Clankerusecase
Windows detection coverage
← Back to main site
Home/ Targets/ Windows

🪟Windows detections

Clankerusecase tracks 1825 detection use cases covering the Windows attack surface across 298 MITRE ATT&CK techniques.

Detections targeting Windows endpoints — Sysmon / Security event log / Defender DeviceProcessEvents.

Open Detection Library → View on the matrix
1825Use cases
298Techniques
60Articles
6Kill-chain phases

Top techniques on Windows (25)

Reconnaissance (10)

[LLM] Internal domain reconnaissance burst (net view/share/session, nltest, session enum) Bespoke recon · hunting DSPDDCS [LLM] Autonomous mass-scan burst: langflow_poc.py multi-threaded FOFA target sweep Bespoke recon · alerting DSΣPDDCS [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] Vulnerable @hypequery/clickhouse package (<2.5.1) present in node_modules Bespoke recon · hunting DSΣPCS [LLM] goshs launched with vulnerable --no-delete + WebDAV config (CVE-2026-64863) Bespoke recon · alerting DSΣPDDCS [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] FileBrowser instance configured with auth.method=proxy (exploitable-config exposure) Bespoke recon · hunting DSΣPDDCS [LLM] SiYuan kernel config (conf.json) written — audit for empty/missing AccessAuthCode Bespoke recon · hunting DSΣPDDCS [LLM] node-ipc geofencing beacon: node.exe resolving/contacting api.ipgeolocation.io during install Bespoke recon · hunting DSΣPDDCS [LLM] Gradle plugin-publish run with verbose logging leaks pre-signed AWS URL (CVE-2020-7599) Bespoke recon · hunting DSΣPDDCS

Delivery (144)

Email attachment opened from external sender Internal delivery · hunting DSP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [LLM] Evooo1Bot loader retrieval — connection to hardcoded loader host 91.92.40.118 Bespoke delivery · hunting DSΣPDDCS [LLM] Rogue vSphere admin account creation via GoodMoodle-VCFleet UA from 146.59.252.178 Bespoke delivery · hunting DSΣPDDCS [LLM] AmnesiaStealer ClickFix loader: macOS shell fetching payload from fake-GitHub / Amnesia C2 host Bespoke delivery · alerting DSΣPCS [LLM] Antino second-stage download from Jewelbug fake-Flash/installer domains Bespoke delivery · alerting DSΣPDDCS [LLM] JWR phishing-kit landing: victim beacon + ws-worker.js load in web proxy telemetry Bespoke delivery · alerting DSΣP [LLM] PATCHCORD delivery via TMS_AfghanTelecom.exe Inno Setup installer / known hashes Bespoke delivery · hunting DSΣPDDCS [LLM] macOS ClickFix: Terminal spawns shell decoding Base64 / curl-pipe payload Bespoke delivery · hunting DSΣPCS [LLM] Armored Likho Tauri donation-app dropper C2 (orderapiserver.info catalog endpoints) Bespoke delivery · alerting DSΣPDDCS [LLM] Trojanized Enveil 'SecurityPDF' viewer downloaded from fake sites and dropping Troy loader (new.exe) Bespoke delivery · hunting DSΣPDDCS [LLM] Nuxt dev server bound to non-loopback interface (nuxi/nuxt dev --host) Bespoke delivery · hunting DSΣPDDCS [LLM] Inbound non-loopback connection to Nuxt/Vite dev server (node.exe HMR port) Bespoke delivery · hunting DSPCS [LLM] mshta.exe launched with inline http/https URL argument Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious JavaScript entity file written into Flowise storage by node Bespoke delivery · hunting DSΣPCS [LLM] Phorpiex dropper D2IP payload retrieval from 178.16.54.109 (no DNS) Bespoke delivery · hunting DSΣPDDCS [LLM] First-seen browser egress to abused cloud-PaaS phishing domains (workers.dev / pages.dev / vercel.app / github.io / netlify.app / dweb.link) Bespoke delivery · hunting DSPDDCS [LLM] keyv npm compromise: malicious payload file drop by SHA256 (setup.mjs / Math_Symbol.js) Bespoke delivery · hunting DSΣPDDCS [LLM] ClickFix execution reaching CaptiveCrunch infrastructure or dropping svchost32 Bespoke delivery · alerting DSΣPDDCS [LLM] XCSSET v40 trojanized Xcode build spawning curl-to-shell downloader Bespoke delivery · hunting DSΣPCS [LLM] Installation of compromised @joyfill/components or @joyfill/layouts 2773 beta packages Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious mrmustard 0.7.4 artifact by hash or filename Bespoke delivery · hunting DSΣPCS [LLM] Vulnerable @prompty/core package present in node_modules (GHSA-w28w-gp39-m4p6 exposure) Bespoke delivery · hunting DSΣPDDCS [LLM] Kiota-generated *-apiplugin.json manifest written to disk (CVE-2026-59864 artifact) Bespoke delivery · hunting DSΣPDDCS [LLM] msaRAT delivery: curl.exe fetching fake Windows-update MSI to ProgramData over HTTP Bespoke delivery · alerting DSΣPDDCS [LLM] Shai-Hulud / GhostAction malicious workflow artifact dropped on runner or repo checkout Bespoke delivery · hunting DSΣPDDCS [LLM] Endpoint DNS resolution or web connection to npm phishing domain npmjs.help Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable @sigstore/oci (<=0.7.0) installed into node_modules — incl. transitive deps (CVE-2026-59891) Bespoke delivery · hunting DSΣPDDCS [LLM] Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke delivery · alerting DSΣPDDCS [LLM] Ruby/gem process downloading payload from git.disroot.org (SleeperGem) Bespoke delivery · alerting DSΣPDDCS [LLM] SleeperGem malicious gem artifacts written to gems path (git_credential_manager / Dendreo / fastlane-plugin) Bespoke delivery · alerting DSΣPDDCS [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) Bespoke delivery · alerting DSΣPDDCS [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious @velora-dex/sdk (9.4.1/9.4.2) pulled into GitHub Actions build runner Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @velora-dex/sdk npm package (9.4.1/9.4.2) installed on CI runner Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of compromised @asyncapi package versions Bespoke delivery · hunting DSΣPDDCS [LLM] TuxBot Telnet/ADB scanner fan-out (credential brute-force propagation) Bespoke delivery · alerting DSPCS [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Bespoke delivery · hunting DSΣPDDCS [LLM] Anyquery server mode bound to all interfaces (exposed unauthenticated MySQL port) Bespoke delivery · hunting DSΣPDDCS [LLM] Inbound connection to Anyquery listener from a public IP Bespoke delivery · hunting DSPCS [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js Bespoke delivery · alerting DSΣPDDCS [LLM] npm maintainer credential-phish lookalike domain npmjs.help (chalk/debug ATO) Bespoke delivery · alerting DSΣPDDCS [LLM] jscrambler npm supply-chain: malicious dist/intro.js binary container drop Bespoke delivery · alerting DSΣPDDCS [LLM] FileBrowser reverse-proxy bypass: direct external access to exposed port 8085 Bespoke delivery · alerting DSΣPDDCS [LLM] Non-SiYuan process writing synced snippet store data\snippets\conf.json Bespoke delivery · hunting DSΣPDDCS [LLM] Transitive install of poisoned @injectivelabs 1.20.21 build under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint Bespoke delivery · hunting DSΣP [LLM] tj-actions/changed-files malicious commit 0e58ed86 referenced on host (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious easy-day-js typosquat package written into node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @immobiliarelabs Backstage plugin on disk (binding.gyp + index.js / known hashes) Bespoke delivery · hunting DSΣPDDCS [LLM] Malicious index.js dropped into codfish/semantic-release-action runner checkout Bespoke delivery · hunting DSΣPDDCS [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) Bespoke delivery · hunting DSΣPDDCS [LLM] Known Miasma index.js payload hash present on CI runner (codfish action) Bespoke delivery · alerting DS [LLM] easy-day-js malicious setup.cjs written/deleted under node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] AUR build pulls malicious npm/Bun dependency (atomic-lockfile / js-digest / lockfile-js) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious easy-day-js package installed into node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 Bespoke