Center for Threat-Informed Defense

Version 18.0 19.0

Analytics : Enterprise ATT&CK Changelog

Added Analytics

Description

Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.

Description

Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals.

Description

Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.

Description

Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity.

Description

Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events.

Description

Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution.

Description

Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation.

Description

Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption.

Description

Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage.

Description

Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction.

Description

Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration.

Description

Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity.

Description

Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.

Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.

Description

Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.

Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.

Description

Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.

Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.

Description

Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.

Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.

Description

Detection identifies execution of scripts or files that appear visually benign (low printable character ratio) but result in runtime decoding, dynamic evaluation, and subsequent process or network activity. Correlation links script execution with abnormal Unicode density and follow-on behavior such as child process creation or outbound connections.

Description

Detection identifies execution of scripts containing high concentrations of invisible Unicode characters followed by decoding or interpretation behaviors (e.g., base64 decode, eval) and subsequent process or network activity. Emphasis is placed on mismatch between file entropy/structure and execution output.

Description

Detection identifies execution of scripts or applications containing invisible Unicode payloads reconstructed at runtime, correlated with abnormal AppleScript, JavaScript for Automation, or shell execution and subsequent process or network behavior inconsistent with visible file content.

Modified Analytics

Description

Detects access attempts to cloud instance metadata endpoints (e.g., 169.254.169.254) from virtual machines or containerized workloads. This includes both direct access and SSRF exploitation patterns.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] CloudTrail:GetInstanceIdentityDocument AWS:CloudTrail

Description

Detects non-standard processes (e.g., PowerShell, python.exe, rundll32.exe) making outbound connections using publish/subscribe protocols (e.g., MQTT, AMQP) over non-browser, encrypted channels, often beaconing to message brokers.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Abnormal modification of the PATH environment variable or registry keys controlling system paths, combined with execution of binaries named after legitimate system tools from user-writable directories. Defender correlates registry modifications, file creation of suspicious binaries, and process execution paths inconsistent with baseline system directories.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-22T18:36:42.025Z 2025-11-12T17:36:06.423Z
x_mitre_log_source_references[0]['channel'] EvenCode=4657 EventCode=4657

Description

Execution of renamed common utilities (e.g., bash, nc, python, sh) from atypical directories or with names intended to deceive defenders or EDRs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] /var/log/syslog or journalctl cron activity

Description

Adversary manipulates dependencies/dev tools used by developers or CI: a package manager (npm/yarn/pnpm, pip/pipenv, nuget/dotnet, chocolatey/winget, maven/gradle) or a compiler/IDE downloads or restores content; files are written under project paths and execution paths (node_modules, packages, .nuget, .gradle, .m2, %AppData%\npm, %UserProfile%.cargo\bin, temp build dirs). First run of newly written components triggers scripts (preinstall/postinstall), shell/PowerShell spawning, or loader DLLs, followed by network egress to non-approved registries/CDNs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14

Description

Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Access to browser artifact locations (e.g., Chrome, Edge, Firefox) by processes like PowerShell, cmd.exe, or unknown tools, followed by file reads, decoding, or export operations indicating enumeration of bookmarks, autofill, or history databases.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detects staging of sensitive files into temporary or public directories, compression with 7zip/WinRAR, or batch copy prior to exfiltration.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] PutObject, CopyObject GetObject, CopyObject

Description

Adversary disables or stops critical services (e.g., Exchange, SQL, AV, endpoint monitoring) using native utilities or API calls, often preceding destructive actions (T1485, T1486). Behavioral chain: Elevated execution context + stop-service or sc.exe or ChangeServiceConfigW + terminated or disabled service + possible follow-up file manipulation.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['name'] WinEventLog:sysmon WinEventLog:Sysmon

Description

Adversary stages a lure that references a remote resource (e.g., LNK/SCF/Office template). When the user opens/renders the file or a shell enumerates icons, the host automatically attempts SMB or WebDAV authentication to the attacker host. The chain is: (1) lure file is created or modified in a user-exposed location → (2) user or system accesses the lure → (3) host makes outbound NTLM (SMB 139/445 or WebDAV over 80/443) to an untrusted destination → (4) repeated attempts from multiple users/hosts or from privileged workstations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Abuse of trusted Electron apps (Teams, Slack, Chrome) to spawn child processes or execute payloads via malicious command-line arguments (e.g., --gpu-launcher) and modified app resources (.asar). Behavior chain: suspicious parent process (Electron app) → unusual command-line args → child process creation → optional DLL/network artifacts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Abuse of Linux Electron binaries by modifying app.asar or config JS files and spawning unexpected child processes (bash, curl, python).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] Modification of .asar in /opt or ~/.config directories EventCode=11

Description

Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=13 EventCode=13, 14

Description

Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Processes invoking network-intensive child processes or uploading large data volumes, often from non-standard user or system contexts, with evidence of long-duration TCP/UDP sessions to unusual destinations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Defenders can observe suspicious replacement or tampering of system accessibility binaries (e.g., utilman.exe, sethc.exe, osk.exe) and anomalous modifications to registry keys used to redirect accessibility programs (such as IFEO keys). Additionally, execution of cmd.exe or other suspicious binaries triggered from the login screen by SYSTEM can be correlated as part of a behavior chain.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Suspicious processes initiating encrypted HTTPS connections to common web service domains, followed by abnormal data upload behavior or automated posting behavior indicative of C2 bidirectional traffic.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[1]['channel'] Event ID 1 EventCode=1

Description

Detects unauthorized access to web browser credential stores (e.g., Chrome Login Data, Edge Credential Locker) by processes other than the browser itself. Correlates file reads of credential databases with subsequent API calls to CryptUnprotectData or memory inspection attempts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4656, 4663 EventCode=4663, 4670, 4656

Description

Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=22'} {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=1'} {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'}

Description

Detects abuse of verclsid.exe to execute COM objects by monitoring process creation, CLSID arguments, DLLs or scriptlet engines loaded into memory, and If the CLSID points to remote SCT/HTA content, verclsid.exe makes outbound connections.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-22T18:38:17.503Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=22 EventCode=3, 22
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14

Description

Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Detects attempts to clear RDP/network history and modify network configuration artifacts through command execution, registry key deletion, firewall rule changes, and suspicious file deletions (e.g., Default.rdp, registry edits to Terminal Server Client keys).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14

Description

Creation or modification of files in directories known to be excluded from AV scanning (e.g., C:\Windows\Temp, Exchange server directories, or default AV exclusions). Defender perspective: correlate file creation with execution behavior or anomalous parent processes writing to excluded paths.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Outlook or Word used to forward suspicious internal attachments with macro content. Defender observes attachment forwarding, auto-opening behaviors, or macro prompt interactions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['name'] WinEventLog:Powershell WinEventLog:PowerShell
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] netconnect connect

Description

Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=4656,4663 EventCode=4663, 4670, 4656

Description

Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=13,14 EventCode=13, 14

Description

Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

PowerShell or script execution with parameters that suppress errors or ignore user interrupts, such as -ErrorAction SilentlyContinue. Defender perspective: detecting discrepancies between suppressed error arguments and continued execution behavior.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Chain: (1) a new external device is recognized by Windows (USB/Thunderbolt/PCIe) or a new block device appears; (2) within a short window, the same user/session spawns processes or the OS mounts a new volume; (3) optional follow-on activity such as HID keystroke injection, DMA driver load, or new network interface MAC on DHCP. Correlate Security EID 6416 / Kernel-PnP with sysmon and DHCP/network metadata.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[5]['channel'] EventCode=22 EventCode=3, 22

Description

Detects file transfers or mounting operations from remote hosts followed by write actions into a local staging directory, often using SMB or remote shell activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventID=31001 EventCode=31001

Description

Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] PutObject, CopyObject GetObject, CopyObject

Description

Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4670, 4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--d27b0089-2c39-4b6c-84ff-303e48657e77', 'name': 'WinEventLog:DirectoryService', 'channel': 'EventID 5136'}

Description

Anomalous process (e.g., rundll32, svchost, cmd) initiates connections to internal peer hosts not seen in typical communication baselines, used to proxy or forward traffic internally, often using SMB, RPC, or high ports.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of file transfer or network access activity through non-primary interfaces (e.g., WiFi, Bluetooth, cellular) by processes not typically associated with such behavior (e.g., rundll32, powershell, regsvr32).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of anomalous RDP or remote service session activity where a logon session is hijacked rather than newly created. Indicators include mismatched user credentials vs. active session tokens, service session takeovers without corresponding successful logon events, or RDP shadowing activity without user consent.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of trusted, Microsoft-signed binaries such as rundll32.exe, msiexec.exe, or regsvr32.exe used to execute externally hosted, unsigned, or suspicious payloads through command-line parameters or network retrieval.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of trusted system binaries (e.g., split, tee, bash, env) used in uncommon sequences or chained behaviors to execute malicious payloads or perform actions inconsistent with normal system or script behavior.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] open or connect connect

Description

Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4670, 4663 EventCode=4663, 4670, 4656

Description

An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of mofcomp.exe, usage of Register-WmiEvent via PowerShell, and anomalous child processes of WmiPrvSE.exe that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] WinEventLog:Microsoft-Windows-WMI-Activity/Operational WinEventLog:WMI
x_mitre_log_source_references[0]['channel'] EventCode=5861 EventCode=5857, 5858, 5860, 5861

Description

Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=22 EventCode=3, 22

Description

Defender observes execution of commands like tasklist, sc query, reg query, or PowerShell WMI/Registry queries targeting known backup products (e.g., Veeam, Acronis, CrashPlan). Behavior often includes parent-child lineage involving PowerShell or cmd.exe with discovery syntax, and enumeration of services, directories, or registry paths tied to backup software.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Monitors suspicious usage of Windows API calls like SetWindowsHookEx, GetKeyState, or polling functions within non-UI service processes, combined with Registry or driver modifications.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4656 EventCode=4663, 4670, 4656
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14

Description

Behavioral sequence where removable media is mounted, files are written/updated, and subsequently read/executed on a separate host, suggesting removable-media relay communication.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-27T15:59:01.140Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] WinEventLog:Microsoft-Windows-Partition/Diagnostic WinEventLog:System

Description

Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Processes using Win32 API calls (e.g., EnumWindows, GetForegroundWindow) or scripting tools (e.g., PowerShell, VBScript) to enumerate open windows. These often appear with reconnaissance or data collection TTPs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4103,4104 EventCode=4103, 4104, 4105, 4106

Description

Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] path PATH

Description

Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Detects network share disconnection attempts using command-line tools like net use /delete, PowerShell Remove-SmbMapping, and correlation with process lineage and SMB session teardown activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Use of hash-cracking tools (e.g., John the Ripper, Hashcat) after credential dumping, combined with high CPU usage or GPU invocation via unsigned binaries accessing password hash files

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-27T15:59:35.823Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=5145, 4663 EventCode=4663, 4670, 4656

Description

Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] azure:signinLogs azure:signinlogs

Description

Atypical processes (e.g., powershell.exe, regsvr32.exe) encode large outbound traffic using Base64 or other character encodings; this traffic is sent over uncommon ports or embedded in protocol fields (e.g., HTTP cookies or headers).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Creation or modification of systemd service units or cron jobs using deceptive naming and untrusted command paths, often followed by lateral network activity or privilege escalation.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] /var/log/syslog or journalctl cron activity

Description

Correlates inbound network access to remote service ports (e.g., SMB/RPC 445/135, RDP 3389, WinRM 5985/5986) with near-time instability in the target service (crash, abnormal restart), suspicious child process creation under the service, and post-access lateral-movement behaviors. The chain indicates likely exploitation rather than normal administration.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=7031,7034,1000,1001 EventCode=1000
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detects execution of image viewers or PowerShell scripts accessing or decoding files with mismatched MIME headers or embedded script-like byte patterns; often correlated with suspicious parent-child process lineage and outbound connections.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4723, 4724, 4726, 4740 EventCode=4723, 4724, 4740

Description

O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] m365:signin m365:signinlogs

Description

Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=13 EventCode=13, 14

Description

Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[3]['channel'] EventCode=1006,10001 EventCode=1006, 10001

Description

Process invokes a standard encoder (e.g., PowerShell -enc, certutil -encode, base64 via .NET/Invoke-Expression) or emits long Base64/hex literals → shortly followed by outbound network egress with high bytesout:bytesin ratio or HTTP headers/payloads containing Base64/MIME blocks.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4103, 4104 EventCode=4103, 4104, 4105, 4106

Description

Shell/utility (base64, xxd -p, od, openssl enc -base64, python/perl base64 libraries) encodes data → subsequent outbound connections (curl/wget/bash TCP, socat, python requests) with high asymmetry or Base64/MIME blobs in HTTP/DNS payloads.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] WinEventLog:Security WinEventLog:System

Description

Suspicious use of scripting parameters or registry edits to hide process windows (e.g., powershell.exe -WindowStyle Hidden, or registry modifications pushing window positions off screen). Defender view: correlation of hidden execution with anomalous process lineage or hVNC-like CreateDesktop API calls.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] PutObject, GetObject, CopyObject, DeleteObject GetObject, CopyObject

