Huntbase Hub · All hunts

Threat hunts for Slack

7 hunts covering Slack, each with a hypothesis, the queries that test it and what the hunt cannot see.

7 hunts

  1. high Part 2 of 2
    Research by Sekoia

    ShinyHunters Cloud Exfiltration and Ransomware

    An adversary is using compromised credentials or OAuth tokens to exfiltrate bulk S3 data and GitHub repositories before deploying ransomware for extortion.

    3 query1 analytic1 checkpoint1 action2 task
    collection · credential access · impact
  2. medium Part 2 of 2
    Research by Sekoia

    Cloud Runtime, Lateral Movement, and Impact

    An adversary has compromised a cloud workload using valid credentials and is moving across network segments before encrypting data and suppressing alerts via webhooks.

    6 query2 analytic1 checkpoint1 action2 task
    execution · impact · initial access
  3. medium Part 1 of 2
    Research by Sekoia

    Identity Access and Exposure Investigation

    An adversary has harvested credentials through a phishing portal and is now using them to access vulnerable assets while attempting to evade multi-factor authentication.

    3 query2 analytic2 checkpoint1 action2 task
    execution · impact · initial access
  4. high
    Research by Elastic Security Labs

    Chrysalis DLL Side-Loading and Execution

    An attacker has achieved code execution by placing a malicious DLL in the same directory as a legitimate Bluetooth service, exploiting the search order to side-load code and bypass standard system directory protections.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution
  5. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  6. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  7. high Part 2 of 2
    Research by Elastic Security Labs

    REVSTEALER: Credential Theft and Follow-on Impact

    An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion