Version 18.0 19.0
Analytics : Enterprise ATT&CK Changelog
Added Analytics
| Description |
|---|
Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns. |
| Description |
|---|
Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals. |
| Description |
|---|
Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions. |
| Description |
|---|
Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity. |
| Description |
|---|
Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events. |
| Description |
|---|
Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution. |
| Description |
|---|
Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation. |
| Description |
|---|
Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption. |
| Description |
|---|
Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage. |
| Description |
|---|
Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction. |
| Description |
|---|
Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration. |
| Description |
|---|
Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity. |
| Description |
|---|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access. |
| Description |
|---|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access. |
| Description |
|---|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access. |
| Description |
|---|
Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access. |
| Description |
|---|
Detection identifies execution of scripts or files that appear visually benign (low printable character ratio) but result in runtime decoding, dynamic evaluation, and subsequent process or network activity. Correlation links script execution with abnormal Unicode density and follow-on behavior such as child process creation or outbound connections. |
| Description |
|---|
Detection identifies execution of scripts containing high concentrations of invisible Unicode characters followed by decoding or interpretation behaviors (e.g., base64 decode, eval) and subsequent process or network activity. Emphasis is placed on mismatch between file entropy/structure and execution output. |
| Description |
|---|
Detection identifies execution of scripts or applications containing invisible Unicode payloads reconstructed at runtime, correlated with abnormal AppleScript, JavaScript for Automation, or shell execution and subsequent process or network behavior inconsistent with visible file content. |
Modified Analytics
| Description |
|---|
Detects access attempts to cloud instance metadata endpoints (e.g., 169.254.169.254) from virtual machines or containerized workloads. This includes both direct access and SSRF exploitation patterns. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | CloudTrail:GetInstanceIdentityDocument | AWS:CloudTrail |
| Description |
|---|
Detects non-standard processes (e.g., PowerShell, python.exe, rundll32.exe) making outbound connections using publish/subscribe protocols (e.g., MQTT, AMQP) over non-browser, encrypted channels, often beaconing to message brokers. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Abnormal modification of the PATH environment variable or registry keys controlling system paths, combined with execution of binaries named after legitimate system tools from user-writable directories. Defender correlates registry modifications, file creation of suspicious binaries, and process execution paths inconsistent with baseline system directories. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-22T18:36:42.025Z | 2025-11-12T17:36:06.423Z |
| x_mitre_log_source_references[0]['channel'] | EvenCode=4657 | EventCode=4657 |
| Description |
|---|
Execution of renamed common utilities (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | /var/log/syslog or journalctl | cron activity |
| Description |
|---|
Adversary manipulates dependencies/dev tools used by developers or CI: a package manager (npm/yarn/pnpm, pip/pipenv, nuget/dotnet, chocolatey/winget, maven/gradle) or a compiler/IDE downloads or restores content; files are written under project paths and execution paths (node_modules, packages, .nuget, .gradle, .m2, %AppData%\npm, %UserProfile%.cargo\bin, temp build dirs). First run of newly written components triggers scripts (preinstall/postinstall), shell/PowerShell spawning, or loader DLLs, followed by network egress to non-approved registries/CDNs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Access to browser artifact locations (e.g., Chrome, Edge, Firefox) by processes like PowerShell, cmd.exe, or unknown tools, followed by file reads, decoding, or export operations indicating enumeration of bookmarks, autofill, or history databases. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects staging of sensitive files into temporary or public directories, compression with 7zip/WinRAR, or batch copy prior to exfiltration. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | PutObject, CopyObject | GetObject, CopyObject |
| Description |
|---|
Adversary disables or stops critical services (e.g., Exchange, SQL, AV, endpoint monitoring) using native utilities or API calls, often preceding destructive actions (T1485, T1486). Behavioral chain: Elevated execution context + stop-service or sc.exe or ChangeServiceConfigW + terminated or disabled service + possible follow-up file manipulation. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['name'] | WinEventLog:sysmon | WinEventLog:Sysmon |
| Description |
|---|
Adversary stages a lure that references a remote resource (e.g., LNK/SCF/Office template). When the user opens/renders the file or a shell enumerates icons, the host automatically attempts SMB or WebDAV authentication to the attacker host. The chain is: (1) lure file is created or modified in a user-exposed location → (2) user or system accesses the lure → (3) host makes outbound NTLM (SMB 139/445 or WebDAV over 80/443) to an untrusted destination → (4) repeated attempts from multiple users/hosts or from privileged workstations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Abuse of trusted Electron apps (Teams, Slack, Chrome) to spawn child processes or execute payloads via malicious command-line arguments (e.g., --gpu-launcher) and modified app resources (.asar). Behavior chain: suspicious parent process (Electron app) → unusual command-line args → child process creation → optional DLL/network artifacts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Abuse of Linux Electron binaries by modifying app.asar or config JS files and spawning unexpected child processes (bash, curl, python). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | Modification of .asar in /opt or ~/.config directories | EventCode=11 |
| Description |
|---|
Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Processes invoking network-intensive child processes or uploading large data volumes, often from non-standard user or system contexts, with evidence of long-duration TCP/UDP sessions to unusual destinations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Defenders can observe suspicious replacement or tampering of system accessibility binaries (e.g., utilman.exe, sethc.exe, osk.exe) and anomalous modifications to registry keys used to redirect accessibility programs (such as IFEO keys). Additionally, execution of cmd.exe or other suspicious binaries triggered from the login screen by SYSTEM can be correlated as part of a behavior chain. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Suspicious processes initiating encrypted HTTPS connections to common web service domains, followed by abnormal data upload behavior or automated posting behavior indicative of C2 bidirectional traffic. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[1]['channel'] | Event ID 1 | EventCode=1 |
| Description |
|---|
Detects unauthorized access to web browser credential stores (e.g., Chrome Login Data, Edge Credential Locker) by processes other than the browser itself. Correlates file reads of credential databases with subsequent API calls to |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4656, 4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs). |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=22'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=1'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'} |
| Description |
|---|
