Huntbase Hub · All hunts

Threat hunts for Windows

134 hunts covering Windows, each with a hypothesis, the queries that test it and what the hunt cannot see.

134 hunts

  1. high Part 2 of 2
    Research by Huntress

    Cloud Identity Hijacking and Mailbox Persistence

    An adversary has bypassed multi-factor authentication via session token theft or device code phishing and established persistence by modifying mailbox rules to hide intercepted communications.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  2. high Part 1 of 2
    Research by Huntress

    Endpoint Social Engineering and Malicious Execution

    An attacker has used AI-tuned phishing lures or ClickFix social engineering to trick a user into executing shell commands from the Run box, eventually deploying rogue RMM tools or infostealers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  3. medium Part 2 of 2
    Research by Cisco Talos

    Unauthorized RMM and Ransomware Precursors

    An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  4. medium Part 1 of 2
    Research by Cisco Talos

    Cloud Identity and AI Agent Anomalies

    An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · discovery · impact
  5. high
    Research by Huntress

    Microsoft Defender Antivirus Exclusion Abuse

    An intruder has modified Microsoft Defender exclusions to shield malicious paths from scanning and enabled stealth settings to hide these changes from local administrators.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion
  6. high Part 2 of 2
    Research by Huntress

    Web Worker Discovery and Payment Data Harvesting

    An intruder is using a compromised IIS web worker to execute discovery tools and search for payment card data or database credentials.

    3 query2 analytic2 checkpoint1 action2 task
    collection · discovery · execution
  7. high Part 1 of 2
    Research by Huntress

    Web Shell Ingress and Platform Probing

    An intruder has exploited a file upload vulnerability to drop web shells in member-facing directories after probing the application boundary and brute-forcing credentials.

    3 query1 analytic1 checkpoint1 action2 task
    collection · discovery · execution
  8. high
    Research by Cisco Talos

    UAT-11587 Antino Backdoor Phased Infection and M365 C2

    An adversary is using Cloudflare-hosted stagers to deliver the Rust-compiled Antino backdoor, which then establishes persistence via Run keys and communicates using Microsoft 365 as a dead-drop C2 channel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  9. medium Part 2 of 2
    Research by Elastic Security Labs

    Administrative AI Configuration File Tampering

    An adversary has modified system-wide AI configuration files or hooks on a Linux endpoint to bypass security constraints or establish persistence outside the managed reconciliation workflow.

    3 query1 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  10. medium Part 1 of 2
    Research by Elastic Security Labs

    Automated EDR Response Action Reconciliation

    An adversary has compromised a management principal or repurposed an Elastic workflow to perform mass remote execution across the Linux fleet, masquerading as a legitimate configuration reconciliation loop.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  11. high Part 1 of 2
    Research by Huntress

    ChatGPT Custom GPT ClickFix Lure and MSI Installer

    An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · initial access
  12. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Exfiltration and Impact

    An adversary is exfiltrating bulk data via SFTP using FileZilla and executing Akira ransomware, evidenced by massive outbound network transfers and the destruction of Volume Shadow Copies.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  13. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Persistence and AD Credential Harvesting

    An adversary has established internal persistence through unauthorized remote access tools like RustDesk and is performing Active Directory credential harvesting by dumping the NTDS database and LSASS memory.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  14. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee Delivery and C2 Establishment

    An intruder has lured an administrator to a look-alike download page via SEO poisoning, leading to a trojanized installer that side-loads Bumblebee via consent.exe and establishes AdaptixC2.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  15. medium
    Research by Sekoia

    Remote access and persistence via scheduled tasks

    An attacker has gained access via an external remote service and established persistence using a scheduled task that executes a remote administration tool or a malicious script.

