Clankerusecase
Windows detection coverage
← Back to main site
Home/ Targets/ Windows

🪟Windows detections

Clankerusecase tracks 1880 detection use cases covering the Windows attack surface across 309 MITRE ATT&CK techniques.

Detections targeting Windows endpoints — Sysmon / Security event log / Defender DeviceProcessEvents.

Open Detection Library → View on the matrix
1880Use cases
309Techniques
60Articles
6Kill-chain phases

Top techniques on Windows (25)

Reconnaissance (9)

[LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] IPMI/BMC service discovery scan across many hosts (UDP/623) Bespoke recon · alerting DSPDDCSCW [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] HelloExecutor recon enumerating ViPNet Client/Administrator Export key stores Bespoke recon · hunting DSΣPDDCS [LLM] The Gentlemen internal reconnaissance via Advanced IP Scanner Bespoke recon · hunting DSΣPDDCS [LLM] FileBrowser instance configured with auth.method=proxy (exploitable-config exposure) Bespoke recon · hunting DSΣPDDCS [LLM] SiYuan kernel config (conf.json) written — audit for empty/missing AccessAuthCode Bespoke recon · hunting DSΣPDDCS [LLM] node-ipc geofencing beacon: node.exe resolving/contacting api.ipgeolocation.io during install Bespoke recon · hunting DSΣPDDCS [LLM] Gradle plugin-publish run with verbose logging leaks pre-signed AWS URL (CVE-2020-7599) Bespoke recon · hunting DSΣPDDCS

Delivery (169)