Detects abuse of verclsid.exe to execute COM objects by monitoring process creation, CLSID arguments, DLLs or scriptlet engines loaded into memory, and If the CLSID points to remote SCT/HTA content, verclsid.exe makes outbound connections. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-22T18:38:17.503Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=22 | EventCode=3, 22 |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects attempts to clear RDP/network history and modify network configuration artifacts through command execution, registry key deletion, firewall rule changes, and suspicious file deletions (e.g., Default.rdp, registry edits to Terminal Server Client keys). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Creation or modification of files in directories known to be excluded from AV scanning (e.g., C:\Windows\Temp, Exchange server directories, or default AV exclusions). Defender perspective: correlate file creation with execution behavior or anomalous parent processes writing to excluded paths. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Outlook or Word used to forward suspicious internal attachments with macro content. Defender observes attachment forwarding, auto-opening behaviors, or macro prompt interactions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['name'] | WinEventLog:Powershell | WinEventLog:PowerShell |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | netconnect | connect |
| Description |
|---|
Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=4656,4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=13,14 | EventCode=13, 14 |
| Description |
|---|
Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
PowerShell or script execution with parameters that suppress errors or ignore user interrupts, such as |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Chain: (1) a new external device is recognized by Windows (USB/Thunderbolt/PCIe) or a new block device appears; (2) within a short window, the same user/session spawns processes or the OS mounts a new volume; (3) optional follow-on activity such as HID keystroke injection, DMA driver load, or new network interface MAC on DHCP. Correlate Security EID 6416 / Kernel-PnP with sysmon and DHCP/network metadata. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[5]['channel'] | EventCode=22 | EventCode=3, 22 |
| Description |
|---|
Detects file transfers or mounting operations from remote hosts followed by write actions into a local staging directory, often using SMB or remote shell activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventID=31001 | EventCode=31001 |
| Description |
|---|
Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | PutObject, CopyObject | GetObject, CopyObject |
| Description |
|---|
Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4670, 4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
Iterable Item Removed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--d27b0089-2c39-4b6c-84ff-303e48657e77', 'name': 'WinEventLog:DirectoryService', 'channel': 'EventID 5136'} |
| Description |
|---|
Anomalous process (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of file transfer or network access activity through non-primary interfaces (e.g., WiFi, Bluetooth, cellular) by processes not typically associated with such behavior (e.g., rundll32, powershell, regsvr32). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of anomalous RDP or remote service session activity where a logon session is hijacked rather than newly created. Indicators include mismatched user credentials vs. active session tokens, service session takeovers without corresponding successful logon events, or RDP shadowing activity without user consent. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of trusted, Microsoft-signed binaries such as |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of trusted system binaries (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | open or connect | connect |
| Description |
|---|
Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4670, 4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | WinEventLog:Microsoft-Windows-WMI-Activity/Operational | WinEventLog:WMI |
| x_mitre_log_source_references[0]['channel'] | EventCode=5861 | EventCode=5857, 5858, 5860, 5861 |
| Description |
|---|
Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=22 | EventCode=3, 22 |
| Description |
|---|
Defender observes execution of commands like |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Monitors suspicious usage of Windows API calls like SetWindowsHookEx, GetKeyState, or polling functions within non-UI service processes, combined with Registry or driver modifications. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Behavioral sequence where removable media is mounted, files are written/updated, and subsequently read/executed on a separate host, suggesting removable-media relay communication. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-27T15:59:01.140Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | WinEventLog:Microsoft-Windows-Partition/Diagnostic | WinEventLog:System |
| Description |
|---|
Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Processes using Win32 API calls (e.g., EnumWindows, GetForegroundWindow) or scripting tools (e.g., PowerShell, VBScript) to enumerate open windows. These often appear with reconnaissance or data collection TTPs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4103,4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | path | PATH |
| Description |
|---|
Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects network share disconnection attempts using command-line tools like |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Use of hash-cracking tools (e.g., John the Ripper, Hashcat) after credential dumping, combined with high CPU usage or GPU invocation via unsigned binaries accessing password hash files |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-27T15:59:35.823Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=5145, 4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | azure:signinLogs | azure:signinlogs |
| Description |
|---|
Atypical processes (e.g., powershell.exe, regsvr32.exe) encode large outbound traffic using Base64 or other character encodings; this traffic is sent over uncommon ports or embedded in protocol fields (e.g., HTTP cookies or headers). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Creation or modification of |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | /var/log/syslog or journalctl | cron activity |
| Description |
|---|
Correlates inbound network access to remote service ports (e.g., SMB/RPC 445/135, RDP 3389, WinRM 5985/5986) with near-time instability in the target service (crash, abnormal restart), suspicious child process creation under the service, and post-access lateral-movement behaviors. The chain indicates likely exploitation rather than normal administration. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=7031,7034,1000,1001 | EventCode=1000 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects execution of image viewers or PowerShell scripts accessing or decoding files with mismatched MIME headers or embedded script-like byte patterns; often correlated with suspicious parent-child process lineage and outbound connections. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4723, 4724, 4726, 4740 | EventCode=4723, 4724, 4740 |
| Description |
|---|
O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | m365:signin | m365:signinlogs |
| Description |
|---|
Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[3]['channel'] | EventCode=1006,10001 | EventCode=1006, 10001 |
| Description |
|---|
Process invokes a standard encoder (e.g., PowerShell -enc, certutil -encode, base64 via .NET/Invoke-Expression) or emits long Base64/hex literals → shortly followed by outbound network egress with high bytesout:bytesin ratio or HTTP headers/payloads containing Base64/MIME blocks. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4103, 4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Shell/utility (base64, xxd -p, od, openssl enc -base64, python/perl base64 libraries) encodes data → subsequent outbound connections (curl/wget/bash TCP, socat, python requests) with high asymmetry or Base64/MIME blobs in HTTP/DNS payloads. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | WinEventLog:Security | WinEventLog:System |
| Description |
|---|
Suspicious use of scripting parameters or registry edits to hide process windows (e.g., powershell.exe -WindowStyle Hidden, or registry modifications pushing window positions off screen). Defender view: correlation of hidden execution with anomalous process lineage or hVNC-like CreateDesktop API calls. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | PutObject, GetObject, CopyObject, DeleteObject | GetObject, CopyObject |
| Description |
|---|
Detects unauthorized use of SMTP/IMAP/POP3 by suspicious binaries (e.g., PowerShell, rundll32) to exfiltrate data or beacon via email, often bypassing proxy or content filters. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of InstallUtil.exe from .NET framework directories with arguments specifying non-standard or attacker-supplied assemblies, especially when followed by suspicious child process creation or script execution. Detection also includes correlation of newly created binaries prior to InstallUtil invocation and anomalous command-line usage compared to historical baselines. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects adversary behavior deleting artifacts (e.g., dropped payloads, evidence files) using native or external utilities (e.g., del, erase, SDelete). Detects deletion events correlated with unusual process lineage or timing post-execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Processes that typically do not perform cryptographic operations loading symmetric encryption libraries (e.g., bcryptprimitives.dll, aes.dll), then initiating outbound connections with high-entropy payloads. Defender correlates process creation, DLL load, and anomalous encrypted traffic patterns. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4634, 4672, 4768, 4769 | EventCode=4672, 4634 |