    3 query2 analytic2 checkpoint1 action2 task
    execution · initial access · persistence
  16. medium
    Research by Cisco Talos

    Legacy System Access and Segmentation Bypass

    An adversary is exploiting unpatchable public-facing services or unauthorized VPN bridges to discover and laterally move toward isolated legacy OT assets.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · initial access · lateral movement
  17. high
    Research by Rapid7

    Windows Zero-Day Privilege Escalation and Ransomware

    Adversaries are exploiting unpatched Windows ALPC or Update Stack vulnerabilities to escalate to SYSTEM integrity and deploy ransomware, leaving traces of rare process elevations and specific link-resolution artifacts.

    4 query1 analytic1 checkpoint2 task
    CVE-2026-81963 · CVE-2026-85880
  18. high
    Research by Microsoft

    NeedyMantis Modular Sideloading and WebSocket C2

    An adversary has established long-term access by sideloading modular components into legitimate processes like Poedit or Vim, using encrypted archives staged in unusual directories to bypass detection.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  19. high Part 2 of 2
    Research by Rapid7

    Internal Coercion and Editor Persistence

    An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  20. high Part 1 of 2
    Research by Rapid7

    Exploitation of Web-Facing GitLab and Langflow

    An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18729 · CVE-2026-20929
  21. high
    Research by Sekoia

    Exvicy ClickFix Social Engineering and PowerShell Execution

    An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.

    4 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  22. high
    Research by Cisco Talos

    Microsoft Patch Tuesday September 2026 Exposure

    An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-58599 · CVE-2026-65669
  23. high
    Research by Rapid7

    SharePoint Business Data Connectivity Service Exploitation

    An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2019-1257 · CVE-2026-55040
  24. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-54988 · CVE-2025-66516
  25. high
    Research by ESET Research

    SparroWocky Backdoor and FamousSparrow APT Activity

    An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · initial access
  26. high
    Research by Sekoia

    Gamaredon GammaLoad Intrusion Lifecycle

    An adversary is using multi-stage VBScript loaders to maintain persistent access by caching C2 configuration in HKCU registry keys and executing payloads from Alternate Data Streams via scheduled tasks.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · persistence
  27. high Part 2 of 2
    Research by Sekoia

    ErrTraffic ClickFix PowerShell and Infostealer Activity

    An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  28. high Part 1 of 2
    Research by Sekoia

    ErrTraffic Infrastructure and Delivery Monitoring

    An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  29. high Part 2 of 2
    Research by Sekoia

    APT28 Edge Hijacking and AI-Driven Exfiltration

    An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  30. high Part 1 of 2
    Research by Sekoia

    APT28: Outlook and Print Spooler Exploitation

    An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.

    4 query2 analytic2 checkpoint1 action2 task
    CVE-2022-38028 · CVE-2023-23397
  31. high Part 2 of 2
    Research by Cisco Talos

    Amatera Stealer and Follow-on Payloads

    An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  32. high Part 2 of 2
    Research by Cisco Talos

    Host Intrusion and Destructive Impact

    An adversary has bypassed local security controls using system patchers and is executing AI-generated scripts to perform mass file encryption for ransomware extortion.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  33. high Part 1 of 2
    Research by Cisco Talos

    Remote access abuse and red-team implants

    An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  34. high Part 2 of 2
    Research by Sekoia

    Gamaredon Gammasteel: Drive Discovery and S3 Exfiltration

    An adversary is using a recurring PowerShell timer to discover documents across user profiles and local/network drives, then exfiltrating them to an S3-compatible storage endpoint.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · discovery · execution
  35. high Part 1 of 2
    Research by Sekoia

    Gammasteel Fileless PowerShell Registry Staging

    An intruder has staged encrypted PowerShell payloads in the user Printers registry hive and is executing them via hidden processes that avoid file-based detection.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · discovery · execution
  36. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  37. high Part 2 of 2
    Research by Cisco Talos

    CLOSEDQUORUM AI Payload Actions

    An autonomous AI implant is performing credential theft, process injection, or WMI persistence based on plurality-vote decisions reached by a panel of LLM providers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  38. high Part 1 of 2
    Research by Cisco Talos

    Autonomous LLM Decision Loop

    An autonomous implant performs host discovery and then queries multiple commercial AI providers to decide its next tactical moves, bypassing traditional C2 infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  39. high Part 2 of 2
    Research by Rapid7

    Metasploit Lateral Movement and Native Persistence

    An intruder uses Metasploit to move laterally via WinRM and SMB and maintains persistence through direct process creation from user-writable paths to evade shell-based detection.

