Protection |
production |
2026-06-08 |
| splunk |
Add or Set Windows Defender Exclusion |
production |
2026-06-08 |
| splunk |
Windows Impair Defense Disable Web Evaluation |
production |
2026-06-08 |
| snort |
ET INFO DYNAMIC_DNS Query to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| snort |
ET INFO DYNAMIC_DNS HTTP Request to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| suricata |
ET DYN_DNS DYNAMIC_DNS HTTP Request to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| suricata |
ET DYN_DNS DYNAMIC_DNS Query to a *.infodomestic .com domain |
rev 1 |
2026-06-06 |
| snort |
ET TROJAN Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| snort |
ET TROJAN Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| snort |
ET TROJAN Fake Updates Victim Click Confirmation |
rev 1 |
2026-06-05 |
| suricata |
ET MALWARE Fake Updates Victim Click Confirmation |
rev 1 |
2026-06-05 |
| suricata |
ET MALWARE Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |
| suricata |
ET EXPLOIT Kingdee Cloud Star Deserialization Vulnerability |
rev 2 |
2026-06-05 |
| suricata |
ET MALWARE Observed Fake Updates Page Inbound |
rev 1 |
2026-06-05 |