Description

Detects unauthorized use of SMTP/IMAP/POP3 by suspicious binaries (e.g., PowerShell, rundll32) to exfiltrate data or beacon via email, often bypassing proxy or content filters.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of InstallUtil.exe from .NET framework directories with arguments specifying non-standard or attacker-supplied assemblies, especially when followed by suspicious child process creation or script execution. Detection also includes correlation of newly created binaries prior to InstallUtil invocation and anomalous command-line usage compared to historical baselines.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detects adversary behavior deleting artifacts (e.g., dropped payloads, evidence files) using native or external utilities (e.g., del, erase, SDelete). Detects deletion events correlated with unusual process lineage or timing post-execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Processes that typically do not perform cryptographic operations loading symmetric encryption libraries (e.g., bcryptprimitives.dll, aes.dll), then initiating outbound connections with high-entropy payloads. Defender correlates process creation, DLL load, and anomalous encrypted traffic patterns.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4634, 4672, 4768, 4769 EventCode=4672, 4634
x_mitre_log_source_references[1]['name'] WinEventLog:Kerberos WinEventLog:Security
x_mitre_log_source_references[1]['channel'] EventCode=4769, 4768 EventCode=4769

Description

Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy also indicate adversarial actions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Forged SAML tokens can be observed as authentication attempts with valid signatures but missing expected preceding Kerberos or authentication events. Defenders may correlate SAML assertions with absent Event IDs 4769, 1200, or 1202, or tokens issued with abnormal lifetimes, issuers, or claims compared to baseline.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'azure:signinLogs', 'channel': 'SAML-based login with anomalous issuer or NotOnOrAfter lifetime'} {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'azure:signinlogs', 'channel': 'SAML-based login with anomalous issuer or NotOnOrAfter lifetime'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4769,1200,1202'} {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4769, 1200, 1202'}

Description

Forged SAML tokens may be used on Windows systems to authenticate to federated apps without normal Kerberos activity. Defenders may detect anomalous event correlation, where access to SaaS/O365 via SAML occurs without prior TGT requests or user logons.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Detects data access or staging events followed by outbound data flows using unencrypted protocols (e.g., FTP, HTTP) initiated by unexpected processes or to rare destinations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T17:35:05.178Z
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--0f72bf50-35b3-419d-ab95-70f9b6a818dd', 'name': 'WinEventLog:Security', 'channel': '4673, 4674'}

Description

Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[4]['channel'] EventCode=4103 EventCode=4103, 4104, 4105, 4106

Description

A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['name'] linux::cron linux:cron
x_mitre_log_source_references[3]['channel'] crontab or at job created within TimeWindow post time discovery cron activity

Description

Unusual processes (e.g., powershell.exe, wscript.exe, mshta.exe) posting data to webhook endpoints (Discord, Slack, webhook.site) using HTTP POST/PUT requests. Defender perspective: suspicious process lineage followed by outbound HTTPS traffic to webhook domains.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\Control Panel\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] WinEventLog:Microsoft-Windows-DriverFrameworks-UserMode/Operational WinEventLog:System

Description

Cause→effect chain: (1) a user or service spawns a shell/PowerShell that queries local/domain password policy via commands/cmdlets (e.g., net accounts, Get-ADDefaultDomainPasswordPolicy, secedit /export); (2) optional directory/LDAP reads from DCs; (3) same principal performs adjacent Discovery or credential-related actions within a short window. Correlate sysmon process creation with PowerShell ScriptBlock and Security logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detects PowerShell Clear-History invocation or deletion of ConsoleHost_history.txt to erase past PowerShell session history.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Adversary registers a malicious Microsoft Exchange transport agent DLL (.NET assembly), configures it via PowerShell or Exchange Management Shell, and persists code execution by manipulating email processing logic based on rules or headers.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Forged web cookies on Windows endpoints can be detected by monitoring unusual modifications of browser cookie stores (e.g., Chrome SQLite DB, Edge cache) by processes outside of browsers, followed by authentication events to SaaS or IaaS services. Defenders may observe processes writing directly to cookie storage paths or injecting tokens into browser sessions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4624 EventCode=4624, 4648

Description

On Linux, defenders may observe forged cookie activity as unauthorized modifications to browser cookie databases (e.g., ~/.mozilla/firefox/*/cookies.sqlite, ~/.config/chromium/Default/Cookies) or scripted injection of session tokens. Suspicious usage includes curl/wget commands embedding forged cookies in headers, correlated with abnormal session activity in SaaS or IaaS logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

High-frequency, repetitive service requests (e.g., HTTP, TLS renegotiation) originating from a single or small set of source IPs targeting endpoint web services or application ports, leading to exhaustion of CPU or memory on targeted Windows services.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of VNC service or executable starting unexpectedly, followed by user session creation and interactive desktop activity (mouse/keyboard simulation).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \host\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[3]['channel'] EventCode=4103 EventCode=4103, 4104, 4105, 4106

Description

Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using auditpol or wevtutil to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=1000-1026 EventCode=1000

Description

Suspicious creation or modification of inbox rules through PowerShell (New-InboxRule, Set-InboxRule) to automatically delete, move, or hide emails. Defender perspective: unusual rule activity correlated with mailbox access and filtering patterns.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T23:17:37.896Z
x_mitre_log_source_references[0]['name'] WinEventLog:Security WinEventLog:PowerShell
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Identify unauthorized creation, deletion, or modification of business-critical stored data such as Office documents, database files, and log archives. Detect anomalous processes modifying stored data outside of expected workflows (e.g., non-database processes modifying database files).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=4656,4663 EventCode=4663, 4670, 4656

Description

Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Suspicious outbound HTTPS connections where the TLS Server Name Indication (SNI) does not match the HTTP Host header, indicating potential use of domain fronting to mask C2 traffic via CDNs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

A non-standard process (or script-hosted process) loads camera/video-capture libraries (e.g., avicap32.dll, mf.dll, ksproxy.ax), opens the Camera Frame Server/device, writes video/image artifacts (e.g., .mp4/.avi/.yuv) to unusual locations, and optionally initiates outbound transfer shortly after.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[4]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%.ssh\config, and network connections from the utility or its child.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects suspicious registry modifications under HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\*\Driver, DLL loads by spoolsv.exe of non-standard or unsigned modules, and abnormal usage of the AddMonitor API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in C:\Windows\System32 not tied to known patches or installations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-27T16:01:17.493Z 2025-11-12T17:13:52.357Z
x_mitre_log_source_references[2]['channel'] 13 EventCode=13

Description

Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary uses a process to establish outbound connections that transmit uniform packet sizes at a consistent interval, avoiding threshold-based network alerts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EvenCode=2 EventCode=2

Description

Detects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Unusual or unauthorized processes accessing microphone APIs (e.g., winmm.dll, avrt.dll) followed by audio file writes to user-accessible or temp directories.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['name'] WinEventlog:Security WinEventLog:Security

Description

Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[4]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[6]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[7]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] WinEventLog:System WinEventLog:Sysmon
x_mitre_log_source_references[5]['channel'] EventCode=13 EventCode=13, 14

Description

Processes initiating outbound connections on uncommon ports or using protocols inconsistent with the assigned port. Correlating process creation with subsequent network connections reveals anomalies such as svchost.exe or Office applications using high, atypical ports.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=5156 EventCode=5156, 5157