| x_mitre_log_source_references[1]['name'] | WinEventLog:Kerberos | WinEventLog:Security |
| x_mitre_log_source_references[1]['channel'] | EventCode=4769, 4768 | EventCode=4769 |
| Description |
|---|
Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy also indicate adversarial actions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Forged SAML tokens can be observed as authentication attempts with valid signatures but missing expected preceding Kerberos or authentication events. Defenders may correlate SAML assertions with absent Event IDs 4769, 1200, or 1202, or tokens issued with abnormal lifetimes, issuers, or claims compared to baseline. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'azure:signinLogs', 'channel': 'SAML-based login with anomalous issuer or NotOnOrAfter lifetime'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'azure:signinlogs', 'channel': 'SAML-based login with anomalous issuer or NotOnOrAfter lifetime'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4769,1200,1202'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4769, 1200, 1202'} |
| Description |
|---|
Forged SAML tokens may be used on Windows systems to authenticate to federated apps without normal Kerberos activity. Defenders may detect anomalous event correlation, where access to SaaS/O365 via SAML occurs without prior TGT requests or user logons. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Detects data access or staging events followed by outbound data flows using unencrypted protocols (e.g., FTP, HTTP) initiated by unexpected processes or to rare destinations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T17:35:05.178Z |
Iterable Item Removed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--0f72bf50-35b3-419d-ab95-70f9b6a818dd', 'name': 'WinEventLog:Security', 'channel': '4673, 4674'} |
| Description |
|---|
Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[4]['channel'] | EventCode=4103 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['name'] | linux::cron | linux:cron |
| x_mitre_log_source_references[3]['channel'] | crontab or at job created within TimeWindow post time discovery | cron activity |
| Description |
|---|
Unusual processes (e.g., powershell.exe, wscript.exe, mshta.exe) posting data to webhook endpoints (Discord, Slack, webhook.site) using HTTP POST/PUT requests. Defender perspective: suspicious process lineage followed by outbound HTTPS traffic to webhook domains. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\Control Panel\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | WinEventLog:Microsoft-Windows-DriverFrameworks-UserMode/Operational | WinEventLog:System |
| Description |
|---|
Cause→effect chain: (1) a user or service spawns a shell/PowerShell that queries local/domain password policy via commands/cmdlets (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects PowerShell |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Adversary registers a malicious Microsoft Exchange transport agent DLL (.NET assembly), configures it via PowerShell or Exchange Management Shell, and persists code execution by manipulating email processing logic based on rules or headers. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Forged web cookies on Windows endpoints can be detected by monitoring unusual modifications of browser cookie stores (e.g., Chrome SQLite DB, Edge cache) by processes outside of browsers, followed by authentication events to SaaS or IaaS services. Defenders may observe processes writing directly to cookie storage paths or injecting tokens into browser sessions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
On Linux, defenders may observe forged cookie activity as unauthorized modifications to browser cookie databases (e.g., ~/.mozilla/firefox/*/cookies.sqlite, ~/.config/chromium/Default/Cookies) or scripted injection of session tokens. Suspicious usage includes curl/wget commands embedding forged cookies in headers, correlated with abnormal session activity in SaaS or IaaS logs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
High-frequency, repetitive service requests (e.g., HTTP, TLS renegotiation) originating from a single or small set of source IPs targeting endpoint web services or application ports, leading to exhaustion of CPU or memory on targeted Windows services. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of VNC service or executable starting unexpectedly, followed by user session creation and interactive desktop activity (mouse/keyboard simulation). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \host\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[3]['channel'] | EventCode=4103 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=1000-1026 | EventCode=1000 |
| Description |
|---|
Suspicious creation or modification of inbox rules through PowerShell (New-InboxRule, Set-InboxRule) to automatically delete, move, or hide emails. Defender perspective: unusual rule activity correlated with mailbox access and filtering patterns. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T23:17:37.896Z |
| x_mitre_log_source_references[0]['name'] | WinEventLog:Security | WinEventLog:PowerShell |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Identify unauthorized creation, deletion, or modification of business-critical stored data such as Office documents, database files, and log archives. Detect anomalous processes modifying stored data outside of expected workflows (e.g., non-database processes modifying database files). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=4656,4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Suspicious outbound HTTPS connections where the TLS Server Name Indication (SNI) does not match the HTTP Host header, indicating potential use of domain fronting to mask C2 traffic via CDNs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
A non-standard process (or script-hosted process) loads camera/video-capture libraries (e.g., avicap32.dll, mf.dll, ksproxy.ax), opens the Camera Frame Server/device, writes video/image artifacts (e.g., .mp4/.avi/.yuv) to unusual locations, and optionally initiates outbound transfer shortly after. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[4]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%.ssh\config, and network connections from the utility or its child. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects suspicious registry modifications under |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-27T16:01:17.493Z | 2025-11-12T17:13:52.357Z |
| x_mitre_log_source_references[2]['channel'] | 13 | EventCode=13 |
| Description |
|---|
Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary uses a process to establish outbound connections that transmit uniform packet sizes at a consistent interval, avoiding threshold-based network alerts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EvenCode=2 | EventCode=2 |
| Description |
|---|
Detects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Unusual or unauthorized processes accessing microphone APIs (e.g., winmm.dll, avrt.dll) followed by audio file writes to user-accessible or temp directories. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['name'] | WinEventlog:Security | WinEventLog:Security |
| Description |
|---|
Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[4]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[6]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[7]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | WinEventLog:System | WinEventLog:Sysmon |
| x_mitre_log_source_references[5]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Processes initiating outbound connections on uncommon ports or using protocols inconsistent with the assigned port. Correlating process creation with subsequent network connections reveals anomalies such as svchost.exe or Office applications using high, atypical ports. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=5156 | EventCode=5156, 5157 |
| Description |
|---|
