Release date: 18 June, 2025Change typeChangesAdded 2 new Informational Analytics BIOCsPotential DCSync by an unusual userUncommon access to cloud platforms' sensitive files by a scripting engineImproved logic of 7 High Analytics BIOCsCopy a process memory fileMemory dumping with comsvcs.dllMimikatz command-line argumentsSuspicious usage of File Server Remote VSS Protocol (FSRVP)Uncommon remote scheduled task creationUnicode RTL Override CharacterUnprivileged process opened a registry hiveImproved logic of 35 Medium Analytics BIOCsA TCP stream was created directly in a shellA process was executed with a command line obfuscated by Unicode character substitutionAutorun.inf created in root C driveCommonly abused AutoIT script connects to an external domainEncoded information using Windows certificate management toolExecutable created to disk by lsass.exeExecution of the Hydra Linux password brute-force toolFodhelper.exe UAC bypassIndirect command execution using the Program Compatibility AssistantInteractive at.exe privilege escalation methodKerberos Traffic from Non-Standard ProcessLSASS dump file written to diskMicrosoft Office Process Spawning a Suspicious One-LinerModification of NTLM restrictions in the RegistryPhantom DLL LoadingPossible Persistence via group policy Registry keysPossible RDP session hijacking using tscon.exePossible code downloading from a remote host by Regsvr32Possible collection of screen captures with Windows Problem Steps RecorderPossible malicious .NET compilation started by a commonly abused processPowerShell runs suspicious base64-encoded commandsPowerShell suspicious flagsProcdump executed from an atypical directoryRemote WMI process executionRundll32.exe running with no command-line argumentsRundll32.exe spawns conhost.exeSuspicious .NET process loads an MSBuild DLLSuspicious PowerSploit's recon module (PowerView) net function was executedSuspicious PowerSploit's recon module (PowerView) used to search for exposed hostsSuspicious certutil command lineUncommon DLL-sideloading from a logical CD-ROM (ISO) deviceUncommon SetWindowsHookEx API invocation of a possible keyloggerUnsigned process injecting into a Windows system binary with no command lineUnusual process access to ld.so.preload fileWindows LOLBIN executable connected to a rare external hostImproved logic of 101 Low Analytics BIOCsA process queried the ADFS database decryption key via LDAPA remote service was created via RPC over SMBA suspicious direct syscall was executedA suspicious process enrolled for a certificateAn uncommon service was startedAn unpopular process accessed the microphone on the hostAttempt to execute a command on a remote host using PsExec.exeCached credentials discovery with cmdkeyChange of sudo caching configurationCompressing data using pythonConhost.exe spawned a suspicious cmd processCopy a user's GnuPG directory with rsyncDownload a script using the python requests moduleElevation to SYSTEM via servicesExecutable or Script file written by a web server processExecution of an uncommon process at an early startup stage by Windows system binaryExecution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binaryExecution of dllhost.exe with an empty command lineExecution of renamed lolbinExtracting credentials from Unix filesGlobally uncommon root domain from a signed processGlobally uncommon root-domain port combination from a signed processImage file execution options (IFEO) registry key setInstallation of a new System-V serviceKeylogging using system commandsKnown service display name with uncommon image-pathKnown service name with an uncommon image-pathLOLBIN process executed with a high integrity levelLinux system firewall was modifiedMasquerading as the Linux crond processMicrosoft Office adds a value to autostart Registry keyMicrosoft Office injects code into a processMicrosoft Office process spawns a commonly abused processNTDS.dit file written by an uncommon executableNew addition to Windows Defender exclusion listOffice process accessed an unusual .LNK filePossible DLL Hijack into a Microsoft processPossible DLL Search Order HijackingPossible Microsoft process masqueradingPossible network sniffing attempt via tcpdump or tsharkPossible webshell file written by a web server processPotential SCCM credential harvesting using WMI detectedRDP connections enabled remotely via RegistryRare process created an SSH session to an uncommon cloud resourceRare process created an SSH session to an uncommon external hostRare process executed by an AppleScriptRare process with VNC server capabilities startedRare scheduled task createdRare service DLL was added to the registryReading bash command history fileRecurring rare domain access from an unsigned processRemote DCOM command executionRemote command execution via wmic.exeRemote service start from an uncommon sourceRundll32.exe executes a rare unsigned moduleSUID/GUID permission discoveryScheduled Task hidden by registry modificationScreensaver process executed from Users or temporary folderScripting engine connected to a rare external hostSensitive browser credential files accessed by a rare non browser processSetuid and Setgid file bit manipulationStored credentials exported using credwiz.exeSuspicious Certutil AD CS contactSuspicious DotNet log file createdSuspicious Print System Remote Protocol usage by a processSuspicious Udev driver rule execution manipulationSuspicious container orchestration jobSuspicious data encryptionSuspicious disablement of the Windows FirewallSuspicious module load using direct syscallSuspicious process accessed certificate filesSuspicious process modified RC script fileSuspicious sshpass command executionSuspicious systemd timer activitySvchost.exe loads a rare unsigned moduleThe Linux system firewall was disabledUncommon AT task-job creation by userUncommon NtWriteVirtualMemoryRemote API invocation with a PE header bufferUncommon PowerShell commands used to create or alter scheduled task parametersUncommon access to Microsoft Teams credential filesUncommon creation or access operation of sensitive shadow copyUncommon execution of ODBCConfUncommon local scheduled task creation via schtasks.exeUncommon msiexec execution of an arbitrary file from a remote locationUncommon remote monitoring and management toolUncommon