◇ SIGN IN

Alerts

89 active · 8 critical

Auto-generated from what's already tagged elsewhere in the graph — correlatable Radar items, P1 KEV entries, tactical-tier reports, open critical/high hunts, plus impersonation infra (a lookalike on live C2 or operator hosting) and fresh MENA malware IOCs. Nothing here is a new judgment call; it's the existing tagging discipline surfaced in one place instead of requiring a manual scan across pages. Also available as a machine-readable feed → for detection pipelines.

HUNT

Hunt CVE8451-HUNT-001

3 hypotheses: NetScaler SAML sequential scanning, probe-then-exploit timing, stolen NSC_TASS session token reuse. See 04-hunts.json for full detail.
high
HUNT

Hunt CVE8451-HUNT-002

3 hypotheses: NetScaler SAML sequential scanning, probe-then-exploit timing, stolen NSC_TASS session token reuse. See 04-hunts.json for full detail.
high
HUNT

Hunt CVE8451-HUNT-003

3 hypotheses: NetScaler SAML sequential scanning, probe-then-exploit timing, stolen NSC_TASS session token reuse. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-001

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-002

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-003

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-004

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-005

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-006

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-007

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-008

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt FB-HUNT-009

9 hypotheses: FortiGate mass scanning, lateral movement via harvested credentials, AD credential spray (spray_da.py), spider.py AD enumeration, hashpanel.log artifact, ad_full_audit.py execution, smb_test.py probing, ransomware pre-staging (INC/Lynx), IAB credential handoff. See 04-hunts.json for full detail.
high
HUNT

Hunt HC-SONICWALL-001

Post-exploitation credential extraction from SMA1000 filesystem — atime forensics on admin credential/VPN session/TOTP seed paths; requires pre-image forensic acquisition
high
HUNT

Hunt HC-SONICWALL-002

VPN session token replay from unusual IPs — impossible-travel and anomalous ASN/geo detection on VPN auth logs for scoped SMA1000 account set
high
HUNT

Hunt HC-SONICWALL-003

TOTP MFA bypass via seed extraction — hunt for TOTP successes at anomalous velocity/hours/geo for SMA1000 accounts; clean result is inconclusive (seeds may be extracted but unused)
high
HUNT

Hunt HC-SONICWALL-004

Retroactive pre-disclosure compromise hunt (June 14, 2026+) — /wsproxy HTTP 101 anomalies → appliance reboot correlation → conf.json mtime → subsequent AD anomalies; log retention may be limiting
high
HUNT

Hunt HC-SONICWALL-005

Appliance fleet sweep for conf.json persistence backdoor — definitive indicator: /__api__/login or /__api__/logout routes in /var/lib/unit/conf.json; positive = confirmed compromise, re-image required
high
HUNT

Hunt HC-ACRSTEALER-001

ClickFix RunMRU artifact sweep — RunMRU registry key retains ClickFix-triggered cmd.exe commands; fleet-queryable, survives execution
high
HUNT

Hunt HC-ACRSTEALER-002

Process lineage: explorer.exe/conhost.exe spawning rundll32 with UNC path or mshta with remote URI — Sysmon EID 1/4688
high
HUNT

Hunt HC-ACRSTEALER-003

Obfuscated PowerShell with ServicePointManager CertificatePolicy bypass and ConsoleHost_history deletion — EID 4104 Script Block Logging
high
HUNT

Hunt HC-ACRSTEALER-007

LogiOptionsPlus masquerade — AppData\Local\Temp\LogiOptionsPlus\ directory + Autoupdate* scheduled task invoking pythonw.exe
high
HUNT

Hunt HC-ACRSTEALER-010

Browser credential database access by scripting engine — SRUM for retrospective coverage; SRUM 30-60 day retention boundary urgent for April-June 2026 campaign window
high
HUNT

Hunt HC-UAT11795-001

Trojanized installer behavioral hunt — zoom_setup.exe/webex_install.exe/mobaxterm.exe etc. as ParentImage spawning python.exe or dropping .bat/.ps1 to %TEMP%; no file hashes available in IOC set
high
HUNT