    3 query2 analytic2 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  40. high Part 1 of 2
    Research by Rapid7

    Metasploit 2026: External Recon and Web Exploitation

    An adversary is using recently released Metasploit scanner and exploit modules to fingerprint organization SCADA infrastructure or exploit unauthenticated vulnerabilities in public-facing web applications.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-0265 · CVE-2026-16232
  41. high
    Research by Sekoia

    Gamaredon Modular Espionage Chain

    An intruder has exploited a Windows WinRAR path traversal vulnerability to execute HTA-based loaders, subsequently deploying VBScript stagers, an ADS-resident worm, and a modular PowerShell stealer persisting in the registry.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-8088
  42. medium Part 2 of 2
    Research by Huntress

    Rogue RMM Persistence and Defense Evasion

    An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  43. medium Part 1 of 2
    Research by Huntress

    Rogue RMM Delivery via Trusted Service Phishing

    An attacker has compromised a host by delivering a rogue RMM installer (ScreenConnect or ITarian) via phishing lures hosted on legitimate cloud services like Adobe or TransferXL, bypassing traditional email security filters.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  44. critical Part 3 of 3
    Research by Microsoft

    Storm-2570 Data Exfiltration and Ransomware Impact

    An intruder is exfiltrating staged directories and Active Directory database fragments using synchronization tools before deploying a ransomware payload for mass encryption.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  45. high Part 1 of 3
    Research by Microsoft

    Storm-2570 Persistent Remote Access and Discovery

    An intruder has established redundant persistent access using commercial RMM tools and outbound tunneling utilities to bypass firewalls and conduct internal reconnaissance.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  46. high Part 2 of 2
    Research by Huntress

    On-Host Miner Compilation and Resource Hijacking

    An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  47. high Part 2 of 2
    Research by Microsoft

    Node.js Backdoor and Lateral Movement

    An intruder is using a portable Node.js runtime and an obfuscated implant staged in LocalAppData to move laterally via WinRM after initial social engineering via Microsoft Teams.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  48. high Part 1 of 2
    Research by Microsoft

    IT Support Impersonation and Remote Access

    An attacker has gained interactive access by impersonating IT support via Microsoft Teams, coaxing a user into initiating an RMM session that bypasses standard perimeter controls.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  49. high Part 3 of 3
    Research by The DFIR Report

    Lateral Movement and Ransomware Deployment: The Gentlemen

    An adversary has moved laterally from an RMM-controlled beachhead using NetExec or GoTo Resolve to dump credentials and exfiltrate data to Wasabi before initiating domain-wide encryption via GPO.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  50. high Part 2 of 3
    Research by The DFIR Report

    Decentralized and SaaS C2 Infrastructure

    An intruder uses decentralized blockchain gateways or SaaS platforms to resolve C2 configuration and tunnel traffic, bypassing static network perimeter filters.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  51. high Part 1 of 3
    Research by The DFIR Report

    EtherRAT and TukTuk Initial Infection and Discovery

    An intruder has gained initial access via a trojanized MSI installer, established persistence using a Node.js-based EtherRAT, and is currently performing system discovery or sideloading TukTuk payloads.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2025-55182
  52. high Part 1 of 2
    Research by The DFIR Report

    Bumblebee Delivery and Persistence

    An intruder has delivered Bumblebee malware through a trojanized MSI installer via SEO poisoning, using DLL side-loading of consent.exe and establishing persistence with remote management tools like RustDesk.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · exfiltration
  53. high Part 1 of 2
    Research by Huntress

    Sideloaded AppX OAuth Token Theft

    An adversary has enabled Developer Mode and sideloaded a malicious AppX package to abuse WWAHost.exe, allowing them to capture MFA-compliant OAuth tokens via a legitimate Microsoft login dialog.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  54. high Part 3 of 3
    Research by The DFIR Report

    Persistence and Exfiltration of Lunar Spider

    An adversary is maintaining long-term access via a masqueraded .NET backdoor and exfiltrating data via Rclone over FTP to a rare external destination.