delivery · alerting DSΣPDDCS [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious 'postmark-mcp' MCP server package present/executing on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Scripting interpreter downloads Bun v1.3.14 runtime from oven-sh GitHub releases Bespoke delivery · hunting DSPCS [LLM] Miasma-tainted package install: binding.gyp dropped into known-compromised npm package paths Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma/Node-gyp loader file hashes present on developer or CI host Bespoke delivery · hunting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) Bespoke delivery · alerting DSΣPDDCS [LLM] jqwik-engine 1.10.0 malicious JAR on disk (SHA256 / filename match) Bespoke delivery · hunting DSΣPDDCS [LLM] Install or update of @redhat-cloud-services npm package post-2026-06-01 (IOC version watchlist) Bespoke delivery · hunting DSΣPDDCS [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint Bespoke delivery · hunting DSΣPDDCS [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree Bespoke delivery · hunting DSΣPDDCS [LLM] Composer install of malicious helpers.php in laravel-lang vendor package Bespoke delivery · hunting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] Endpoint DNS or web traffic to fake FIFA World Cup 2026 typosquat domain Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised Nx Console VS Code extension (nrwl.angular-console v18.94.0/18.95.0/18.100.0) install on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious node-ipc package landed on disk under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm payload dropped under node_modules (router_init.js / tanstack_runner.js / known SHA256) Bespoke delivery · hunting DSΣPDD [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) Bespoke delivery · alerting DSΣPDDCS [LLM] Install of trojaned elementary-data 0.23.3 via pip / poetry / uv Bespoke delivery · alerting DSΣPDDCS [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image Bespoke delivery · alerting DSΣPDDCS [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) Bespoke delivery · alerting DSPDDCS [LLM] Known-bad tanstack 2.0.4-2.0.7 package tarball SHA256 file hash on disk Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host Bespoke delivery · alerting DSΣPDDCS [LLM] Qinglong cryptominer payload download from file.551911.xyz Bespoke delivery · alerting DSΣPDDCS [LLM] Context.ai compromised Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) present on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Access to NGate distribution domain protecaocartao[.]online (HandyPay trojan + APK delivery) Bespoke delivery · hunting DSΣP [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious axios or plain-crypto-js package files written to node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release Bespoke delivery · alerting DSΣPDD [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 Bespoke delivery · alerting DSΣPDDCS [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 Bespoke delivery · hunting DSΣPDDCS [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk Bespoke delivery · hunting DSΣPDD [LLM] Compromised react-native-international-phone-number / react-native-country-select files written to node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Attacker-controlled scoped npm relay packages on disk (@usebioerhold8733 / @agnoliaarisian7180) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious typosquat npm packages installed on disk (ts-bign / big-nunber / levex-refa / lint-builder) Bespoke delivery · hunting DSΣPDD [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious litellm 1.82.7/1.82.8 wheel install drops litellm_init.pth in site-packages Bespoke delivery · alerting DSΣPDDCS [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Bespoke delivery · alerting DSPDD [LLM] PromptSpy/VNCSpy Android trojan distribution & fake-JPMorgan domains (mgardownload.com / m-mgarg.com) Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of unauthorized cline@2.3.0 npm package on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) Bespoke delivery · hunting DSΣPDD [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) Bespoke delivery · alerting DSΣPDDCS [LLM] Dev endpoint contacts ClawHub / skills.sh agent-skill marketplace Bespoke delivery · hunting DSΣPDDCS [LLM] Executable dropped into C:\inetpub\pub\ shared directory Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) Bespoke delivery · alerting DSΣPDDCS [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] IndonesianFoods npm spam package install on developer/CI endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Browser/HTTPS traffic to npmjs.help credential-harvesting page Bespoke delivery · alerting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS [LLM] Scavenger Loader DLL (node-gyp.dll) written inside node_modules of CVE-2025-54313 packages Bespoke delivery · alerting DSΣPDDCS [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) Bespoke delivery · alerting DSΣPDDCS [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry Bespoke delivery · alerting DSΣPDDCS [LLM] Browser/proxy fetch of compromised @lottiefiles/lottie-player from unpkg or jsDelivr CDN Bespoke delivery · alerting DSΣP [LLM] npm/yarn/pnpm install of himanshutester002 suspicious aliased packages (string-width-cjs et al) Bespoke delivery · alerting DSΣPDDCS [LLM] Inbound UDP/631 (CUPS IPP discovery) from external network Bespoke delivery · hunting DSΣPDDCS [LLM] Polyfill.io supply-chain compromise: egress to Funnull-controlled CDN cluster Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable Moq 4.20.0 or Devlooped.SponsorLink NuGet package landed on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] JVM outbound fetch of remote class/JAR to public host — URLClassLoader gadget Bespoke delivery · hunting DSPDDCS [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) Bespoke delivery · hunting DSΣPDDCS [LLM] Lockfile injection: npm/yarn fetching dependencies from GitHub gist/repo instead of the registry Bespoke delivery · hunting DSΣPDDCS [LLM] node-ipc protestware dropper file 'ssl-geospec.js' written under node_modules\node-ipc Bespoke delivery · alerting DSΣPDDCS [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) Bespoke delivery · alerting DSΣPDDCS [LLM] gxm-reference encrypted-payload artifacts written to disk (obfusc/mac/win/lin .enc.js) Bespoke delivery · alerting DSΣPDDCS [LLM] Install/resolution of sabotaged npm packages colors@1.4.1/1.4.2/liberty-2 or faker@6.6.6 Bespoke delivery · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI connection (Log4Shell second-stage class fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Known-malicious npm packages flatmap-stream / lyft-dataset-sdk landing on host Bespoke delivery · alerting DSΣPDDCS [LLM] Attacker-staged .session deserialization payload written outside Tomcat's session store Bespoke delivery · hunting DSΣPDDCS [LLM] Maven fetching dependencies over cleartext HTTP (MITM-exposed artifact download) — CVE-2021-26291 Bespoke delivery · hunting DSPDDCS [LLM] Installation of Snyk-flagged malicious npm packages (radar-cms, rcenodejs, paychex-*) Bespoke delivery · alerting DSΣPDDCS [LLM] hacktask typosquat npm package drops postinstall payload 'package-setup.js' Bespoke delivery · hunting DSΣPDDCS [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) Bespoke delivery · hunting DSΣPDDCS [LLM] Typosquatted PyPI package install: jeIlyfish / python3-dateutil Bespoke delivery · alerting DSΣPDDCS [LLM] npm/yarn dependency fetched from non-registry source (lockfile resolved-URL hijack) Bespoke delivery · hunting DSΣPDDCS [LLM] Malicious flatmap-stream npm package present in node_modules (event-stream supply-chain backdoor) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious npm flatmap-stream / event-stream@3.3.6 dependency dropped to endpoint disk Bespoke delivery · alerting DSΣPDDCS