Description

Initial process initiates outbound connection to first-stage C2, receives payloads or commands, then spawns or injects into a second process that establishes a new outbound connection to an unrelated destination (second-stage C2).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Enumeration of global address lists or email account metadata via PowerShell cmdlets (e.g., Get-GlobalAddressList) or MAPI/RPC from non-admin, non-mailserver systems.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Abnormal usage of Preview, ImageMagick, or binary editors to alter images/documents, followed by exfiltration or outbound connections with mismatched file MIME types or payload structure.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] macos:unified macos:unifiedlog

Description

Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] GetObject GetObject, CopyObject

Description

Monitor for abnormal certificate enrollment and usage activity in Active Directory Certificate Services (AD CS), registry access to certificate storage locations, and unusual process executions that attempt to export or access private keys.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T18:12:53.100Z
x_mitre_log_source_references[0]['channel'] EventCode=4886, 4887, 4899, 4900, 4768, 4624 EventCode=4768

Description

Monitor for abnormal certificate enrollment events in identity platforms, unexpected use of token-signing certificates, and unusual CA configuration modifications.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] azure:SigninLogs azure:signinlogs

Description

Detects forged Kerberos Silver Tickets by identifying anomalous Kerberos service ticket activity such as malformed fields in logon events, TGS requests without interaction with the KDC, and access attempts using service accounts outside expected hosts/resources. Also monitors suspicious processes accessing LSASS memory for credential dumping.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4634, 4672, 4769 EventCode=4672, 4634

Description

Database client execution (e.g., sqlcmd.exe, isql.exe) by users or from locations not tied to enterprise automation or backups. Often followed by creation of .sql/.bak/.csv files, registry artifacts for ODBC/JDBC drivers, or encrypted ZIPs. Defender sees SQL tools launched by explorer.exe, Powershell, or odd parent processes, plus file writes in user temp locations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Behavior chain involving unexpected API calls to capture keyboard input, driver loads for keyloggers, or remote use of smart card authentication via logon sessions not initiated by local user interaction

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--1887a270-576a-4049-84de-ef746b2572d6', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=10, 7'} {'x_mitre_data_component_ref': 'x-mitre-data-component--1887a270-576a-4049-84de-ef746b2572d6', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=10'}
x_mitre_log_source_references[2] {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=13'} {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=13, 14'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624 with LogonType=9 or smartcard logon'} {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624, 4648'}

Description

Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] CloudTrail:RunInstances AWS:CloudTrail

Description

IAAS (Cloud images/VMs): A new VM/instance is launched from a non-approved or newly-seen image (AMI/GCP Image/Azure Image). On first boot, cloud-init/user-data or embedded agents download code, spawn system utilities, or open outbound C2/mining traffic. The analytic correlates Instance/Image Creation → Instance Start → in-guest Process/Command Execution and/or anomalous network traffic.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] CloudTrail:RunInstances AWS:CloudTrail
x_mitre_log_source_references[0]['channel'] RunInstances: AMI not in allowlist OR AMI owner != enterprise owner/account RunInstances

Description

Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Monitor for anomalies in transmitted data streams, including mismatched file integrity checks, API interception, or man-in-the-middle modifications. Detect unexpected use of APIs that handle network I/O where transmitted data integrity could be manipulated.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Monitor for use of native utilities such as wevtutil.exe or PowerShell cmdlets (Get-WinEvent, Get-EventLog) to enumerate or export logs. Unusual access to security or system event channels, especially by non-administrative users or processes, should be correlated with subsequent file export or network transfer activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Forged web credentials may manifest as anomalous SAML token issuance, OpenID Connect token minting, or Zimbra pre-auth key usage. Defenders may see tokens issued without normal authentication events, multiple valid tokens generated simultaneously, or signing anomalies in IdP logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] azure:signinLogs azure:signinlogs

Description

Forged web credentials on Windows endpoints may be detected by anomalous browser cookie files, local token cache manipulations, or tools injecting tokens into sessions. Defenders may observe processes accessing LSASS or browser credential stores unexpectedly, followed by unusual logon sessions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Forged web credentials in Office Suite contexts may appear as abnormal authentication headers in Outlook or Teams traffic, or unexplained OAuth grants in M365/Azure logs. Defenders should correlate token usage events with missing authentication flows and mismatched device/user context.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] m365:signin m365:signinlogs

Description

Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Monitor DNS query results where subsequent connections use derived or unusual port numbers not explicitly resolved, especially when tied to suspicious processes. Correlate Sysmon DNS logs (Event ID 22) with process creation and socket activity.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=22'} {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=1'} {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'}

Description

Detects mailbox manipulation or deletion via PowerShell (e.g., Remove-MailboxExportRequest), file deletion from Outlook data stores (Unistore.db), or tampering with quarantined mail logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] CloudWatch:Metrics AWS:CloudWatch

Description

Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 (LogonType=10 or 3), EventCode=4648 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=5136,5137,5138,5139,5141 EventCode=5136
x_mitre_log_source_references[1]['channel'] EventCode=4670 EventCode=4663, 4670, 4656

Description

Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Monitor for abnormal creation or modification of Windows services (e.g., via sc.exe, PowerShell, or API calls) that load non-standard executables. Correlate registry changes in service keys with service creation events and process execution to detect service abuse for persistence or execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4672 EventCode=4672, 4634
x_mitre_log_source_references[4]['name'] WinEventLog:DirectoryService WinEventLog:Security

Description

Unexpected processes (e.g., powershell.exe, wscript.exe, office apps) initiating HTTP POST/PUT requests to text storage domains like pastebin.com or hastebin.com, particularly when preceded by file access in sensitive directories. Defender perspective: correlation of process lineage, large clipboard/file read operations, and outbound uploads to text storage services.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 (LogonType=3) EventCode=4624, 4648
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Monitor for anomalous email activity originating from Windows-hosted applications (e.g., Outlook) where the sending account name or display name does not match the underlying SMTP address. Detect abnormal volume of outbound messages containing sensitive keywords (e.g., 'payment', 'wire transfer') or anomalous login locations for accounts associated with email sending activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T17:10:37.357Z
x_mitre_log_source_references[1]['name'] WinEventLog:Directory Service WinEventLog:Security

Description

Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] CloudTrail:UpdatePolicy AWS:CloudTrail

Description

Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4670'} {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4663, 4670, 4656'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3'} {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'}

Description

Sequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypass

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4670 EventCode=4663, 4670, 4656
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[4]['channel'] EventCode=4103,4104 EventCode=4103, 4104, 4105, 4106

Description

Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] WinEventLog:Microsoft-Windows-Partition/Diagnostic WinEventLog:System

Description

A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=2004,2005,2006 EventCode=2004, 2005, 2006

Description

Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] path PATH

Description

Exploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=1000, 1001, 1002 EventCode=1000

Description

Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=5136,5137,5138,5139,5141 EventCode=5136
x_mitre_log_source_references[1]['channel'] EventCode=4670 EventCode=4663, 4670, 4656