Email attachment opened from external sender Internal delivery · hunting DSP Phishing-link click correlated to endpoint execution Internal delivery · alerting DSP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [LLM] Inbound network access to Ruflo bridge (3001) / MongoDB (27017) from public source Bespoke delivery · hunting DSPDDCSCW [LLM] Inbound OT-segment connections from CyberAv3ngers infrastructure (185.82.73.160/28, 135.136.1.133) Bespoke delivery · hunting DSΣPDDCS [LLM] Internet-sourced access to OT/ICS PLCs on EtherNet/IP, Modbus & S7comm ports Bespoke delivery · hunting DSΣP [LLM] Endpoint contact with F6 fraud-campaign hosting infra (212.127.73.235 / 167.86.100.68) Bespoke delivery · hunting DSΣPDDCS [LLM] DNS / web resolution of F6 counterfeit Russian-company domains Bespoke delivery · alerting DSΣPDDCS [LLM] Flying Eagle / SpyNote malicious APK download by hash or distribution domain Bespoke delivery · hunting DSΣPDDCS [LLM] Install/import of compromised @joyfill 2773 beta package versions Bespoke delivery · alerting DSΣPDDCS [LLM] goshs process accepting inbound SFTP/SSH connections (exposed file server) Bespoke delivery · hunting DSPDDCS [LLM] Endpoint traffic to cubepilot.org during 24 Jul 2026 DNS-hijack / AiTM window Bespoke delivery · hunting DSPDDCS [LLM] CubePilot firmware/file downloaded from cubepilot.org on 24-25 Jul 2026 (possible tampered supply chain) Bespoke delivery · hunting DSP [LLM] Telnet credential brute force against internet-exposed IoT/Linux devices (Tengu dropper entry) Bespoke delivery · alerting DSP [LLM] ARToken/EvilTokens device-code phishing: contact with pamconj C2 and Cloudflare Workers lures Bespoke delivery · alerting DSΣPDDCS [LLM] Inbound connections from Arista-attributed VeloCloud Orchestrator attacker IPs (CVE-2026-16812) Bespoke delivery · hunting DSΣPCS [LLM] Compromised device Telnet/SSH weak-password worm fan-out Bespoke delivery · alerting DSPDDCS [LLM] Operation BlueDash fake Teams/Zoom update payload-host infrastructure contact Bespoke delivery · alerting DSΣPDDCS [LLM] ISO-delivered signed RegSchdTask.exe executed from non-standard/removable path Bespoke delivery · hunting DSΣPDDCS [LLM] SourTrade malvertising infrastructure contact (campaign domains + Bun-runtime host) Bespoke delivery · alerting DSΣPDDCS [LLM] SourTrade ServiceWorker build-instruction fetch (/config + /sw.js on campaign domains) Bespoke delivery · hunting DSΣP [LLM] InsureTrap malvertising: Google Ads referrer landing on free-hosting insurance phish Bespoke delivery · hunting DSΣP [LLM] Malicious mrmustard 0.7.4 artifact by hash or filename Bespoke delivery · hunting DSΣPCS [LLM] Vulnerable @prompty/core package present in node_modules (GHSA-w28w-gp39-m4p6 exposure) Bespoke delivery · hunting DSΣPDDCS [LLM] Kiota-generated *-apiplugin.json manifest written to disk (CVE-2026-59864 artifact) Bespoke delivery · hunting DSΣPDDCS [LLM] BlueNoroff typosquatted Zoom/Teams infrastructure network contact Bespoke delivery · alerting DSΣPDDCS [LLM] UAC-0099 VBScript-as-PDF downloader dropping second-stage Evernote.zip Bespoke delivery · alerting DSΣPDDCS [LLM] msaRAT: curl.exe downloading MSI payload into ProgramData Bespoke delivery · alerting DSΣPDDCS [LLM] Financial_report.bat dropper downloaded from ClickUp attachment host Bespoke delivery · alerting DSΣPDDCS [LLM] msaRAT delivery: curl.exe fetching fake Windows-update MSI to ProgramData over HTTP Bespoke delivery · alerting DSΣPDDCS [LLM] Shai-Hulud / GhostAction malicious workflow artifact dropped on runner or repo checkout Bespoke delivery · hunting DSΣPDDCS [LLM] Endpoint DNS resolution or web connection to npm phishing domain npmjs.help Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable @sigstore/oci (<=0.7.0) installed into node_modules — incl. transitive deps (CVE-2026-59891) Bespoke delivery · hunting DSΣPDDCS [LLM] Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke delivery · alerting DSΣPDDCS [LLM] Ruby/gem process downloading payload from git.disroot.org (SleeperGem) Bespoke delivery · alerting DSΣPDDCS [LLM] SleeperGem malicious gem artifacts written to gems path (git_credential_manager / Dendreo / fastlane-plugin) Bespoke delivery · alerting DSΣPDDCS [LLM] ClickFix RunMRU entry launching rundll32 against WebDAV GUID share (ACR Stealer) Bespoke delivery · alerting DSΣPDDCS [LLM] MSHTA remote HTA launched by explorer→powershell chain (ACR Stealer fileless campaign) Bespoke delivery · alerting DSΣPDDCS [LLM] Trojanized WebEx/Zoom/MobaXterm installer spawns Python or script host (UAT-11795 Starland RAT) Bespoke delivery · alerting DSΣPDDCS [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @asyncapi npm package versions resolved into node_modules / Yarn cache Bespoke delivery · alerting DSΣPDDCS [LLM] Node.js retrieving Miasma second stage from IPFS gateway (specific CIDs) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious @velora-dex/sdk (9.4.1/9.4.2) pulled into GitHub Actions build runner Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @velora-dex/sdk npm package (9.4.1/9.4.2) installed on CI runner Bespoke delivery · alerting DSΣPDDCS [LLM] TuxBot Telnet/ADB scanner fan-out (credential brute-force propagation) Bespoke delivery · alerting DSPCS [LLM] Malicious startup-module tiddler (.js.tid) written into a TiddlyWiki tiddlers/ directory Bespoke delivery · hunting DSΣPDDCS [LLM] Anyquery server mode bound to all interfaces (exposed unauthenticated MySQL port) Bespoke delivery · hunting DSΣPDDCS [LLM] Inbound connection to Anyquery listener from a public IP Bespoke delivery · hunting DSPCS [LLM] pip install redirected to non-PyPI index / find-links (dependency confusion) Bespoke delivery · hunting DSΣPDDCS [LLM] Miasma/AsyncAPI first-stage: node spawns detached 'node -e' downloader referencing IPFS/sync.js Bespoke delivery · alerting DSΣPDDCS [LLM] npm maintainer credential-phish lookalike domain npmjs.help (chalk/debug ATO) Bespoke delivery · alerting DSΣPDDCS [LLM] jscrambler npm supply-chain: malicious dist/intro.js binary container drop Bespoke delivery · alerting DSΣPDDCS [LLM] FileBrowser reverse-proxy bypass: direct external access to exposed port 8085 Bespoke delivery · alerting DSΣPDDCS [LLM] Non-SiYuan process writing synced snippet store data\snippets\conf.json Bespoke delivery · hunting DSΣPDDCS [LLM] Transitive install of poisoned @injectivelabs 1.20.21 build under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Joro proxy-mode confused-deputy: browser POSTs to loopback API 127.0.0.1:9090 (CVE-2026-53649) Bespoke delivery · hunting DSΣPCS [LLM] PromptSpy dropper APK sample hash landing on monitored endpoint Bespoke delivery · hunting DSΣP [LLM] Null-byte inflated PE loader (>200 MB) written to user staging folder Bespoke delivery · hunting DSPCS [LLM] Browser-dropped .bin password-protected archive (fake software crack lure) Bespoke delivery · hunting DSΣPDDCS [LLM] Vulnerable halo2_gadgets / orchard / zcash_primitives crate unpacked in cargo dirs Bespoke delivery · hunting DSPCS [LLM] ZDI-CAN-25373 (CVE-2025-9491) LNK spawning PowerShell to fetch BusySnake loader Bespoke delivery · alerting DSΣPDDCS [LLM] tj-actions/changed-files malicious commit 0e58ed86 referenced on host (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] curl/wget child of 9router node fetching tailscale.com/install.sh (probe or exploit delivery) Bespoke delivery · hunting DSΣPDDCS [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) Bespoke delivery · alerting DSΣPDDCS [LLM] kubectl apply of attacker-crafted Rancher import URL (authImage payload delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious easy-day-js typosquat package written into node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @immobiliarelabs Backstage plugin on disk (binding.gyp + index.js / known hashes) Bespoke delivery · hunting DSΣPDDCS [LLM] Malicious index.js dropped into codfish/semantic-release-action runner checkout Bespoke delivery · hunting DSΣPDDCS [LLM] Install of known-malicious JetBrains Marketplace plugin (15 trojanized plugin IDs) Bespoke delivery · hunting DSΣPDDCS [LLM] Montana Empire phishing-kit ZIP + companion APK by SHA256 on endpoints Bespoke delivery · hunting DSΣPCS [LLM] Known Miasma index.js payload hash present on CI runner (codfish action) Bespoke delivery · alerting DS [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper Bespoke delivery · hunting DSΣPCS [LLM] easy-day-js malicious setup.cjs written/deleted under node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] AUR build pulls malicious npm/Bun dependency (atomic-lockfile / js-digest / lockfile-js) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious easy-day-js package installed into node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 Bespoke delivery · alerting DSΣPDDCS [LLM] FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious 'postmark-mcp' MCP server package present/executing on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Scripting interpreter downloads Bun v1.3.14 runtime from oven-sh GitHub releases Bespoke delivery · hunting DSPCS [LLM] Miasma-tainted package install: binding.gyp dropped into known-compromised npm package paths Bespoke delivery · alerting DSΣPDDCS [LLM] Miasma/Node-gyp loader file hashes present on developer or CI host Bespoke delivery · hunting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Nx Console v18.95.0 Malicious Payload Bootstrap via Orphan Commit (npx github:nrwl/nx#558b09d7) Bespoke delivery · alerting DSΣPDDCS [LLM] jqwik-engine 1.10.0 malicious JAR on disk (SHA256 / filename match) Bespoke delivery · hunting DSΣPDDCS [LLM] Install or update of @redhat-cloud-services npm package post-2026-06-01 (IOC version watchlist) Bespoke delivery · hunting DSΣPDDCS [LLM] npm/pnpm install of trojanized codexui-android package on developer endpoint Bespoke delivery · hunting DSΣPDDCS [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree Bespoke delivery · hunting DSΣPDDCS [LLM] Composer install of malicious helpers.php in laravel-lang vendor package Bespoke delivery · hunting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] Endpoint DNS or web traffic to fake FIFA World Cup 2026 typosquat domain Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised Nx Console VS Code extension (nrwl.angular-console v18.94.0/18.95.0/18.100.0) install on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Nx Console v18.95.0 compromised extension installed (May 2026 supply-chain attack) Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised Microsoft durabletask PyPI Package Install (TeamPCP 1.4.1-1.4.3) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious node-ipc package landed on disk under node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm payload dropped under node_modules (router_init.js / tanstack_runner.js / known SHA256) Bespoke delivery · hunting DSΣPDD [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) Bespoke delivery · alerting DSΣPDDCS [LLM] Install of trojaned elementary-data 0.23.3 via pip / poetry / uv Bespoke delivery · alerting DSΣPDDCS [LLM] Docker / Kubernetes pull of compromised ghcr.io/elementary-data/elementary image Bespoke delivery · alerting DSΣPDDCS [LLM] Bun runtime fetched from github.com/oven-sh/bun during npm install (Bitwarden CLI hijack) Bespoke delivery · alerting DSPDDCS [LLM] Known-bad tanstack 2.0.4-2.0.7 package tarball SHA256 file hash on disk Bespoke delivery · hunting DSΣPDDCS [LLM] Compromised elementary-data==0.23.3 PyPI install on developer / CI host Bespoke delivery · alerting DSΣPDDCS [LLM] Qinglong cryptominer payload download from file.551911.xyz Bespoke delivery · alerting DSΣPDDCS [LLM] Context.ai compromised Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) present on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] Access to NGate distribution domain protecaocartao[.]online (HandyPay trojan + APK delivery) Bespoke delivery · hunting DSΣP [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious axios or plain-crypto-js package files written to node_modules Bespoke delivery · hunting DSΣPDDCS [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release Bespoke delivery · alerting DSΣPDD [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] pip install of malicious telnyx versions 4.87.1 / 4.87.2 Bespoke delivery · alerting DSΣPDDCS [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 Bespoke delivery · hunting DSΣPDDCS [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Telnyx PyPI compromise: malicious telnyx 4.87.1 / 4.87.2 hash on disk Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP WAV-stego payload drop (hangup.wav / ringtone.wav) Bespoke delivery · alerting DSPDDCS [LLM] Compromised bittensor-wallet 4.0.2 source-tarball SHA256 on disk Bespoke delivery · hunting DSΣPDD [LLM] Compromised react-native-international-phone-number / react-native-country-select files written to node_modules Bespoke delivery · alerting DSΣPDDCS [LLM] Attacker-controlled scoped npm relay packages on disk (@usebioerhold8733 / @agnoliaarisian7180) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious typosquat npm packages installed on disk (ts-bign / big-nunber / levex-refa / lint-builder) Bespoke delivery · hunting DSΣPDD [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious litellm 1.82.7/1.82.8 wheel install drops litellm_init.pth in site-packages Bespoke delivery · alerting DSΣPDDCS [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) Bespoke delivery · alerting DSΣPDDCS [LLM] VSCode/VSCodium spawning shell or curl to raw.githubusercontent.com/BlokTrooper Bespoke delivery · alerting DSΣPDDCS [LLM] VSCode-family host fetching from raw.githubusercontent.com/BlokTrooper/extension path Bespoke delivery · hunting DSΣPDDCS [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Bespoke delivery · alerting DSPDD [LLM] PromptSpy/VNCSpy Android trojan distribution & fake-JPMorgan domains (mgardownload.com / m-mgarg.com) Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of unauthorized cline@2.3.0 npm package on developer endpoints Bespoke delivery · alerting DSΣPDDCS [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] tj-actions/changed-files compromise: self-hosted runner egress to nikitastupin memdump gist (CVE-2025-30066) Bespoke delivery · hunting DSΣPDD [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) Bespoke delivery · alerting DSΣPDDCS [LLM] Dev endpoint contacts ClawHub / skills.sh agent-skill marketplace Bespoke delivery · hunting DSΣPDDCS [LLM] Executable dropped into C:\inetpub\pub\ shared directory Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised npm package @vietmoney/react-big-calendar@0.26.2 installation (Shai-Hulud 3.0) Bespoke delivery · alerting DSΣPDDCS [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] IndonesianFoods npm spam package install on developer/CI endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] Browser/HTTPS traffic to npmjs.help credential-harvesting page Bespoke delivery · alerting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS [LLM] Scavenger Loader DLL (node-gyp.dll) written inside node_modules of CVE-2025-54313 packages Bespoke delivery · alerting DSΣPDDCS [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) Bespoke delivery · alerting DSΣPDDCS [LLM] Self-hosted GitHub Action runner downloads memdump.py from compromised gist (CVE-2025-30066) Bespoke delivery · alerting DSΣPDDCS [LLM] Go typosquat module reference: github.com/boltdb-go/bolt in process or build telemetry Bespoke delivery · alerting DSΣPDDCS [LLM] Browser/proxy fetch of compromised @lottiefiles/lottie-player from unpkg or jsDelivr CDN Bespoke delivery · alerting DSΣP [LLM] npm/yarn/pnpm install of himanshutester002 suspicious aliased packages (string-width-cjs et al) Bespoke delivery · alerting DSΣPDDCS [LLM] Inbound UDP/631 (CUPS IPP discovery) from external network Bespoke delivery · hunting DSΣPDDCS [LLM] Polyfill.io supply-chain compromise: egress to Funnull-controlled CDN cluster Bespoke delivery · alerting DSΣPDDCS [LLM] Vulnerable Moq 4.20.0 or Devlooped.SponsorLink NuGet package landed on endpoint Bespoke delivery · alerting DSΣPDDCS [LLM] JVM outbound fetch of remote class/JAR to public host — URLClassLoader gadget Bespoke delivery · hunting DSPDDCS [LLM] Install of ypvpctpbamdhxtkzdu malicious package set (django-yauth + siblings) Bespoke delivery · hunting DSΣPDDCS [LLM] Lockfile injection: npm/yarn fetching dependencies from GitHub gist/repo instead of the registry Bespoke delivery · hunting DSΣPDDCS [LLM] node-ipc protestware dropper file 'ssl-geospec.js' written under node_modules\node-ipc Bespoke delivery · alerting DSΣPDDCS [LLM] Python interpreter drops EXE sourced from Discord CDN (cyphers/stealthpy PyPI malware) Bespoke delivery · alerting DSΣPDDCS [LLM] gxm-reference encrypted-payload artifacts written to disk (obfusc/mac/win/lin .enc.js) Bespoke delivery · alerting DSΣPDDCS [LLM] Install/resolution of sabotaged npm packages colors@1.4.1/1.4.2/liberty-2 or faker@6.6.6 Bespoke delivery · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI connection (Log4Shell second-stage class fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Known-malicious npm packages flatmap-stream / lyft-dataset-sdk landing on host Bespoke delivery · alerting DSΣPDDCS [LLM] Attacker-staged .session deserialization payload written outside Tomcat's session store Bespoke delivery · hunting DSΣPDDCS [LLM] Maven fetching dependencies over cleartext HTTP (MITM-exposed artifact download) — CVE-2021-26291 Bespoke delivery · hunting DSPDDCS [LLM] Installation of Snyk-flagged malicious npm packages (radar-cms, rcenodejs, paychex-*) Bespoke delivery · alerting DSΣPDDCS [LLM] hacktask typosquat npm package drops postinstall payload 'package-setup.js' Bespoke delivery · hunting DSΣPDDCS [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) Bespoke delivery · alerting DSΣPDDCS [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) Bespoke delivery · hunting DSΣPDDCS [LLM] Typosquatted PyPI package install: jeIlyfish / python3-dateutil Bespoke delivery · alerting DSΣPDDCS [LLM] Install of malicious npm package versions angular-bmap@0.0.9 / ng-ui-library@1.0.987 Bespoke delivery · alerting DSΣPDDCS [LLM] npm/yarn dependency fetched from non-registry source (lockfile resolved-URL hijack) Bespoke delivery · hunting DSΣPDDCS [LLM] Malicious flatmap-stream npm package present in node_modules (event-stream supply-chain backdoor) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious npm flatmap-stream / event-stream@3.3.6 dependency dropped to endpoint disk Bespoke delivery · alerting DSΣPDDCS

Exploitation (594)

Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal exploit · alerting DSΣP Office app spawning script/LOLBin child process Internal exploit · alerting DSΣP PowerShell encoded / obfuscated command Internal exploit · alerting DSΣP Trusted vendor binary / installer launching unusual children Internal exploit · hunting DSΣP [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [LLM] JFrog Artifactory service process spawning a shell or downloader (RCE exploitation) Bespoke exploit · alerting DSΣPCS [LLM] Ruflo/Node MCP bridge spawning interactive shell inside container (RufRoot RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Outdated Tor Browser bundling vulnerable Firefox (CVE-2026-10702 exposure) Bespoke exploit · hunting DSPDDCS [LLM] Firefox/Tor renderer (content) process spawning an unexpected child — sandbox escape / RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Check Point mgmt server contact from CVE-2026-16232 exploitation source IPs Bespoke exploit · hunting DSΣPDDCS [LLM] Gitea git process spawning shell / network tool via planted hook (CVE-2026-60004 RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates Bespoke exploit · hunting DSP Article-specific behavioural hunt — Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Bespoke exploit · hunting DSP [LLM] Node.js spawning shell/recon binaries or detached node -e loader Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable @hypequery/clickhouse dependency present (< 2.0.2, CVE-2026-54658) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf Bespoke exploit · alerting DSΣPDDCS [LLM] JFrog Artifactory service process spawning a shell or network tool (RCE) Bespoke exploit · alerting DSΣPCS [LLM] Internet-exposed BMC IPMI RAKP hash disclosure exposure (UDP/623) Bespoke exploit · hunting DSΣPDDCSCW Article-specific behavioural hunt — Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays Bespoke exploit · hunting DSP Article-specific behavioural hunt — IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack Bespoke exploit · hunting DSP [LLM] TeamCity server (java) process spawning an OS command interpreter — CVE-2026-63077 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Linux root process executed from memfd (CVE-2026-53264 core-dump payload) Bespoke exploit · alerting DSΣPDDCS [LLM] Unprivileged Linux tc clsact/flower/gact traffic-control manipulation (CVE-2026-53264 trigger) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Mirage Kitten targets Middle East and Africa region with new malware Bespoke exploit · hunting DSP [LLM] AppVShNotify.exe spawning child processes (NightLedger command dispatcher execution) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process Bespoke exploit · hunting DSP [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update Bespoke exploit · hunting DSP Article-specific behavioural hunt — Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware Bespoke exploit · hunting DSP [LLM] Cruciferra known-sample SHA256 execution/write Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executabl Bespoke exploit · hunting DSP [LLM] GitLab Puma/Ruby worker (running as git) spawns shell or network tool — Oj .ipynb RCE landing Bespoke exploit · hunting DSΣPDDCS [LLM] PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Bespoke exploit · hunting DSP [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection t Bespoke exploit · hunting DSP [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-7gfh-x38p-prh3: Velocity.js: Remote Code Execution via pr Bespoke exploit · hunting DSP [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] `kiota info` run against a remote/untrusted OpenAPI description (CVE-2026-59865) Bespoke exploit · hunting DSΣPDDCS [LLM] ClickFix PowerShell loader spawning wscript to run downloaded VBScript Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Doma Bespoke exploit · hunting DSP [LLM] AD CS CA server initiates SMB(445)+LDAP(389) to a non-DC host (Certighost chase relay) Bespoke exploit · hunting DSPCS [LLM] Domain Controller machine account obtains TGT via PKINIT certificate (Certighost impersonation) Bespoke exploit · hunting SΣP Article-specific behavioural hunt — Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Min Bespoke exploit · hunting DSP [LLM] Web/interpreter process connecting to internal HiveServer2 (10000) or Hadoop NameNode (50070) Bespoke exploit · alerting DSΣPCS [LLM] LinPEAS / SUID sweep privilege-escalation enumeration on Linux Bespoke exploit · hunting DSΣPDDCS [LLM] redis-server spawns a shell/interpreter (system() from Redis RCE chain) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks Bespoke exploit · hunting DSP [LLM] Notepad++ spawning WinRAR/schtasks/shell children (LUNCHPOKE post-load execution) Bespoke exploit · alerting DSΣPDDCS [LLM] ZimReaper CVE-2025-66376 payload staging — DNS to js-*.i.zimbrasoft.com.ua Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Don’t swing at everything Bespoke exploit · hunting DSP Article-specific behavioural hunt — Email threat landscape: Q2 2026 trends and insights Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-8fpg-xm3f-6cx3: Auth.js: Configuration errors can cause e Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-7rqj-j65f-68wh: Auth.js: Email normalizer validates the a Bespoke exploit · hunting DSP Article-specific behavioural hunt — Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel Bespoke exploit · hunting DSP Article-specific behavioural hunt — Finding eight high-severity vulnerabilities in NodeBB in six hours Bespoke exploit · hunting DSP [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analy Bespoke exploit · hunting DSP [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-p63j-vcc4-9vmv: @vitest/browser: Browser Mode provider co Bespoke exploit · hunting DSP [LLM] Vitest Browser Mode / test API (node.exe) accepting inbound connections on 63315/51204 from non-loopback host Bespoke exploit · hunting DSΣPDDCS [LLM] MSSQL sqlservr.exe spawning OS shell via xp_cmdshell (XEntry Team) Bespoke exploit · alerting DSΣPDDCS [LLM] AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA rec Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimite Bespoke exploit · hunting DSP Article-specific behavioural hunt — SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems D Bespoke exploit · hunting DSP [LLM] Ruby interpreter spawning PowerShell -ExecutionPolicy bypass or /bin/sh (SleeperGem dropper) Bespoke exploit · hunting DSΣPDDCS [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — ACR Stealer: Two observed intrusion chains amid increased threat activity Bespoke exploit · hunting DSP [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Begun, the Patch Wars have Bespoke exploit · hunting DSP [LLM] PowerShell AMSI/ETW bypass reflection (UAT-11795 WLDR evasion) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — HelloNet campaign: new malicious modules launched through the ViPNet update syst Bespoke exploit · hunting DSP Article-specific behavioural hunt — GoSerpent: a persistent threat evolves with sophisticated data collection and ex Bespoke exploit · hunting DSP Article-specific behavioural hunt — UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially Bespoke exploit · hunting DSP Article-specific behavioural hunt — Unpacking the AsyncAPI npm supply chain compromise and import-time payload deliv Bespoke exploit · hunting DSP [LLM] npm/node install-time payload: package manager spawning curl/launchctl/osascript on a runner Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Bespoke exploit · hunting DSP Article-specific behavioural hunt — OkoBot: new sophisticated malware framework targets cryptocurrency users Bespoke exploit · hunting DSP [LLM] OkoBot UAC bypass via auto-elevated msconfig.exe spawning payload Bespoke exploit · hunting DSΣPDDCS [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir Bespoke exploit · alerting DSPCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-9hc2-hjx8-q6pv: TidGi Desktop Remote Code Execution via M Bespoke exploit · hunting DSP [LLM] TidGi Desktop wiki worker spawning a command interpreter (TiddlyWiki startup-module RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — The serpent’s tongue: Luring the Python out of its den Bespoke exploit · hunting DSP [LLM] Python setup.py install-time code execution spawning shell/LOLBin Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — AsyncAPI npm packages backdoored via GitHub Actions Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enab Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Bespoke exploit · hunting DSP [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP Article-specific behavioural hunt — What is a dependency firewall? Bespoke exploit · hunting DSP Article-specific behavioural hunt — jscrambler npm package publishes malicious preinstall binary Bespoke exploit · hunting DSP Article-specific behavioural hunt — Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Bespoke exploit · hunting DSP Article-specific behavioural hunt — No Manners Here: The Ruthless Rise of The Gentlemen Ransomware Bespoke exploit · hunting DSP [LLM] GentleKiller BYOVD: ThrottleBlood.sys vulnerable driver load (CVE-2025-7771) Bespoke exploit · alerting DSΣPDDCS [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) Bespoke exploit · alerting DSΣPDDCS [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] External browser process connects to SiYuan kernel loopback admin port 127.0.0.1:6806 Bespoke exploit · hunting DSΣPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Bespoke exploit · hunting DSP [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Winning 54% of the time Bespoke exploit · hunting DSP Article-specific behavioural hunt — Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry Bespoke exploit · hunting DSP Article-specific behavioural hunt — One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforce Bespoke exploit · hunting DSP [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] Joro native plugin RCE: joro process spawns interactive /bin/bash shell (CVE-2026-53649) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55500: 9routers has Exposure of Sensitive Information Bespoke exploit · hunting DSP [LLM] Execution of unpatched Zcash node binary (zebrad / zcashd / zcash-cli) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55615: Langroid: Neo4jChatAgent executes LLM-generate Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-vjc7-jrh9-9j86: 9router has unauthenticated CRUD on /api/ Bespoke exploit · hunting DSP [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) Bespoke exploit · hunting DSΣPCS [LLM] Langroid eval() exploit signature: __import__('os') / full_eval=True in cmdline or app logs Bespoke exploit · alerting DSΣPDDCS [LLM] Craft/PHP/IIS web worker spawning a command shell (Formie SSTI RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Camel gridfs.* control-header injection inbound (CVE-2026-48204 exploit) Bespoke exploit · hunting SΣPDD Article-specific behavioural hunt — Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign Bespoke exploit · hunting DSP Article-specific behavioural hunt — How We Added WebAuthn to a Browser-Based RDP Client Bespoke exploit · hunting DSP [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS Bespoke exploit · hunting DSΣPDDCS [LLM] 9router unauthenticated MCP / cli-tools route RCE via process spawn — CVE-2026-46339 Bespoke exploit · alerting DSΣPCS [LLM] LaunchServer path-traversal exploit signature: request-target without leading slash / %2e%2e on port 9274 Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52830: fast-mcp-telegram: Bearer token path traversal Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59800: 9router: Missing Authorization and OS Command Bespoke exploit · hunting DSP [LLM] Unauthenticated POST to 9router /api/tunnel/tailscale-install (CVE-2026-59800 auth bypass) Bespoke exploit · alerting DSΣP [LLM] 9router (node) process spawning 'sudo -S sh' — CVE-2026-59800 command injection primitive Bespoke exploit · hunting DSΣPDDCS [LLM] 9router chain: node fetches tailscale.com/install.sh then spawns sudo -S sh within seconds Bespoke exploit · alerting DSPCS [LLM] Mautic Twig SSTI RCE: PHP/web process spawns OS shell (CVE-2026-9558) Bespoke exploit · alerting DSΣPDDCS [LLM] zebrad node process execution at vulnerable version (CVE-2026-52735) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Catan and Mouse Bespoke exploit · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50027: mcp-memory-service: Missing Authentication on Bespoke exploit · hunting DSP Article-specific behavioural hunt — Missed incidents, persistent threats, and response gaps: Insights from compromis Bespoke exploit · hunting DSP [LLM] Web shell execution: web server process spawning command interpreters Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Multiple @immobiliarelabs Backstage Plugins Compromised on npm Bespoke exploit · hunting DSP [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised Bespoke exploit · hunting DSP [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — codfish/semantic-release-action GitHub Action has been compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice? Bespoke exploit · hunting DSP [LLM] FortiBleed MSSQL login-failure burst then success (internet-exposed SQL spraying) Bespoke exploit · alerting DSP Article-specific behavioural hunt — CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Bespoke exploit · hunting DSP [LLM] IIS web shell (w3wp.exe) spawning recon, curl exfil, or RAR staging Bespoke exploit · hunting DSΣPDDCS [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets Bespoke exploit · hunting DSP Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc Bespoke exploit · hunting DSP Article-specific behavioural hunt — What nearly 10,000 developer environments reveal about agentic development risk Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosqu Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi Bespoke exploit · hunting DSP Article-specific behavioural hunt — A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE Bespoke exploit · hunting DSP Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Bespoke exploit · hunting DSP Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori Bespoke exploit · hunting DSP [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Bespoke exploit · hunting DSP Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Bespoke exploit · hunting DSP [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Bespoke exploit · hunting DSP Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Nx Console VS Code Extension Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Bespoke exploit · hunting DSP Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Bespoke exploit · hunting DSP Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory Bespoke exploit · hunting DSP Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Bespoke exploit · hunting DSP Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub Bespoke exploit · hunting DSP Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Bespoke exploit · hunting DSP Article-specific behavioural hunt — Webworm: New burrowing techniques Bespoke exploit · hunting DSP Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Bespoke exploit · hunting DSP Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Bespoke exploit · hunting DSP Article-specific behavioural hunt — Active Supply Chain Attack: Malicious node-ipc Versions Published to npm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious node-ipc versions published to npm in suspected maintainer account com Bespoke exploit · hunting DSP Article-specific behavioural hunt — FrostyNeighbor: Fresh mischief and digital shenanigans Bespoke exploit · hunting DSP [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromi Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Bespoke exploit · hunting DSP Article-specific behavioural hunt — TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Bespoke exploit · hunting DSP