Exploitation (594)

Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal exploit · alerting DSΣP Office app spawning script/LOLBin child process Internal exploit · alerting DSΣP PowerShell encoded / obfuscated command Internal exploit · alerting DSΣP Trusted vendor binary / installer launching unusual children Internal exploit · hunting DSΣP [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Gitea Service Account Post-Exploitation: git/gitea Spawning Interpreters or Egressing to Cloud Metadata Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) Internal exploit · alerting DSΣPDDCS [WEEKLY] Public-Facing App Auth-Bypass to Server-Side Code Execution (web-server process spawning a shell/interpreter) Internal exploit · alerting DSΣPDDCS [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [LLM] Ray host OOB callback to oast.fun/interact.sh (ShadowRay exploit validation) Bespoke exploit · alerting DSΣPDDCSCW [LLM] One host fanning out to multiple internal Ray dashboards (8265/10001) Bespoke exploit · hunting DSPDDCSCW [LLM] MLflow/Python server egress to cloud metadata IP 169.254.169.254 (SSRF landing) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-m5w8-4gq2-6f8x: vm2: NodeVM `builtin: ['*']` exposes `os` Bespoke exploit · hunting DSP [LLM] Node.js runtime spawning a shell/command interpreter (vm2 sandbox breakout RCE) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47686: VM2 has Missing Error.cause Sanitization that Bespoke exploit · hunting DSP [LLM] Node.js runtime spawning shell/recon child process (vm2 CVE-2026-47686 escape RCE) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55158: conflibot vulnerable to command injection via Bespoke exploit · hunting DSP [LLM] conflibot command injection: shell spawned by Node action with git + shell metacharacters (CVE-2026-55158) Bespoke exploit · alerting DSΣPCS [LLM] PTC Windchill Java/Tomcat process spawning shell or flst.txt recon Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Pro Bespoke exploit · hunting DSP Article-specific behavioural hunt — Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Bespoke exploit · hunting DSP [LLM] vCenter CVE-2026-59310 PoC cron drop + backdoor fetch (zz-poc59310-syslog.log) Bespoke exploit · hunting DSΣPDDCS [LLM] Passwordless root sudoers grant for perfcharts (/etc/sudoers.d/vmware-perf) Bespoke exploit · alerting DSΣPDDCS [LLM] vmdir credential theft via /tmp/.vmware-perf-upd.sh and vmafd module Bespoke exploit · hunting DSΣPDDCS [LLM] Endpoint traffic to SafePal phishing site safepal.support / lookalike domains Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-dro Bespoke exploit · hunting DSP [LLM] SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff Bespoke exploit · hunting DSΣPDDCS [LLM] Inbound Screen Sharing (VNC port 5900) from a public IP to a Mac — CVE-2026-65400 exposure Bespoke exploit · hunting DSΣPCS [LLM] macOS screensharingd spawning a shell or downloader as root (post-exploit RCE) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — Top enterprise SCA tools in 2026 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Window Bespoke exploit · hunting DSP [LLM] Browser navigation to BitB Calendly-lookalike phishing host (rare .cfd/.work TLD) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Window Bespoke exploit · hunting DSP [LLM] HoneyMyte DLL side-load: renamed Sangfor defender.exe loads malicious libngs.dll from fake Defender dir Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud Bespoke exploit · hunting DSP Article-specific behavioural hunt — Curiouser and Curiouser Bespoke exploit · hunting DSP Article-specific behavioural hunt — New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure Bespoke exploit · hunting DSP Article-specific behavioural hunt — Dissecting the JWR phishing framework Bespoke exploit · hunting DSP Article-specific behavioural hunt — Armored Likho expands its cyber-espionage toolkit Bespoke exploit · hunting DSP Article-specific behavioural hunt — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Bespoke exploit · hunting DSP [LLM] FudModule SYSTEM injection: msiexec.exe spawned by services.exe running as SYSTEM Bespoke exploit · alerting DSΣPDDCS [LLM] ColdFusion server process spawning OS shell / LOLBin (CVE-2026-48362 / CVE-2026-48273 RCE) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Acce Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Att Bespoke exploit · hunting DSP Article-specific behavioural hunt — Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to d Bespoke exploit · hunting DSP Article-specific behavioural hunt — Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channe Bespoke exploit · hunting DSP Article-specific behavioural hunt — The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Co Bespoke exploit · hunting DSP Article-specific behavioural hunt — DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized rec Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptograph Bespoke exploit · hunting DSP Article-specific behavioural hunt — ChainDrop: Inside a Self-Propagating npm Worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Why metaphor may dictate your security strategy Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication Bypass via Path Traver Bespoke exploit · hunting DSP [LLM] Nuxt/Vite dev server (node.exe) spawns shell or LOLBin child — DevTools RPC RCE Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — ChainDrop supply chain compromise: Anatomy of a self-propagating worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-70477: Flowise: CSV Agent Prompt Injection Remote Cod Bespoke exploit · hunting DSP [LLM] Flowise (node) process spawning a shell — CVE-2026-70477 pyodide→child_process RCE landing Bespoke exploit · alerting DSΣPCS [LLM] mshta.exe spawning command interpreter or secondary LOLBin Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69264: Flowise: RCE via CSVAgent csvFile data URI bas Bespoke exploit · hunting DSP [LLM] Flowise Node.js process spawning shell/interpreter child (CSVAgent RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Flowise Node process burst-spawning shell/recon children within seconds (post-RCE) Bespoke exploit · alerting DSPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph b Bespoke exploit · hunting DSP [LLM] Flowise node runtime spawns shell interpreter (post-exploit command execution) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via P Bespoke exploit · hunting DSP [LLM] Flowise node.js spawns Unix shell/command binaries as root (CSVAgent Pyodide RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sandbox Escape in exec Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69251: Flowise RCE via TypeORM DataSource Bespoke exploit · hunting DSP [LLM] Flowise node process spawning shell/netcat (TypeORM DataSource RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Keyv and friends compromised in active Shai-Hulud supply chain attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69240: Sequelize: SQL Injection (Oracle DB) Bespoke exploit · hunting DSP Article-specific behavioural hunt — An analysis of incidents at Brazilian educational institutions Bespoke exploit · hunting DSP [LLM] Potato privilege-escalation tooling (GodPotato / SweetPotato / BadPotato) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution Bespoke exploit · hunting DSP Article-specific behavioural hunt — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware deliver Bespoke exploit · hunting DSP Article-specific behavioural hunt — Anthropic's Fever Dream: Claude's package that stole real keys Bespoke exploit · hunting DSP [LLM] AWS Amplify UI Builder create-component CLI invocation on endpoint/CI host (CVE-2025-4318) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfus Bespoke exploit · hunting DSP [LLM] Node.js spawning a shell or detached node -e child (Joyfill RAT execution) Bespoke exploit · hunting DSΣPDDCS [LLM] Ruby/Puma Rails web process spawns a shell (post-file-read RCE via forged secret_key_base cookie) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — You were onto something with “It’s the Climb,” Miley Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-67426: Flyto2 Core: Unauthenticated flyto-verificatio Bespoke exploit · hunting DSP [LLM] Flyto2 flyto-verification unauthenticated POST /run on :8344 (CVE-2026-67426 SSRF entry) Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-67429: Flyto2 Core: Arbitrary file write via image.do Bespoke exploit · hunting DSP Article-specific behavioural hunt — OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage cam Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Bespoke exploit · hunting DSP [LLM] Langflow CVE-2026-33017 unauthenticated RCE exploitation (build_public_tmp) Bespoke exploit · hunting DSΣPDD [LLM] Fluentd aggregator pod spawns shell/curl via injected out_exec (CVE-2026-54680 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] goshs launched with exploitable empty-credential SFTP config (CVE-2026-62325) Bespoke exploit · alerting DSΣPDDCS [LLM] goshs basic-auth flag with empty username or password (config-audit hunt) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2 key generation in N Bespoke exploit · hunting DSP [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection t Bespoke exploit · hunting DSP [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73649: Velocity.js: Remote Code Execution via propert Bespoke exploit · hunting DSP [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] `kiota info` run against a remote/untrusted OpenAPI description (CVE-2026-59865) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Don’t swing at everything Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73421: Auth.js: Configuration errors can cause existe Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73420: Auth.js: Email normalizer validates the addres Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding eight high-severity vulnerabilities in NodeBB in six hours Bespoke exploit · hunting DSP [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analy Bespoke exploit · hunting DSP [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Client-supplied X-WEBAUTH-USER header reaching Gitea (CVE-2026-20896 impersonation) Bespoke exploit · hunting DSPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-73653: @vitest/browser: Browser Mode provider command Bespoke exploit · hunting DSP [LLM] Vitest Browser Mode / test API (node.exe) accepting inbound connections on 63315/51204 from non-loopback host Bespoke exploit · hunting DSΣPDDCS [LLM] AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimite Bespoke exploit · hunting DSP Article-specific behavioural hunt — SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems D Bespoke exploit · hunting DSP [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) Bespoke exploit · hunting DSΣPDDCS [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Begun, the Patch Wars have Bespoke exploit · hunting DSP [LLM] PowerShell AMSI/ETW bypass reflection (UAT-11795 WLDR evasion) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially Bespoke exploit · hunting DSP [LLM] npm/node install-time payload: package manager spawning curl/launchctl/osascript on a runner Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised C Bespoke exploit · hunting DSP Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Bespoke exploit · hunting DSP [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir Bespoke exploit · alerting DSPCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-9hc2-hjx8-q6pv: TidGi Desktop Remote Code Execution via M Bespoke exploit · hunting DSP [LLM] TidGi Desktop wiki worker spawning a command interpreter (TiddlyWiki startup-module RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — AsyncAPI npm packages backdoored via GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enab Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Bespoke exploit · hunting DSP [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP Article-specific behavioural hunt — What is a dependency firewall? Bespoke exploit · hunting DSP Article-specific behavioural hunt — jscrambler npm package publishes malicious preinstall binary Bespoke exploit · hunting DSP Article-specific behavioural hunt — Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Bespoke exploit · hunting DSP [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) Bespoke exploit · alerting DSΣPDDCS [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] External browser process connects to SiYuan kernel loopback admin port 127.0.0.1:6806 Bespoke exploit · hunting DSΣPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Bespoke exploit · hunting DSP [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry Bespoke exploit · hunting DSP Article-specific behavioural hunt — One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforce Bespoke exploit · hunting DSP [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Multiple @immobiliarelabs Backstage Plugins Compromised on npm Bespoke exploit · hunting DSP [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised Bespoke exploit · hunting DSP [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — codfish/semantic-release-action GitHub Action has been compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Bespoke exploit · hunting DSP [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets Bespoke exploit · hunting DSP Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc Bespoke exploit · hunting DSP Article-specific behavioural hunt — What nearly 10,000 developer environments reveal about agentic development risk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosqu Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi Bespoke exploit · hunting DSP Article-specific behavioural hunt — A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Bespoke exploit · hunting DSP Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori Bespoke exploit · hunting DSP [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Bespoke exploit · hunting DSP [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Nx Console VS Code Extension Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Bespoke exploit · hunting DSP Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Bespoke exploit · hunting DSP Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory Bespoke exploit · hunting DSP Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Bespoke exploit · hunting DSP Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Bespoke exploit · hunting DSP Article-specific behavioural hunt — Webworm: New burrowing techniques Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Bespoke exploit · hunting DSP Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Bespoke exploit · hunting DSP

Installation (435)