Description

Correlated file access to insecure credential files (e.g., *.env, *.xml, *.ps1) followed by suspicious process execution or authentication using retrieved credentials. Detected through Sysmon logs and Windows Security Event logs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T18:16:01.708Z

Description

Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[4]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[5]['channel'] EventCode=22 EventCode=3, 22

Description

Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] WinEventLog:Microsoft-Windows-Security-Auditing WinEventLog:Security
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Adversaries create the 'Office Test\Special\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=13 EventCode=13, 14

Description

Processes such as PowerShell, Git, or curl initiating outbound HTTPS POST requests to known code repository APIs (e.g., github.com, gitlab.com) immediately following large file reads. Defender view: correlation between file access of sensitive directories (e.g., Documents, Finance) and abnormal data uploads to repository domains.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Unusual process (e.g., rundll32, mshta, wscript, or custom payloads) initiates network connection to external IPs/domains that proxy C2 traffic, often over uncommon ports or high entropy HTTP/S connections.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

A process/script constructs or references a custom/alphabet translation table (e.g., 64/85/32+ arbitrary chars, XOR/base-N loops) or emits long high-entropy strings that do NOT validate as standard Base64/Hex → shortly after, the same process (or its child) generates outbound traffic with asymmetric bytesout:bytesin, fixed-size beacons, or protocol/header mismatches (e.g., Content-Type says JSON but body fails JSON parse / contains non-standard alphabet).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4103, 4104 EventCode=4103, 4104, 4105, 4106

Description

Shell scripts or binaries implement custom mapping tables (tr/sed/awk/golang/rust/python encode loops), or emit long high-entropy tokens that fail Base64/Hex validation → correlated with egress showing asymmetric flow, protocol-mismatch payloads, or DNS/HTTP bodies containing low-diversity-but-long custom alphabets.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 (LogonType=10), EventCode=4648 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[5]['channel'] EventCode=13 EventCode=13, 14

Description

Process chains that use native utilities (vssadmin, wbadmin, diskshadow, bcdedit, REAgentC, wmic) with arguments to delete shadow copies, disable recovery, or remove backup catalogs

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14

Description

Cloud API calls disabling snapshot scheduling, backup policies, versioning, followed by DeleteSnapshot/DeleteVolume operations

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T18:17:38.273Z
x_mitre_log_source_references[1]['channel'] PutBackupVaultAccessPolicy DeleteBucket, DeleteDBCluster, DeleteSnapshot, TerminateInstances

Description

Use of stolen Kerberos tickets or token impersonation resulting in logon sessions from accounts without expected interactive logon events.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4672, 4648 EventCode=4624, 4648

Description

Token replay or impersonation in federated logins without interactive browser session or MFA prompts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] azure:signinLogs azure:signinlogs

Description

A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

VM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] CloudWatch:InstanceMetrics AWS:CloudWatch

Description

Correlate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Monitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] azure:signinLogs azure:signinlogs

Description

Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[3]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detects unauthorized Kerberos ticket injection by correlating service ticket (TGS - 4769) requests with absent corresponding account logons (4624) and prior Ticket Granting Ticket (TGT - 4768) activity. Highlights anomalous service ticket generation chains involving unexpected users, hosts, or times, and suspicious injection of tickets via mimikatz-like tooling into LSASS memory. Behavior also includes network lateral movement using Kerberos authentication absent expected interactive logon patterns.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Registry modifications to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList setting user visibility to 0, or creation of user accounts not shown on login screen. Defender view: correlation of account creation with registry edits that mark users hidden.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4625 EventCode=4776, 4625
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Execution of utilities (e.g., ping, tracert, Test-NetConnection) or scripted methods to test Internet connectivity by interacting with external IPs/domains.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[2]['channel'] EventCode=5156 EventCode=5156, 5157

Description

Suspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of domain group enumeration through command-line utilities such as 'net group /domain' or PowerShell cmdlets, followed by suspicious access to API calls or LSASS memory.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Abuse of Regsvcs.exe or Regasm.exe to execute arbitrary code embedded in .NET assemblies via [ComRegisterFunction]/[ComUnregisterFunction]. Behavioral chain: (1) Process creation of regsvcs/regasm with suspicious assembly paths/flags → (2) Assembly/DLL load inside regsvcs/regasm → (3) Registry writes to HKCR\CLSID/ProgID during COM registration → (4) Optional child process or network activity spawned by installer/registration code.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[5]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[6]['channel'] EventCode=3 EventCode=3, 22

Description

A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[4]['channel'] EventCode=13 EventCode=13, 14

Description

Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=5857, 5858 EventCode=5857, 5858, 5860, 5861

Description

Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4016,5312 EventCode=4016, 5312

Description

Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Unauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] WinEventLog:Security WinEventLog:System

Description

Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-10-29T17:10:15.891Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'}

Description

Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4720, EventCode=4781 EventCode=4720

Description

Detects anomalous ARP traffic or cache modifications on Windows endpoints that indicate ARP poisoning. Behavioral focus is on multiple IP addresses resolving to a single MAC, or unsolicited ARP replies from unauthorized devices.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe)

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:security', 'channel': 'EventCode=4688'} {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4688'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3'} {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'}

Description

Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=22 EventCode=3, 22

Description

Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Outbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victim

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] 4624 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Monitor DNS queries, proxy logs, and user-agent strings for anomalous patterns associated with adversary attempts to hide infrastructure. Defenders may observe DNS resolutions to short-lived domains, abnormal WHOIS registration data, or filtering of known defensive/responder IP addresses.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=5156 EventCode=5156, 5157

Description

Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] CloudTrail:GetSecretValue AWS:CloudTrail
x_mitre_log_source_references[1]['channel'] API call to retrieve secret or access key GetSecretValue

Description

Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Automated abuse of cloud-hosted applications (e.g., web apps, REST endpoints, internal APIs) causing compute exhaustion, high 5xx error rates, or frequent autoscaling triggers logged in app insights or cloudwatch.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] CloudTrail:InvokeFunction AWS:CloudTrail
x_mitre_log_source_references[2]['name'] CloudMetrics:InstanceHealth AWS:CloudMetrics

Description

Detects FTP, SMB, or TFTP traffic initiated by suspicious processes like PowerShell, cmd.exe, or rundll32.exe—especially with large outbound file transfers or unbalanced traffic volume.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Multi-stage Windows DACL manipulation behavioral chain: (1) Process creation of permission-modifying utilities (icacls.exe, takeown.exe, attrib.exe, cacls.exe) or PowerShell ACL cmdlets, (2) Command-line analysis revealing privilege escalation intent through suspicious parameters (/grant, /takeown, /T, Set-Acl), (3) DACL modification events (4670) correlating with process execution, (4) Subsequent file access attempts (4663) indicating successful permission bypass, (5) Potential follow-on persistence or lateral movement activities