Hunt HC-UAT11795-002

Starland RAT HWID URL path — HTTP POST from python.exe with spoofed Chrome UA where URL path ends in 8-char hex segment (volume serial format); WLDR PowerShell beacon interval analysis
high
HUNT

Hunt HC-UAT11795-003

Shellcode loader AMSI/ETW patching — Sysmon EID 8 to amsi.dll/ntdll.dll as memory acquisition trigger; YARA rules UAT11795_Shellcode_HashAPI_Resolver + Starland_RAT_XOR_Key_helo1_InMemory in 04-hunts.json
high
HUNT

Hunt HC-ASYNCAPI-002

pwn-request misconfiguration sweep — scan all org GitHub Actions workflows for pull_request_target + untrusted ref checkout anti-pattern; proactive, not reactive
high
HUNT

Hunt HC-ASYNCAPI-003

pull_request_target workflow abuse — same root cause as HC-002; scan for manual-netlify-preview.yml pattern across repos
high
HUNT

Hunt HC-IRAN-001

AI-accelerated ICS recon — correlate mass EtherNet/IP/Modbus scanning against Rockwell-exposed assets; sectoral targeting pattern (water/wastewater/energy) in Gulf region
high
HUNT

Hunt HC-IRAN-002

GhostFetch anti-analysis evasion — mouse-movement/screen-res/debugger/VM checks before payload execution; requires sandbox detonation or EDR behavioral analysis
high
HUNT

Hunt HC-IRAN-003

Fileless GhostBackDoor/HTTP_VIP/CHAR delivery — in-memory execution via GhostFetch; requires EDR with kernel-level visibility or memory forensics on candidate endpoints
high
HUNT

Hunt CA-HUNT-003

Engineering workstation compromise — off-hours logons, unexpected remote-access tool installation, engineering software launched by non-engineer accounts, sequential multi-PLC connections (<15 min)
high
HUNT

Hunt CA-HUNT-004

IOCONTROL artifact sweep on Linux IoT/OT devices — process name 'iocontrol', S93InitSystemd.sh boot script, UPX-packed ELF in non-standard paths, outbound TCP 8883, Dropbear SSH; any positive = confirmed compromise
high
HUNT

Hunt CI-HUNT-002

node.exe spawned via npm run from transient directories (Downloads/Desktop/Temp) — BeaverTail triggers on npm run dev/npm start; correlate working directory creation timestamp
high
HUNT

Hunt CI-HUNT-003

Trojanized npm repo artifacts — serverValidation.js, country-flag SVG directories (>20 SVG files), ZIP archives named next-ecommerce/shopping-platform/ecommerce-platform
high
HUNT

Hunt CI-HUNT-004

node.exe reading >10 SVG files within 5s window followed by outbound network connection — Base64/eval sequence from SVG HTML comment payloads; requires EDR file-read telemetry
high
HUNT

Hunt CI-HUNT-005

SVG files in assets/public/static directories >5KB — country flag SVGs are typically <2KB; YARA rule for HTML comment blocks with >200-char Base64 content
high
HUNT

Hunt CI-HUNT-006

node.exe or npm-cache reading browser credential stores (Chrome Login Data, Firefox profiles, crypto wallets) — npm-cache masquerade is near-direct fingerprint
high
HUNT

Hunt CI-HUNT-010

C2 beaconing to rightwidth.dev subdomains (controller/upload/ldb/file) from node.exe/npm-cache — WebSocket/Socket.IO; any hit = high-confidence compromise, escalate to IR immediately
high
HUNT

Hunt MS-HUNT-001

ClickUp CDN / pixeldrain phishing link delivery — hunt EmailUrlInfo for non-blocked emails with t[0-9]+.p.clickup-attachments.com or pixeldrain.com URLs pointing to executable extensions
high
HUNT

Hunt MS-HUNT-002

AiTM session token reuse — interactive auth IP vs. non-interactive token use IP differ within 30 min on same CorrelationId in SigninLogs; AiTM inferred from Tycoon2FA aftermath
high
HUNT

Hunt MS-HUNT-003

MFA bypass artifacts — successful MFA via SMS/phone call with Entra risk signals, or MFA required in token but authMethod field absent (ghost satisfaction); correlate with MS-HUNT-002
high
HUNT