    4 query1 analytic1 checkpoint1 action2 task
    CVE-2020-1472
  55. high Part 3 of 3
    Research by The DFIR Report

    Apache ActiveMQ Lateral Movement and Ransomware Impact

    An attacker has transitioned from an exploited ActiveMQ server to lateral movement via RDP using stolen credentials, ultimately deploying LockBit ransomware from user-writable directories or with specific execution flags.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  56. high Part 1 of 3
    Research by The DFIR Report

    ActiveMQ Exploitation and Metasploit Staging

    An intruder has exploited CVE-2023-46604 on an ActiveMQ server to run arbitrary code, staged a Metasploit payload, and escalated to SYSTEM privileges using named pipe impersonation.

    4 query2 analytic1 checkpoint1 action2 task
    CVE-2023-46604
  57. critical Part 2 of 2
    Research by Huntress

    Settra Ransomware Local Impact and Recovery Inhibition

    An adversary is executing Settra ransomware, using a domain-specific launcher and a BYOVD driver to disable defenses before inhibiting recovery and encrypting files.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  58. high Part 1 of 2
    Research by Huntress

    Settra Persistence via MeshAgent and Remote Access

    An adversary has established a beachhead via compromised external remote services and installed MeshAgent, potentially renamed, to maintain persistent command-and-control access.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  59. high Part 2 of 2
    Research by Huntress

    INC Ransomware Wave 2: BYOVD and RAT Deployment

    An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  60. high Part 2 of 2
    Research by Huntress

    DarkMe RAT: COM Hijacking and Application Profiling

    An intruder has established persistence and stealthy execution by hijacking a COM object via script and launching it with Rundll32's /sta flag, followed by a broad profiling of local financial and security applications.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2023-38831 · CVE-2024-21412
  61. high
    Research by Elastic Security Labs

    Rapid Phishing and Proxy-based Exfiltration

    An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  62. high
    Research by Elastic Security Labs

    Living off the coding agent: Tunnels and LaunchAgents

    An adversary is using a signed coding agent to proxy shell execution, establish reverse tunnels for service exposure, and install LaunchAgent persistence on a developer workstation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  63. high
    Research by Sekoia

    Gamaredon GammaLoad Multi-stage Persistence and Execution

    An intruder has established persistent access using GammaLoad VBScripts that manage C2 configuration via registry keys in HKCU\Console and execute via a high-frequency task invoking an Alternate Data Stream.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  64. medium
    Research by Elastic Security Labs

    Endpoint-to-Cloud Phased Intrusion Hunt

    An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  65. medium
    Research by Microsoft

    Managed Access and Tenant Integrity

    An adversary has established persistence via cross-tenant delegated administration or unattended remote support, subsequently deploying autonomous agents that communicate through multi-hop proxies.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · persistence
  66. medium
    Research by Elastic Security Labs

    Vulnerable Driver Exploitation and Kernel Escalation

    An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.

    4 query2 analytic2 checkpoint1 action2 task
    execution · initial access · privilege escalation
  67. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  68. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  69. high
    Research by Microsoft

    AI-Themed Social Engineering and Multi-Stage Fraud

    An adversary is using lookalike AI domains and installers to trick users into downloading stealers or performing device-code authentication, leading to token theft and financial fraud.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  70. high
    Research by Huntress

    AD RMS Discovery and Administrative Reconnaissance

    An adversary is identifying on-premises AD RMS clusters via DNS and rights-policy template enumeration before escalating privileges via local group membership to reach the administrative surface.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · privilege escalation
  71. high
    Research by Unit 42

    Commodity Loader and Multi-Payload PPI Activity

    An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  72. high Part 2 of 2
    Research by Huntress

    Knight Office Token Theft and Device Persistence

    An adversary has stolen Microsoft 365 session tokens via a device-code phishing flow and secured persistence by enrolling an unauthorized rogue device into the Entra ID tenant.

