Clankerusecase
Linux detection coverage
← Back to main site
Home/ Targets/ Linux

🐧Linux detections

Clankerusecase tracks 549 detection use cases covering the Linux attack surface across 161 MITRE ATT&CK techniques.

Detections targeting Linux servers and workstations — auditd / Sysmon for Linux / syslog.

Open Detection Library → View on the matrix
549Use cases
161Techniques
60Articles
6Kill-chain phases

Top techniques on Linux (25)

Reconnaissance (3)

[LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] FileBrowser instance configured with auth.method=proxy (exploitable-config exposure) Bespoke recon · hunting DSΣPDDCS

Delivery (49)

[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [LLM] Inbound network access to Ruflo bridge (3001) / MongoDB (27017) from public source Bespoke delivery · hunting DSPDDCSCW [LLM] Anonymous access to Artifactory Terraform/Cargo/Ansible remote repositories Bespoke delivery · hunting SPDD [LLM] Malicious mrmustard 0.7.4 artifact by hash or filename Bespoke delivery · hunting DSΣPCS [LLM] Vulnerable @sigstore/oci (<=0.7.0) installed into node_modules — incl. transitive deps (CVE-2026-59891) Bespoke delivery · hunting DSΣPDDCS [LLM] Malicious @velora-dex/sdk (9.4.1/9.4.2) pulled into GitHub Actions build runner Bespoke delivery · alerting DSΣPDDCS [LLM] Anyquery server mode bound to all interfaces (exposed unauthenticated MySQL port) Bespoke delivery · hunting DSΣPDDCS [LLM] Joro proxy-mode confused-deputy: browser POSTs to loopback API 127.0.0.1:9090 (CVE-2026-53649) Bespoke delivery · hunting DSΣPCS [LLM] curl/wget child of 9router node fetching tailscale.com/install.sh (probe or exploit delivery) Bespoke delivery · hunting DSΣPDDCS [LLM] Ghost x-ghost-preview cache-poisoning header in inbound HTTP requests (CVE-2026-53943) Bespoke delivery · hunting SΣPDD [LLM] kubectl apply of attacker-crafted Rancher import URL (authImage payload delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] AUR build pulls malicious npm/Bun dependency (atomic-lockfile / js-digest / lockfile-js) Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma-tainted package install: binding.gyp dropped into known-compromised npm package paths Bespoke delivery · alerting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) Bespoke delivery · alerting DSΣPDDCS [LLM] jqwik-engine 1.10.0 malicious JAR on disk (SHA256 / filename match) Bespoke delivery · hunting DSΣPDDCS [LLM] Install or update of @redhat-cloud-services npm package post-2026-06-01 (IOC version watchlist) Bespoke delivery · hunting DSΣPDDCS [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint Bespoke delivery · hunting DSΣPDDCS [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree Bespoke delivery · hunting DSΣPDDCS [LLM] Composer install of malicious helpers.php in laravel-lang vendor package Bespoke delivery · hunting DSΣPDDCS [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious node-ipc package landed on disk under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Install of trojaned elementary-data 0.23.3 via pip / poetry / uv Bespoke delivery · alerting DSΣPDDCS [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host Bespoke delivery · alerting DSΣPDDCS [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious axios or plain-crypto-js package files written to node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 Bespoke delivery · alerting DSΣPDDCS [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 Bespoke delivery · hunting DSΣPDDCS [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Telnyx PyPI compromise: malicious telnyx 4.87.1 / 4.87.2 hash on disk Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP WAV-stego payload drop (hangup.wav / ringtone.wav) Bespoke delivery · alerting DSPDDCS [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk Bespoke delivery · hunting DSΣPDD [LLM] Malicious typosquat npm packages installed on disk (ts-bign / big-nunber / levex-refa / lint-builder) Bespoke delivery · hunting DSΣPDD [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious litellm 1.82.7/1.82.8 wheel install drops litellm_init.pth in site-packages Bespoke delivery · alerting DSΣPDDCS [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) Bespoke delivery · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) Bespoke delivery · hunting DSΣPDD [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) Bespoke delivery · alerting DSΣPDDCS [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry Bespoke delivery · alerting DSΣPDDCS [LLM] Inbound UDP/631 (CUPS IPP discovery) from external network Bespoke delivery · hunting DSΣPDDCS [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) Bespoke delivery · hunting DSΣPDDCS [LLM] Installation of Snyk-flagged malicious npm packages (radar-cms, rcenodejs, paychex-*) Bespoke delivery · alerting DSΣPDDCS [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) Bespoke delivery · alerting DSΣPDDCS

Exploitation (122)

[WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD Article-specific behavioural hunt — Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Bespoke exploit · hunting DSP [LLM] Cisco FMC www account runs package_info.pl on staged /var/tmp/license.tmp (CVE-2026-20316/20079) Bespoke exploit · alerting SΣPDD [LLM] Cisco FMC www web-service account escalating to root via sudo under /usr/local/sf/bin/ Bespoke exploit · hunting SPDD [LLM] JFrog Artifactory service process spawning a shell or downloader (RCE exploitation) Bespoke exploit · alerting DSΣPCS [LLM] Ruflo MCP bridge unauthenticated tools/call terminal_execute (RufRoot CVE-2026-59726) Bespoke exploit · alerting SΣPDD [LLM] Ruflo/Node MCP bridge spawning interactive shell inside container (RufRoot RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Gitea git process spawning shell / network tool via planted hook (CVE-2026-60004 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] ClickHouse query_log shows injected SQL from @hypequery escapeValue bypass Bespoke exploit · hunting SPDD [LLM] ClickHouse SQL syntax-error spike from @hypequery/clickhouse injection probing Bespoke exploit · alerting SPDD [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf Bespoke exploit · alerting DSΣPDDCS [LLM] JFrog Artifactory service process spawning a shell or network tool (RCE) Bespoke exploit · alerting DSΣPCS [LLM] Linux root process executed from memfd (CVE-2026-53264 core-dump payload) Bespoke exploit · alerting DSΣPDDCS [LLM] Unprivileged Linux tc clsact/flower/gact traffic-control manipulation (CVE-2026-53264 trigger) Bespoke exploit · hunting DSΣPDDCS [LLM] Fastjson 1.x CVE-2026-16723 exploit payload in inbound JSON (@type + nested JAR / /proc/self/fd) Bespoke exploit · hunting SΣP [LLM] GitLab Puma/Ruby worker (running as git) spawns shell or network tool — Oj .ipynb RCE landing Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Bespoke exploit · hunting DSP [LLM] OpenDJ SASL PLAIN bind invoking proxied authorization (authzid) — impersonation Bespoke exploit · hunting SΣPDD Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Bespoke exploit · hunting DSP [LLM] Web/interpreter process connecting to internal HiveServer2 (10000) or Hadoop NameNode (50070) Bespoke exploit · alerting DSΣPCS [LLM] LinPEAS / SUID sweep privilege-escalation enumeration on Linux Bespoke exploit · hunting DSΣPDDCS [LLM] redis-server spawns a shell/interpreter (system() from Redis RCE chain) Bespoke exploit · alerting DSΣPCS [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Bespoke exploit · hunting DSP [LLM] ATTACH DATABASE statement targeting persistence paths in Anyquery query logs Bespoke exploit · hunting SPDD Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Bespoke exploit · hunting DSP [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) Bespoke exploit · hunting SPDD [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests Bespoke exploit · hunting SPDD [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] FileBrowser proxy-auth header forgery naming admin on /api/login Bespoke exploit · alerting SΣPDD [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog Bespoke exploit · hunting SPDD [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] Joro native plugin RCE: joro process spawns interactive /bin/bash shell (CVE-2026-53649) Bespoke exploit · alerting DSΣPCS [LLM] Nuclio CronJob container args carry injected shell (CVE-2026-52831 header/body OS command injection) Bespoke exploit · alerting SPDD [LLM] Cypher injection primitives in Langroid LLM prompt / inbound HTTP input Bespoke exploit · hunting SPDD [LLM] Neo4j executes attacker-primitive Cypher (apoc.*, dbms.*, LOAD CSV) via query.log Bespoke exploit · alerting SΣPDD [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) Bespoke exploit · hunting DSΣPCS [LLM] Langroid eval() exploit signature: __import__('os') / full_eval=True in cmdline or app logs Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Camel gridfs.* control-header injection inbound (CVE-2026-48204 exploit) Bespoke exploit · hunting SΣPDD [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS Bespoke exploit · hunting DSΣPDDCS [LLM] 9router (node) process spawning 'sudo -S sh' — CVE-2026-59800 command injection primitive Bespoke exploit · hunting DSΣPDDCS [LLM] zebrad node process execution at vulnerable version (CVE-2026-52735) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50027: mcp-memory-service: Missing Authentication on Bespoke exploit · hunting DSP [LLM] Ghost x-ghost-preview request carrying XSS payload markers (CVE-2026-53943 execution) Bespoke exploit · alerting SΣPDD [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) Bespoke exploit · hunting DSΣPDDCS [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Bespoke exploit · hunting DSP [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Bespoke exploit · hunting DSP Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Bespoke exploit · hunting DSP [LLM] TeamPCP Linux/Mac stdin-piped Python second stage (sys.executable -) Bespoke exploit · hunting DSPDDCS Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran Bespoke exploit · hunting DSP Article-specific behavioural hunt — TeamPCP deploys CanisterWorm on NPM following Trivy compromise Bespoke exploit · hunting DSP [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Bespoke exploit · hunting DSP Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Bespoke exploit · hunting DSP Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Bespoke exploit · hunting DSP [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters Bespoke exploit · alerting DSΣPDDCS [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL Bespoke exploit · alerting DSΣPDDCS [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app Bespoke exploit · hunting DSΣPDDCS [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Bespoke exploit · hunting DSP [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Bespoke exploit · hunting DSP [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) Bespoke exploit · alerting DSΣPCS [LLM] Pistache CVE-2022-26068 path traversal reading /etc/passwd via /doc/../ Bespoke exploit · alerting SΣP [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — NPM security: preventing supply chain attacks Bespoke exploit · hunting DSP [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) Bespoke exploit · alerting DSΣPCS [LLM] Node.js web process overwriting application .js service file (GraphQL path-traversal file write) Bespoke exploit · hunting DSΣPCS [LLM] Dirty Pipe (CVE-2022-0847): /etc/passwd or /etc/shadow modified by unexpected process Bespoke exploit · alerting DSΣPCS [LLM] Dirty Pipe SUID hijack: root-privileged process executing from /tmp or /dev/shm Bespoke exploit · alerting DSΣPDDCS [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection Bespoke exploit · hunting DSΣPCS [LLM] PwnKit pkexec executed with empty argv (CVE-2021-4034 exploit primitive) Bespoke exploit · alerting DSΣPDDCS [LLM] PwnKit GCONV_PATH artifact directory/file creation Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — URL confusion vulnerabilities in the wild: Exploring parser inconsistencies Bespoke exploit · hunting DSP [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Snyk uncovers malicious code activities in open source supply chain security on Bespoke exploit · hunting DSP Article-specific behavioural hunt — Developer driven workflows: Dockerfile image scanning, prioritization, and remed Bespoke exploit · hunting DSP Article-specific behavioural hunt — How I was hacking docker containers by exploiting ImageMagick vulnerabilities Bespoke exploit · hunting DSP [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — 10 Kubernetes Security Context settings you should understand Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command line tools for containers—using Snyk with Buildah, Podman, and Skopeo Bespoke exploit · hunting DSP [LLM] Unprivileged user-namespace creation (unshare CLONE_NEWUSER) preceding Linux privilege escalation Bespoke exploit · hunting DSΣPDDCS [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Python Poetry package manager and security integration with software composition Bespoke exploit · hunting DSP [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) Bespoke exploit · alerting DSΣPCS [LLM] Apache Airflow task run with --pickle flag (pickle deserialization, CVE-2020-11982) Bespoke exploit · hunting DSΣPDDCS [LLM] Prototype pollution payload in CLI args (--__proto__ / constructor.prototype) to Node tool Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Understanding filesystem takeover vulnerabilities in npm JavaScript package mana Bespoke exploit · hunting DSP [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) Bespoke exploit · alerting DSΣPDDCS [LLM] EC2 instance IMDS credential theft via curl/wget to security-credentials path Bespoke exploit · hunting DSΣPDDCS [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) Bespoke exploit · hunting DSΣPDDCS [LLM] Bower archive extraction arbitrary file write to sensitive paths (CVE-2019-5484 / Zip Slip) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Attacking an FTP Client: MGETting more than you bargained for Bespoke exploit · hunting DSP [LLM] FTP control-channel connection followed by write to Unix system path (CVE-2018-1315 traversal chain) Bespoke exploit · hunting DSPCS Article-specific behavioural hunt — Type Manipulation: Escaping Template Sandboxes Bespoke exploit · hunting DSP [LLM] Dust.js qs type-manipulation RCE payload in web request query string Bespoke exploit · alerting SΣP [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE) Bespoke exploit · hunting DSΣPCS

Installation (169)

[WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Article-specific behavioural hunt — Cisco warns of FMC static credential flaw exploited in zero-day attacks Bespoke install · hunting DSP [LLM] Fluentd aggregator pod spawns a shell (out_exec RCE execution) Bespoke install · alerting DSΣPDDCS [LLM] Backdoor payload written to /app by shell/downloader after Ruflo RCE Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands Bespoke install · hunting DSP [LLM] Git server-side hook file written (hooks/post-index-change) - CVE-2026-60004 persistence Bespoke install · alerting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Bespoke install · hunting DSP [LLM] Tengu ELF-header corruption ('ELFOOD') of Linux reboot/shutdown utilities Bespoke install · hunting DSΣPCS [LLM] Tengu guardian process masquerading as kernel thread [kworker/0:0] Bespoke install · hunting DSΣPDDCS [LLM] Tengu immutable-binary persistence via chattr +i on Linux/IoT Bespoke install · hunting DSΣPDDCS [LLM] BMC firmware flash / rogue admin account creation (iLOBleed-style persistence) Bespoke install · hunting SPDD [LLM] Linux core_pattern overwritten to memfd/pipe handler (CVE-2026-53264 privesc payoff) Bespoke install · alerting DSΣPDDCS [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc Bespoke install · alerting DSΣPCS [LLM] Recurring cron/shell-rc execution of .tf_cache/hw_probe.pyc payload Bespoke install · alerting DSΣPDDCS [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Bespoke install · hunting DSP [LLM] Hidden dot-prefixed PHP webshell dropped in web root (.journald-cache.php) Bespoke install · alerting DSΣPCS [LLM] Hermes AI agent launched in unattended YOLO mode (--yolo / HERMES_YOLO_MODE) Bespoke install · alerting DSΣPDDCS [LLM] redis-server writes to persistence paths (cron / SSH authorized_keys / systemd) Bespoke install · alerting DSΣPCS [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem persistence: git-credential-manager daemon installs systemd + cron Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem Unix persistence: cron/systemd/LaunchAgent write by Ruby-descended shell Bespoke install · hunting DSΣPDDCS [LLM] Siemens ROX II root cron table injection via web task scheduler (CVE-2025-40949) Bespoke install · hunting DSΣDD Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Bespoke install · hunting DSP [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] Malicious 'SHA1HULUD' self-hosted GitHub Actions runner installation / persistence Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Bespoke install · hunting DSP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot Bespoke install · alerting DSΣPDDCS [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) Bespoke install · hunting DSP [LLM] SSH authorized_keys written by non-SSH tooling (symlink repo payload) Bespoke install · hunting DSΣPDDCS [LLM] Joro writes a native .so plugin: attacker plugin drop before restart (CVE-2026-53649) Bespoke install · hunting DSΣPCS [LLM] EGroupware header.inc.php overwritten by web process (CVE-2026-27823 RCE persistence) Bespoke install · alerting DSΣPCS [LLM] DOGLEASH ELF payload download from UAT-7810 servers on Linux/embedded devices Bespoke install · hunting DSΣPDDCS [LLM] Langroid Neo4jChatAgent launched with allow_dangerous_operations enabled Bespoke install · hunting DSPDDCS [LLM] Node archive-extraction process writing to Linux persistence paths (decompress dir-escape) Bespoke install · hunting DSΣDDCS [LLM] Node extraction writing ld.so.preload or setuid/privileged path as root (CVE-2026-53486 privesc) Bespoke install · alerting DSΣDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54617: LaunchServer FileServerHandler has an unauthen Bespoke install · hunting DSP [LLM] Web-server process writes PHP file into Mautic config/cache/media/logs (zip-slip landing) Bespoke install · alerting DSΣPCS [LLM] Phantom Gyp binding.gyp install-time payload execution (Miasma npm worm) Bespoke install · alerting DSΣPDDCS [LLM] Passwordless sudo backdoor written for runner account (runner ALL=(ALL) NOPASSWD:ALL) Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing payload index.js from semantic-release-action path Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing codfish/semantic-release-action index.js payload on CI runner Bespoke install · alerting DSΣPDDCS [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) Bespoke install · alerting DSPDDCS [LLM] Atomic Arch persistence: systemd unit, cron or shell-rc written by AUR build / JS runtime Bespoke install · hunting DSΣPCS [LLM] Bun runtime executed from temp dir running _index.js payload (Hades Campaign) Bespoke install · alerting DSΣPDDCS [LLM] Miasma payload SHA256 hash hit (published Phantom Gyp IOCs) Bespoke install · hunting DSΣPDDCS [LLM] Miasma loader fetches standalone Bun v1.3.13 from oven-sh GitHub releases during install Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook executing oversized node index.js from @redhat-cloud-services package Bespoke install · alerting DSΣPDDCS [LLM] Bun spawned from npm install context executing /tmp/p*.js implant Bespoke install · alerting DSΣPDDCS [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan Bespoke install · alerting DSΣPDDCS [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match Bespoke install · hunting DSΣPDDCS [LLM] macOS LaunchAgent Persistence — com.user.kitty-monitor.plist (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Miasma worm index.js SHA256 IOC hit (Mini Shai-Hulud variant) Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook spawns node index.js under @redhat-cloud-services package path Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud 'gh-token-monitor' persistence daemon (LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] Laravel-Lang stealer file drop in .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Megalodon backdoor workflow file (SysDiag.yml / Optimize-Build.yml) written to .github/workflows/ Bespoke install · alerting DSΣPDDCS [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Bespoke install · hunting DSΣPDDCS [LLM] macOS LaunchAgent/LaunchDaemon plist persistence pointing at Python interpreter Bespoke install · hunting DSΣPDDCS [LLM] VS Code/Cursor extension host fetches dropper from nrwl/nx orphan commit on GitHub Bespoke install · hunting DSΣPDDCS [LLM] macOS Python backdoor persistence via kitty-monitor LaunchAgent and cat.py drop Bespoke install · alerting DSΣPDDCS [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node Bespoke install · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux Bespoke install · alerting DSΣPDDCS [LLM] durabletask PyPI dropper launches second-stage zipapp (python3 /tmp/managed.pyz) Bespoke install · alerting DSΣPDDCS [LLM] bun runtime executed on CI runner spawning python3 with sudo escalation Bespoke install · alerting DSΣPDDCS [LLM] Compromised node-ipc.cjs bundle write (~117KB) under node_modules Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud Linux daemon persistence: kitty/cat.py and systemd user service Bespoke install · alerting DSΣPDDCS [LLM] node-ipc stealer __ntw=1 environment marker in process command line Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP Mini Shai-Hulud stealer payload hash match (SHA256/SHA1) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm preinstall: node spawns Bun runtime from bun-dl-* tmpdir Bespoke install · alerting DSΣPDD [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops Bespoke install · alerting DSPDD Article-specific behavioural hunt — elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub A Bespoke install · hunting DSP [LLM] Malicious elementary.pth dropped in Python site-packages Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud: Python subprocess spawns `_runtime/start.py` from lightning site-packages Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Bespoke install · alerting DSΣPDD [LLM] npm preinstall hook executes 'node setup.mjs' / 'bun execution.js' (Mini Shai-Hulud SAP supply chain) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) Bespoke install · hunting DSΣPDD [LLM] Malicious tanstack npm postinstall hook executing postinstall.cjs Bespoke install · alerting DSΣPDDCS [LLM] Trinny marker file creation (.trinny-security-update) Bespoke install · alerting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] npm/PyPI dropper self-cleanup: find rm -rf of kube-health-tools in node_modules Bespoke install · alerting DSΣPDD [LLM] launchctl persistence registering zsh.profiler service from non-admin location Bespoke install · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP sysmon.py systemd-user persistence on developer host Bespoke install · alerting DSΣPDD [LLM] hackerbot-claw second-stage download: curl -sSfL pipe-bash from hackmoltrepeat.com/molt Bespoke install · alerting DSΣPDDCS [LLM] npm postinstall chain installs malicious 'openclaw' global package (cline@2.3.0 supply-chain IOC) Bespoke install · alerting DSΣPDDCS [LLM] OpenClaw persistence — launchd plist / systemd unit drop referencing 'openclaw' Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec Bespoke install · alerting DSΣPDD [LLM] Compromised litellm 1.82.7 / 1.82.8 PyPI install (TeamPCP supply-chain) Bespoke install · alerting DSΣPDDCS [LLM] litellm_init.pth Python autoload persistence drop Bespoke install · alerting DSΣPDDCS [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) Bespoke install · alerting DSΣPDDCS [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) Bespoke install · alerting DSΣPDDCS [LLM] macOS Axios RAT daemon spoof + ad-hoc codesign of hidden /private/tmp binary Bespoke install · alerting DSΣPDDCS [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 Bespoke install · alerting DSΣPDD [LLM] Malicious litellm_init.pth dropped to site-packages by pip (litellm==1.82.8 install artifact) Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP systemd backdoor — sysmon.py / sysmon.service persistence on CI runner Bespoke install · alerting DSΣPDD [LLM] Compromised trivy binary (v0.69.4-v0.69.6) execution by SHA1 hash Bespoke install · alerting DSΣPDD [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] ForceMemo: Node.js v22.9.0 spawned by Python from user home directory Bespoke install · alerting DSΣPDD [LLM] ForceMemo: init.json persistence file or i.js loader dropped by Python in user home root Bespoke install · hunting DSΣPDD [LLM] Python .pth startup hook executes subprocess to curl C2 (litellm fork-bomb pattern) Bespoke install · alerting DSΣPDDCS [LLM] CanisterWorm persistence: pglog/pg_state/internal-monitor systemd unit and /tmp/pglog drop Bespoke install · alerting DSΣPDDCS [LLM] Cacheract memdump.py download/execution on CI runner or developer host Bespoke install · alerting DSΣPDD [LLM] Secondary payload install: 'npm install -g openclaw' postinstall hook execution Bespoke install · alerting DSΣPDDCS [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity Bespoke install · alerting DSΣPDDCS [LLM] XZ Utils (CVE-2024-3094) build-time backdoor extraction from disguised test corpus Bespoke install · alerting DSΣPDDCS [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin Bespoke install · hunting DSΣPDDCS [LLM] SHA1-Hulud worm payload execution via npm preinstall (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node Bespoke install · alerting DSΣPDDCS [LLM] Execution / write of ESET APT Q2-Q3 2025 known-bad SHA256 payload Bespoke install · hunting DSΣPDDCS [LLM] Installation or presence of malicious postmark-mcp npm package (v1.0.16+) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud bundle.js postinstall payload by known SHA256 hash Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk Bespoke install · alerting DSΣPDDCS [LLM] Install / lockfile mention of the 28 compromised Qix-campaign package@versions Bespoke install · hunting DSΣPDDCS [LLM] Node/npm postinstall spawning AI coding agent CLI (s1ngularity execution chain) Bespoke install · alerting DSΣPDDCS [LLM] Installation of poisoned Ultralytics PyPI package (v8.3.41 / 8.3.42 / 8.3.45 / 8.3.46) Bespoke install · alerting DSΣPDDCS [LLM] cups-browsed writing new PPD or config under /etc/cups or /var/cache/cups Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Identifying insecure C Code with Valgrind and fixing with Snyk Code Bespoke install · hunting DSP [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Code injection in Python: examples and prevention Bespoke install · hunting DSP Article-specific behavioural hunt — High severity vulnerability found in libcurl and curl (CVE-2023-38545) Bespoke install · hunting DSP [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Mitigating path traversal vulns in Java with Snyk Code Bespoke install · hunting DSP [LLM] Bash reverse shell via /dev/tcp file-descriptor redirection Bespoke install · alerting DSPDDCS Article-specific behavioural hunt — Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit Bespoke install · hunting DSP Article-specific behavioural hunt — Exploring 3 types of directory traversal vulnerabilities in C/C++ Bespoke install · hunting DSP [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — "Dirty Pipe" Linux vulnerability and your containerized applications (CVE-2022-0 Bespoke install · hunting DSP [LLM] Root shell spawned by pkexec with empty parent command line (PwnKit post-exploitation) Bespoke install · alerting DSΣPCS [LLM] npm/node install lifecycle spawning interactive or reverse shell Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — SourMint malicious SDK research write up Bespoke install · hunting DSP Article-specific behavioural hunt — SourMint malicious SDK research writeup Bespoke install · hunting DSP Article-specific behavioural hunt — Breaking out of message brokers Bespoke install · hunting DSP [LLM] World-writable executable run as a shell (-c) — minimist polluted shell privesc payload Bespoke install · hunting DSΣPDDCS [LLM] npm/yarn/pnpm planting or overwriting a binary in a system bin directory Bespoke install · hunting DSΣPCS [LLM] Malicious bootstrap-sass 3.2.0.3 gem implant on disk (middleware.rb backdoor / SHA256) Bespoke install · hunting DSΣPCS Article-specific behavioural hunt — Snyking in - Directory traversal vulnerability exploit in the st package Bespoke install · hunting DSP [LLM] Host runc binary overwrite from container (CVE-2019-5736 escape-to-host) Bespoke install · alerting DSΣPCS Article-specific behavioural hunt — The most common vulnerabilities in Maven Central and npm Bespoke install · hunting DSP Article-specific behavioural hunt — Using ES2015 Proxy for fun and profit Bespoke install · hunting DSP