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4670 EventCode=4663, 4670, 4656
x_mitre_log_source_references[4]['channel'] EventCode=4103,4104,4105, 4106 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[5]['name'] WinEventLog:Microsoft-Windows-WMI-Activity/Operational WinEventLog:WMI
x_mitre_log_source_references[5]['channel'] EventCode=5857, 5860, 5861 EventCode=5857, 5858, 5860, 5861

Description

Correlate DNS queries that generate domains with high entropy or gibberish patterns, combined with short-lived connections from unusual processes. Monitor Sysmon DNS events and Windows Security logs for abnormal query rates and failed lookups.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=22 EventCode=3, 22

Description

Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Monitors suspicious access to password stores such as LSASS, DPAPI, Windows Credential Manager, or browser credential databases. Detects anomalous process-to-process access (e.g., Mimikatz accessing LSASS) and correlation of credential store file reads with execution of non-standard processes.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Abuse of mavinject.exe to inject DLLs or import descriptors into another running process. Chain: (1) mavinject.exe starts with /INJECTRUNNING or /HMODULE → (2) mavinject obtains high-access handles to a target process (VMWRITE/CREATETHREAD) → (3) target process loads attacker DLL (module load) → (4) optional follow-on child activity or network egress from the target process.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[4]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[5]['channel'] EventCode=3 EventCode=3, 22

Description

Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEYLOCALMACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[4]['channel'] EventCode=13 EventCode=13, 14

Description

Detection of anomalous registry modifications to Subject Interface Packages (SIPs) or trust provider DLL mappings, unexpected loading of non-Microsoft cryptographic modules, or attempts to redirect WinVerifyTrust validation logic. Defender view focuses on registry tampering, suspicious DLL loads into trusted processes, and abnormal trust validation failures correlated across event streams.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['name'] WinEventLog:Application WinEventLog:CodeIntegrity
x_mitre_log_source_references[2]['channel'] 81,3033 EventCode=3033

Description

Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Suspicious process spawning (e.g., rundll32, svchost, powershell, or netsh) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_mutable_elements[2]['field'] path PATH

Description

Detection focuses on abnormal or unauthorized cloud instance creation events. From a defender’s perspective, suspicious behavior includes VM/instance creation by rarely used or newly created accounts, creation events from unusual geolocations, or rapid sequences of snapshot creation followed by instance creation and mounting. Unexpected network or IAM policy changes applied to new instances can indicate adversarial use rather than legitimate provisioning.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] CloudTrail:EC2 AWS:CloudTrail
x_mitre_log_source_references[1]['name'] CloudTrail:EC2 AWS:CloudTrail

Description

Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[2]['channel'] EventCode=400,403 EventCode=400, 403

Description

A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a new process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=4624, 4672 EventCode=4672, 4634
x_mitre_log_source_references[4]['name'] WinEventLog:DirectoryService WinEventLog:Security

Description

Anomalous use of ICMP or UDP by non-network service processes for data exfiltration or remote control, especially if traffic bypasses proxy infrastructure or shows unusual flow patterns.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary modifies Active Directory domain trust settings via netdom, nltest, or PowerShell to add new domain trust or alter federation. Modifications occur in AD object attributes like trustDirection, trustType, trustAttributes, often paired with SeEnableDelegationPrivilege or certificate injection.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T18:15:01.136Z
x_mitre_log_source_references[0]['channel'] EventCode=5136,5137,5141 EventCode=5136

Description

Adversary adds federated identity provider (IdP) or modifies tenant domain authentication from Managed to Federated. Detected via API, PowerShell, or Admin Portal through federation events like Set domain authentication, Add federated identity provider, or Update-MsolFederatedDomain.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] azure:signinLogs azure:signinlogs

Description

Anomalous creation or mounting of hidden partitions or virtual file systems. Defender view: detection of registry modifications linked to non-standard file systems, suspicious disk I/O patterns, or bootkit-like behavior where hidden volumes are accessed outside normal file system APIs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4625, 4624 EventCode=4776, 4625

Description

Enumeration of saved Wi-Fi profiles and cleartext password retrieval using netsh wlan or API-level access to wlanAPI.dll.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4103 EventCode=4103, 4104, 4105, 4106

Description

Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=1341,1342,1020,1063 EventCode=1341, 1342, 1020, 1063

Description

Untrusted processes creating outbound TLS/HTTPS connections with malformed certificates or header fields, often mismatched with target service behavior. Detects protocol impersonation attempts via traffic metadata analysis and host process lineage.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Windows-specific environmental keying behavioral chain: (1) Rapid system information discovery through multiple techniques (WMI queries, registry enumeration, network share discovery, hostname/domain checks), (2) Target validation through specific environmental artifact collection (AD domain membership, network topology, installed software versions), (3) Cryptographic operation correlation indicating payload decryption based on collected environmental values, (4) Subsequent malicious code execution following successful environmental validation, (5) Temporal clustering of discovery activities suggesting automated environmental assessment

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624,4648, 4672 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[5]['channel'] EventCode=5857, 5860, 5861 EventCode=5857, 5858, 5860, 5861
x_mitre_log_source_references[6]['channel'] EventCode=4103 EventCode=4103, 4104, 4105, 4106

Description

Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=1000,1001 EventCode=1000
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22

Description

Enumeration of services via native CLI tools (e.g., sc query, tasklist /svc, net start) or API calls via PowerShell and WMI.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Spike in object access from new IAM user or role followed by data exfiltration to external IPs

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] GetObject GetObject, CopyObject

Description

Identify repeated DNS resolutions where the same domain name returns multiple IPs in short succession, combined with low TTL values and high query volume from unusual processes. Correlate with process lineage (e.g., Office apps spawning abnormal DNS lookups).

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=22 EventCode=3, 22

Description

Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Behavioral chain: (1) a login from a third-party account or untrusted source network establishes an interactive/remote session; (2) the session acquires elevated privileges or accesses sensitive resources atypical for that account; (3) subsequent lateral movement or data access occurs from the same session/device. Correlate Windows logon events, token elevation/privileged use, and resource access with third-party context.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624,4648,4672,4769'} {'x_mitre_data_component_ref': 'x-mitre-data-component--9ce98c86-8d30-4043-ba54-0784d478d0b5', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4624, 4648'}
x_mitre_log_source_references[2] {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3'} {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=3, 22'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4776,4771,4770'} {'x_mitre_data_component_ref': 'x-mitre-data-component--39b9db72-8b48-4595-a18d-db5bbba3091b', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4776, 4771, 4770'}
x_mitre_log_source_references[3] {'x_mitre_data_component_ref': 'x-mitre-data-component--9c2fa0ae-7abc-485a-97f6-699e3b6cf9fa', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4663'} {'x_mitre_data_component_ref': 'x-mitre-data-component--9c2fa0ae-7abc-485a-97f6-699e3b6cf9fa', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4663, 4670, 4656'}

