| elastic |
Web Server Potential Spike in Error Response Codes |
production |
2026-09-18 |
| elastic |
Multiple Elastic Defend Alerts by Agent |
production |
2026-09-18 |
| elastic |
Sudoers File Activity |
production |
2026-09-18 |
| elastic |
Potential Cookies Theft via Browser Debugging |
production |
2026-09-18 |
| elastic |
Suspicious Instance Metadata Service (IMDS) API Command Line Execution |
production |
2026-09-18 |
| elastic |
AWS S3 Bucket ACL Modified to Allow Public Access by New Identity |
production |
2026-09-18 |
| elastic |
First Seen Network Flow Exporter Followed by Suspicious Source Activity |
production |
2026-09-18 |
| elastic |
Potential Spike in Web Server Error Logs |
production |
2026-09-18 |
| elastic |
Suspicious Instance Metadata Service (IMDS) API Request |
production |
2026-09-18 |
| elastic |
Multiple Vulnerabilities by Asset via Wiz |
production |
2026-09-18 |
| elastic |
Alerts From Multiple Integrations by User Name |
production |
2026-09-18 |
| elastic |
Bash Shell Profile Modification |
production |
2026-09-18 |
| elastic |
Credential Access via TruffleHog Execution |
production |
2026-09-18 |
| elastic |
AWS IAM Roles Anywhere Profile Creation |
production |
2026-09-18 |
| elastic |
Initial Access via File Upload Followed by GET Request |
production |
2026-09-18 |
| elastic |
AWS SES Full Access Policy Attached to IAM Entity by Unusual User |
production |
2026-09-18 |
| elastic |
FortiGate SSL VPN Login Followed by SIEM Alert by User |
production |
2026-09-18 |
| elastic |
Multiple External EDR Alerts by Host |
production |
2026-09-18 |
| elastic |
Web Server Cloud Metadata SSRF Request |
production |
2026-09-18 |
| elastic |
Lateral Movement Alerts from a Newly Observed Source Address |
production |
2026-09-18 |
| elastic |
SSH Authorized Keys File Activity |
production |
2026-09-18 |
| elastic |
AWS EKS Access Entry Modified |
production |
2026-09-18 |
| elastic |
AWS IAM Roles Anywhere Trust Anchor Created with External CA |
production |
2026-09-18 |
| elastic |
PANW and Elastic Defend - Command and Control Correlation |
production |
2026-09-18 |
| elastic |
Agent Spoofing - Multiple Hosts Using Same Agent |
production |
2026-09-18 |
| elastic |
Kubectl Network Configuration Modification |
production |
2026-09-18 |
| elastic |
Potential Credential Discovery via Recursive Grep |
production |
2026-09-18 |
| elastic |
Potential Privilege Escalation via Sudoers File Modification |
production |
2026-09-18 |
| elastic |
Web Server Potential SQL Injection Request |
production |
2026-09-18 |
| elastic |
Zoom Meeting with no Passcode |
production |
2026-09-18 |
| elastic |
Suspicious Java Class File Created in PaperCut Server Library |
production |
2026-09-18 |
| elastic |
Data Encrypted via OpenSSL Utility |
production |
2026-09-18 |
| elastic |
WebServer Access Logs Deleted |
production |
2026-09-18 |
| elastic |
Active Directory Forced Authentication from Linux Host - SMB Named Pipes |
production |
2026-09-18 |
| elastic |
AWS IAM API Calls via Temporary Session Tokens |
production |
2026-09-18 |
| elastic |
Tampering of Shell Command-Line History |
production |
2026-09-18 |
| elastic |
Web Server Suspicious User Agent Requests |
production |
2026-09-18 |
| elastic |
Alerts From Multiple Integrations by Source Address |
production |
2026-09-18 |
| elastic |
Potential Traffic Tunneling using QEMU |
production |
2026-09-18 |
| elastic |
Trap Signals Execution |
production |
2026-09-18 |