    3 query1 analytic1 checkpoint1 action3 task
    credential access · initial access · persistence
  73. high Part 1 of 2
    Research by Huntress

    Knight Office Phishing Delivery and Redirects

    An adversary is using Monday.com redirects and .vu landing pages to deliver Knight Office phishing lures to M365 users.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · initial access · persistence
  74. high
    Research by Elastic Security Labs

    Chrysalis DLL Side-Loading and Execution

    An attacker has achieved code execution by placing a malicious DLL in the same directory as a legitimate Bluetooth service, exploiting the search order to side-load code and bypass standard system directory protections.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution
  75. high
    Research by Huntress

    BiTB Phishing to Rogue RMM Persistence

    An adversary has used browser-in-the-browser phishing to deceive a user into installing a rogue ScreenConnect instance, which established service-based persistence and executed evasion tools to hide its activity.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  76. high
    Research by Elastic Security Labs

    Bulk Directory Discovery via AAD Graph API

    An adversary uses legacy Azure AD Graph API endpoints and known offensive Client IDs to perform bulk directory enumeration, specifically targeting internal API versions that expose sensitive authentication methods.

    3 query2 analytic2 checkpoint1 action2 task
    discovery · execution · initial access
  77. high Part 1 of 2
    Research by Sekoia

    ErrTraffic: WordPress Infrastructure and Backdoor Maintenance

    An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  78. critical
    Research by Volexity

    SonicWall Appliance Zero-Day Exploitation and Webshells

    An adversary has exploited a pre-authentication proxy bypass and CVE-2026-15410 to execute commands on a SonicWall SMA appliance, established persistence via Nginx rewrites, and moved laterally using specific browser fingerprints.

    6 query2 analytic1 checkpoint1 action2 task
    CVE-2026-15410
  79. high
    Research by Unit 42

    SPIFFE/SPIRE Workload Identity Spoofing

    An attacker with root access on a Kubernetes node is spoofing cgroup metadata to trick the SPIRE agent into issuing identities belonging to co-located workloads for unauthorized service impersonation.

    4 query2 analytic1 checkpoint1 action3 task
    command and control · credential access · defense evasion
  80. medium
    Research by Elastic Security Labs

    WMI Lateral Movement and Proxy-based C2

    An intruder has moved laterally using WMI to execute code on internal Windows hosts and is maintaining command-and-control through multi-hop proxies or Tor to obfuscate traffic.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution
  81. high
    Research by Elastic Security Labs

    Bypass of npm Cooldown and Dependency Compromise

    An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · initial access
  82. high Part 2 of 2
    Research by Huntress

    Malicious C2 Infrastructure Polling

    An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.

    5 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  83. high Part 1 of 2
    Research by Huntress

    Cross-Platform Malware Execution and Persistence

    An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  84. high Part 2 of 2
    Research by Huntress

    Tampered Exodus Wallet Persistence and C2

    An intruder has deployed a tampered Exodus wallet that suppresses its UI and maintains persistence through a headless PowerShell scheduled task while communicating with a hardcoded C2 IP.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  85. high Part 2 of 2
    Research by Unit 42

    Spring Ring: NTLM Relay and RAT C2

    An attacker has deployed a custom Python environment to facilitate NTLM relay attacks and a PowerShell-based RAT that beacons to external command-and-control infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  86. high Part 1 of 2
    Research by Unit 42

    Microsoft Teams Vishing and Malicious Payload Execution

    An adversary is using external Microsoft Teams accounts to masquerade as IT support and coerce employees into executing RMM tools or custom payloads that perform discovery and persistence.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  87. high Part 3 of 3
    Research by The DFIR Report