Description

Detects anomalous use of COM, DDE, or named pipes for execution. Correlates creation or access of IPC mechanisms (e.g., named pipes, COM objects) with unusual parent-child process relationships or code injection patterns (e.g., Office spawning cmd.exe via DDE).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 EventCode=4624, 4648

Description

Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[3]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[5]['channel'] EventCode=3 EventCode=3, 22

Description

Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] WinEventLog:Security WinEventLog:System
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Modified Description View changes side-by-side
Detection Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of adversaries attempting to stop or disable host-based security agents by killing daemons, unloading kernel modules, or modifying init/systemd service configurations. logs after privileged shell execution.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:33:02.253Z
description Detection of adversaries attempting to stop or disable host-based security agents by killing daemons, unloading kernel modules, or modifying init/systemd service configurations. Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.
x_mitre_version 1.0 1.1

Modified Description View changes side-by-side
Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or using security/uninstall commands to remove agents. disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:32:42.659Z
description Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or using security/uninstall commands to remove agents. Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.
x_mitre_version 1.0 1.1

Modified Description View changes side-by-side
Detection of adversaries Correlates control-plane API actions disabling cloud cloud-native monitoring and logging or sensor agents such as CloudWatch, Google Cloud Monitoring, (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or Azure Monitor by API calls or instance agent process termination. uninstall events
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:31:55.528Z
description Detection of adversaries disabling cloud monitoring and logging agents such as CloudWatch, Google Cloud Monitoring, or Azure Monitor by API calls or agent process termination. Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events
x_mitre_version 1.0 1.1

Modified Description View changes side-by-side
Detection of adversaries tampering with Detects disabling container runtime security plugins, disabling admission controllers, controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or stopping killing in-container monitoring sidecars. agents.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:33:43.898Z
description Detection of adversaries tampering with container runtime security plugins, disabling admission controllers, or stopping monitoring sidecars. Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.
x_mitre_version 1.0 1.1

Modified Description View changes side-by-side
Detection of adversaries modifying startup configuration files to disable signature verification, Detects disabling AAA, syslog, SNMP traps, ACL logging, or monitoring features. security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:33:32.261Z
description Detection of adversaries modifying startup configuration files to disable signature verification, logging, or monitoring features. Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.
x_mitre_version 1.0 1.1
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--85a533a4-5fa4-4dba-b45d-f0717bedd6e6', 'name': 'networkdevice:syslog', 'channel': 'no logging host, no aaa new-model, no snmp-server, commit'}

Description

A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-10-28T19:57:23.683Z
x_mitre_log_source_references[1]['channel'] EventCode=4624,4672 EventCode=4672

Description

Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects compilation activity using csc.exe, ilasm.exe, or msbuild.exe initiated by user-space processes outside typical development environments, followed by execution or network activity from newly written binaries.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Detects the execution of non-browser processes establishing outbound encrypted network connections using uncommon symmetric encryption protocols (e.g., AES via PowerShell or custom scripts) to alternate external destinations.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4656 EventCode=4663, 4670, 4656

Description

Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648
x_mitre_log_source_references[6]['channel'] EventCode=3 EventCode=3, 22

Description

Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[1]['channel'] EventCode=20001/20003 EventCode=2003

Description

Detects non-browser processes that establish encrypted outbound connections (e.g., TLS/SSL) to unfamiliar or atypical destinations for the host/user, following a data staging or compression event.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detects adversary behavior accessing Windows cached domain credential files using tools like Mimikatz, reg.exe, or PowerShell, often combined with registry exports or LSASS memory scraping.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4672, 4634, 4768, 4769 EventCode=4672, 4634

Description

A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[2]['channel'] EventCode=2004,2005,2006 EventCode=2004, 2005, 2006
x_mitre_log_source_references[3]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Modified Description View changes side-by-side
Process creation and command-line Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution of native retrieving system discovery utilities such as `systeminfo`, `hostname`, `wmic`, or use of PowerShell/WMI for system enumeration. configuration metadata immediately after process startup.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T22:32:32.447Z
description Process creation and command-line execution of native system discovery utilities such as `systeminfo`, `hostname`, `wmic`, or use of PowerShell/WMI for system enumeration. Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup.
x_mitre_version 1.0 1.1
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=1'}
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--da85d358-741a-410d-9433-20d6269a6170', 'name': 'WinEventLog:Sysmon', 'channel': 'EventCode=13, 14'}

Description

Execution of files containing right-to-left override characters (U+202E) to masquerade true file extensions. Often found in phishing payloads or file downloads.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624 (LogonType=3) EventCode=4624, 4648
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Microsoft-Windows-WLAN-AutoConfig', 'channel': '8001, 8002, 8003'} {'x_mitre_data_component_ref': 'x-mitre-data-component--181a9f8c-c780-4f1f-91a8-edb770e904ba', 'name': 'WinEventLog:Microsoft-Windows-WLAN-AutoConfig', 'channel': 'EventCode=8001, 8002, 8003'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': '4624, 4625'} {'x_mitre_data_component_ref': 'x-mitre-data-component--a953ca55-921a-44f7-9b8d-3d40141aa17e', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4776, 4625'}

Description

Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Description

Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Processes not typically associated with encryption loading asymmetric crypto libraries (e.g., rsaenh.dll, crypt32.dll) and subsequently initiating outbound TLS/SSL connections with abnormal certificate chains or handshakes. Defender correlates process creation, module load, and unusual encrypted sessions.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['name'] m365:signin m365:signinlogs

Description

Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects creation or modification of Windows Services through command-line tools (e.g., sc.exe, powershell.exe), Registry key changes under HKLM\System\CurrentControlSet\Services, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or CreateServiceW usage. Correlates parent-child lineage, startup behavior, and rare service names.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-27T15:56:07.094Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventID=4624 EventCode=4624
x_mitre_log_source_references[1]['channel'] EventID=4625 EventCode=4776, 4625

Description

Adversary installs or side-loads an IDE extension (VS Code, IntelliJ/JetBrains, Eclipse) or enables IDE tunneling. Chain: (1) IDE binary starts on a non-developer endpoint or server, often with install/force/tunnel flags → (2) extension files/registrations appear under user profile → (3) browser/IDE initiates outbound connections to extension marketplaces, update endpoints, or IDE remote/tunnel services → (4) optional child tools (ssh, node, powershell) execute under the IDE context.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Windows environmental validation behavioral chain: (1) Rapid system discovery reconnaissance through WMI queries, registry enumeration, and network share discovery, (2) Environment-specific artifact collection (hostname, domain, IP addresses, installed software, hardware identifiers), (3) Cryptographic operations or conditional logic based on collected environmental values, (4) Selective payload execution contingent on environmental validation results, (5) Temporal correlation between discovery activities and subsequent execution or network communication

