
Aaron Mog
@amog1 follower76 downloads34 copies2 likes2,030 views
5 detections
Filters
Last updated
All Time
Detection languages
3
1
1
Categories
2
2
2
1
1
Platforms
2
2
1
Products / Services
1
1
1
1
1
MITRE Techniques
3
1
1
1
1
CVEs
1
1
1
Detects the execution of commands used to disable the algif_aead module to mitigate CVE-2026-31431 (Copy Fail). This rule monitors for dynamic unloading of the module using 'rmmod' or persistent configuration changes via 'modprobe.d' to disable the module. While this is a mitigation step, monitoring for it ensures compliance and tracks remediation efforts.
Detects the use of a PowerShell download cradle, a technique observed in the PhantomCaptcha campaign to download and execute a next-stage payload. This pattern often involves stealthy flags to evade detection.
Detects the crash of lsass.exe caused by WLDAP32.dll, which is a strong indicator of exploitation of the LDAPNightmare vulnerability (CVE-2024-49113). This exploit causes a denial of service on unpatched Windows Servers.
Detects potential exploitation of CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools and Aria Operations.
An attacker can stage a malicious binary in a world-writable directory (e.g., /tmp) which is then executed with root privileges by the VMware service discovery mechanism when it attempts to determine the binary's version.
An attacker can stage a malicious binary in a world-writable directory (e.g., /tmp) which is then executed with root privileges by the VMware service discovery mechanism when it attempts to determine the binary's version.
MFA Fatigue Attack
Sigma
Detects a high number of failed or denied Multi-Factor Authentication (MFA) attempts followed by a success for the same user account within a short time frame. This pattern, known as MFA fatigue or push bombing, is a technique actively used by threat actors like Scattered Spider to overwhelm a user with push notifications until they approve one, granting the attacker access.