Command & Control (61)

[WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [LLM] Shell/curl spawned under Fluentd aggregator makes external network egress (post-RCE C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] Artifactory host egress to public internet (package-registry sandbox escape) Bespoke c2 · hunting DSΣPCS [LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) Bespoke c2 · hunting DSΣPCS [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 Bespoke c2 · hunting DSΣPDDCS [LLM] Java (fat-JAR) outbound fetch of remote JAR / SSRF egress to public IP (CVE-2026 Bespoke c2 · hunting DSPDDCS [LLM] Callback to Hermes operator staging/C2 infrastructure (VShell / ShadowPad / Hades) Bespoke c2 · hunting DSΣPDDCS [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) Bespoke c2 · alerting DSΣPDDCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 Bespoke c2 · hunting DSΣPCS [LLM] Atomic Arch C2/exfil: build-spawned egress to temp.sh and github.com/fardewoak/nodejs-argo Bespoke c2 · alerting DSΣPDDCS [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper Bespoke c2 · alerting DSΣPDDCS [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) Bespoke c2 · alerting DSΣPCS [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud Bespoke c2 · alerting DSΣPDDCS [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host Bespoke c2 · alerting DSΣPDD [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky Bespoke c2 · alerting DSΣPDDCS [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) Bespoke c2 · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDD [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) Bespoke c2 · alerting DSΣPDD [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner Bespoke c2 · hunting DSΣPDDCS [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil Bespoke c2 · hunting DSΣPDDCS [LLM] GlassWorm Solana blockchain dead-drop C2 lookup via public RPC endpoints from Node Bespoke c2 · hunting DSΣPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com Bespoke c2 · alerting DSΣPDD [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) Bespoke c2 · alerting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1 Bespoke c2 · hunting DSΣPDDCS [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] Reverse shell via ncat -e spawned by Node.js app (SonicJS GraphQL path-traversal RCE) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound or inbound connection to TrojanOrders C2/source IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCS [LLM] ImageMagick convert lineage egress to public IP (url() delegate / netcat reverse shell) Bespoke c2 · hunting DSΣPCS [LLM] Ruby/Rails process fetching remote code from pastebin.com raw (rest-client 1.6.13 backdoor) Bespoke c2 · alerting DSΣPCS [LLM] strong_password 0.0.7 backdoor: Ruby app server fetches second-stage payload from pastebin.com/raw/xa456PFt Bespoke c2 · alerting DSΣPCS [LLM] strong_password 0.0.7 backdoor: beacon to home server smiley.zzz.com.ua Bespoke c2 · alerting DSΣPDDCS