Hunt CI-HUNT-009

Compound: npm startup → credential reads AND file enumeration AND outbound network within 30s from same PID — three-category correlation rules out legitimate dev workflows
high
HUNT

Hunt MS-HUNT-004

BEC lookalike domain detection — EmailEvents inbound to financial role mailboxes where DMARC/SPF fails or sender matches known BEC IOC domains: 9i6pokerdepot.com, ecajovna.sk, ilyff.com, j-gmails.com, x2mails.com, compliance-protectionoutlook.de, businesshellosign.de
high
HUNT

Hunt MS-HUNT-005

External Teams tenants with generic infrastructure display names (support/helpdesk/IT/security/azure/365) contacting internal users — focus on 14:00-20:00 UTC concentration window
high
HUNT

Hunt MS-HUNT-006

Compromised internal accounts as BEC relay — anomalous outbound email volume, unique external recipient count, BEC financial keywords, off-hours activity
high
HUNT

Hunt MS-HUNT-007

ClickUp CDN / pixeldrain download → cmd.exe/PowerShell execution within 5 min — Financial_report.bat kill chain; known SHA-256 hashes in 04-hunts.json
high
HUNT

Hunt CP-HUNT-001

Vishing precursor to Salesforce OAuth approval — Teams external call to IT/finance/exec roles within 30 min preceding non-admin AppAuthorization event; IOC IPs 138.226.246.94 / 212.86.125.24 / 213.111.148.90 / 94.154.32.160 in SourceIp = confirmed ShinyHunters
high
HUNT

Hunt CP-HUNT-002

Vendor OAuth foothold (Salesloft/Gainsight/Klue) — bulk Salesforce API calls by these vendor connected apps deviating from 90-day baseline volume or running off-hours
high
HUNT

Hunt CP-HUNT-004

CylindricalCanine DigiCert-signed binary audit — MDE DeviceProcessEvents where Signer has 'DigiCert' and SignatureState in (Revoked/Invalid/Unknown); window 90 days back (April-June 2026)
high
HUNT

Hunt CP-HUNT-006

WAF/IDS CVE probe hits without downstream exploitation alert (detection gap) — SharePoint /_api/ and WordPress /wp-json/batch/v1 POST patterns; HTTP 200/201 on unauthenticated POST = possible silent exploit success
high
HUNT

Hunt CP-HUNT-007

ShinyHunters OAuth token geographic anomaly — Salesforce API calls from IPs outside user historical login set; IOC IPs are immediate escalation trigger regardless of volume
high
HUNT

Hunt CP-HUNT-008

Spirals ransomware precursor chain — w3wp.exe→cmd/PS spawn + WmiPrvSE.exe lateral exec + PSEXESVC install + destruction commands (vssadmin/bcdedit/wbadmin) in compressed window
high
HUNT

Hunt CP-HUNT-009

WMI persistence subscriptions (Filter/Consumer/Binding triplets) and off-hours mofcomp.exe — Sysmon EID 19/20/21 or WMI-Activity 5861; note WMI-Activity/Operational logging must be explicitly enabled
high
HUNT

Hunt MK-HUNT-001

LinkedIn social engineering recruitment phishing — extended pre-attack rapport building (weeks-to-months); no cold-phish pattern; identity-validation and insider threat controls
high
HUNT

Hunt MK-HUNT-002

ISO-delivered NightLedger implant staging — AppVShNotify.exe outside system paths after ISO mount from non-C drive
high
HUNT

Hunt MK-HUNT-003

Remote command execution via NightLedger C2 — process execution from AppVShNotify.exe context via DoH-resolved C2 channel
high
HUNT

Hunt MK-HUNT-007

BridgeHead SOCKS5 relay traffic pattern — long-duration TCP tunnel through AppVShNotify.exe or BridgeHead process to aecert.org infrastructure
high
HUNT

Hunt MK-HUNT-009

DoH tunneling to non-browser resolver endpoints — non-browser process HTTPS to cloudflare-dns.com/dns-query or dns.google/resolve; any non-browser DoH = anomaly
critical
HUNT

Hunt TS-HUNT-001

ISO-packaged software delivery lure — disk mount followed by execution of RegSchdTask.exe or GoProAlertService.exe from non-C drive
high
HUNT