Suspicious browser extension installation Internal install · hunting DSΣP File hash IOCs — endpoint file/process match Internal install · alerting DSΣP RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal install · hunting DSΣP Scheduled task created with suspicious image / encoded args Internal install · hunting DSΣP Service install for persistence — sc.exe / new service registry write Internal install · hunting DSΣP [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes Internal install · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress Internal install · alerting DSΣPDDCS [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Internal install · alerting DSΣPDDCSCW [LLM] Ray raylet/python spawning shell + ingress tooling (ShadowRay payload execution) Bespoke install · alerting DSΣPDDCS [LLM] Clop hex-named JSP webshell dropped under PTC Windchill /login (CVE-2026-12569) Bespoke install · alerting DSΣPDDCS [LLM] Evooo1Bot wget.sh fetch-and-execute loader chain on Linux Bespoke install · hunting DSΣPDDCS [LLM] Evooo1Bot anti-forensics — bash history clearing after payload execution Bespoke install · hunting DSΣPDDCS [LLM] Evooo1Bot ELF payload drop by known SHA256 Bespoke install · hunting DSΣPCS [LLM] VMware-impersonating cron jobs drop JSP webshell (vmware-perf-update.jsp) Bespoke install · alerting DSΣPDDCS [LLM] esxi.sh downloader deploys architecture-specific reverse_ssh from 185.144.28.120 Bespoke install · hunting DSΣPDDCS [LLM] Install of TeamPCP-backdoored PyPI packages (litellm 1.82.7/1.82.8, telnyx 4.87.1/4.87.2) Bespoke install · alerting DSΣPDDCS [LLM] Execution/write of known TeamPCP stealer binary by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] Evooo1Bot loader download cradle (wget.sh / wget||curl pipe-to-shell into /tmp) Bespoke install · alerting DSΣPDDCS [LLM] Evooo1Bot persistence: 5-min cron re-download & 'Apache HTTPD Cache Manager' systemd masquerade Bespoke install · alerting DSΣPDDCS [LLM] Attacker-controlled sudoers policy written under /etc/sudoers.d (CVE-2026-43760 root file-create primitive) Bespoke install · alerting DSΣPCS [LLM] Execution/write of published Sable Squirrel malware sample (SHA256 0464caa1...) Bespoke install · hunting DSΣPDDCS [LLM] HoneyMyte DLL side-load: renamed Sangfor 'defender.exe' loading malicious libngs.dll Bespoke install · hunting DSΣPDDCS [LLM] CoolClient signed kernel rootkit msagent.sys dropped and registered as 'msagent' driver service Bespoke install · hunting DSΣPDDCS [LLM] CoolClient persistence: 'goopdate' Run key and 'media_updaten' service creation Bespoke install · hunting DSΣPDDCS [LLM] PlugX adds Microsoft Defender exclusions for CoolClient components and fake Defender dir Bespoke install · hunting DSΣPDDCS [LLM] CoolClient injection target: masqueraded 'synchost.exe' (svchost typosquat) execution Bespoke install · alerting DSΣPDDCS [LLM] CDP-Enable-BOF: CreateRemoteThread injection into chrome.exe / msedge.exe Bespoke install · alerting DSΣPDDCS [LLM] HoneyMyte Defender exclusion for fake 'Microsoft\Windows Defender' path via WMIC MSFT_MpPreference Bespoke install · alerting DSΣPDDCS [LLM] CoolClient sideloader staging: xcopy clones legit Windows Defender folder into fake Microsoft\Windows Defender dir Bespoke install · hunting DSΣPDDCS [LLM] CoolClient persistence: schtasks onstart SYSTEM task masquerading as 'Windows Defender ATP Service' running defender.exe Bespoke install · alerting DSΣPDDCS [LLM] CoolClient signed kernel rootkit: msagent.sys driver service install (Nanjing Ranyi cert) Bespoke install · alerting DSΣPDDCS [LLM] Jewelbug XG-Web native-messaging host 'com.microsoft.runedge' registered Bespoke install · alerting DSΣPDD [LLM] 'PDF Viewer' extension sideloaded into browser profile by non-browser process Bespoke install · hunting DSΣPDDCS [LLM] PATCHCORD 'BeaconBrowserHijack' Run-key persistence (APT36) Bespoke install · alerting DSΣPDDCS [LLM] PATCHCORD/SHEETCORD browser shortcut (.lnk) hijack write Bespoke install · hunting DSΣPDDCS [LLM] SHEETCORD VBS Startup-folder persistence drop Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control Bespoke install · hunting DSP [LLM] macOS root LaunchDaemon persistence dropped by untrusted process (Apple crash-reporter impersonation) Bespoke install · hunting DSΣPCS [LLM] WindRelay / SpyNote malicious APK hash observed on managed endpoint Bespoke install · hunting DSΣP [LLM] Still Sync TReload service persistence + implant CLI flags (--firefly/--console) Bespoke install · alerting DSΣPDDCS [LLM] Lazarus MISTPEN DLL side-load chain via trojanized PDF viewer (libmupdf.dll + recon modules) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You H Bespoke install · hunting DSP Article-specific behavioural hunt — Kimwolf v7: An Evolution of the Kimwolf Botnet Bespoke install · hunting DSP [LLM] npm preinstall lifecycle hook launching 'node setup.mjs' (ChainDrop/Shai-Hulud loader) Bespoke install · alerting DSΣPDDCS [LLM] setup.mjs spawning Bun runtime to execute obfuscated payload from node_modules/bun-dl Bespoke install · alerting DSΣPDDCS [LLM] ChainDrop known-bad file drop: setup.mjs / Math_*.js hashes on disk Bespoke install · hunting DSΣPDDCS [LLM] ChainDrop persistence: node/bun injecting .claude and .vscode config files into repositories Bespoke install · hunting DSΣPDDCS [LLM] RunMRU registry write launching mshta / URL / PowerShell (ClickFix-style user persistence) Bespoke install · alerting DSΣPDD Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-69259: Flowise RCE via SQLite Record Manager Node Bespoke install · hunting DSP [LLM] Flowise node process writes SQLite DB file to system directory (arbitrary-write RCE primitive) Bespoke install · alerting DSΣPCS [LLM] Flowise node process writes to cron / systemd / SSH persistence path Bespoke install · alerting DSΣPCS [LLM] Flowise/node process spawning Unix shell or netcat reverse shell (CVE-2026-69254 vm2 escape) Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook executing node setup.mjs (Shai-Hulud dropper) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud payload files setup.mjs / Math_Symbol.js written into node_modules Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook executing setup.mjs / Math_Symbol.js (keyv/cacheable worm) Bespoke install · alerting DSΣPDDCS [LLM] keyv worm planting .claude / .vscode auto-run hooks in project (agentic dev target) Bespoke install · alerting DSΣPDDCS [LLM] keyv/cacheable npm compromise: node executing preinstall setup.mjs / Math_Symbol.js dropper Bespoke install · alerting DSΣPDDCS [LLM] keyv npm compromise: IDE-hook persistence files planted in .claude / .vscode Bespoke install · hunting DSΣPDDCS [LLM] keyv npm compromise: gh-token-monitor credential-persistence artifacts (macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] RDP re-enable + EDR/Defender disable batch script (LockBit intrusion) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — Pass the Passkey: A Novel Attack Surface in Passwordless Authentication Bespoke install · hunting DSP [LLM] CornFlake RAT persistence via svchost32.exe masquerade in %APPDATA% Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52887: NocoBase: SQL injection in /api/myInAppChannel Bespoke install · hunting DSP [LLM] PostgreSQL container process spawning shell — COPY TO PROGRAM RCE (CVE-2026-52887) Bespoke install · alerting DSΣPCS [LLM] Malicious 'anthropickit' PyPI package installed via pip (supply-chain cred stealer) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version Bespoke install · hunting DSP [LLM] XCSSET v40 chrome_remote CDP backdoor binary execution Bespoke install · alerting DSΣPCS [LLM] XCSSET v40 worming: non-IDE process modifying multiple Xcode .pbxproj files Bespoke install · alerting DSPCS [LLM] Joyfill RAT persistence injection into developer tool modules (VS Code / Discord / GitHub Desktop / npm) Bespoke install · alerting DSΣPDDCS [LLM] Known-malicious Joyfill package bundle hash observed on disk Bespoke install · hunting DSΣPDD [LLM] Compromised @joyfill package artifacts written under node_modules or lock files Bespoke install · hunting DSΣPDDCS [LLM] Zoho Assist Unattended Agent deployment (Warlock / Storm-2603 ransomware) Bespoke install · alerting DSΣPDDCS [LLM] OctLurk deployment via 'GoogleUpDate' scheduled task launching Videos\1.bat Bespoke install · alerting DSΣPDDCS [LLM] OctLurk/LurkProxy loader service registration (ServiceMain=RegisterService loading oleasapi.dll/msbasesysdc.dll) Bespoke install · alerting DSΣPDDCS [LLM] Hermes Agent autonomous attack framework execution (fofoapi.py / FofaMap MCP) Bespoke install · hunting DSΣPDDCS [LLM] AI coding-tool anti-attribution / permission-bypass config artifacts Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration inj Bespoke install · hunting DSP [LLM] Unexpected write to Fluentd fluent.conf introducing exec/block-close directives Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Bespoke install · hunting DSP [LLM] Trojanized MeshAgent installed as SYSTEM auto-start service (Sinobi covert