Actions on Objectives (145)

[WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Linux Add Files In Known Crontab Directories ESCU actions · hunting P Linux Auditd At Application Execution ESCU actions · hunting P Linux Auditd Copy Fail Privilege Escalation ESCU actions · alerting P Linux Auditd Edit Cron Table Parameter ESCU actions · hunting P Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File ESCU actions · hunting P Linux Auditd Service Restarted ESCU actions · hunting P Linux Auditd Service Started ESCU actions · hunting P Linux Common Process For Elevation Control ESCU actions · hunting P Linux Deleting Critical Directory Using RM Command ESCU actions · alerting P Linux Deletion Of Cron Jobs ESCU actions · hunting P Linux Dirty Frag Kernel Privilege Escalation ESCU actions · alerting P Linux Disable Services ESCU actions · alerting P Linux Docker Shell Execution ESCU actions · hunting P Linux Indicator Removal Clear Cache ESCU actions · alerting P Linux Iptables Firewall Modification ESCU actions · hunting P Linux Kworker Process In Writable Process Path ESCU actions · hunting P Linux Magic SysRq Key Abuse ESCU actions · alerting P Linux Medusa Rootkit ESCU actions · alerting P Linux Possible Access To Credential Files ESCU actions · hunting P Linux Possible Append Cronjob Entry on Existing Cronjob File ESCU actions · hunting P Linux Possible Cronjob Modification With Editor ESCU actions · hunting P Linux Service File Created In Systemd Directory ESCU actions · hunting P Linux Service Restarted ESCU actions · hunting P Linux Service Started Or Enabled ESCU actions · hunting P Linux Stop Services ESCU actions · alerting P Linux System Reboot Via System Request Key ESCU actions · alerting P Linux Unix Shell Enable All SysRq Functions ESCU actions · hunting P MacOS Keychains Dumped ESCU actions · alerting P MacOS plutil ESCU actions · alerting P [LLM] Cloud instance metadata (IMDS 169.254.169.254) queried by a recon tool inside a workload Bespoke actions · hunting DSΣPDDCS [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) Bespoke actions · alerting SΣPCS [LLM] Fluentd aggregator pod reaches cloud IMDS 169.254.169.254 (credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Ruflo AgentDB memory poisoning via MCP pattern-store write Bespoke actions · hunting SΣPDD [LLM] Cloud instance-metadata (IMDS 169.254.169.254) credential theft by interpreter/shell in pipeline pod Bespoke actions · alerting DSΣDDCS [LLM] goshs process deletes or renames served files while launched with --no-delete (impact confirmation) Bespoke actions · alerting DSΣPDDCS [LLM] vBulletin web-server process (php-fpm/apache/nginx) spawning OS shell after CVE-2026-61511 Bespoke actions · alerting DSΣPDDCS [LLM] Successful IPMI/BMC login from unexpected source using default ADMIN/root accounts Bespoke actions · hunting SPDD [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation Bespoke actions · alerting DSΣPDDCS [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores Bespoke actions · alerting DSΣPDDCS [LLM] OpenDJ proxied-auth fan-out — one source assuming many distinct authz identities Bespoke actions · hunting SPDD [LLM] Microsoft Kiota APIPlugin manifest generation from OpenAPI spec (CVE-2026-59864) Bespoke actions · hunting DSΣPDDCS [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] actions/attest push-to-registry invocation using @sigstore/oci — externally influenced destination (CVE-2026-59891) Bespoke actions · hunting DSΣPDDCS [LLM] Build/attestation tooling reading ~/.docker/config.json (credential harvest surface, CVE-2026-59891) Bespoke actions · hunting DSΣPCS [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) Bespoke actions · hunting DSΣDD [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host Bespoke actions · hunting DSΣPDDCS [LLM] DIRAC service process deletes or truncates its own logs (anti-forensics post-RCE) Bespoke actions · hunting DSΣPDDCS [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) Bespoke actions · hunting DSΣPDDCS [LLM] TSDProxy management API abuse: /api/v1 request with forged x-tsdproxy-id and auth token Bespoke actions · alerting SPDD [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd Bespoke actions · hunting DSΣPDDCS [LLM] Nuclio cron pod shell reads Kubernetes service-account token (CVE-2026-52831 credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] EGroupware web runtime (php-fpm/apache) spawning a shell or network tool — CVE-2026-27823 RCE execution Bespoke actions · hunting DSΣPCS [LLM] Mass graph destruction via unbounded DETACH DELETE in Neo4j query.log Bespoke actions · alerting SΣPDD [LLM] Cilium Envoy admin socket abuse: TLS secret / config disclosure via admin.sock (CVE-2026-49445) Bespoke actions · hunting DSΣPDDCS [LLM] Cilium Envoy admin socket abuse: destructive DoS via /quitquitquit /drain_listeners (CVE-2026-49445) Bespoke actions · alerting DSΣPDDCS [LLM] Credential harvest via /proc/<pid>/mem read of GitHub Actions Runner.Worker Bespoke actions · hunting DSΣPDDCS [LLM] GitHub Actions Runner.Worker memory read via /proc/<pid>/mem (CI secret unmasking) Bespoke actions · alerting DSΣPDDCS [LLM] Runner.Worker process memory scrape via /proc on self-hosted GitHub Actions runner Bespoke actions · alerting DSΣPDDCS [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions Bespoke actions · hunting DSΣPCS [LLM] CI runner secret theft via /proc/<pid>/mem read of Runner.Worker (Miasma memory scraper) Bespoke actions · hunting SΣPCS [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] Cloud credential file access by node/python runtime Bespoke actions · hunting DSΣPDDCS [LLM] Locale-conditional rm -rf wiper command from python/node runtime Bespoke actions · alerting DSΣPDDCS [LLM] Process reading /proc/<pid>/mem of GitHub Actions Runner.Worker (in-memory secret extraction) Bespoke actions · alerting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host Bespoke actions · alerting DSΣPDDCS [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) Bespoke actions · hunting DSPDDCS [LLM] AI coding agent bulk-deleting JUnit test files after jqwik resolution Bespoke actions · alerting DSPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org Bespoke actions · alerting DSPDDCS [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session Bespoke actions · hunting DSPDDCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) Bespoke actions · alerting DSΣPDDCS [LLM] GitHub Actions Runner.Worker process-memory secret scraping via /proc Bespoke actions · hunting DSΣPDDCS [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets Bespoke actions · alerting DSΣPDDCS [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) Bespoke actions · alerting DSΣPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary Bespoke actions · alerting DSΣPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] Svix Ingest webhook exfiltration relay (src_3387PLMB2uhXOBe3Q8sHu) Bespoke actions · alerting DSΣPDDCS [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Credential archive staging — trin.tar.gz created by python process Bespoke actions · alerting DSΣPDDCS [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) Bespoke actions · alerting DSΣPDD [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk Bespoke actions · alerting DSΣPDDCS [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) Bespoke actions · alerting DSΣPDDCS [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem Bespoke actions · hunting DSPDD [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in temp Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Host-root mount wiper: chroot /mnt/host reboot -f or rm -rf / --no-preserve-root Bespoke actions · alerting DSΣPDDCS [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` Bespoke actions · alerting DSΣPDD [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint Bespoke actions · alerting DSΣPDDCS [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt Bespoke actions · hunting DSΣPDDCS [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx Bespoke actions · alerting DSΣPDDCS [LLM] Ultralytics PyPI supply-chain XMRig coinminer execution from /tmp/ultralytics_runner Bespoke actions · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke actions · hunting DSPDDCS [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' Bespoke actions · alerting DSΣPDDCS [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] Cloud metadata service (IMDS) access from npm / node child process Bespoke actions · alerting DSPDDCS [LLM] SHA1-Hulud wiper: mass deletion of user home directory by npm/node descendant Bespoke actions · alerting DSPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS [LLM] Node process creating GitHub repo via api.github.com (s1ngularity exfil channel) Bespoke actions · hunting DSPDDCS [LLM] Runner.Worker process memory dumped via /proc/PID/mem read on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Git checkout of compromised tj-actions/changed-files commit on runner host Bespoke actions · hunting DSPDDCS [LLM] HTTP/2 server crash-loop on internet-facing host (CONTINUATION flood DoS exploitation signal) Bespoke actions · alerting DSPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal Bespoke actions · alerting SΣP [LLM] Spring4Shell post-exploitation arbitrary file read (/etc/passwd via relocated docBase) Bespoke actions · alerting SΣPCS [LLM] CodeCov Bash Uploader CI env-var exfiltration via curl (<<<<<< ENV marker) Bespoke actions · alerting DSΣPDDCS [LLM] SuiteCRM upload/files .htaccess deleted by web-server process (PHAR gadget) Bespoke actions · alerting DSΣPCS [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file Bespoke actions · alerting DSΣPDDCS [LLM] Arbitrary child process from systeminformation inetChecksite shell pipeline Bespoke actions · hunting DSΣP [LLM] Python interpreter reading SSH/GPG private keys (jeIlyfish key theft) Bespoke actions · hunting DSΣPCS [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE Bespoke actions · hunting DSΣPCS [LLM] FTP client / Hive (commons-net) overwrites Unix auth files via path-traversal LIST (CVE-2018-1315) Bespoke actions · alerting DSΣPCS [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) Bespoke actions · alerting DSΣPDDCS

Recent articles citing Linux-targeted detections