|
Anthropic Admin Role Assigned to User
|
elastic/detection-rules
|
High |
T1098
T1098.003
|
2026-10-07
|
|
Anthropic Primary Owner Transferred
|
elastic/detection-rules
|
High |
T1098
T1098.003
|
2026-10-07
|
|
AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox
|
elastic/detection-rules
|
High |
T1078
T1078.004
+1
|
2026-10-07
|
|
Connection to WebService by a Signed Binary Proxy
|
elastic/protections-artifacts
|
Undefined |
T1218
T1071
+2
|
2026-10-07
|
|
Creation of Hidden Shared Object File
|
elastic/protections-artifacts
|
Undefined |
T1129
T1564
+1
|
2026-10-07
|
|
DNS Request by Recently Created Executable
|
elastic/protections-artifacts
|
Undefined |
T1204
T1204.002
+3
|
2026-10-07
|
|
ET EXPLOIT Sunhillo SureLine Unauthenticated OS Command Injection Inbound (CVE-2021-36380)
|
Emerging Threats Open
|
High |
T1210
|
2026-10-07
|
|
ET HUNTING Javascript Redirect to Google .com
|
Emerging Threats Open
|
Informational |
|
2026-10-07
|
|
GCP Vertex AI Caller Impossible Travel
|
elastic/detection-rules
|
Medium |
T1528
T1078
+1
|
2026-10-07
|
|
GCP Vertex AI High Request and Token Volume
|
elastic/detection-rules
|
Medium |
T1496
|
2026-10-07
|
|
Hidden Payload Executed via Scheduled Job
|
elastic/protections-artifacts
|
Undefined |
T1053
T1053.003
+2
|
2026-10-07
|
|
Ingress Tool Transfer via CURL
|
elastic/protections-artifacts
|
Undefined |
T1105
|
2026-10-07
|
|
Long Base64 Command Execution via Interactive Shell
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.001
+6
|
2026-10-07
|
|
Microsoft Windows Defender Tampering
|
elastic/detection-rules
|
Medium |
T1112
T1562
+1
|
2026-10-07
|
|
Non-interactive Shell Upgrade
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
|
2026-10-07
|
|
Potential Remote Code Execution via URL Encoded Payload
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
+5
|
2026-10-07
|
|
Potential Reverse Shell Activity via TCP/UDP Socket
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
+1
|
2026-10-07
|
|
Potential Reverse Shell Activity via Terminal
|
elastic/protections-artifacts
|
Undefined |
T1059
T1071
|
2026-10-07
|
|
Potential SUID/SGID Files Enumeration
|
elastic/protections-artifacts
|
Undefined |
T1548
T1548.001
+1
|
2026-10-07
|
|
Socat Reverse Shell or Listener Activity
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
+1
|
2026-10-07
|
|
Suspicious Echo Execution
|
elastic/protections-artifacts
|
Undefined |
T1053
T1053.003
+8
|
2026-10-07
|
|
Suspicious Enumeration via LDAP Search
|
elastic/protections-artifacts
|
Undefined |
T1069
T1069.002
+3
|
2026-10-07
|
|
Suspicious File Downloaded by Curl/Wget and Piped to Interpreter
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
+1
|
2026-10-07
|
|
Suspicious PowerShell Execution
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.001
|
2026-10-07
|
|
Suspicious Remote Javascript Evaluation via Nodejs
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.007
|
2026-10-07
|
|
Suspicious Ruby Command Execution
|
elastic/protections-artifacts
|
Undefined |
T1059
|
2026-10-07
|
|
System Reconnaissance from Unsigned Parent Followed by Network Connection
|
elastic/protections-artifacts
|
Undefined |
T1082
T1071
+1
|
2026-10-07
|
|
Unusual Command Execution via Cron
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
+4
|
2026-10-07
|
|
Unusual Command Execution via Systemd Scheduled Task
|
elastic/protections-artifacts
|
Undefined |
T1059
T1059.004
+4
|
2026-10-07
|
|
Access to a Sensitive LDAP Attribute
|
elastic/detection-rules
|
Medium |
T1003
T1552
+5
|
2026-10-06
|
|
AdFind Command Activity
|
elastic/detection-rules
|
Low |
T1016
T1018
+5
|
2026-10-06
|
|
AWS Bedrock Foundation Model Access Enabled or Entitlement Granted
|
elastic/detection-rules
|
Medium |
T1098
|
2026-10-06
|
|
AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key
|
elastic/detection-rules
|
High |
T1526
T1078
+1
|
2026-10-06
|
|
AWS Bedrock Unauthorized Foundation Model Access Attempt
|
elastic/detection-rules
|
Low |
T1098
|
2026-10-06
|
|
AWS EC2 Instance Console Login via Assumed Role
|
elastic/detection-rules
|
High |
T1021
T1021.007
+6
|
2026-10-06
|
|
AWS IAM CompromisedKeyQuarantine Policy Attached to User
|
elastic/detection-rules
|
High |
T1552
T1078
+1
|
2026-10-06
|
|
AWS S3 Bucket Replicated to Another Account
|
elastic/detection-rules
|
High |
T1537
T1567
+1
|
2026-10-06
|
|
AWS S3 Object Encryption Using External KMS Key
|
elastic/detection-rules
|
Medium |
T1486
|
2026-10-06
|
|
AWS S3 Object Versioning Suspended
|
elastic/detection-rules
|
Medium |
T1490
|
2026-10-06
|
|
AWS Suspicious User Agent Fingerprint
|
elastic/detection-rules
|
High |
T1078
T1078.004
|
2026-10-06
|
|
Azure OpenAI Insecure Output Handling
|
elastic/detection-rules
|
Low |
|
2026-10-06
|
|
Cobalt Strike Command and Control Beacon
|
elastic/detection-rules
|
High |
T1071
T1071.001
+2
|
2026-10-06
|
|
Command Execution via SolarWinds Process
|
elastic/detection-rules
|
Medium |
T1059
T1059.001
+3
|
2026-10-06
|
|
Entra ID Conditional Access Policy (CAP) Modified
|
elastic/detection-rules
|
High |
T1556
T1556.009
|
2026-10-06
|
|
ET EXPLOIT eMerge E3 card_scan.php ReaderNo Parameter Command Injection Inbound (CVE-2019-7256)
|
Emerging Threats Open
|
High |
T1190
|
2026-10-06
|
|
ET EXPLOIT EnGenius EnShare IoT Gigabit Cloud Service usbinteract.gi path parameter Command Injection Attempt (CVE-2025-34035)
|
Emerging Threats Open
|
High |
T1190
|
2026-10-06
|
|
ET EXPLOIT_KIT ClickFix Payload Response M1
|
Emerging Threats Open
|
Medium |
T1189
|
2026-10-06
|
|
ET EXPLOIT_KIT ClickFix Payload Response M2
|
Emerging Threats Open
|
High |
T1189
|
2026-10-06
|
|
ET EXPLOIT_KIT ClickFix Visitor Tracking
|
Emerging Threats Open
|
Medium |
T1189
|
2026-10-06
|
|
ET MALWARE ContEXE Stealer Data Exfiltration Attempt M1
|
Emerging Threats Open
|
High |
T1005
|
2026-10-06
|