Initial process initiates outbound connection to first-stage C2, receives payloads or commands, then spawns or injects into a second process that establishes a new outbound connection to an unrelated destination (second-stage C2). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Enumeration of global address lists or email account metadata via PowerShell cmdlets (e.g., Get-GlobalAddressList) or MAPI/RPC from non-admin, non-mailserver systems. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Abnormal usage of Preview, ImageMagick, or binary editors to alter images/documents, followed by exfiltration or outbound connections with mismatched file MIME types or payload structure. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | macos:unified | macos:unifiedlog |
| Description |
|---|
Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | GetObject | GetObject, CopyObject |
| Description |
|---|
Monitor for abnormal certificate enrollment and usage activity in Active Directory Certificate Services (AD CS), registry access to certificate storage locations, and unusual process executions that attempt to export or access private keys. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T18:12:53.100Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4886, 4887, 4899, 4900, 4768, 4624 | EventCode=4768 |
| Description |
|---|
Monitor for abnormal certificate enrollment events in identity platforms, unexpected use of token-signing certificates, and unusual CA configuration modifications. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | azure:SigninLogs | azure:signinlogs |
| Description |
|---|
Detects forged Kerberos Silver Tickets by identifying anomalous Kerberos service ticket activity such as malformed fields in logon events, TGS requests without interaction with the KDC, and access attempts using service accounts outside expected hosts/resources. Also monitors suspicious processes accessing LSASS memory for credential dumping. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4634, 4672, 4769 | EventCode=4672, 4634 |
| Description |
|---|
Database client execution (e.g., sqlcmd.exe, isql.exe) by users or from locations not tied to enterprise automation or backups. Often followed by creation of .sql/.bak/.csv files, registry artifacts for ODBC/JDBC drivers, or encrypted ZIPs. Defender sees SQL tools launched by explorer.exe, Powershell, or odd parent processes, plus file writes in user temp locations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Behavior chain involving unexpected API calls to capture keyboard input, driver loads for keyloggers, or remote use of smart card authentication via logon sessions not initiated by local user interaction |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--1887a270-576a-4049-84de-ef746b2572d6', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=10, 7'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--1887a270-576a-4049-84de-ef746b2572d6', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=10'} |
| x_mitre_log_source_references[2] | {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=13'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=13, 14'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624 with LogonType=9 or smartcard logon'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624, 4648'} |
| Description |
|---|
Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | CloudTrail:RunInstances | AWS:CloudTrail |
| Description |
|---|
IAAS (Cloud images/VMs): A new VM/instance is launched from a non-approved or newly-seen image (AMI/GCP Image/Azure Image). On first boot, cloud-init/user-data or embedded agents download code, spawn system utilities, or open outbound C2/mining traffic. The analytic correlates Instance/Image Creation → Instance Start → in-guest Process/Command Execution and/or anomalous network traffic. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | CloudTrail:RunInstances | AWS:CloudTrail |
| x_mitre_log_source_references[0]['channel'] | RunInstances: AMI not in allowlist OR AMI owner != enterprise owner/account | RunInstances |
| Description |
|---|
Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Monitor for anomalies in transmitted data streams, including mismatched file integrity checks, API interception, or man-in-the-middle modifications. Detect unexpected use of APIs that handle network I/O where transmitted data integrity could be manipulated. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Monitor for use of native utilities such as wevtutil.exe or PowerShell cmdlets (Get-WinEvent, Get-EventLog) to enumerate or export logs. Unusual access to security or system event channels, especially by non-administrative users or processes, should be correlated with subsequent file export or network transfer activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Forged web credentials may manifest as anomalous SAML token issuance, OpenID Connect token minting, or Zimbra pre-auth key usage. Defenders may see tokens issued without normal authentication events, multiple valid tokens generated simultaneously, or signing anomalies in IdP logs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | azure:signinLogs | azure:signinlogs |
| Description |
|---|
Forged web credentials on Windows endpoints may be detected by anomalous browser cookie files, local token cache manipulations, or tools injecting tokens into sessions. Defenders may observe processes accessing LSASS or browser credential stores unexpectedly, followed by unusual logon sessions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Forged web credentials in Office Suite contexts may appear as abnormal authentication headers in Outlook or Teams traffic, or unexplained OAuth grants in M365/Azure logs. Defenders should correlate token usage events with missing authentication flows and mismatched device/user context. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | m365:signin | m365:signinlogs |
| Description |
|---|
Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Monitor DNS query results where subsequent connections use derived or unusual port numbers not explicitly resolved, especially when tied to suspicious processes. Correlate Sysmon DNS logs (Event ID 22) with process creation and socket activity. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=22'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=1'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'} |
| Description |
|---|
Detects mailbox manipulation or deletion via PowerShell (e.g., Remove-MailboxExportRequest), file deletion from Outlook data stores (Unistore.db), or tampering with quarantined mail logs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | CloudWatch:Metrics | AWS:CloudWatch |
| Description |
|---|
Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 (LogonType=10 or 3), EventCode=4648 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=5136,5137,5138,5139,5141 | EventCode=5136 |
| x_mitre_log_source_references[1]['channel'] | EventCode=4670 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Monitor for abnormal creation or modification of Windows services (e.g., via sc.exe, PowerShell, or API calls) that load non-standard executables. Correlate registry changes in service keys with service creation events and process execution to detect service abuse for persistence or execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4672 | EventCode=4672, 4634 |
| x_mitre_log_source_references[4]['name'] | WinEventLog:DirectoryService | WinEventLog:Security |
| Description |
|---|
Unexpected processes (e.g., powershell.exe, wscript.exe, office apps) initiating HTTP POST/PUT requests to text storage domains like pastebin.com or hastebin.com, particularly when preceded by file access in sensitive directories. Defender perspective: correlation of process lineage, large clipboard/file read operations, and outbound uploads to text storage services. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 (LogonType=3) | EventCode=4624, 4648 |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Monitor for anomalous email activity originating from Windows-hosted applications (e.g., Outlook) where the sending account name or display name does not match the underlying SMTP address. Detect abnormal volume of outbound messages containing sensitive keywords (e.g., 'payment', 'wire transfer') or anomalous login locations for accounts associated with email sending activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T17:10:37.357Z |
| x_mitre_log_source_references[1]['name'] | WinEventLog:Directory Service | WinEventLog:Security |
| Description |
|---|
Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | CloudTrail:UpdatePolicy | AWS:CloudTrail |
| Description |
|---|
Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4670'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4663, 4670, 4656'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'} |
| Description |
|---|
Sequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypass |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4670 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[4]['channel'] | EventCode=4103,4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | WinEventLog:Microsoft-Windows-Partition/Diagnostic | WinEventLog:System |