C2) Bespoke install · alerting DSΣDDCS [LLM] Zoho Assist Unattended Agent deployment for headless remote access (Warlock / Storm-2603) Bespoke install · alerting DSΣDDCS [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc Bespoke install · alerting DSΣPCS [LLM] Recurring cron/shell-rc execution of .tf_cache/hw_probe.pyc payload Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-f25v-x6vr-962g: Pheditor: Authentication Bypass in Forced Bespoke install · hunting DSP [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) Bespoke install · hunting DSΣPDDCS [LLM] Vulnerable sm-crypto@0.4.0 dependency installed via npm/yarn/pnpm (predictable SM2 keys) Bespoke install · hunting DSΣPDDCS [LLM] On-disk presence of vulnerable sm-crypto package (node_modules\sm-crypto\) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-mqhr-6j6h-74p5: Budibase: Unauthenticated REST Datasource Bespoke install · hunting DSP [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Bespoke install · hunting DSP [LLM] msaRAT msiexec executing update_ms.msi (fake Windows update custom action) Bespoke install · alerting DSΣPDDCS [LLM] fast16 sabotage implant carrier (svcmgmt.exe) by hash / Lua-carrier behaviour Bespoke install · alerting DSΣPDDCS [LLM] fast16 kernel driver (fast16.sys) drop / load — sabotage patching engine Bespoke install · alerting DSΣPDDCS [LLM] Malicious PHP plugin/webshell dropped in wp-content by web server (wp2shell) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC amb Bespoke install · hunting DSP [LLM] Gitea container started with reverse-proxy auth exposing permissive trusted-proxies (CVE-2026-20896) Bespoke install · hunting DSΣPDDCS [LLM] Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke install · alerting DSΣP [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem persistence: git-credential-manager daemon installs systemd + cron Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Bespoke install · hunting DSP [LLM] SleeperGem Unix persistence: cron/systemd/LaunchAgent write by Ruby-descended shell Bespoke install · hunting DSΣPDDCS [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Bespoke install · hunting DSP [LLM] Siemens ROX II root cron table injection via web task scheduler (CVE-2025-40949) Bespoke install · hunting DSΣDD Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' w Bespoke install · hunting DSP [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell Bespoke install · alerting DSΣPDDCS [LLM] Pheditor source tampering: modification of pheditor.php (hash rewrite / backdoor persistence) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro Bespoke install · hunting DSP [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Bespoke install · alerting DSΣPDDCS [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) Bespoke install · hunting DSΣPCS [LLM] Shai-Hulud worm artifacts written on GitHub Actions runner (shai-hulud-workflow.yml / bundle.js) Bespoke install · hunting DSΣPCS [LLM] MiniRAT launchctl persistence established during macOS CI build Bespoke install · hunting DSΣPCS [LLM] Detached 'node -e' launcher downloading Miasma second stage from IPFS Bespoke install · alerting DSΣPDDCS [LLM] Miasma sync.js payload dropped to hidden 'NodeJS' directory Bespoke install · hunting DSΣPDDCS [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun Bespoke install · alerting DSΣPDDCS [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development Bespoke install · hunting DSP [LLM] TuxBot/Akiru known ELF sample execution and drop (SHA256 pivot) Bespoke install · hunting DSΣPCS [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Bespoke install · hunting DSP [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in Bespoke install · hunting DSP [LLM] Miasma stage-2 dropped: sync.js written to per-user NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Miasma stage-2 executed: node runs sync.js from NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Vulnerable UEFI shim/GRUB bootloader written to the EFI System Partition Bespoke install · hunting DSΣPDDCS [LLM] EFI System Partition mounted via mountvol /S (rogue shim staging) Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud npm worm payload/workflow file drop (bundle.js, setup_bun.js, shai-hulud-workflow.yml) Bespoke install · hunting DSΣPDDCS [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] axios RAT persistence: HKCU Run value MicrosoftUpdate pointing to system.bat Bespoke install · alerting DSΣPDDCS [LLM] IronWorm preinstall loader: detached hidden binary executed from OS temp by node.exe Bespoke install · alerting DSΣPDDCS [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Bespoke install · hunting DSΣPDDCS [LLM] Backdoored @injectivelabs/sdk-ts 1.20.21 payload file dropped on disk Bespoke install · hunting DSΣPDDCS [LLM] Sha1-Hulud 2.0 npm worm payload files (setup_bun.js / bun_environment.js) written or executed Bespoke install · hunting DSΣPDDCS [LLM] Malicious 'SHA1HULUD' self-hosted GitHub Actions runner installation / persistence Bespoke install · alerting DSΣPDDCS [LLM] Browser extension manifest rewritten adding networking/host permissions (supply-chain) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Bespoke install · hunting DSP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot Bespoke install · alerting DSΣPDDCS [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) Bespoke install · alerting DSΣPDDCS [LLM] Malicious @injectivelabs SDK build artifact by SHA-256 on disk Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) Bespoke install · hunting DSP [LLM] SSH authorized_keys written by non-SSH tooling (symlink repo payload) Bespoke install · hunting DSΣPDDCS [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) Bespoke install · hunting DSΣPDDCS [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Bespoke install · hunting DSΣPDDCS [LLM] Phantom Gyp binding.gyp install-time payload execution (Miasma npm worm) Bespoke install · alerting DSΣPDDCS [LLM] Miasma infectHost persistence in AI coding assistant configs Bespoke install · hunting DSΣPDDCS [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant Bespoke install · alerting DSΣPDDCS [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] Passwordless sudo backdoor written for runner account (runner ALL=(ALL) NOPASSWD:ALL) Bespoke install · alerting DSΣPDDCS [LLM] Compromised simonecorsi/mawesome GitHub Action payload by known hash Bespoke install · hunting DSΣPDDCS [LLM] Bun runtime executing payload index.js from semantic-release-action path Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Bespoke install · hunting DSP [LLM] Gamaredon WinRAR CVE-2025-8088 ADS path-traversal dropping HTA/VBS into Startup folder Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js npm postinstall dropper: node executing setup.cjs --no-warnings Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js Windows persistence: Run key 'NvmProtocal' / protocal.cjs autostart Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js implant artifacts dropped: protocal.cjs / NodePackages / cross-OS persistence files Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing codfish/semantic-release-action index.js payload on CI runner Bespoke install · alerting DSΣPDDCS [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Bespoke install · hunting DSΣPCS [LLM] Mastra easy-day-js postinstall dropper: node setup.cjs --no-warnings Bespoke install · alerting DSΣPDDCS [LLM] Miasma/Hades Bun dropper executed via npm/pip lifecycle hook (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud/Miasma malicious GitHub Actions workflow file written to .github/workflows Bespoke install · alerting DSΣPDDCS [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) Bespoke install · alerting DSPDDCS [LLM] Atomic Arch persistence: systemd unit, cron or shell-rc written by AUR build / JS runtime Bespoke install · hunting DSΣPCS [LLM] Miasma/Hades auto-exec editor & AI-tool config files dropped in project tree Bespoke install · hunting DSΣPDDCS [LLM] Phantom Gyp: malicious binding.gyp executing during npm install Bespoke install · hunting DSΣPDDCS [LLM] Hades PyPI startup hook: malicious -setup.pth dropped in site-packages Bespoke install · hunting DSΣPDDCS [LLM] easy-day-js postinstall dropper spawning node.exe with C2 IP passed as argument Bespoke install · alerting DSΣPDDCS [LLM] Node.js writing a random 24-hex-char .js dropper to the OS temp directory Bespoke install · hunting DSΣPDDCS [LLM] npm install pulls malicious easy-day-js dropper (setup.cjs + .pkg marker files) Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] Mastra easy-day-js second-stage stealer payload by SHA256 Bespoke install · hunting DSΣPDDCS [LLM] Malicious JetBrains Marketplace plugin install (15 DeepSeek/CodeGPT clone IDs) Bespoke install · hunting DSΣPDDCS [LLM] SprySOCKS WIN_DRV/WIN_PLUS backdoor binary by ESET SHA1 hash Bespoke install · hunting DSΣPDDCS [LLM] SprySOCKS WIN_DRV BlackLotus-style Secure Boot downgrade / EFI bootkit (CVE-2023-24932) Bespoke install · hunting DSΣPDDCS