Installation (460)

Suspicious browser extension installation Internal install · hunting DSΣP File hash IOCs — endpoint file/process match Internal install · alerting DSΣP RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal install · hunting DSΣP Scheduled task created with suspicious image / encoded args Internal install · hunting DSΣP Service install for persistence — sc.exe / new service registry write Internal install · hunting DSΣP [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes Internal install · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress Internal install · alerting DSΣPDDCS [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Article-specific behavioural hunt — Cisco warns of FMC static credential flaw exploited in zero-day attacks Bespoke install · hunting DSP Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration inj Bespoke install · hunting DSP [LLM] Fluentd aggregator pod spawns a shell (out_exec RCE execution) Bespoke install · alerting DSΣPDDCS [LLM] Backdoor payload written to /app by shell/downloader after Ruflo RCE Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands Bespoke install · hunting DSP [LLM] Git server-side hook file written (hooks/post-index-change) - CVE-2026-60004 persistence Bespoke install · alerting DSΣPCS [LLM] Node.js modifying developer-tool modules for RAT self-reload persistence Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty pas Bespoke install · hunting DSP [LLM] Tengu ELF-header corruption ('ELFOOD') of Linux reboot/shutdown utilities Bespoke install · hunting DSΣPCS [LLM] Tengu guardian process masquerading as kernel thread [kworker/0:0] Bespoke install · hunting DSΣPDDCS [LLM] Tengu immutable-binary persistence via chattr +i on Linux/IoT Bespoke install · hunting DSΣPDDCS [LLM] NightLedger DLL side-load: AppVShNotify.exe loading SspiCli.dll from non-System32 Bespoke install · alerting DSΣPDDCS [LLM] Zoho Assist Unattended Agent deployed for headless remote control (Warlock/Storm-2603) Bespoke install · hunting DSΣPDDCS [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 Bespoke install · hunting DSΣPDDCS [LLM] Linux core_pattern overwritten to memfd/pipe handler (CVE-2026-53264 privesc payoff) Bespoke install · alerting DSΣPDDCS [LLM] NightLedger DLL search-order hijack: SspiCli.dll side-loaded by AppVShNotify.exe Bespoke install · alerting DSΣPDDCS [LLM] BridgeHead/ArcBridge tunneler deployment: unbcl.dll & libwinpthread-1.dll in anomalous paths Bespoke install · alerting DSΣPDDCS [LLM] supportdev.exe Inno Setup loader spawning hidden-window PowerShell Bespoke install · alerting DSΣPDDCS [LLM] Level RMM enrollment with BlueDash attacker API key (GxSCHE8EZwfyYN3iPQHPai8D) Bespoke install · alerting DSΣPDDCS [LLM] Multiple RMM agents co-resident on one host (BlueDash redundant access) Bespoke install · alerting DSPDDCS [LLM] Cruciferra persistence: Run key 'putty' value pointing to non-PuTTY binary Bespoke install · alerting DSΣPDDCS [LLM] Cruciferra BYOVD: vulnerable driver (GoFlyDrv.sys) load for EDR tampering Bespoke install · alerting DSΣPDDCS [LLM] Cruciferra loader side-load DLLs and Remcos logs.dat drop Bespoke install · alerting DSΣPDDCS [LLM] Process Ghosting: executable created then deleted while backing a live process Bespoke install · hunting DSPCS [LLM] TELESHIM DLL side-load: RegSchdTask.exe loads rogue AsTaskSched.dll Bespoke install · hunting DSΣPDD [LLM] MIXEDKEY encrypted payload: .PCPKEY file dropped on disk Bespoke install · hunting DSΣPDDCS [LLM] TELESHIM/MIXEDKEY/BINDCLOAK known-bad file hash execution Bespoke install · hunting DSΣPDDCS [LLM] Browser-assembled SourTrade executable dropped with campaign-domain origin (MotW) Bespoke install · hunting DSPDDCS [LLM] Spring Boot Java process spawning shell/LOLBin child (Fastjson RCE execution) Bespoke install · hunting DSΣPDDCS [LLM] Web shell (.jsp/.jspx/.war) written by Java process post-Fastjson RCE Bespoke install · alerting DSΣPDDCS [LLM] Cl0p hex-named JSP web shell dropped under /Windchill/login/ (CVE-2026-12569) Bespoke install · hunting DSΣPDDCS [LLM] DevMan/Funky Mantis locker execution by known SHA256/MD5 hash Bespoke install · hunting DSΣPDDCS [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc Bespoke install · alerting DSΣPCS [LLM] Recurring cron/shell-rc execution of .tf_cache/hw_probe.pyc payload Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-f25v-x6vr-962g: Pheditor: Authentication Bypass in Forced Bespoke install · hunting DSP [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-mqhr-6j6h-74p5: Budibase: Unauthenticated REST Datasource Bespoke install · hunting DSP [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into gener Bespoke install · hunting DSP [LLM] BlueNoroff ClickFix Defender tamper: exclude C:\Users + disable realtime monitoring Bespoke install · alerting DSΣPDDCS [LLM] Certighost precursor: domain computer account created by low-privileged user (MAQ abuse) Bespoke install · hunting DSΣPDD [LLM] Hidden dot-prefixed PHP webshell dropped in web root (.journald-cache.php) Bespoke install · alerting DSΣPCS [LLM] Hermes AI agent launched in unattended YOLO mode (--yolo / HERMES_YOLO_MODE) Bespoke install · alerting DSΣPDDCS [LLM] TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) Bespoke install · alerting DSΣPDDCS [LLM] redis-server writes to persistence paths (cron / SSH authorized_keys / systemd) Bespoke install · alerting DSΣPCS [LLM] Notepad++ side-loading malicious NppExport.dll (LUNCHPOKE) from non-standard path Bespoke install · hunting DSΣPDDCS [LLM] RemoteLibUpdater.exe (BURNYBEAR) 3-minute scheduled-task persistence heartbeat Bespoke install · alerting DSPDDCS [LLM] BURNYBEAR loading InitTest.dll (MATCHBOIL.V2) loader payload Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Bespoke install · hunting DSP [LLM] msaRAT: MSI impersonating Windows update executed from ProgramData Bespoke install · alerting DSΣPDDCS [LLM] Hidden PowerShell pulls installer.exe from pixeldrain.com to %Temp% (self-deleting dropper) Bespoke install · alerting DSΣPDDCS [LLM] msaRAT msiexec executing update_ms.msi (fake Windows update custom action) Bespoke install · alerting DSΣPDDCS [LLM] fast16 sabotage implant carrier (svcmgmt.exe) by hash / Lua-carrier behaviour Bespoke install · alerting DSΣPDDCS [LLM] fast16 kernel driver (fast16.sys) drop / load — sabotage patching engine Bespoke install · alerting DSΣPDDCS [LLM] Malicious PHP plugin/webshell dropped in wp-content by web server (wp2shell) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC amb Bespoke install · hunting DSP [LLM] Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke install · alerting DSΣP [LLM] CAV3RN AzureCommunication.dll config file 'logAzure.txt' written to disk Bespoke install · alerting DSΣPDDCS [LLM] CAV3RN framework module DLLs loaded/dropped (AzureCommunication / n-HTCommp / masqueraded uxtheme) Bespoke install · hunting DSΣPDDCS [LLM] SleeperGem loader: ruby install script spawns shell running deploy.sh Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem persistence: git-credential-manager daemon installs systemd + cron Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts Bespoke install · hunting DSP [LLM] SleeperGem Unix persistence: cron/systemd/LaunchAgent write by Ruby-descended shell Bespoke install · hunting DSΣPDDCS [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy Bespoke install · hunting DSP [LLM] Siemens ROX II root cron table injection via web task scheduler (CVE-2025-40949) Bespoke install · hunting DSΣDD [LLM] rundll32 loading DLL from remote WebDAV @ssl GUID share with ordinal export (ACR Stealer) Bespoke install · alerting DSΣPDDCS [LLM] Masqueraded 'Autoupdate' scheduled task run by PowerShell loader (ACR Stealer persistence) Bespoke install · alerting DSΣPDDCS [LLM] pythonw.exe loader executing from deceptive %LocalAppData%\Temp dir (ACR Stealer) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' w Bespoke install · hunting DSP [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell Bespoke install · alerting DSΣPDDCS [LLM] Pheditor source tampering: modification of pheditor.php (hash rewrite / backdoor persistence) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Impro Bespoke install · hunting DSP [LLM] HelloInjector DLL side-load: wtsapi32.dll dropped into ViPNet Update System dir Bespoke install · alerting DSΣPDDCS [LLM] GoSerpent/McMx masquerading proxy binaries lass.exe and updates.exe Bespoke install · alerting DSΣPDDCS [LLM] Trojanized software installer spawning embedded Python payload (Starland loader) Bespoke install · alerting DSΣPDDCS [LLM] Second-stage sync.js dropped under OS 'NodeJS' masquerade directory Bespoke install · alerting DSΣPDDCS [LLM] Detached hidden node.exe executing sync.js from NodeJS masquerade path Bespoke install · alerting DSΣPDDCS [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) Bespoke install · hunting DSΣPCS [LLM] Shai-Hulud worm artifacts written on GitHub Actions runner (shai-hulud-workflow.yml / bundle.js) Bespoke install · hunting DSΣPCS [LLM] MiniRAT launchctl persistence established during macOS CI build Bespoke install · hunting DSΣPCS [LLM] npm/node lifecycle script fetching Bun runtime from