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4624 EventCode=4624, 4648
x_mitre_log_source_references[3]['channel'] EventCode=3 EventCode=3, 22
x_mitre_log_source_references[7]['channel'] EventCode=13 EventCode=13, 14
x_mitre_log_source_references[8]['channel'] EventCode=5857, 5860, 5861 EventCode=5857, 5858, 5860, 5861
x_mitre_log_source_references[9]['channel'] EventCode=4103, 4104 EventCode=4103, 4104, 4105, 4106

Description

Detection of PowerShell history suppression using Set-PSReadLineOption with SaveNothing or altered HistorySavePath. Correlating these options with PowerShell usage highlights adversarial evasion attempts.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4103 EventCode=4103, 4104, 4105, 4106

Description

Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects suspicious USB HID device enumeration and keystroke injection patterns, such as rapid sequences of input with no user context, scripts executed through simulated keystrokes, or rogue devices presenting themselves as keyboards.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0] {'x_mitre_data_component_ref': 'x-mitre-data-component--3d6e6b3b-4aa8-40e1-8c47-91db0f313d9f', 'name': 'WinEventLog:System', 'channel': '20001-20003'} {'x_mitre_data_component_ref': 'x-mitre-data-component--3d6e6b3b-4aa8-40e1-8c47-91db0f313d9f', 'name': 'WinEventLog:System', 'channel': 'EventCode=2003'}
x_mitre_log_source_references[2] {'x_mitre_data_component_ref': 'x-mitre-data-component--685f917a-e95e-4ba0-ade1-c7d354dae6e0', 'name': 'WinEventLog:PowerShell', 'channel': 'EventCode=4104'} {'x_mitre_data_component_ref': 'x-mitre-data-component--685f917a-e95e-4ba0-ade1-c7d354dae6e0', 'name': 'WinEventLog:PowerShell', 'channel': 'EventCode=4103, 4104, 4105, 4106'}
x_mitre_log_source_references[1] {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': '4688, 4104'} {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4688'}

Description

Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Detects command-line or API-based creation/modification of Windows Services via sc.exe, powershell.exe, services.exe, or ChangeServiceConfig. Looks for creation/modification of autostart services via registry changes, file drops to System32\services, and anomalous parent-child process trees.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=13 EventCode=13, 14

Description

Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows).

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] GetObject GetObject, CopyObject

Description

Monitor for suspicious usage of driver enumeration utilities (driverquery.exe) or API calls such as EnumDeviceDrivers(). Registry queries against HKLM\SYSTEM\CurrentControlSet\Services and HardwareProfiles that are abnormal may also indicate attempts to discover installed drivers and services. Correlate command execution, process creation, and registry access to build a behavioral chain of driver discovery.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=13 EventCode=13, 14

Description

Suspicious process initiating outbound connections to web services without corresponding response or return traffic, indicative of one-way command channels.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=3 EventCode=3, 22

Modified Description View changes side-by-side
Detection of suspicious enumeration of processes performing local or domain accounts via command-line tools, WMI, account enumeration by invoking account directory queries or scripts. security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T22:22:07.647Z
description Detection of suspicious enumeration of local or domain accounts via command-line tools, WMI, or scripts. Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.
x_mitre_version 1.0 1.1
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--3d20385b-24ef-40e1-9f56-f39750379077', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4688'}
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--8e44412e-3238-4d64-8878-4f11e27784fe', 'name': 'WinEventLog:Security', 'channel': 'EventCode=4798, 4799'}

Modified Description View changes side-by-side
Detection of user account enumeration through tools like dscl, dscacheutil, directory service queries or loginshell system utilities accessing account metadata stores, followed by structured enumeration via command-line. output.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T22:24:28.695Z
description Detection of user account enumeration through tools like dscl, dscacheutil, or loginshell enumeration via command-line. Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.
x_mitre_version 1.0 1.1
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_log_source_references {'x_mitre_data_component_ref': 'x-mitre-data-component--b5d0492b-cda4-421c-8e51-ed2b8d85c5d0', 'name': 'macos:unifiedlog', 'channel': 'DirectoryService queries retrieving account information'}

Modified Description View changes side-by-side
Detection of API calls listing users, enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM roles, users or groups roles in cloud environments. rapid succession.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T22:30:14.543Z
description Detection of API calls listing users, IAM roles, or groups in cloud environments. Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession.

Modified Description View changes side-by-side
Enumeration Detection of user identity directory enumeration through API calls or role administrative queries retrieving multiple account objects via IdP API endpoints or LDAP queries. within a short interval.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T22:29:39.660Z
description Enumeration of user or role objects via IdP API endpoints or LDAP queries. Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.

Modified Description View changes side-by-side
Account Detection of enumeration via esxcli, vim-cmd, activity when system processes query ESXi host account configuration or API calls management APIs to vSphere. retrieve user account listings.
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-03-13T22:28:56.147Z
description Account enumeration via esxcli, vim-cmd, or API calls to vSphere. Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings.

Description

Detection of suspicious use of tscon.exe or equivalent methods to hijack legitimate RDP sessions. Defenders can observe anomalies such as session reassignments without corresponding authentication, processes spawned in the context of hijacked sessions, or unusual RDP network traffic flows that deviate from expected baselines.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4624, 4634 EventCode=4624, 4648
x_mitre_log_source_references[2]['channel'] EventCode=3 EventCode=3, 22

Description

Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106

Description

Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[2]['channel'] GetObject GetObject, CopyObject

Description

Detects attempts to modify file timestamps via API usage (e.g., SetFileTime), CLI tools (e.g., w32tm, PowerShell), or double-timestomp behavior where $SI and $FN timestamps are mismatched or reverted.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=15 EventCode=15
x_mitre_log_source_references[1]['channel'] EventCode=4663 EventCode=4663, 4670, 4656

Description

Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['name'] WinEventLog:DirectoryService WinEventLog:Security

Modified Description View changes side-by-side
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).
Details
Values Changed
FIELD OLD VALUE NEW VALUE
description Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).

Modified Description View changes side-by-side
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).
Details
Values Changed
FIELD OLD VALUE NEW VALUE
description Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).

Modified Description View changes side-by-side
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).
Details
Values Changed
FIELD OLD VALUE NEW VALUE
description Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Defense Evasion](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)). Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).

Description

Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators. User-Agent strings can be gathered with API calls such as ShellExecuteW to open the default browser on a socket to receive an HTTP reply, or by hard coding the User-Agent string for a specific browser.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-24T15:00:29.811Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[1]['channel'] EventCode=3 EventCode=3, 22

Description

A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems. Or a file system enumeration for specific file names andcritical extensions like .dll, .exe, .sys, or specific directories such as 'Program Files' or security tool paths or system component discovery for the exclusion of the files or components.

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-23T20:07:29.933Z 2025-11-12T22:03:39.105Z
x_mitre_log_source_references[0]['channel'] EventCode=4104 EventCode=4103, 4104, 4105, 4106
x_mitre_log_source_references[2]['channel'] EventCode=4670 EventCode=4663, 4670, 4656