Command & Control (227)

Beaconing — periodic outbound to small set of destinations Internal c2 · alerting DSP DNS tunneling / TXT-heavy domain queries Internal c2 · hunting DSP Network connections to article IPs / domains Internal c2 · alerting DSΣP [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [LLM] Egress to Interactsh/OAST out-of-band callback domains (*.oast.me family) Bespoke c2 · alerting DSΣPDDCS [LLM] Node.js process direct DNS egress to external resolver (vm2 dns.setServers host hijack) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound connection to known Clop CVE-2026-12569 C2 / exploitation IPs Bespoke c2 · hunting DSΣPDDCSCW [LLM] linuxFile backdoor WebSocket C2 to intel.se9ly9upbhay.shop and campaign C2 IPs Bespoke c2 · hunting DSΣPDDCS [LLM] AmnesiaStealer C2/relay egress to Amnesia Panel host (allllowef.space / aoitour.com) Bespoke c2 · alerting DSΣPCS [LLM] TeamPCP CI/CD credential-stealer C2 egress to 83.142.209.203 / checkmarx.zone Bespoke c2 · hunting DSΣPDDCSCW [LLM] Evooo1Bot C2/loader traffic to relay host 91.92.40.118 Bespoke c2 · hunting DSΣPCSCW [LLM] Evooo1Bot SOCKS5 relay listener on TCP 1080 from a /tmp-resident binary Bespoke c2 · hunting DSΣPCS [LLM] Endpoint callback to Sable Squirrel dropcatch C2 domains (Quasar RAT via cel-robox[.]com) Bespoke c2 · alerting DSΣPDDCS [LLM] CoolClient C2 beacon to HoneyMyte dynamic-DNS command-and-control domains Bespoke c2 · alerting DSΣPDDCS [LLM] Browser directly spawning cmd.exe (XG-Web native-messaging shell) Bespoke c2 · hunting DSΣPDDCS [LLM] Jewelbug XG-Web C2 beacon to Google-Fonts-mimicking domains and IPs Bespoke c2 · hunting DSΣPDDCS [LLM] JWR real-time exfil & operator WebSocket channel (the_final_interface / addCvv / webSocket/QT) Bespoke c2 · alerting DSΣP [LLM] PATCHCORD C2 beacon to appstoore.solutions / 46.30.188.13:8080 Bespoke c2 · hunting DSΣPDDCS [LLM] AmnesiaStealer C2 beacon to debug.allllowef[.]space Bespoke c2 · alerting DSΣPCS [LLM] WindRelay NFC-relay C2 beacon to Group-IB-attributed WebSocket infrastructure Bespoke c2 · hunting DSΣPCS [LLM] Managed endpoint network egress to DPRK IT-worker VPS / AstrillVPN IPs Bespoke c2 · hunting DSΣPDDCS [LLM] JWR phishing framework C2 WebSocket channel (khkjsahfjkwhakjlsdwdddddd88 auth suffix) Bespoke c2 · alerting DSΣP [LLM] Armored Likho Still Sync gRPC C2 beacon (tg4service.com / still.rpc.Sync) Bespoke c2 · alerting DSΣPDDCS [LLM] Armored Likho Still Toolkit C2 infrastructure IOC match (domains + IPs) Bespoke c2 · hunting DSΣPDDCS [LLM] ForestTiger/MISTPEN C2 to Enveil-impersonation domains and hijacked-infrastructure IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Browser egress to Myxa SOCKS5 proxy infrastructure (known IPs) Bespoke c2 · hunting DSΣPDDCS [LLM] DNS/connection to Myxa fake-VPN impersonation domains Bespoke c2 · alerting DSΣPDDCS [LLM] Browser-initiated SOCKS5 to TCP/1082 — new proxy infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound traffic to known AI token-jacking transfer-station infrastructure (Unit42 IPs) Bespoke c2 · hunting DSΣPDDCSCW [LLM] ChainDrop C2 exfiltration from node/bun to npm-cache.com / pypi-get.com / js-mirror.com Bespoke c2 · alerting DSΣPDDCS [LLM] Reverse shell / egress from Flowise node-spawned interpreter (CVE-2026-70477 post-exploit) Bespoke c2 · hunting DSPCS [LLM] mshta.exe outbound connection to public host (remote HTA C2 retrieval) Bespoke c2 · hunting DSΣPDDCS [LLM] Reverse shell / Meterpreter egress from Flowise node or its shell child Bespoke c2 · hunting DSPCS [LLM] Reverse-shell egress from Flowise node process tree (nc/shell child dialing out) Bespoke c2 · alerting DSPCS [LLM] Reverse-shell egress from netcat/socat on Flowise host Bespoke c2 · alerting DSΣPCS [LLM] SectopRAT in-browser proxy /churl traffic mirroring to attacker IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Hardcoded WebSocket backdoor to 154.92.19.71:39989 (no DNS) Bespoke c2 · hunting DSΣPDDCS [LLM] ZT-IP hunt: direct-to-IP egress with no preceding DNS resolution Bespoke c2 · hunting DSPDDCS [LLM] Bun runtime fetched from oven-sh GitHub releases during npm install Bespoke c2 · hunting DSPCS [LLM] keyv worm loader pulling Bun 1.3.13 runtime from GitHub during install Bespoke c2 · alerting DSPDDCS [LLM] keyv npm compromise: Bun runtime executing second-stage math_init.js / Math_Symbol.js Bespoke c2 · alerting DSΣPDDCS [LLM] AnyDesk silent/unattended install used for DragonForce access Bespoke c2 · alerting DSΣPDDCS [LLM] Endpoint connections to Storm-2945 CaptiveCrunch AiTM doppelganger infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] CornFlake C2 egress from masqueraded svchost32.exe in AppData Bespoke c2 · hunting DSΣPDDCS [LLM] vault-secrets-webhook pod outbound SSRF egress to cloud IMDS (CVE-2026-54725) Bespoke c2 · alerting DSΣPCS [LLM] DNS tunneling: high-volume long/high-entropy subdomain queries to a single parent domain Bespoke c2 · hunting DSΣPCS [LLM] Endpoint issuing DNS directly to unauthorised/external resolvers (resolver bypass) Bespoke c2 · hunting DSΣPDDCS [LLM] XCSSET v40 Chrome launched with CDP remote-debugging enabled (browser hijack) Bespoke c2 · hunting DSΣPCS [LLM] XCSSET v40 outbound retrieval to rotating C2 module/binary paths (/s/, /d/) Bespoke c2 · hunting DSPCS [LLM] Node.js host callout to Joyfill DEV#POPPER RAT C2 infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Trojanized MeshAgent running outside its install path (Sinobi ransomware C2) Bespoke c2 · alerting DSΣPDDCS [LLM] OctLurk/SilkLurk/LurkProxy C2 beacon to named backdoor infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Egress to AI-tool anonymizing proxy code.newcli[.]com (knaithe/KnYuan campaign) Bespoke c2 · alerting DSΣPDDCS [LLM] Direct egress to Chinese-market LLM APIs (DeepSeek/Qwen) from the estate Bespoke c2 · hunting DSΣPDDCS [LLM] Endpoint egress/DNS to UAT-11764 / ARToken IOC infrastructure Bespoke c2 · alerting DSΣDDCS [LLM] mrmustard stealer C2 exfil to metrics.femboy.energy Bespoke c2 · alerting DSΣPCS [LLM] CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT CDP abuse: headless Chrome/Edge with remote-debugging port spawned by non-browser parent Bespoke c2 · alerting DSΣPDDCS [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev Bespoke c2 · hunting DSΣPDDCS [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) Bespoke c2 · hunting DSPDDCS [LLM] Blockchain-anchored C2 fallback: non-browser process contacting polygon-rpc.com Bespoke c2 · alerting DSΣPDDCS [LLM] Connection to known UAT-11795 Starland RAT C2 / distribution domains Bespoke c2 · alerting DSΣPDDCS [LLM] Starland RAT / WLDR C2 beaconing to UAT-11795 HWID-parameterized domains Bespoke c2 · alerting DSΣPDDCS [LLM] Starland RAT blockchain fallback C2 via Polygon eth_call (polygon-rpc.com) Bespoke c2 · hunting DSΣPDDCS [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] CI runner egress to MiniRAT C2 89.36.224.5 (Velora SDK backdoor) Bespoke c2 · hunting DSΣPDDCS [LLM] Miasma RAT C2 beacon to 85.137.53.71 from Node.js runtime Bespoke c2 · hunting DSΣPDDCS [LLM] Node.js resolving Miasma fallback C2 channels (BitTorrent DHT / Nostr relays) Bespoke c2 · alerting DSΣPDDCS [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) Bespoke c2 · alerting DSΣPDDCS [LLM] TuxBot/Akiru IoT botnet C2 connection to known infrastructure Bespoke c2 · hunting DSΣPCS [LLM] TuxBot fallback C2 via digikalas.online DGA subdomains and DNS TXT queries Bespoke c2 · hunting DSΣPCS [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) Bespoke c2 · alerting DSΣPDDCS [LLM] Miasma M-RED-TEAM HTTP C2 beacon to 85.137.53.71 Bespoke c2 · hunting DSΣPDDCS [LLM] axios RAT C2 beacon to sfrclak[.]com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] IronWorm C2 beacon to hardcoded IPs and Tor endpoints from temp-dir process Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound network connection from a child process of SiYuan.exe (post-RCE C2/exfil) Bespoke c2 · alerting DSPCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] PromptSpy Android GenAI malware C2/distribution domain contact (mgardownload.com, m-mgarg.com) Bespoke c2 · alerting DSΣPDDCS [LLM] GitHub Actions runner outbound to gist.githubusercontent.com (tj-actions/changed-files CVE-2025-30066) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 Bespoke c2 · hunting DSΣPCS [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPCS [LLM] easy-day-js second-stage C2 beacon to Mastra supply-chain infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Jackson Maven typosquat C2 — beacon to fasterxml.org / 103.127.243.82 Bespoke c2 · alerting DSΣPDDCS [LLM] Bun v1.3.13 runtime pulled from GitHub Releases during npm install (Phantom Gyp staging) Bespoke c2 · alerting DSΣP [LLM] GitHub dead-drop C2 — commit-search for RevokeAndItGoesKaboom / TheBeautifulSandsOfTime Bespoke c2 · hunting DSPCS [LLM] JetBrains IDE process beaconing to malicious plugin C2 39.107.60.51 Bespoke c2 · alerting DSΣPDDCS [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts Bespoke c2 · alerting DSΣPDDCS [LLM] easy-day-js stealer C2 beacon to Hostwinds 23.254.164.0/24 (ports 8000/443) Bespoke c2 · hunting DSΣPDDCS [LLM] Bun process reaching GitHub commit-search API — Miasma dead-drop C2 Bespoke c2 · hunting DSΣPDDCS [LLM] macOS.Gaslight Telegram Bot API C2 polling from non-browser process Bespoke c2 · hunting DSΣPCS [LLM] easy-day-js Mastra dropper C2 callout to 23.254.164.92 / .123 Bespoke c2 · hunting DSΣPDDCS [LLM] Atomic Arch C2/exfil: build-spawned egress to temp.sh and github.com/fardewoak/nodejs-argo Bespoke c2 · alerting DSΣPDDCS [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime Bespoke c2 · alerting DSΣPDDCS [LLM] Sapphire Sleet easy-day-js RAT C2 beacon to Hostwinds 23.254.164.92 / 23.254.164.123 Bespoke c2 · hunting DSΣPDDCS [LLM] Cross-platform stealer RAT C2 beacon to 23.254.164.123 Bespoke c2 · alerting DSPDDCS [LLM] JetBrains AI-key stealer HTTP exfil: cleartext POST to /api/software/ path Bespoke c2 · hunting DSΣP [LLM] SprySOCKS (FishMonger/I-SOON) C2 beacon to hardcoded Vultr IPs 207.148.78.36 / 207.148.75.122 Bespoke c2 · hunting DSΣPDDCS [LLM] axios npm RAT C2 beacon to UNC1069 infra (142.11.206.73 / sfrclak.com) Bespoke c2 · alerting DSΣPDDCS [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs Bespoke c2 · hunting DSΣPDDCS [LLM] SPECTRALVIPER injected OneDrive.Sync.Service.exe beaconing (Cookie-header C2) Bespoke c2 · alerting DSPDDCS [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Rust build script making outbound network connection (build-time exfil) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] node child of npm install initiating outbound network to non-registry destination Bespoke c2 · hunting DSPDDCS [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) Bespoke c2 · hunting DSPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper Bespoke c2 · alerting DSΣPDDCS [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 Bespoke c2 · hunting DSΣPDDCS [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke c2 · hunting DSΣPDDCS [LLM] GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke c2 · hunting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 Bespoke c2 · hunting DSΣPDDCS [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) Bespoke c2 · alerting DSΣPCS [LLM] FIRESCALE GitHub dead-drop fallback C2 lookup (api.github.com commit search) Bespoke c2 · alerting DSΣP [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint Bespoke c2 · alerting DSΣPDDCS [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud C2 backchannel: python polling GitHub commit search for 'firedalazer' Bespoke c2 · alerting DSPDDCS [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud Bespoke c2 · alerting DSΣPDDCS [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host Bespoke c2 · alerting DSΣPDD [LLM] BirdCall RokRAT cloud-storage C2 beacon (Dropbox/pCloud) from non-browser process Bespoke c2 · hunting DSPDDCS [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL Bespoke c2 · alerting DSΣPDD [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro Bespoke c2 · hunting DSΣPDDCS [LLM] Non-browser process posting to Slack Web API (LaxGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Non-browser process posting to Discord API (RatGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Beaconing to GopherWhisper C2 IP 43.231.113.50 (incl. SSLORDoor raw TLS/443) Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) Bespoke c2 · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes Bespoke c2 · hunting DSΣPDD [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] node.exe contacting Solana JSON-RPC endpoints (suspected blockchain dead-drop C2) Bespoke c2 · hunting DSPDDCS [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) Bespoke c2 · alerting DSΣPDD [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner Bespoke c2 · hunting DSΣPDDCS [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) Bespoke c2 · hunting DSΣPDDCS [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download Bespoke c2 · alerting DSΣPDDCS [LLM] DRILLAPP C2 staging: msedge.exe contacting pastefy.app Bespoke c2 · alerting DSΣPDDCS [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] BeardShell C2: outbound to Icedrive cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] Covenant C2: outbound to Filen cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) Bespoke c2 · hunting DSΣPDDCS [LLM] Ultralytics coinminer C2 — Stratum to connect.consrensys.com:8080 mining pool Bespoke c2 · alerting DSΣPCS [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com Bespoke c2 · alerting DSΣPDD [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) Bespoke c2 · alerting DSΣPDDCS [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ru Bespoke c2 · hunting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2) Bespoke c2 · alerting DSΣP [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] PlushDaemon EdgeStepper hijacking infrastructure (wcsset.com / 47.242.198.250 / 8.212.132.120) contact Bespoke c2 · hunting DSΣP [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpoint Bespoke c2 · hunting DSΣPDDCS [LLM] Beamglea mad-* dead-drop fetch from raw.githubusercontent.com/Abassdos2992 Bespoke c2 · alerting DSΣPDDCS [LLM] DNS or HTTP egress to giftshop.club exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1 Bespoke c2 · hunting DSΣPDDCS [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] Log4Shell outbound JNDI callback from Java process to LDAP/RMI (CVE-2021-44228) Bespoke c2 · alerting DSΣPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob Bespoke c2 · hunting DSΣPDDCS [LLM] npm/PyPI install-script beacon to hardcoded C2 3.72.6.53 (django-yauth supply chain) Bespoke c2 · alerting DSΣPDDCSCW [LLM] CircleCI breach C2 egress to potrax[.]com and 8 hardcoded attacker IPs Bespoke c2 · hunting DSΣPCSCW [LLM] Java process outbound LDAP/RMI to fetch remote class — SnakeYAML JNDI gadget Bespoke c2 · alerting DSΣPDDCS