    SystemBC C2 and WinSCP Exfiltration

    An adversary is using SystemBC for proxy tunneling and WinSCP for unencrypted FTP exfiltration from the Public Music directory to known ransomware affiliate infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  88. high Part 2 of 3
    Research by The DFIR Report

    Identity-Based Lateral Movement and Credential Access

    An intruder has moved laterally to high-value infrastructure like domain controllers and backup servers using hijacked accounts or newly created local admins, then executed scripts to harvest credentials.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  89. high Part 1 of 3
    Research by The DFIR Report

    EarthTime Trojan to Ransomware Reconnaissance

    An adversary has gained initial access via a trojanized EarthTime installer, established a beachhead using SectopRAT with MSBuild injection, and is now performing environment discovery using specialized ransomware reconnaissance tools.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  90. high
    Research by Microsoft

    IT Support Impersonation and WinRM Lateral Expansion

    An adversary has hijacked a remote-support session to execute PowerShell, use a portable Node.js runtime for C2, and expand laterally via WinRM to domain controllers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  91. high
    Research by Rapid7

    SharePoint Unauthenticated Remote Code Execution

    An attacker is exploiting the CVE-2026-55040 and CVE-2026-63520 chain to bypass authentication and execute arbitrary commands via the SharePoint worker process on unpatched servers.

    3 query1 analytic1 checkpoint2 task
    CVE-2026-55040 · CVE-2026-63520
  92. medium
    Research by Microsoft

    Exploitation and Obfuscated C2 in the Patch Window

    An adversary has exploited a critical vulnerability in a public-facing web application during the window before patching and is using a multi-hop proxy to mask command-and-control traffic.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  93. medium
    Research by Elastic Security Labs

    AI Coding Agent Tool-Call Auditing

    An AI agent operating under developer credentials is executing rare shell commands, accessing sensitive configuration files, or communicating with third-party MCP servers without explicit developer intent.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  94. high
    Research by Sekoia

    OysterLoader Multi-stage Execution and C2 Discovery

    An adversary has gained initial access via a signed MSI impersonating IT software and is executing in-memory shellcode to establish C2 and deploy ransomware or infostealers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  95. high Part 2 of 2
    Research by Unit 42

    AMOS Stealer C2 and Exfiltration Patterns

    An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  96. high Part 1 of 2
    Research by Unit 42

    Atomic macOS (AMOS) Stealer Activity

    An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  97. high Part 1 of 2
    Research by Mandiant

    Interactive Remote Access and Support Tool Abuse

    An intruder uses vishing to direct users to a self-destructing note service and installs unauthorized RMM tools to pivot into corporate VDI infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · execution · exfiltration
  98. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  99. high Part 2 of 2
    Research by Cisco Talos

    VoidLink Lateral Scanning and Mesh C2

    An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  100. high Part 1 of 2
    Research by Cisco Talos

    VoidLink: Exploitation and Kernel-Level Implant Deployment

    An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  101. high Part 2 of 2
    Research by Huntress

    PaperCut NG and MF Pre-Auth RCE Exploitation

    An unauthenticated intruder has exploited PaperCut NG/MF authorization bypass and unsafe class loading to execute arbitrary Java bytecode, profiled the system, and deleted server logs to hide their activities.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-81578 · CVE-2026-82078
  102. high Part 2 of 2
    Research by Unit 42

    Aeternum Decentralized C2 and Telegram Exfiltration

    An intruder is using public blockchain RPC endpoints to retrieve C2 instructions and the Telegram Bot API to exfiltrate system reconnaissance data, evading traditional domain-based filtering.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · exfiltration
  103. high Part 1 of 2
    Research by Unit 42

    Aeternum Loader Persistence and Execution

    The Aeternum loader has established persistence by creating a uniquely named LNK file in the user Startup directory and is executing auxiliary binaries from the local AppData profile.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · exfiltration
  104. high
    Research by Unit 42