| Description |
|---|
A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=2004,2005,2006 | EventCode=2004, 2005, 2006 |
| Description |
|---|
Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | path | PATH |
| Description |
|---|
Exploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=1000, 1001, 1002 | EventCode=1000 |
| Description |
|---|
Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf). |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=5136,5137,5138,5139,5141 | EventCode=5136 |
| x_mitre_log_source_references[1]['channel'] | EventCode=4670 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Correlated file access to insecure credential files (e.g., *.env, *.xml, *.ps1) followed by suspicious process execution or authentication using retrieved credentials. Detected through Sysmon logs and Windows Security Event logs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T18:16:01.708Z |
| Description |
|---|
Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[4]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[5]['channel'] | EventCode=22 | EventCode=3, 22 |
| Description |
|---|
Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | WinEventLog:Microsoft-Windows-Security-Auditing | WinEventLog:Security |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Adversaries create the 'Office Test\Special\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Processes such as PowerShell, Git, or curl initiating outbound HTTPS POST requests to known code repository APIs (e.g., github.com, gitlab.com) immediately following large file reads. Defender view: correlation between file access of sensitive directories (e.g., Documents, Finance) and abnormal data uploads to repository domains. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Unusual process (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
A process/script constructs or references a custom/alphabet translation table (e.g., 64/85/32+ arbitrary chars, XOR/base-N loops) or emits long high-entropy strings that do NOT validate as standard Base64/Hex → shortly after, the same process (or its child) generates outbound traffic with asymmetric bytesout:bytesin, fixed-size beacons, or protocol/header mismatches (e.g., Content-Type says JSON but body fails JSON parse / contains non-standard alphabet). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4103, 4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Shell scripts or binaries implement custom mapping tables (tr/sed/awk/golang/rust/python encode loops), or emit long high-entropy tokens that fail Base64/Hex validation → correlated with egress showing asymmetric flow, protocol-mismatch payloads, or DNS/HTTP bodies containing low-diversity-but-long custom alphabets. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 (LogonType=10), EventCode=4648 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[5]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Process chains that use native utilities (vssadmin, wbadmin, diskshadow, bcdedit, REAgentC, wmic) with arguments to delete shadow copies, disable recovery, or remove backup catalogs |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Cloud API calls disabling snapshot scheduling, backup policies, versioning, followed by DeleteSnapshot/DeleteVolume operations |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T18:17:38.273Z |
| x_mitre_log_source_references[1]['channel'] | PutBackupVaultAccessPolicy | DeleteBucket, DeleteDBCluster, DeleteSnapshot, TerminateInstances |
| Description |
|---|
Use of stolen Kerberos tickets or token impersonation resulting in logon sessions from accounts without expected interactive logon events. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4672, 4648 | EventCode=4624, 4648 |
| Description |
|---|
Token replay or impersonation in federated logins without interactive browser session or MFA prompts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | azure:signinLogs | azure:signinlogs |
| Description |
|---|
A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
VM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | CloudWatch:InstanceMetrics | AWS:CloudWatch |
| Description |
|---|
Correlate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Monitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | azure:signinLogs | azure:signinlogs |
| Description |
|---|
Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[3]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects unauthorized Kerberos ticket injection by correlating service ticket (TGS - 4769) requests with absent corresponding account logons (4624) and prior Ticket Granting Ticket (TGT - 4768) activity. Highlights anomalous service ticket generation chains involving unexpected users, hosts, or times, and suspicious injection of tickets via mimikatz-like tooling into LSASS memory. Behavior also includes network lateral movement using Kerberos authentication absent expected interactive logon patterns. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Registry modifications to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList setting user visibility to 0, or creation of user accounts not shown on login screen. Defender view: correlation of account creation with registry edits that mark users hidden. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4625 | EventCode=4776, 4625 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Execution of utilities (e.g., ping, tracert, Test-NetConnection) or scripted methods to test Internet connectivity by interacting with external IPs/domains. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[2]['channel'] | EventCode=5156 | EventCode=5156, 5157 |
| Description |
|---|
Suspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of domain group enumeration through command-line utilities such as 'net group /domain' or PowerShell cmdlets, followed by suspicious access to API calls or LSASS memory. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Abuse of Regsvcs.exe or Regasm.exe to execute arbitrary code embedded in .NET assemblies via [ComRegisterFunction]/[ComUnregisterFunction]. Behavioral chain: (1) Process creation of regsvcs/regasm with suspicious assembly paths/flags → (2) Assembly/DLL load inside regsvcs/regasm → (3) Registry writes to HKCR\CLSID/ProgID during COM registration → (4) Optional child process or network activity spawned by installer/registration code. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[5]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[6]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[4]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=5857, 5858 | EventCode=5857, 5858, 5860, 5861 |
| Description |
|---|
Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4016,5312 | EventCode=4016, 5312 |
| Description |
|---|
Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Unauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | WinEventLog:Security | WinEventLog:System |
| Description |
|---|
Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-10-29T17:10:15.891Z |
Iterable Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'} |
| Description |
|---|
Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4720, EventCode=4781 | EventCode=4720 |
| Description |
|---|
Detects anomalous ARP traffic or cache modifications on Windows endpoints that indicate ARP poisoning. Behavioral focus is on multiple IP addresses resolving to a single MAC, or unsolicited ARP replies from unauthorized devices. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe) |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:security', 'channel': 'EventCode=4688'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4688'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'} |
| Description |
|---|
Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=22 | EventCode=3, 22 |
| Description |
|---|
Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Outbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victim |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | 4624 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Monitor DNS queries, proxy logs, and user-agent strings for anomalous patterns associated with adversary attempts to hide infrastructure. Defenders may observe DNS resolutions to short-lived domains, abnormal WHOIS registration data, or filtering of known defensive/responder IP addresses. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=5156 | EventCode=5156, 5157 |
| Description |
|---|
Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | CloudTrail:GetSecretValue | AWS:CloudTrail |
| x_mitre_log_source_references[1]['channel'] | API call to retrieve secret or access key | GetSecretValue |
| Description |
|---|
Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Automated abuse of cloud-hosted applications (e.g., web apps, REST endpoints, internal APIs) causing compute exhaustion, high 5xx error rates, or frequent autoscaling triggers logged in app insights or cloudwatch. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | CloudTrail:InvokeFunction | AWS:CloudTrail |