github.com/oven-sh/bun Bespoke install · alerting DSΣPDDCS [LLM] Malicious @bitwarden/cli payload artifacts on disk (bw_setup.js, bw1.js, Shai-Hulud markers) Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development Bespoke install · hunting DSP [LLM] TuxBot/Akiru known ELF sample execution and drop (SHA256 pivot) Bespoke install · hunting DSΣPCS [LLM] OkoBot 'Apple Sync' scheduled task maintaining reverse SSH tunnel forwarding RDP Bespoke install · alerting DSΣPDDCS [LLM] OkoBot termsrv.dll patch enabling concurrent RDP sessions Bespoke install · alerting DSΣPDDCS [LLM] OkoBot HDUtil launcher execution (target/nouac) with HWID guardrail Bespoke install · alerting DSΣPDDCS [LLM] OkoBot browser-extension loader extl.exe deployed via HDUtil Bespoke install · alerting DSΣPDDCS [LLM] OkoBot RDP back-connection: local RDP user creation + firewall opening Bespoke install · hunting DSΣPDDCS [LLM] OkoBot disabling Windows Defender notifications via registry Bespoke install · hunting DSΣPDD [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which cou Bespoke install · hunting DSP [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in Bespoke install · hunting DSP [LLM] Malicious .pth file dropped into site-packages by pip/python Bespoke install · hunting DSΣPDDCS [LLM] Persistent PIP_ index/config environment variable set in registry Bespoke install · alerting DSΣPDD [LLM] Miasma stage-2 dropped: sync.js written to per-user NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Miasma stage-2 executed: node runs sync.js from NodeJS data directory Bespoke install · alerting DSΣPDDCS [LLM] Vulnerable UEFI shim/GRUB bootloader written to the EFI System Partition Bespoke install · hunting DSΣPDDCS [LLM] EFI System Partition mounted via mountvol /S (rogue shim staging) Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud npm worm payload/workflow file drop (bundle.js, setup_bun.js, shai-hulud-workflow.yml) Bespoke install · hunting DSΣPDDCS [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] axios RAT persistence: HKCU Run value MicrosoftUpdate pointing to system.bat Bespoke install · alerting DSΣPDDCS [LLM] IronWorm preinstall loader: detached hidden binary executed from OS temp by node.exe Bespoke install · alerting DSΣPDDCS [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Bespoke install · hunting DSΣPDDCS [LLM] Backdoored @injectivelabs/sdk-ts 1.20.21 payload file dropped on disk Bespoke install · hunting DSΣPDDCS [LLM] Sha1-Hulud 2.0 npm worm payload files (setup_bun.js / bun_environment.js) written or executed Bespoke install · hunting DSΣPDDCS [LLM] Malicious 'SHA1HULUD' self-hosted GitHub Actions runner installation / persistence Bespoke install · alerting DSΣPDDCS [LLM] The Gentlemen ransomware scheduled task named gentlemen* Bespoke install · alerting DSΣPDDCS [LLM] GentleKiller EDR-killer binaries Allpatch2.exe / All.exe execution Bespoke install · alerting DSΣPDDCS [LLM] Browser extension manifest rewritten adding networking/host permissions (supply-chain) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calcu Bespoke install · hunting DSP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot Bespoke install · alerting DSΣPDDCS [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) Bespoke install · alerting DSΣPDDCS [LLM] Talos prevalent-malware SHA256 execution (UAT-7810 telemetry batch) Bespoke install · hunting DSΣPDDCS [LLM] Malicious @injectivelabs SDK build artifact by SHA-256 on disk Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) Bespoke install · hunting DSP [LLM] SSH authorized_keys written by non-SSH tooling (symlink repo payload) Bespoke install · hunting DSΣPDDCS [LLM] Joro writes a native .so plugin: attacker plugin drop before restart (CVE-2026-53649) Bespoke install · hunting DSΣPCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-52831: Nuclio: Unsanitized cron trigger event headers Bespoke install · hunting DSP [LLM] Fake Windows Defender MpClient.dll side-load (Vidar/Factory-v3 loader) Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-27823: EGroupware has a Remote Code Execution Vulnera Bespoke install · hunting DSP [LLM] EGroupware header.inc.php overwritten by web process (CVE-2026-27823 RCE persistence) Bespoke install · alerting DSΣPCS [LLM] DOGLEASH ELF payload download from UAT-7810 servers on Linux/embedded devices Bespoke install · hunting DSΣPDDCS [LLM] Langroid Neo4jChatAgent launched with allow_dangerous_operations enabled Bespoke install · hunting DSPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54769: Langroid: Sandbox Escape to Remote Code Execut Bespoke install · hunting DSP [LLM] Node archive-extraction process writing to Linux persistence paths (decompress dir-escape) Bespoke install · hunting DSΣDDCS [LLM] Node extraction writing ld.so.preload or setuid/privileged path as root (CVE-2026-53486 privesc) Bespoke install · alerting DSΣDDCS [LLM] BusySnake NSIS dropper: pnx.exe injected from Temp\ns*.tmp staging folder Bespoke install · alerting DSΣPDDCS [LLM] BusySnake Python stealer executed from %APPDATA%\WindowsHelper (module.pyw) Bespoke install · alerting DSΣPDDCS [LLM] BusySnake VBScript persistence: wh_selfdelete.vbs / run.vbs in WindowsHelper Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-54617: LaunchServer FileServerHandler has an unauthen Bespoke install · hunting DSP [LLM] Web-server process writes PHP file into Mautic config/cache/media/logs (zip-slip landing) Bespoke install · alerting DSΣPCS [LLM] Weaponized Twig theme written under Mautic themes/ by web process (CVE-2026-9558) Bespoke install · hunting DSΣPDDCS [LLM] PurpleFox fileless infection: remote MSI via msiexec + reflective PE injection Bespoke install · alerting DSΣPDDCS [LLM] PurpleFox persistence via auto-generated AC0[0-9] Windows service Bespoke install · alerting DSΣPDDCS [LLM] LionTail backdoor: DLL search-order hijack via phantom System32 DLLs Bespoke install · alerting DSΣPDDCS [LLM] LoLBin abuse: certutil decode/urlcache, bitsadmin transfer, wmic process-call-create Bespoke install · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-44939: Rancher vulnerable to command injection throug Bespoke install · hunting DSP [LLM] npm/node postinstall script spawning a download or shell process (Mastra dropper pattern) Bespoke install · hunting DSΣPDDCS [LLM] Known-malicious Mastra supply-chain payload file hashes on disk or in execution Bespoke install · hunting DSΣPDDCS [LLM] Phantom Gyp binding.gyp install-time payload execution (Miasma npm worm) Bespoke install · alerting DSΣPDDCS [LLM] Miasma infectHost persistence in AI coding assistant configs Bespoke install · hunting DSΣPDDCS [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant Bespoke install · alerting DSΣPDDCS [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] Passwordless sudo backdoor written for runner account (runner ALL=(ALL) NOPASSWD:ALL) Bespoke install · alerting DSΣPDDCS [LLM] Compromised simonecorsi/mawesome GitHub Action payload by known hash Bespoke install · hunting DSΣPDDCS [LLM] Bun runtime executing payload index.js from semantic-release-action path Bespoke install · alerting DSΣPDDCS Article-specific behavioural hunt — 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Bespoke install · hunting DSP [LLM] Montana Empire kit PHP components staged on web infrastructure Bespoke install · hunting DSΣPDDCS [LLM] TinyRCT backdoor masquerading as PerfWatson2.exe executing from %LOCALAPPDATA% Bespoke install · alerting DSΣPDDCS [LLM] Scheduled task persistence for GoogleUpdater or VMware-disguised VNT binary Bespoke install · hunting DSΣPDDCS [LLM] Gamaredon WinRAR CVE-2025-8088 ADS path-traversal dropping HTA/VBS into Startup folder Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js npm postinstall dropper: node executing setup.cjs --no-warnings Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js Windows persistence: Run key 'NvmProtocal' / protocal.cjs autostart Bespoke install · alerting DSΣPDDCS [LLM] easy-day-js implant artifacts dropped: protocal.cjs / NodePackages / cross-OS persistence files Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime executing codfish/semantic-release-action index.js payload on CI runner Bespoke install · alerting DSΣPDDCS [LLM] cluw macOS stealer shell dropper fetching payload from ClawHavoc/AMOS C2 IP Bespoke install · hunting DSΣPCS [LLM] cluw infostealer and malicious ClawHub skill payload hashes on macOS Bespoke install · hunting DSΣPCS [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Bespoke install · hunting DSΣPCS [LLM] Mastra easy-day-js postinstall dropper: node setup.cjs --no-warnings Bespoke install · alerting DSΣPDDCS [LLM] Miasma/Hades Bun dropper executed via npm/pip lifecycle hook (setup_bun.js / bun_environment.js) Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud/Miasma malicious GitHub Actions workflow file written to .github/workflows Bespoke install · alerting DSΣPDDCS [LLM] Atomic Arch payload execution: JS runtime spawning shell/network tooling under AUR build (or known payload hash) Bespoke install · alerting DSPDDCS [LLM] Atomic Arch persistence: systemd unit, cron or shell-rc written by AUR build / JS runtime Bespoke install · hunting DSΣPCS