    Endpoint AI-Assisted Scripting and Credential Dumping

    An intruder is using AI-generated scripts with iterative naming conventions to facilitate credential dumping and proxy tunneling across target organizations in Latin America.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  105. high Part 2 of 2
    Research by The DFIR Report

    Interlock RAT C2 and RDP Lateral Movement

    An intruder has established a PHP-based RAT beachhead and is using Cloudflare Tunnels for C2 before moving laterally via RDP.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  106. high Part 1 of 2
    Research by The DFIR Report

    Interlock RAT Endpoint Execution and Reconnaissance

    An intruder has deployed a PHP-based RAT into user-writable directories via a PowerShell stager and is conducting automated system reconnaissance to map the environment.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  107. critical Part 3 of 3
    Research by The DFIR Report

    Akira Ransomware Deployment and Credential Access

    An intruder has escalated privileges through NTDS dumping and database credential harvesting, and is now exfiltrating data before deploying Akira ransomware.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  108. high Part 2 of 3
    Research by The DFIR Report

    Bumblebee Reconnaissance and Privileged Persistence

    An intruder is performing domain discovery and establishing privileged persistence by creating rogue administrator accounts and external SSH tunnels from compromised systems.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  109. high Part 1 of 3
    Research by The DFIR Report

    Bumblebee SEO Poisoning and DLL Sideloading

    An intruder compromises privileged workstations by poisoning search results for IT tools, tricking users into running a trojanized MSI that side-loads Bumblebee malware via consent.exe.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  110. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  111. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  112. high
    Research by Elastic Security Labs

    ClickFix DLL Sideloading and Infostealer Injection

    An adversary has deployed a ClickFix script to sideload a malicious library into a signed Microsoft binary, followed by hollowing a system process to run an infostealer and using a BYOVD driver to blind endpoint security.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · defense evasion · execution
  113. high Part 2 of 2
    Research by Elastic Security Labs

    REVSTEALER: Credential Theft and Follow-on Impact

    An intruder has deployed an infostealer to harvest credentials from gaming and communication platforms, utilizing blockchain-based fallback infrastructure to maintain C2 and deploying impact modules like miners and proxies.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  114. medium
    Research by Huntress

    VSS Manipulation and Lateral Movement Correlation

    An attacker has moved laterally into the environment and is abusing Volume Shadow Copy Service utilities to either steal the Active Directory database or inhibit system recovery before a ransomware event.

    4 query2 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  115. high Part 2 of 2
    Research by Huntress

    GTA 6 Hype: RAT C2 and Data Theft

    An adversary is leveraging Grand Theft Auto VI hype to deploy RATs and infostealers that use ngrok tunnels for command and control and Discord for credential exfiltration.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  116. high Part 1 of 2
    Research by Huntress

    GTA6 Malicious Installer and Chaos Wiper Activity

    An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution
  117. high Part 2 of 2
    Research by Microsoft

    Microsoft Graph and Cloud Application Exfiltration

    An adversary is using automated Graph API tools to enumerate organizational resources and exfiltrate SharePoint/OneDrive data after obtaining a cloud session via passkey-themed social engineering.

    4 query1 analytic1 checkpoint1 action2 task
    discovery · exfiltration · initial access
  118. high
    Research by Elastic Security Labs

    KREMLIN Loader and Malicious Browser Extension Forgery

    An adversary is using multi-stage JavaScript loaders to install a persistent Node.js task that sideloads malware via SentinelOne to forge browser integrity checks and install malicious extensions.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  119. high Part 2 of 2
    Research by Sekoia

    PureCrypter Loader and Mallox Ransomware Execution

    An adversary is using PureCrypter to deliver Mallox ransomware, identified by Windows Defender exclusion commands followed by the retrieval of encrypted payloads disguised as media files and persistent Run keys in user profiles.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  120. high Part 1 of 2
    Research by Sekoia