reverse SSH tunnel to external domain/ipUnsigned process creates a scheduled task via file accessUnusual AWS credentials creationUnusual AWS user added to groupUnusual Azure AD sync module loadUnusual CIM repository file accessUnusual compressed file password protectionUnusual process accessed FTP Client credentialsUnusual process accessed a crypto wallet's filesUnusual process accessed a messaging app's filesUnusual process accessed a web browser history fileUsage of homograph characters detected in an email's from headerWindows Event Log was cleared using wevtutil.exeWindows event logs were cleared with PowerShellWmiPrvSe.exe Rare Child Command LineWsmprovhost.exe Rare Child ProcessImproved logic of 5 Low Analytics AlertsFailed ConnectionsMultiple Rare LOLBIN Process Executions by UserMultiple discovery commandsMultiple discovery commands on a Windows host by the same processOutlook files accessed by an unsigned processImproved logic of 90 Informational Analytics BIOCsA LOLBIN was copied to a different locationA browser extension was installed or loaded in an uncommon wayA cloud identity invoked IAM related persistence operationsA compressed file was exfiltrated over SSHA non-browser process accessed a website UIA process connected to a rare cloud resourceA process connected to a rare external hostA process connected to rare external hostA process modified an SSH authorized_keys fileA service was disabledAccess to Kubernetes configuration fileAdding execution privilegesAn uncommon file added to startup-related Registry keysAn uncommon file was created in the startup folderAppleScript executed a shell scriptAppleScript process executed with a rare command lineBrowser bookmark files accessed by a rare non-browser processCloud Unusual Instance Metadata Service (IMDS) accessCommand execution via wmiexecCommonly abused AutoIT script drops an executable file to diskCreation or modification of the default command executed when opening an applicationDiscovery of host users via WMICExecution of an uncommon process at an early startup stageExecution of an uncommon process with a local/domain user SID at an early startup stageGlobally uncommon IP address connection from a signed processGlobally uncommon high entropy process was executedGlobally uncommon image load from a signed processGlobally uncommon injection from a signed processGlobally uncommon process execution from a signed processIndicator blockingInjection into rundll32.exeLOLBAS executable injects into another processLOLBIN created a PSScriptPolicyTest PowerShell script fileLinux network share discoveryLocal account discoveryModification of PAMMsiexec execution of an executable from an uncommon remote locationPermission Groups discovery commandsPossible DLL Side-LoadingPossible Email collection using Outlook RPCPossible binary padding using ddPossible data obfuscationPsExec was executed with a suspicious command linePython HTTP server startedRare LOLBIN Process Execution by UserRare Unix process divided files by sizeRare connection to external IP address or host by an application using RMI-IIOP or LDAP protocolRare process accessed a Keychain fileRemote PsExec-like command executionRun downloaded script using pipeService execution via sc.exeSigned process performed an unpopular DLL injectionSigned process performed an unpopular injectionSpace after filenameSuspicious AMSI decode attemptSuspicious Unicode character detected in emailSuspicious access to shadow fileSuspicious active setup registeredSuspicious container runtime connection from within a Kubernetes PodSuspicious curl user agentSuspicious process executed with a high integrity levelSuspicious process execution from tmp folderSuspicious proxy environment variable settingSuspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdletTampering with Internet Explorer Protected Mode configurationTampering with the Windows User Account Controls (UAC) configurationUncommon DotNet module load relationshipUncommon GetClipboardData API function invocation of a possible information stealerUncommon cloud CLI tool usageUncommon communication to an instant messaging serverUncommon driver loadedUncommon kernel module loadUncommon macOS shell command executionUncommon net group or localgroup executionUncommon network tunnel creationUncommon remote shell command executionUncommon service stop operationUncommon shell command executionUnpopular rsync process executionUnusual ADConnect database file accessUnusual DB process spawning a shellUnusual Kubernetes service account file readUnusual access to the AD Sync credential filesUnusual access to the Windows Internal Database on an ADFS serverUnusual process accessed a macOS notes DB fileUnusual process accessed web browser cookiesUnusual process accessed web browser credentialsUnusual use of a 'SysInternals' toolVM Detection attempt on LinuxWeb server CGO executed an uncommon processImproved logic of 7 Informational Analytics AlertsMassive file activity abnormal to processMultiple discovery commands on a Linux host by the same processMultiple discovery-like commandsPort ScanPossible data exfiltration over a USB storage deviceSuspicious access to cloud credential filesSuspicious container reconnaissance activity in a Kubernetes podChanged metadata of 3 Low Analytics BIOCsEmail was received from an unknown sender using a disposable domainExternal email display name impersonation of internal personnelUnusual hostname for the sending mail server in the email headersChanged metadata of a Low Analytics AlertRisk indicators detected in emailChanged metadata of 19 Informational Analytics BIOCsEmail Punycode characters in URL(s)Email attachment with a potentially malicious file extensionEmail attachment with multiple extensionsEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail suspicious Moniker link detectedEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedRarely seen URL(s) within a well-known domain detected in your organization's emailUnpopular URL domain(s) in your organization detected in emailUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUsage of homograph characters detected in an emailX-Forefront-Antispam-Report has flagged this email as a potential threatChanged metadata of an Informational Analytics AlertSuspicious theme and sentiment in email