Actions on Objectives (415)

Infostealer — non-browser process accessing browser cookie/login DBs Internal actions · alerting DSΣP Crypto-wallet file/keystore access by non-wallet process Internal actions · alerting DSΣP Remote service execution — PsExec / SMB lateral movement Internal actions · alerting DSΣP LSASS process access / dump (credential theft) Internal actions · alerting DSΣP Ransomware-style mass file rename / extension change Internal actions · alerting DSP [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Dev/CI Toolchain Credential Read + Egress to Non-Canonical Registry Internal actions · alerting DSPDDCS [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] SSRF-Driven Secret Egress: Public-Facing App Reaches Cloud Metadata/Attacker Host Internal actions · alerting DSΣPDDCSCW [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Access LSASS Memory for Dump Creation ESCU actions · alerting P Anomalous usage of 7zip ESCU actions · hunting P Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI ESCU actions · hunting P Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download ESCU actions · hunting P Cisco NVM - Suspicious Download From File Sharing Website ESCU actions · hunting P Cisco NVM - Suspicious Network Connection From Process With No Args ESCU actions · hunting P Clop Ransomware Known Service Name ESCU actions · alerting P Create Remote Thread In Shell Application ESCU actions · alerting P Creation of lsass Dump with Taskmgr ESCU actions · alerting P Creation of Shadow Copy ESCU actions · alerting P Deleting Shadow Copies ESCU actions · alerting P Detect Credential Dumping through LSASS access ESCU actions · alerting P Detect New Local Admin account ESCU actions · alerting P Detect Prohibited Applications Spawning cmd exe ESCU actions · hunting P Detect Regasm with Network Connection ESCU actions · alerting P Detect Regsvcs with Network Connection ESCU actions · alerting P Detect Use of cmd exe to Launch Script Interpreters ESCU actions · hunting P Domain Account Discovery with Wmic ESCU actions · alerting P Domain Controller Discovery with Wmic ESCU actions · hunting P Drop IcedID License dat ESCU actions · hunting P Elevated Group Discovery With Wmic ESCU actions · alerting P Executable File Written in Administrative SMB Share ESCU actions · alerting P Get ADUser with PowerShell ESCU actions · hunting P Get ADUserResultantPasswordPolicy with Powershell ESCU actions · alerting P Get DomainPolicy with Powershell ESCU actions · alerting P Get DomainUser with PowerShell ESCU actions · alerting P Get-ForestTrust with PowerShell ESCU actions · alerting P Get WMIObject Group Discovery ESCU actions · hunting P GetAdComputer with PowerShell ESCU actions · hunting P GetAdGroup with PowerShell ESCU actions · hunting P GetCurrent User with PowerShell ESCU actions · hunting P GetDomainComputer with PowerShell ESCU actions · alerting P GetDomainController with PowerShell ESCU actions · hunting P GetDomainGroup with PowerShell ESCU actions · alerting P GetLocalUser with PowerShell ESCU actions · hunting P GetNetTcpconnection with PowerShell ESCU actions · hunting P GetWmiObject User Account with PowerShell ESCU actions · hunting P High Frequency Copy Of Files In Network Share ESCU actions · hunting P Impacket Lateral Movement Commandline Parameters ESCU actions · alerting P Impacket Lateral Movement smbexec CommandLine Parameters ESCU actions · alerting P Kerberoasting spn request with RC4 encryption ESCU actions · alerting P Kerberos Service Ticket Request Using RC4 Encryption ESCU actions · alerting P Kerberos TGT Request Using RC4 Encryption ESCU actions · alerting P Kerberos User Enumeration ESCU actions · hunting P LOLBAS With Network Traffic ESCU actions · alerting P Malicious Powershell Executed As A Service ESCU actions · alerting P Network Share Discovery Via Dir Command ESCU actions · hunting P PetitPotam Network Share Access Request ESCU actions · alerting P PetitPotam Suspicious Kerberos TGT Request ESCU actions · alerting P Possible Lateral Movement PowerShell Spawn ESCU actions · hunting P PowerShell Get LocalGroup Discovery ESCU actions · hunting P Powershell Remote Thread To Known Windows Process ESCU actions · alerting P Process Deleting Its Process File Path ESCU actions · alerting P Randomly Generated Windows Service Name ESCU actions · hunting P Ransomware Notes bulk creation ESCU actions · hunting P Remote System Discovery with Wmic ESCU actions · alerting P Resize ShadowStorage volume ESCU actions · alerting P Rubeus Kerberos Ticket Exports Through Winlogon Access ESCU actions · alerting P Rundll32 Create Remote Thread To A Process ESCU actions · alerting P Rundll32 LockWorkStation ESCU actions · hunting P Rundll32 Process Creating Exe Dll Files ESCU actions · alerting P Rundll32 with no Command Line Arguments with Network ESCU actions · alerting P SchCache Change By App Connect And Create ADSI Object ESCU actions · hunting P Scheduled Task Deleted Or Created via CMD ESCU actions · hunting P Spoolsv Suspicious Process Access ESCU actions · alerting P Spoolsv Writing a DLL - Sysmon ESCU actions · alerting P Sqlite Module In Temp Folder ESCU actions · alerting P Suspicious Copy on System32 ESCU actions · hunting P Suspicious Kerberos Service Ticket Request ESCU actions · alerting P Suspicious mshta child process ESCU actions · alerting P Suspicious Reg exe Process ESCU actions · hunting P Suspicious Rundll32 no Command Line Arguments ESCU actions · alerting P Suspicious Ticket Granting Ticket Request ESCU actions · hunting P Suspicious wevtutil Usage ESCU actions · alerting P Unusual Number of Computer Service Tickets Requested ESCU actions · hunting P Unusual Number of Kerberos Service Tickets Requested ESCU actions · hunting P Unusual Number of Remote Endpoint Authentication Events ESCU actions · hunting P User Discovery With Env Vars PowerShell ESCU actions · hunting P Wermgr Process Create Executable File ESCU actions · alerting P Windows Access Token Manipulation Winlogon Duplicate Token Handle ESCU actions · hunting P Windows Access Token Winlogon Duplicate Handle In Uncommon Path ESCU actions · hunting P Windows Account Access Removal via Logoff Exec ESCU actions · hunting P Windows AD Domain Controller Promotion ESCU actions · alerting P Windows AD Replication Request Initiated by User Account ESCU actions · alerting P Windows AD Replication Request Initiated from Unsanctioned Location ESCU actions · alerting P Windows AD Short Lived Domain Controller SPN Attribute ESCU actions · alerting P Windows AD Suspicious Attribute Modification ESCU actions · alerting P Windows Administrative Shares Accessed On Multiple Hosts ESCU actions · alerting P Windows Alternate DataStream - Process Execution ESCU actions · alerting P Windows Bluetooth Service Installed From Uncommon Location ESCU actions · hunting P Windows Cloud Files Filter Log Created by Non-System Process ESCU actions · alerting P Windows Cmdline Tool Execution From Non-Shell Process ESCU actions · hunting P Windows Command Shell DCRat ForkBomb Payload ESCU actions · alerting P Windows Computer Account Requesting Kerberos Ticket ESCU actions · alerting P Windows Crowdstrike RTR Script Execution ESCU actions · hunting P Windows Detect Network Scanner Behavior ESCU actions · hunting P Windows DnsAdmins New Member Added ESCU actions · alerting P Windows EventLog Recon Activity Using Log Query Utilities ESCU actions · hunting P Windows Explorer LNK Exploit Process Launch With Padding ESCU actions · alerting P Windows File Transfer Protocol In Non-Common Process Path ESCU actions · hunting P Windows Handle Duplication in Known UAC-Bypass Binaries ESCU actions · hunting P Windows Hunting System Account Targeting Lsass ESCU actions · hunting P Windows Identify PowerShell Web Access IIS Pool ESCU actions · hunting P Windows Kerberos Local Successful Logon ESCU actions · alerting P Windows KrbRelayUp Service Creation ESCU actions · alerting P Windows Large Number of Computer Service Tickets Requested ESCU actions · hunting P Windows List ENV Variables Via SET Command From Uncommon Parent ESCU actions · hunting P Windows Local Administrator Credential Stuffing ESCU actions · alerting P Windows Mail Protocol In Non-Common Process Path ESCU actions · hunting P Windows Masquerading Explorer As Child Process ESCU actions · alerting P Windows MOF Event Triggered Execution via WMI ESCU actions · alerting P Windows MSHTA Writing to World Writable Path ESCU actions · alerting P Windows MSIExec Spawn Discovery Command ESCU actions · hunting P Windows MsMpEng Writing to System32 ESCU actions · alerting P Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos ESCU actions · alerting P Windows Multiple Invalid Users Fail To Authenticate Using Kerberos ESCU actions · alerting P Windows Multiple Invalid Users Failed To Authenticate Using NTLM ESCU actions · alerting P Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials ESCU actions · alerting P Windows Multiple Users Failed To Authenticate From Host Using NTLM ESCU actions · alerting P Windows Multiple Users Failed To Authenticate From Process ESCU actions · alerting P Windows Multiple Users Remotely Failed To Authenticate From Host ESCU actions · alerting P Windows Non-System Account Targeting Lsass ESCU actions · alerting P Windows Obfuscated Files or Information via RAR SFX ESCU actions · hunting P Windows Office Product Spawned Uncommon Process ESCU actions · alerting P Windows Possible Credential Dumping ESCU actions · alerting P Windows PowGoop Beacon Decoding ESCU actions · alerting P Windows Process Executed From Removable Media ESCU actions · hunting P Windows Process Injection into Commonly Abused Processes ESCU actions · hunting P Windows Process Injection into Notepad ESCU actions · hunting P Windows Process Injection Remote Thread ESCU actions · alerting P Windows Rapid Authentication On Multiple Hosts ESCU actions · alerting P Windows RDP Login Session Was Established ESCU actions · hunting P Windows Remote Management Execute Shell ESCU actions · hunting P Windows Renamed Powershell Execution ESCU actions · alerting P Windows Rundll32 WebDAV Request ESCU actions · hunting P Windows Rundll32 with Non-Standard File Extension ESCU actions · hunting P Windows Scheduled Task Created in a Group Policy Object ESCU actions · alerting P Windows Scheduled Task Service Spawned Shell ESCU actions · alerting P Windows Sensitive Registry Hive Dump Via CommandLine ESCU actions · alerting P Windows Service Create RemComSvc ESCU actions · hunting P Windows Service Create SliverC2 ESCU actions · alerting P Windows Service Created with Suspicious Service Name ESCU actions · hunting P Windows Service Created with Suspicious Service Path ESCU actions · alerting P Windows Shell or Script Execution From IIS Directory ESCU actions · hunting P Windows Snake Malware Service Create ESCU actions · alerting P Windows Special Privileged Logon On Multiple Hosts ESCU actions · alerting P Windows SpeechRuntime Suspicious Child Process ESCU actions · alerting P Windows Steal Authentication Certificates - ESC1 Authentication ESCU actions · alerting P Windows Steal or Forge Kerberos Tickets Klist ESCU actions · hunting P Windows Suspicious Child Process of TieringEngineService.exe ESCU actions · alerting P Windows Suspicious Child Process Spawned From WebServer ESCU actions · hunting P Windows Suspicious React or Next.js Child Process ESCU actions · alerting P Windows Suspicious VMWare Tools Child Process ESCU actions · alerting P Windows Terminating Lsass Process ESCU actions · hunting P Windows UAC Bypass Suspicious Child Process ESCU actions · alerting P Windows Uncommon Remote Thread Creation In Browser Process ESCU actions · hunting P Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos ESCU actions · hunting P Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos ESCU actions · hunting P Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM ESCU actions · hunting P Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials ESCU actions · hunting P Windows Unusual Count Of Users Failed To Authenticate From Process ESCU actions · hunting P Windows Unusual Count Of Users Failed To Authenticate Using NTLM ESCU actions · hunting P Windows Unusual Count Of Users Remotely Failed To Auth From Host ESCU actions · hunting P Windows USBSTOR Registry Key Modification ESCU actions · hunting P Windows VSSVC Process Accessing Defender Engine ESCU actions · alerting P Windows Vulnerable Driver Installed ESCU actions · alerting P Windows WMI Impersonate Token ESCU actions · hunting P Windows WMI Reconnaissance Class Query ESCU actions · hunting P Windows WMIC Shadowcopy Delete ESCU actions · hunting P Windows WPDBusEnum Registry Key Modification ESCU actions · hunting P WinEvent Scheduled Task Created to Spawn Shell ESCU actions · alerting P WinRM Spawning a Process ESCU actions · alerting P Wmic Group Discovery ESCU actions · hunting P Wmic NonInteractive App Uninstallation ESCU actions · hunting P Wscript Or Cscript Suspicious Child Process ESCU actions · hunting P Rundll32 DNSQuery ESCU actions · alerting P Suspicious Process DNS Query Known Abuse Web Services ESCU actions · alerting P Attempted Credential Dump From Registry via Reg exe ESCU actions · alerting P Cmdline Tool Not Executed In CMD Shell ESCU actions · alerting P Detect Activity Related to Pass the Hash Attacks ESCU actions · hunting P Detect Mimikatz Via PowerShell And EventCode 4703 ESCU actions · alerting P Detect Webshell Exploit Behavior ESCU actions · alerting P First time seen command line argument ESCU actions · hunting P Rundll32 CreateRemoteThread In Browser ESCU actions · alerting P Suspicious Powershell Command-Line Arguments ESCU actions · alerting P Suspicious Rundll32 Rename ESCU actions · hunting P Suspicious writes to System Volume Information ESCU actions · hunting P

Recent articles citing Windows-targeted detections