    Mallox Ransomware MSSQL Authentication and Service Abuse

    An adversary is brute-forcing the MSSQL sa account to enable administrative features and execute a PowerShell loader from the SQL process.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  121. high Part 2 of 2
    Research by Sekoia

    iClickFix: NetSupport RAT Execution and Persistence

    An intruder has used a ClickFix social engineering lure to execute a PowerShell downloader that installs NetSupport RAT and establishes persistent communication with a multi-hop proxy C2 infrastructure.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  122. high Part 1 of 2
    Research by Sekoia

    iClickFix Web Redirection and Delivery

    An adversary is using compromised WordPress sites to redirect visitors through a YOURLS-based Traffic Distribution System to fetch ClickFix-style malicious scripts.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  123. high Part 2 of 2
    Research by Red Canary

    Abused RMM Infrastructure and Network Patterns

    An adversary is using unauthorized remote monitoring and management (RMM) tools for command and control, detectable via rare DNS lookups to RMM domains and specific User-Agent strings.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  124. high Part 2 of 3
    Research by Cisco Talos

    UAT-10147: Host Elevation and Evasion

    An adversary is executing automated staging scripts to deploy privilege escalation tools and blind security software on compromised web servers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  125. high Part 1 of 3
    Research by Cisco Talos

    Web Exploit and Telemetry Theft (UAT-10147)

    The adversary exploits known web vulnerabilities in Zimbra, Telerik, or AjaxPro to achieve initial access and exfiltrates system identifiers to a Nacos configuration server via HTTP POST requests.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  126. high
    Research by Sekoia

    MuddyRot Custom Implant Lifecycle

    An intruder has deployed the MuddyRot implant on a public-facing server, establishing persistence via a custom scheduled task and initiating a reverse shell to known Iranian C2 infrastructure.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  127. high Part 2 of 2
    Research by Huntress

    RMM Command and Control and Redundancy

    An attacker is using rogue ScreenConnect instances and secondary RMM tools to maintain persistence, identified by non-standard port connections and rare binaries running from user-writable directories.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  128. high Part 1 of 2
    Research by Huntress

    Rogue ScreenConnect Host Execution and Persistence

    An adversary is using social engineering to deploy rogue ScreenConnect clients that execute a multi-stage VBScript chain for host profiling and persistent access via registry run keys.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  129. high Part 2 of 2
    Research by Huntress

    RMM-Driven Endpoint Lateral Movement and Masquerading

    An intruder who has compromised an N-central appliance is abusing the Take Control feature to drop masqueraded binaries in user folders and perform process enumeration on managed hosts.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  130. high Part 1 of 2
    Research by Huntress

    N-central Web Exploitation and Persistence

    An attacker has exploited unauthenticated N-central web vulnerabilities to gain administrative control, subsequently establishing persistence through rogue user accounts and Cloudflare protocol tunnels.

    5 query2 analytic1 checkpoint1 action2 task
    CVE-2026-18556 · CVE-2026-18577
  131. high Part 3 of 3
    Research by Microsoft

    TerminalFix Asynchronous Shell and Reverse Tunnel

    An intruder has established long-term C2 presence using a PowerShell file-watch loop for asynchronous command execution and a Python-based reverse tunnel for persistent network-level proxying.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  132. high Part 2 of 3
    Research by Microsoft

    TerminalFix ClickFix Delivery and Automated Reconnaissance

    An intruder has used a fake Cloudflare verification lure to trick a user into pasting a PowerShell command, facilitating local directory staging and automated domain discovery.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · discovery
  133. high Part 2 of 2
    Research by Microsoft

    Persistent implant using repurposed update utilities

    An attacker has established persistence through a scheduled task that executes a randomized binary from a world-writable path, which then uses a legitimate update utility to communicate with Alibaba OSS infrastructure.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  134. high Part 1 of 2
    Research by Microsoft

    Counterfeit software delivery and randomized execution

    An intruder has established initial access by tricking a user into downloading a polymorphic installer from a spoofed vendor site, which then launches a masqueraded payload from a randomized directory.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access