Command & Control (236)

Beaconing — periodic outbound to small set of destinations Internal c2 · alerting DSP DNS tunneling / TXT-heavy domain queries Internal c2 · hunting DSP Network connections to article IPs / domains Internal c2 · alerting DSΣP [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [LLM] OWAReaper C2 / exfiltration egress to TA488 CDN and DNS-tunnel domains Bespoke c2 · alerting DSΣPDDCS [LLM] Shell/curl spawned under Fluentd aggregator makes external network egress (post-RCE C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] Artifactory host egress to public internet (package-registry sandbox escape) Bespoke c2 · hunting DSΣPCS [LLM] Improvised C2 over public request-capture / pastebin / file-drop services from server infra Bespoke c2 · hunting DSΣCS [LLM] Flying Eagle Android RAT C2 / panel infrastructure callback (confirmed IOCs) Bespoke c2 · alerting DSΣPDDCS [LLM] RAT C2 egress to hardcoded joyfill IPs and /$/boot request paths Bespoke c2 · hunting DSΣPDDCS [LLM] Node.js resolving C2 via Tron + Binance Smart Chain dead-drop RPC Bespoke c2 · hunting DSPDDCS [LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) Bespoke c2 · hunting DSΣPCS [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 Bespoke c2 · hunting DSΣPDDCS [LLM] BridgeHead SOCKS5 relay drop: unbcl.dll + libwinpthread-1.dll co-located outside System32 Bespoke c2 · alerting DSΣPDDCS [LLM] Trojanized MeshAgent covert backdoor: SYSTEM service beaconing over WSS (Sinobi) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 / reverse shell from TeamCity server process — CVE-2026-63077 Bespoke c2 · hunting DSPDDCS [LLM] NightLedger C2 beacon to realhealthshop[.]com / tjconsultingservices[.]com with hardcoded URIs Bespoke c2 · alerting DSΣPDDCS [LLM] BridgeHead WebSocket SOCKS5 tunnel to smartconnect.azurewebsites.net with hardcoded Edg/86 UA Bespoke c2 · alerting DSΣPDDCS [LLM] Mirage Kitten (UNC1549) infrastructure & payload IOC sweep Bespoke c2 · alerting DSPDDCS [LLM] Outbound beacon/callback from internal host to VeloCloud Orchestrator attacker IPs (CVE-2026-16812) Bespoke c2 · alerting DSΣPDDCS [LLM] Dysphoria botnet blockchain C2 resolution via ENS/SNS (.eth/.sol) domains Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Dysphoria distribution-node / relay IPs (194.87.198.x, 194.58.38.x) Bespoke c2 · hunting DSΣPDDCS [LLM] Dysphoria relay node: public-to-public traffic bridging (UPnP port-forwarding relay) Bespoke c2 · hunting DSPCS [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] Cruciferra C2 beacon to known IOC domains/IPs (incl. .gu.cc cluster) Bespoke c2 · hunting DSΣPDDCS [LLM] Telegram Bot API used for C2 by non-browser/non-messaging process Bespoke c2 · hunting DSΣPDDCS [LLM] BINDCLOAK C2 beacon to cert.hypersnet.com / ssl.blsouqs.com Bespoke c2 · alerting DSΣPDDCS [LLM] Java (fat-JAR) outbound fetch of remote JAR / SSRF egress to public IP (CVE-2026 Bespoke c2 · hunting DSPDDCS [LLM] Outbound reverse-shell egress from GitLab Ruby/Puma worker as git — Oj RCE connect-back Bespoke c2 · hunting DSPCS [LLM] Network connections to Cl0p CVE-2026-12569 C2 / staging infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] mrmustard stealer C2 exfil to metrics.femboy.energy Bespoke c2 · alerting DSΣPCS [LLM] Callback to Hermes operator staging/C2 infrastructure (VShell / ShadowPad / Hades) Bespoke c2 · hunting DSΣPDDCS [LLM] TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] RemoteLibUpdater.exe (BURNYBEAR) outbound C2 egress to external hosts Bespoke c2 · hunting DSPDDCS [LLM] ZimReaper C2 & mail exfiltration to actor IPs/domains (TGZ upload + DNS exfil) Bespoke c2 · hunting DSΣPDDCSCW [LLM] msaRAT: Headless Chrome/Edge launched with remote-debugging (CDP abuse) Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT: Connection to Chaos delivery IP / workers.dev signaling relay Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT: Headless browser initiating WebRTC STUN/TURN egress Bespoke c2 · hunting DSΣPDDCS [LLM] Network/DNS contact to Q2 2026 campaign infrastructure (pixeldrain payload + ClickUp dropper hosts) Bespoke c2 · alerting DSΣPDDCS [LLM] CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT CDP abuse: headless Chrome/Edge with remote-debugging port spawned by non-browser parent Bespoke c2 · alerting DSΣPDDCS [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev Bespoke c2 · hunting DSΣPDDCS [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Unsanctioned RMM trio deployment: Endpoint Central, Mesh Agent, Tactical RMM Bespoke c2 · hunting DSPDDCS [LLM] CAV3RN/HOLLOWGRAPH DNS AAAA config-recovery beaconing to cloudlanecdn[.]com Bespoke c2 · alerting DSΣPCS [LLM] Anomalous DLL-host process reaching Microsoft Graph/login.microsoftonline for calendar C2 Bespoke c2 · hunting DSΣPDDCS [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] Endpoint traffic to ACR Stealer C2 / dead-drop domains Bespoke c2 · alerting DSΣPDDCS [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) Bespoke c2 · hunting DSPDDCS [LLM] Blockchain-anchored C2 fallback: non-browser process contacting polygon-rpc.com Bespoke c2 · alerting DSΣPDDCS [LLM] Connection to known UAT-11795 Starland RAT C2 / distribution domains Bespoke c2 · alerting DSΣPDDCS [LLM] HelloNet renamed-PuTTY reverse SSH tunnel to 5.39.253.206 Bespoke c2 · alerting DSΣPDDCS [LLM] HelloProxy C2-handler artifact: tesh4RPC.txt written to C:\Users\Public Bespoke c2 · alerting DSΣPDDCS [LLM] HelloNet C2 egress to 5.39.253.206 / 176.32.34.135 Bespoke c2 · hunting DSΣPDDCS [LLM] HelloProxy listener: svchost.exe binding TCP 5003/5060 Bespoke c2 · alerting DSP [LLM] Starland RAT / WLDR C2 beaconing to UAT-11795 HWID-parameterized domains Bespoke c2 · alerting DSΣPDDCS [LLM] Starland RAT blockchain fallback C2 via Polygon eth_call (polygon-rpc.com) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to Miasma controller 85.137.53.71 on ports 8080/8081/8091 Bespoke c2 · hunting DSΣPDDCS [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] CI runner egress to MiniRAT C2 89.36.224.5 (Velora SDK backdoor) Bespoke c2 · hunting DSΣPDDCS [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) Bespoke c2 · alerting DSΣPDDCS [LLM] TuxBot/Akiru IoT botnet C2 connection to known infrastructure Bespoke c2 · hunting DSΣPCS [LLM] TuxBot fallback C2 via digikalas.online DGA subdomains and DNS TXT queries Bespoke c2 · hunting DSΣPCS [LLM] Reverse shell via cron/webshell payload dropped through Anyquery AFW (/dev/tcp) Bespoke c2 · alerting DSΣPDDCS [LLM] Miasma M-RED-TEAM HTTP C2 beacon to 85.137.53.71 Bespoke c2 · hunting DSΣPDDCS [LLM] axios RAT C2 beacon to sfrclak[.]com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] IronWorm C2 beacon to hardcoded IPs and Tor endpoints from temp-dir process Bespoke c2 · hunting DSΣPDDCS [LLM] The Gentlemen SystemBC C2 beacon to known operator IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound network connection from a child process of SiYuan.exe (post-RCE C2/exfil) Bespoke c2 · alerting DSPCS [LLM] File Browser hook-auth RCE follow-on: reverse shell / egress tooling under filebrowser (CVE-2026-54088) Bespoke c2 · alerting DSΣPCS [LLM] UAT-7810 ORB relay C2 — outbound to LONGLEASH/DOGLEASH relay IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Edge device recruited as ORB relay — inbound sessions from UAT-7810 IPs Bespoke c2 · hunting DSPDDCS [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] PromptSpy Android GenAI malware C2/distribution domain contact (mgardownload.com, m-mgarg.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to UAT-7810 (LapDogs ORB) SHORTLEASH/DOGLEASH C2 VPS Bespoke c2 · hunting DSΣPDDCS [LLM] UAT-7810 self-signed 'exploit' TLS certificate served on non-standard port 99 Bespoke c2 · hunting DSΣPDDCS [LLM] Neo4j server outbound egress to public IP (LOAD CSV / apoc.load SSRF) Bespoke c2 · hunting DSPDDCS [LLM] Outbound egress from shell/downloader child of a Python (Langroid) process Bespoke c2 · hunting DSPCS [LLM] BusySnake reverse SSH tunnel: ssh.exe -R launched by bundled Python payload Bespoke c2 · hunting DSΣPDDCS [LLM] GitHub Actions runner outbound to gist.githubusercontent.com (tj-actions/changed-files CVE-2025-30066) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 Bespoke c2 · hunting DSΣPCS [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPCS [LLM] easy-day-js second-stage C2 beacon to Mastra supply-chain infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Jackson Maven typosquat C2 — beacon to fasterxml.org / 103.127.243.82 Bespoke c2 · alerting DSΣPDDCS [LLM] Bun v1.3.13 runtime pulled from GitHub Releases during npm install (Phantom Gyp staging) Bespoke c2 · alerting DSΣP [LLM] GitHub dead-drop C2 — commit-search for RevokeAndItGoesKaboom / TheBeautifulSandsOfTime Bespoke c2 · hunting DSPCS [LLM] JetBrains IDE process beaconing to malicious plugin C2 39.107.60.51 Bespoke c2 · alerting DSΣPDDCS [LLM] AI coding-assistant egress to first-seen external domain (phantom squatting) Bespoke c2 · hunting DSPDDCS [LLM] Outbound connection to CL-STA-1062 / TinyRCT C2 and tool-staging infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] SoftEther VPN / VNT tunneler masquerading as VMware vmtools.exe Bespoke c2 · hunting DSΣPDDCS [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts Bespoke c2 · alerting DSΣPDDCS [LLM] easy-day-js stealer C2 beacon to Hostwinds 23.254.164.0/24 (ports 8000/443) Bespoke c2 · hunting DSΣPDDCS [LLM] Bun process reaching GitHub commit-search API — Miasma dead-drop C2 Bespoke c2 · hunting DSΣPDDCS [LLM] Network egress to ClawHavoc cluw / AMOS C2 infrastructure Bespoke c2 · hunting DSΣPCS [LLM] macOS.Gaslight Telegram Bot API C2 polling from non-browser process Bespoke c2 · hunting DSΣPCS [LLM] easy-day-js Mastra dropper C2 callout to 23.254.164.92 / .123 Bespoke c2 · hunting DSΣPDDCS [LLM] Atomic Arch C2/exfil: build-spawned egress to temp.sh and github.com/fardewoak/nodejs-argo Bespoke c2 · alerting DSΣPDDCS [LLM] Hades on-import payload: Python process spawning Bun JavaScript runtime Bespoke c2 · alerting DSΣPDDCS [LLM] Sapphire Sleet easy-day-js RAT C2 beacon to Hostwinds 23.254.164.92 / 23.254.164.123 Bespoke c2 · hunting DSΣPDDCS [LLM] Cross-platform stealer RAT C2 beacon to 23.254.164.123 Bespoke c2 · alerting DSPDDCS [LLM] JetBrains AI-key stealer HTTP exfil: cleartext POST to /api/software/ path Bespoke c2 · hunting DSΣP [LLM] SprySOCKS (FishMonger/I-SOON) C2 beacon to hardcoded Vultr IPs 207.148.78.36 / 207.148.75.122 Bespoke c2 · hunting DSΣPDDCS [LLM] axios npm RAT C2 beacon to UNC1069 infra (142.11.206.73 / sfrclak.com) Bespoke c2 · alerting DSΣPDDCS [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs Bespoke c2 · hunting DSΣPDDCS [LLM] SPECTRALVIPER injected OneDrive.Sync.Service.exe beaconing (Cookie-header C2) Bespoke c2 · alerting DSPDDCS [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Rust build script making outbound network connection (build-time exfil) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] node child of npm install initiating outbound network to non-registry destination Bespoke c2 · hunting DSPDDCS [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) Bespoke c2 · hunting DSPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper Bespoke c2 · alerting DSΣPDDCS [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 Bespoke c2 · hunting DSΣPDDCS [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke c2 · hunting DSΣPDDCS [LLM] GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke c2 · hunting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 Bespoke c2 · hunting DSΣPDDCS [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) Bespoke c2 · alerting DSΣPCS [LLM] FIRESCALE GitHub dead-drop fallback C2 lookup (api.github.com commit search) Bespoke c2 · alerting DSΣP [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint Bespoke c2 · alerting DSΣPDDCS [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud C2 backchannel: python polling GitHub commit search for 'firedalazer' Bespoke c2 · alerting DSPDDCS [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud Bespoke c2 · alerting DSΣPDDCS [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host Bespoke c2 · alerting DSΣPDD [LLM] BirdCall RokRAT cloud-storage C2 beacon (Dropbox/pCloud) from non-browser process Bespoke c2 · hunting DSPDDCS [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL Bespoke c2 · alerting DSΣPDD [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro Bespoke c2 · hunting DSΣPDDCS [LLM] Non-browser process posting to Slack Web API (LaxGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Non-browser process posting to Discord API (RatGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Beaconing to GopherWhisper C2 IP 43.231.113.50 (incl. SSLORDoor raw TLS/443) Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) Bespoke c2 · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes Bespoke c2 · hunting DSΣPDD [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDD [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] node.exe contacting Solana JSON-RPC endpoints (suspected blockchain dead-drop C2) Bespoke c2 · hunting DSPDDCS [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) Bespoke c2 · alerting DSΣPDD [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner Bespoke c2 · hunting DSΣPDDCS [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) Bespoke c2 · hunting DSΣPDDCS [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) Bespoke c2 · alerting DSΣPDDCS [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil Bespoke c2 · hunting DSΣPDDCS [LLM] GlassWorm Solana blockchain dead-drop C2 lookup via public RPC endpoints from Node Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound TCP beacon to BlokTrooper Socket.IO C2 195.201.104.53:6931/6936/6939 Bespoke c2 · alerting DSΣPDDCS [LLM] Glassworm stage-2/stage-3 C2 callback to 45.32.150.251 or 217.69.3.152 Bespoke c2 · hunting DSΣPDD [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download Bespoke c2 · alerting DSΣPDDCS [LLM] DRILLAPP C2 staging: msedge.exe contacting pastefy.app Bespoke c2 · alerting DSΣPDDCS [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] BeardShell C2: outbound to Icedrive cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] Covenant C2: outbound to Filen cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) Bespoke c2 · hunting DSΣPDDCS [LLM] Ultralytics coinminer C2 — Stratum to connect.consrensys.com:8080 mining pool Bespoke c2 · alerting DSΣPCS [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com Bespoke c2 · alerting DSΣPDD [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) Bespoke c2 · alerting DSΣPDDCS [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ru Bespoke c2 · hunting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] rsocx SOCKS5 reverse proxy beacon to 31.172.71.5:8008 (Sandworm Poland C2) Bespoke c2 · alerting DSΣP [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] PlushDaemon EdgeStepper hijacking infrastructure (wcsset.com / 47.242.198.250 / 8.212.132.120) contact Bespoke c2 · hunting DSΣP [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpoint Bespoke c2 · hunting DSΣPDDCS [LLM] Beamglea mad-* dead-drop fetch from raw.githubusercontent.com/Abassdos2992 Bespoke c2 · alerting DSΣPDDCS [LLM] DNS or HTTP egress to giftshop.club exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1 Bespoke c2 · hunting DSΣPDDCS