| x_mitre_log_source_references[2]['name'] | CloudMetrics:InstanceHealth | AWS:CloudMetrics |
| Description |
|---|
Detects FTP, SMB, or TFTP traffic initiated by suspicious processes like PowerShell, cmd.exe, or rundll32.exe—especially with large outbound file transfers or unbalanced traffic volume. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Multi-stage Windows DACL manipulation behavioral chain: (1) Process creation of permission-modifying utilities (icacls.exe, takeown.exe, attrib.exe, cacls.exe) or PowerShell ACL cmdlets, (2) Command-line analysis revealing privilege escalation intent through suspicious parameters (/grant, /takeown, /T, Set-Acl), (3) DACL modification events (4670) correlating with process execution, (4) Subsequent file access attempts (4663) indicating successful permission bypass, (5) Potential follow-on persistence or lateral movement activities |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4670 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[4]['channel'] | EventCode=4103,4104,4105, 4106 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[5]['name'] | WinEventLog:Microsoft-Windows-WMI-Activity/Operational | WinEventLog:WMI |
| x_mitre_log_source_references[5]['channel'] | EventCode=5857, 5860, 5861 | EventCode=5857, 5858, 5860, 5861 |
| Description |
|---|
Correlate DNS queries that generate domains with high entropy or gibberish patterns, combined with short-lived connections from unusual processes. Monitor Sysmon DNS events and Windows Security logs for abnormal query rates and failed lookups. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=22 | EventCode=3, 22 |
| Description |
|---|
Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Monitors suspicious access to password stores such as LSASS, DPAPI, Windows Credential Manager, or browser credential databases. Detects anomalous process-to-process access (e.g., Mimikatz accessing LSASS) and correlation of credential store file reads with execution of non-standard processes. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Abuse of mavinject.exe to inject DLLs or import descriptors into another running process. Chain: (1) mavinject.exe starts with /INJECTRUNNING or /HMODULE → (2) mavinject obtains high-access handles to a target process (VMWRITE/CREATETHREAD) → (3) target process loads attacker DLL (module load) → (4) optional follow-on child activity or network egress from the target process. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[4]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[5]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEYLOCALMACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[4]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detection of anomalous registry modifications to Subject Interface Packages (SIPs) or trust provider DLL mappings, unexpected loading of non-Microsoft cryptographic modules, or attempts to redirect WinVerifyTrust validation logic. Defender view focuses on registry tampering, suspicious DLL loads into trusted processes, and abnormal trust validation failures correlated across event streams. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['name'] | WinEventLog:Application | WinEventLog:CodeIntegrity |
| x_mitre_log_source_references[2]['channel'] | 81,3033 | EventCode=3033 |
| Description |
|---|
Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Suspicious process spawning (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_mutable_elements[2]['field'] | path | PATH |
| Description |
|---|
Detection focuses on abnormal or unauthorized cloud instance creation events. From a defender’s perspective, suspicious behavior includes VM/instance creation by rarely used or newly created accounts, creation events from unusual geolocations, or rapid sequences of snapshot creation followed by instance creation and mounting. Unexpected network or IAM policy changes applied to new instances can indicate adversarial use rather than legitimate provisioning. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | CloudTrail:EC2 | AWS:CloudTrail |
| x_mitre_log_source_references[1]['name'] | CloudTrail:EC2 | AWS:CloudTrail |
| Description |
|---|
Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[2]['channel'] | EventCode=400,403 | EventCode=400, 403 |
| Description |
|---|
A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a new process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=4624, 4672 | EventCode=4672, 4634 |
| x_mitre_log_source_references[4]['name'] | WinEventLog:DirectoryService | WinEventLog:Security |
| Description |
|---|
Anomalous use of ICMP or UDP by non-network service processes for data exfiltration or remote control, especially if traffic bypasses proxy infrastructure or shows unusual flow patterns. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary modifies Active Directory domain trust settings via |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T18:15:01.136Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=5136,5137,5141 | EventCode=5136 |
| Description |
|---|
Adversary adds federated identity provider (IdP) or modifies tenant domain authentication from Managed to Federated. Detected via API, PowerShell, or Admin Portal through federation events like |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | azure:signinLogs | azure:signinlogs |
| Description |
|---|
Anomalous creation or mounting of hidden partitions or virtual file systems. Defender view: detection of registry modifications linked to non-standard file systems, suspicious disk I/O patterns, or bootkit-like behavior where hidden volumes are accessed outside normal file system APIs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4625, 4624 | EventCode=4776, 4625 |
| Description |
|---|
Enumeration of saved Wi-Fi profiles and cleartext password retrieval using |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4103 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=1341,1342,1020,1063 | EventCode=1341, 1342, 1020, 1063 |
| Description |
|---|
Untrusted processes creating outbound TLS/HTTPS connections with malformed certificates or header fields, often mismatched with target service behavior. Detects protocol impersonation attempts via traffic metadata analysis and host process lineage. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Windows-specific environmental keying behavioral chain: (1) Rapid system information discovery through multiple techniques (WMI queries, registry enumeration, network share discovery, hostname/domain checks), (2) Target validation through specific environmental artifact collection (AD domain membership, network topology, installed software versions), (3) Cryptographic operation correlation indicating payload decryption based on collected environmental values, (4) Subsequent malicious code execution following successful environmental validation, (5) Temporal clustering of discovery activities suggesting automated environmental assessment |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624,4648, 4672 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[5]['channel'] | EventCode=5857, 5860, 5861 | EventCode=5857, 5858, 5860, 5861 |
| x_mitre_log_source_references[6]['channel'] | EventCode=4103 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=1000,1001 | EventCode=1000 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Enumeration of services via native CLI tools (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Spike in object access from new IAM user or role followed by data exfiltration to external IPs |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | GetObject | GetObject, CopyObject |
| Description |
|---|
Identify repeated DNS resolutions where the same domain name returns multiple IPs in short succession, combined with low TTL values and high query volume from unusual processes. Correlate with process lineage (e.g., Office apps spawning abnormal DNS lookups). |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=22 | EventCode=3, 22 |
| Description |
|---|
Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Behavioral chain: (1) a login from a third-party account or untrusted source network establishes an interactive/remote session; (2) the session acquires elevated privileges or accesses sensitive resources atypical for that account; (3) subsequent lateral movement or data access occurs from the same session/device. Correlate Windows logon events, token elevation/privileged use, and resource access with third-party context. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624,4648,4672,4769'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624, 4648'} |
| x_mitre_log_source_references[2] | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4776,4771,4770'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4776, 4771, 4770'} |
| x_mitre_log_source_references[3] | {'x_mitre_data_component_ref': 'x-mitre-data-component--9c2fa0ae-7abc-485a-97f6-699e3b6cf9fa', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4663'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--9c2fa0ae-7abc-485a-97f6-699e3b6cf9fa', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4663, 4670, 4656'} |
| Description |
|---|
Detects anomalous use of COM, DDE, or named pipes for execution. Correlates creation or access of IPC mechanisms (e.g., named pipes, COM objects) with unusual parent-child process relationships or code injection patterns (e.g., Office spawning cmd.exe via DDE). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| Description |
|---|
Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[3]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[5]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | WinEventLog:Security | WinEventLog:System |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Modified Description View changes side-by-side |
|---|
| Detection Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of adversaries attempting to stop or disable host-based security agents by killing daemons, unloading kernel modules, or modifying init/systemd service configurations. logs after privileged shell execution. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:33:02.253Z |
| description | Detection of adversaries attempting to stop or disable host-based security agents by killing daemons, unloading kernel modules, or modifying init/systemd service configurations. | Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution. |
| x_mitre_version | 1.0 | 1.1 |
| Modified Description View changes side-by-side |
|---|
| Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or using security/uninstall commands to remove agents. disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:32:42.659Z |
| description | Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or using security/uninstall commands to remove agents. | Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss. |
| x_mitre_version | 1.0 | 1.1 |
| Modified Description View changes side-by-side |
|---|
| Detection of adversaries Correlates control-plane API actions disabling cloud cloud-native monitoring and logging or sensor agents such as CloudWatch, Google Cloud Monitoring, (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or Azure Monitor by API calls or instance agent process termination. uninstall events |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:31:55.528Z |
| description | Detection of adversaries disabling cloud monitoring and logging agents such as CloudWatch, Google Cloud Monitoring, or Azure Monitor by API calls or agent process termination. | Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events |
| x_mitre_version | 1.0 | 1.1 |
| Modified Description View changes side-by-side |
|---|
| Detection of adversaries tampering with Detects disabling container runtime security plugins, disabling admission controllers, controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or stopping killing in-container monitoring sidecars. agents. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:33:43.898Z |
| description | Detection of adversaries tampering with container runtime security plugins, disabling admission controllers, or stopping monitoring sidecars. | Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents. |
| x_mitre_version | 1.0 | 1.1 |
| Modified Description View changes side-by-side |
|---|
| Detection of adversaries modifying startup configuration files to disable signature verification, Detects disabling AAA, syslog, SNMP traps, ACL logging, or monitoring features. security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:33:32.261Z |
| description | Detection of adversaries modifying startup configuration files to disable signature verification, logging, or monitoring features. | Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility. |
| x_mitre_version | 1.0 | 1.1 |
Iterable Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--85a533a4-5fa4-4dba-b45d-f0717bedd6e6', 'name': 'networkdevice:syslog', 'channel': 'no logging host, no aaa new-model, no snmp-server, commit'} |
| Description |
|---|
A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-10-28T19:57:23.683Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4624,4672 | EventCode=4672 |
| Description |
|---|
Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects compilation activity using csc.exe, ilasm.exe, or msbuild.exe initiated by user-space processes outside typical development environments, followed by execution or network activity from newly written binaries. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detects the execution of non-browser processes establishing outbound encrypted network connections using uncommon symmetric encryption protocols (e.g., AES via PowerShell or custom scripts) to alternate external destinations. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4656 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| x_mitre_log_source_references[6]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[1]['channel'] | EventCode=20001/20003 | EventCode=2003 |
| Description |
|---|
Detects non-browser processes that establish encrypted outbound connections (e.g., TLS/SSL) to unfamiliar or atypical destinations for the host/user, following a data staging or compression event. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects adversary behavior accessing Windows cached domain credential files using tools like Mimikatz, reg.exe, or PowerShell, often combined with registry exports or LSASS memory scraping. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4672, 4634, 4768, 4769 | EventCode=4672, 4634 |
| Description |
|---|
A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[2]['channel'] | EventCode=2004,2005,2006 | EventCode=2004, 2005, 2006 |
| x_mitre_log_source_references[3]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Modified Description View changes side-by-side |
|---|
| Process creation and command-line Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution of native retrieving system discovery utilities such as `systeminfo`, `hostname`, `wmic`, or use of PowerShell/WMI for system enumeration. configuration metadata immediately after process startup. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T22:32:32.447Z |
| description | Process creation and command-line execution of native system discovery utilities such as `systeminfo`, `hostname`, `wmic`, or use of PowerShell/WMI for system enumeration. | Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup. |
| x_mitre_version | 1.0 | 1.1 |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
Iterable Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'} | |
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=13, 14'} |
| Description |
|---|
Execution of files containing right-to-left override characters (U+202E) to masquerade true file extensions. Often found in phishing payloads or file downloads. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624 (LogonType=3) | EventCode=4624, 4648 |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Microsoft-Windows-WLAN-AutoConfig', 'channel': '8001, 8002, 8003'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Microsoft-Windows-WLAN-AutoConfig', 'channel': 'EventCode=8001, 8002, 8003'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': '4624, 4625'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4776, 4625'} |
| Description |
|---|
Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Processes not typically associated with encryption loading asymmetric crypto libraries (e.g., rsaenh.dll, crypt32.dll) and subsequently initiating outbound TLS/SSL connections with abnormal certificate chains or handshakes. Defender correlates process creation, module load, and unusual encrypted sessions. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['name'] | m365:signin | m365:signinlogs |
| Description |
|---|
Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects creation or modification of Windows Services through command-line tools (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-27T15:56:07.094Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventID=4624 | EventCode=4624 |
| x_mitre_log_source_references[1]['channel'] | EventID=4625 | EventCode=4776, 4625 |
| Description |
|---|
Adversary installs or side-loads an IDE extension (VS Code, IntelliJ/JetBrains, Eclipse) or enables IDE tunneling. Chain: (1) IDE binary starts on a non-developer endpoint or server, often with install/force/tunnel flags → (2) extension files/registrations appear under user profile → (3) browser/IDE initiates outbound connections to extension marketplaces, update endpoints, or IDE remote/tunnel services → (4) optional child tools (ssh, node, powershell) execute under the IDE context. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Windows environmental validation behavioral chain: (1) Rapid system discovery reconnaissance through WMI queries, registry enumeration, and network share discovery, (2) Environment-specific artifact collection (hostname, domain, IP addresses, installed software, hardware identifiers), (3) Cryptographic operations or conditional logic based on collected environmental values, (4) Selective payload execution contingent on environmental validation results, (5) Temporal correlation between discovery activities and subsequent execution or network communication |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4624 | EventCode=4624, 4648 |
| x_mitre_log_source_references[3]['channel'] | EventCode=3 | EventCode=3, 22 |
| x_mitre_log_source_references[7]['channel'] | EventCode=13 | EventCode=13, 14 |
| x_mitre_log_source_references[8]['channel'] | EventCode=5857, 5860, 5861 | EventCode=5857, 5858, 5860, 5861 |
| x_mitre_log_source_references[9]['channel'] | EventCode=4103, 4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of PowerShell history suppression using Set-PSReadLineOption with SaveNothing or altered HistorySavePath. Correlating these options with PowerShell usage highlights adversarial evasion attempts. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4103 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects suspicious USB HID device enumeration and keystroke injection patterns, such as rapid sequences of input with no user context, scripts executed through simulated keystrokes, or rogue devices presenting themselves as keyboards. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0] | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d6e6b3b-4aa8-40e1-8c47-91db0f313d9f', 'name': 'WinEventLog:System', 'channel': '20001-20003'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d6e6b3b-4aa8-40e1-8c47-91db0f313d9f', 'name': 'WinEventLog:System', 'channel': 'EventCode=2003'} |
| x_mitre_log_source_references[2] | {'x_mitre_data_component_ref': 'x-mitre-data-component--685f917a-e95e-4ba0-ade1-c7d354dae6e0', 'name': 'WinEventLog:PowerShell', 'channel': 'EventCode=4104'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--685f917a-e95e-4ba0-ade1-c7d354dae6e0', 'name': 'WinEventLog:PowerShell', 'channel': 'EventCode=4103, 4104, 4105, 4106'} |
| x_mitre_log_source_references[1] | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': '4688, 4104'} | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4688'} |
| Description |
|---|
Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects command-line or API-based creation/modification of Windows Services via |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | GetObject | GetObject, CopyObject |
| Description |
|---|
Monitor for suspicious usage of driver enumeration utilities (driverquery.exe) or API calls such as EnumDeviceDrivers(). Registry queries against HKLM\SYSTEM\CurrentControlSet\Services and HardwareProfiles that are abnormal may also indicate attempts to discover installed drivers and services. Correlate command execution, process creation, and registry access to build a behavioral chain of driver discovery. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=13 | EventCode=13, 14 |
| Description |
|---|
Suspicious process initiating outbound connections to web services without corresponding response or return traffic, indicative of one-way command channels. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=3 | EventCode=3, 22 |
| Modified Description View changes side-by-side |
|---|
| Detection of suspicious enumeration of processes performing local or domain accounts via command-line tools, WMI, account enumeration by invoking account directory queries or scripts. security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T22:22:07.647Z |
| description | Detection of suspicious enumeration of local or domain accounts via command-line tools, WMI, or scripts. | Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward. |
| x_mitre_version | 1.0 | 1.1 |
Iterable Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4688'} | |
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--8e44412e-3238-4d64-8878-4f11e27784fe', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4798, 4799'} |
| Modified Description View changes side-by-side |
|---|
| Detection of user account enumeration through tools like dscl, dscacheutil, directory service queries or loginshell system utilities accessing account metadata stores, followed by structured enumeration via command-line. output. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T22:24:28.695Z |
| description | Detection of user account enumeration through tools like dscl, dscacheutil, or loginshell enumeration via command-line. | Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output. |
| x_mitre_version | 1.0 | 1.1 |
Iterable Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_log_source_references | {'x_mitre_data_component_ref': 'x-mitre-data-component--b5d0492b-cda4-421c-8e51-ed2b8d85c5d0', 'name': 'macos:unifiedlog', 'channel': 'DirectoryService queries retrieving account information'} |
| Modified Description View changes side-by-side |
|---|
| Detection of API calls listing users, enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM roles, users or groups roles in cloud environments. rapid succession. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T22:30:14.543Z |
| description | Detection of API calls listing users, IAM roles, or groups in cloud environments. | Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession. |
| Modified Description View changes side-by-side |
|---|
| Enumeration Detection of user identity directory enumeration through API calls or role administrative queries retrieving multiple account objects via IdP API endpoints or LDAP queries. within a short interval. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T22:29:39.660Z |
| description | Enumeration of user or role objects via IdP API endpoints or LDAP queries. | Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval. |
| Modified Description View changes side-by-side |
|---|
| Account Detection of enumeration via esxcli, vim-cmd, activity when system processes query ESXi host account configuration or API calls management APIs to vSphere. retrieve user account listings. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-03-13T22:28:56.147Z |
| description | Account enumeration via esxcli, vim-cmd, or API calls to vSphere. | Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings. |
| Description |
|---|
Detection of suspicious use of |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4624, 4634 | EventCode=4624, 4648 |
| x_mitre_log_source_references[2]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| Description |
|---|
Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[2]['channel'] | GetObject | GetObject, CopyObject |
| Description |
|---|
Detects attempts to modify file timestamps via API usage (e.g., |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=15 | EventCode=15 |
| x_mitre_log_source_references[1]['channel'] | EventCode=4663 | EventCode=4663, 4670, 4656 |
| Description |
|---|
Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['name'] | WinEventLog:DirectoryService | WinEventLog:Security |
| Modified Description View changes side-by-side |
|---|
| Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| description | Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). | Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). |
| Modified Description View changes side-by-side |
|---|
| Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| description | Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). | Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). |
| Modified Description View changes side-by-side |
|---|
| Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| description | Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). | Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). |
| Description |
|---|
Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators. User-Agent strings can be gathered with API calls such as |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-24T15:00:29.811Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[1]['channel'] | EventCode=3 | EventCode=3, 22 |
| Description |
|---|
A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems. Or a file system enumeration for specific file names andcritical extensions like .dll, .exe, .sys, or specific directories such as 'Program Files' or security tool paths or system component discovery for the exclusion of the files or components. |
Details
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-23T20:07:29.933Z | 2025-11-12T22:03:39.105Z |
| x_mitre_log_source_references[0]['channel'] | EventCode=4104 | EventCode=4103, 4104, 4105, 4106 |
| x_mitre_log_source_references[2]['channel'] | EventCode=4670 | EventCode=4663, 4670, 4656 |