Actions on Objectives (412)

Infostealer — non-browser process accessing browser cookie/login DBs Internal actions · alerting DSΣP Crypto-wallet file/keystore access by non-wallet process Internal actions · alerting DSΣP Remote service execution — PsExec / SMB lateral movement Internal actions · alerting DSΣP LSASS process access / dump (credential theft) Internal actions · alerting DSΣP Ransomware-style mass file rename / extension change Internal actions · alerting DSP [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Rundll32 CreateRemoteThread In Browser ESCU actions · alerting P Access LSASS Memory for Dump Creation ESCU actions · alerting P Anomalous usage of 7zip ESCU actions · hunting P Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI ESCU actions · hunting P Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download ESCU actions · hunting P Cisco NVM - Suspicious Download From File Sharing Website ESCU actions · hunting P Cisco NVM - Suspicious Network Connection From Process With No Args ESCU actions · hunting P Clop Ransomware Known Service Name ESCU actions · alerting P Create Remote Thread In Shell Application ESCU actions · alerting P Creation of lsass Dump with Taskmgr ESCU actions · alerting P Creation of Shadow Copy ESCU actions · alerting P Deleting Shadow Copies ESCU actions · alerting P Detect Credential Dumping through LSASS access ESCU actions · alerting P Detect New Local Admin account ESCU actions · alerting P Detect Prohibited Applications Spawning cmd exe ESCU actions · hunting P Detect Regasm with Network Connection ESCU actions · alerting P Detect Regsvcs with Network Connection ESCU actions · alerting P Detect Use of cmd exe to Launch Script Interpreters ESCU actions · hunting P Domain Account Discovery with Wmic ESCU actions · alerting P Domain Controller Discovery with Wmic ESCU actions · hunting P Drop IcedID License dat ESCU actions · hunting P Elevated Group Discovery With Wmic ESCU actions · alerting P Executable File Written in Administrative SMB Share ESCU actions · alerting P Get ADUser with PowerShell ESCU actions · hunting P Get ADUserResultantPasswordPolicy with Powershell ESCU actions · alerting P Get DomainPolicy with Powershell ESCU actions · alerting P Get DomainUser with PowerShell ESCU actions · alerting P Get-ForestTrust with PowerShell ESCU actions · alerting P Get WMIObject Group Discovery ESCU actions · hunting P GetAdComputer with PowerShell ESCU actions · hunting P GetAdGroup with PowerShell ESCU actions · hunting P GetCurrent User with PowerShell ESCU actions · hunting P GetDomainComputer with PowerShell ESCU actions · alerting P GetDomainController with PowerShell ESCU actions · hunting P GetDomainGroup with PowerShell ESCU actions · alerting P GetLocalUser with PowerShell ESCU actions · hunting P GetNetTcpconnection with PowerShell ESCU actions · hunting P GetWmiObject User Account with PowerShell ESCU actions · hunting P High Frequency Copy Of Files In Network Share ESCU actions · hunting P Impacket Lateral Movement Commandline Parameters ESCU actions · alerting P Impacket Lateral Movement smbexec CommandLine Parameters ESCU actions · alerting P Kerberoasting spn request with RC4 encryption ESCU actions · alerting P Kerberos Service Ticket Request Using RC4 Encryption ESCU actions · alerting P Kerberos TGT Request Using RC4 Encryption ESCU actions · alerting P Kerberos User Enumeration ESCU actions · hunting P LOLBAS With Network Traffic ESCU actions · alerting P Malicious Powershell Executed As A Service ESCU actions · alerting P Network Share Discovery Via Dir Command ESCU actions · hunting P PetitPotam Network Share Access Request ESCU actions · alerting P PetitPotam Suspicious Kerberos TGT Request ESCU actions · alerting P Possible Lateral Movement PowerShell Spawn ESCU actions · hunting P PowerShell Get LocalGroup Discovery ESCU actions · hunting P Powershell Remote Thread To Known Windows Process ESCU actions · alerting P Process Deleting Its Process File Path ESCU actions · alerting P Randomly Generated Windows Service Name ESCU actions · hunting P Ransomware Notes bulk creation ESCU actions · hunting P Remote System Discovery with Wmic ESCU actions · alerting P Resize ShadowStorage volume ESCU actions · alerting P Rubeus Kerberos Ticket Exports Through Winlogon Access ESCU actions · alerting P Rundll32 Create Remote Thread To A Process ESCU actions · alerting P Rundll32 LockWorkStation ESCU actions · hunting P Rundll32 Process Creating Exe Dll Files ESCU actions · alerting P Rundll32 with no Command Line Arguments with Network ESCU actions · alerting P SchCache Change By App Connect And Create ADSI Object ESCU actions · hunting P Scheduled Task Deleted Or Created via CMD ESCU actions · hunting P Spoolsv Suspicious Process Access ESCU actions · alerting P Spoolsv Writing a DLL - Sysmon ESCU actions · alerting P Sqlite Module In Temp Folder ESCU actions · alerting P Suspicious Copy on System32 ESCU actions · hunting P Suspicious Kerberos Service Ticket Request ESCU actions · alerting P Suspicious mshta child process ESCU actions · alerting P Suspicious Reg exe Process ESCU actions · hunting P Suspicious Rundll32 no Command Line Arguments ESCU actions · alerting P Suspicious Ticket Granting Ticket Request ESCU actions · hunting P Suspicious wevtutil Usage ESCU actions · alerting P Unusual Number of Computer Service Tickets Requested ESCU actions · hunting P Unusual Number of Kerberos Service Tickets Requested ESCU actions · hunting P Unusual Number of Remote Endpoint Authentication Events ESCU actions · hunting P User Discovery With Env Vars PowerShell ESCU actions · hunting P Wermgr Process Create Executable File ESCU actions · alerting P Windows Access Token Manipulation Winlogon Duplicate Token Handle ESCU actions · hunting P Windows Access Token Winlogon Duplicate Handle In Uncommon Path ESCU actions · hunting P Windows Account Access Removal via Logoff Exec ESCU actions · hunting P Windows AD Domain Controller Promotion ESCU actions · alerting P Windows AD Replication Request Initiated by User Account ESCU actions · alerting P Windows AD Replication Request Initiated from Unsanctioned Location ESCU actions · alerting P Windows AD Short Lived Domain Controller SPN Attribute ESCU actions · alerting P Windows AD Suspicious Attribute Modification ESCU actions · alerting P Windows Administrative Shares Accessed On Multiple Hosts ESCU actions · alerting P Windows Alternate DataStream - Process Execution ESCU actions · alerting P Windows Bluetooth Service Installed From Uncommon Location ESCU actions · hunting P Windows Cloud Files Filter Log Created by Non-System Process ESCU actions · alerting P Windows Cmdline Tool Execution From Non-Shell Process ESCU actions · hunting P Windows Command Shell DCRat ForkBomb Payload ESCU actions · alerting P Windows Computer Account Requesting Kerberos Ticket ESCU actions · alerting P Windows Crowdstrike RTR Script Execution ESCU actions · hunting P Windows Detect Network Scanner Behavior ESCU actions · hunting P Windows DnsAdmins New Member Added ESCU actions · alerting P Windows EventLog Recon Activity Using Log Query Utilities ESCU actions · hunting P Windows Explorer LNK Exploit Process Launch With Padding ESCU actions · alerting P Windows File Transfer Protocol In Non-Common Process Path ESCU actions · hunting P Windows Handle Duplication in Known UAC-Bypass Binaries ESCU actions · hunting P Windows Hunting System Account Targeting Lsass ESCU actions · hunting P Windows Identify PowerShell Web Access IIS Pool ESCU actions · hunting P Windows Kerberos Local Successful Logon ESCU actions · alerting P Windows KrbRelayUp Service Creation ESCU actions · alerting P Windows Large Number of Computer Service Tickets Requested ESCU actions · hunting P Windows List ENV Variables Via SET Command From Uncommon Parent ESCU actions · hunting P Windows Local Administrator Credential Stuffing ESCU actions · alerting P Windows Mail Protocol In Non-Common Process Path ESCU actions · hunting P Windows Masquerading Explorer As Child Process ESCU actions · alerting P Windows MOF Event Triggered Execution via WMI ESCU actions · alerting P Windows MSHTA Writing to World Writable Path ESCU actions · alerting P Windows MSIExec Spawn Discovery Command ESCU actions · hunting P Windows MsMpEng Writing to System32 ESCU actions · alerting P Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos ESCU actions · alerting P Windows Multiple Invalid Users Fail To Authenticate Using Kerberos ESCU actions · alerting P Windows Multiple Invalid Users Failed To Authenticate Using NTLM ESCU actions · alerting P Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials ESCU actions · alerting P Windows Multiple Users Failed To Authenticate From Host Using NTLM ESCU actions · alerting P Windows Multiple Users Failed To Authenticate From Process ESCU actions · alerting P Windows Multiple Users Remotely Failed To Authenticate From Host ESCU actions · alerting P Windows Non-System Account Targeting Lsass ESCU actions · alerting P Windows Obfuscated Files or Information via RAR SFX ESCU actions · hunting P Windows Office Product Spawned Uncommon Process ESCU actions · alerting P Windows Possible Credential Dumping ESCU actions · alerting P Windows PowGoop Beacon Decoding ESCU actions · alerting P Windows Process Executed From Removable Media ESCU actions · hunting P Windows Process Injection into Commonly Abused Processes ESCU actions · hunting P Windows Process Injection into Notepad ESCU actions · hunting P Windows Process Injection Remote Thread ESCU actions · alerting P Windows Rapid Authentication On Multiple Hosts ESCU actions · alerting P Windows RDP Login Session Was Established ESCU actions · hunting P Windows Remote Management Execute Shell ESCU actions · hunting P Windows Renamed Powershell Execution ESCU actions · alerting P Windows Rundll32 WebDAV Request ESCU actions · hunting P Windows Rundll32 with Non-Standard File Extension ESCU actions · hunting P Windows Scheduled Task Created in a Group Policy Object ESCU actions · alerting P Windows Scheduled Task Service Spawned Shell ESCU actions · alerting P Windows Sensitive Registry Hive Dump Via CommandLine ESCU actions · alerting P Windows Service Create RemComSvc ESCU actions · hunting P Windows Service Create SliverC2 ESCU actions · alerting P Windows Service Created with Suspicious Service Name ESCU actions · hunting P Windows Service Created with Suspicious Service Path ESCU actions · alerting P Windows Shell or Script Execution From IIS Directory ESCU actions · hunting P Windows Snake Malware Service Create ESCU actions · alerting P Windows Special Privileged Logon On Multiple Hosts ESCU actions · alerting P Windows SpeechRuntime Suspicious Child Process ESCU actions · alerting P Windows Steal Authentication Certificates - ESC1 Authentication ESCU actions · alerting P Windows Steal or Forge Kerberos Tickets Klist ESCU actions · hunting P Windows Suspicious Child Process of TieringEngineService.exe ESCU actions · alerting P Windows Suspicious Child Process Spawned From WebServer ESCU actions · hunting P Windows Suspicious React or Next.js Child Process ESCU actions · alerting P Windows Suspicious VMWare Tools Child Process ESCU actions · alerting P Windows Terminating Lsass Process ESCU actions · hunting P Windows UAC Bypass Suspicious Child Process ESCU actions · alerting P Windows Uncommon Remote Thread Creation In Browser Process ESCU actions · hunting P Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos ESCU actions · hunting P Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos ESCU actions · hunting P Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM ESCU actions · hunting P Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials ESCU actions · hunting P Windows Unusual Count Of Users Failed To Authenticate From Process ESCU actions · hunting P Windows Unusual Count Of Users Failed To Authenticate Using NTLM ESCU actions · hunting P Windows Unusual Count Of Users Remotely Failed To Auth From Host ESCU actions · hunting P Windows USBSTOR Registry Key Modification ESCU actions · hunting P Windows VSSVC Process Accessing Defender Engine ESCU actions · alerting P Windows Vulnerable Driver Installed ESCU actions · alerting P Windows WMI Impersonate Token ESCU actions · hunting P Windows WMI Reconnaissance Class Query ESCU actions · hunting P Windows WMIC Shadowcopy Delete ESCU actions · hunting P Windows WPDBusEnum Registry Key Modification ESCU actions · hunting P WinEvent Scheduled Task Created to Spawn Shell ESCU actions · alerting P WinRM Spawning a Process ESCU actions · alerting P Wmic Group Discovery ESCU actions · hunting P Wmic NonInteractive App Uninstallation ESCU actions · hunting P Wscript Or Cscript Suspicious Child Process ESCU actions · hunting P Rundll32 DNSQuery ESCU actions · alerting P Suspicious Process DNS Query Known Abuse Web Services ESCU actions · alerting P Attempted Credential Dump From Registry via Reg exe ESCU actions · alerting P Cmdline Tool Not Executed In CMD Shell ESCU actions · alerting P Detect Activity Related to Pass the Hash Attacks ESCU actions · hunting P Detect Mimikatz Via PowerShell And EventCode 4703 ESCU actions · alerting P Detect Webshell Exploit Behavior ESCU actions · alerting P First time seen command line argument ESCU actions · hunting P Suspicious Powershell Command-Line Arguments ESCU actions · alerting P Suspicious Rundll32 Rename ESCU actions · hunting P Suspicious writes to System Volume Information ESCU actions · hunting P Windows AD Suspicious GPO Modification ESCU actions · alerting P Windows Command Shell Fetch Env Variables ESCU actions · alerting P

Recent articles citing Windows-targeted detections