Hunt CA-HUNT-001

Shodan/Censys OT reconnaissance of exposed engineering ports (44818, 102, 2404) — self-query org IP ranges and correlate with subsequent firewall connection attempts
high
HUNT

Hunt CA-HUNT-004

HMI view manipulation to mask setpoint changes — HMI display value divergence from PLC historian values
high
HUNT

Hunt CA-HUNT-005

Coordinated multi-utility disruption timing patterns — simultaneous EtherNet/IP connection events across multiple water/energy sites within a 30-minute window
critical
HUNT

Hunt CPW-HUNT-001

AI-generated phishing / LNK delivery infrastructure — LNK or HTA file downloads from corporate endpoints; any .lnk/.hta in Downloads/Temp/Desktop
high
HUNT

Hunt CPW-HUNT-004

Browser credential theft (Chromium) — BeaverTail/OmniStealer access to Chrome Login Data SQLite from node.exe or python.exe
high
HUNT

Hunt CPW-HUNT-005

Telegram tdata session theft — file read of %APPDATA%\Telegram Desktop\tdata\* by non-Telegram process
high
HUNT

Hunt CPW-HUNT-008

BeaverTail obfuscated JavaScript staging — node.exe executing heavily base64-encoded/eval-wrapped scripts from %TEMP%
high
HUNT

Hunt CPW-HUNT-009

OmniStealer Python stealer execution — python.exe reading browser credential DBs and SSH key files, exfiltrating to api.telegram.org
high
HUNT

Hunt CPW-HUNT-010

Cross-platform credential theft pattern — macOS/Linux python3 accessing browser credential stores (Keychain, .mozilla/firefox)
high
HUNT

Hunt CPW-HUNT-012

PolinRider npm package registry monitoring — any install of packages matching Check Point Research IOC list; integrate with Socket.dev/Snyk feed
critical
HUNT

Hunt CPW-HUNT-013

Blockchain dead-drop C2 resolution pattern — non-browser process HTTPS to tronscan.org, bscscan.com, aptoslabs.com, trongrid.io, infura.io
high
HUNT

Hunt TALOSQ2-HUNT-001

AitM proxy patterns — dual IP sign-in within 5 min for same UPN; Evilginx/Modlishka reverse proxy fingerprinting
critical
HUNT

Hunt TALOSQ2-HUNT-002

ARToken PhaaS OAuth app registrations in Entra ID — unusual app registrations with Mail.Read/Files.Read permissions; device-code flow enabled
high
HUNT

Hunt TALOSQ2-HUNT-003

Device-code phishing lures via email header analysis — emails containing 'deviceauth' or XXXX-XXXX device code pattern
high
HUNT

Hunt TALOSQ2-HUNT-004

Post-AitM M365 mass email access — MailItemsAccessed >500 items/session or from unusual IP/UA (requires E5/Purview Audit Premium)
high
HUNT

Hunt TALOSQ2-HUNT-006

Ransomware staging — network share enumeration; single host connecting to port 445 across >20 unique targets in 10 minutes
high
HUNT

Hunt TALOSQ2-HUNT-011

Warlock ransomware SharePoint exploitation artifacts — w3wp.exe spawning cmd.exe/powershell.exe; web shell drops to SharePoint LAYOUTS path
critical
HUNT

Hunt TALOSQ2-HUNT-012

Machine key reuse persistence on patched SharePoint — POST to _layouts/_vti_bin with anomalous ViewState and no preceding auth session
high
HUNT

Hunt TALOSQ2-HUNT-017

Mirage Kitten NightLedger C2 IOC correlation (cross-case) — any connection to aecert.org, realhealthshop.com, or tjconsultingservices.com; immediate isolation
critical
HUNT

Hunt TALOSQ2-HUNT-007

Volume Shadow Copy deletion (vssadmin/wmic/PowerShell) — automate host isolation response on any positive; near-zero FP
critical
HUNT

Hunt TALOSQ2-HUNT-008

Lateral movement via Pass-the-Hash post NTDS dump — privileged account NTLM LogonType 3 from non-primary workstations
high
HUNT

Hunt TALOSQ2-HUNT-009

BeaverTail JS staging via npm postinstall hook — node.exe spawned by npm/yarn with 'postinstall' then connecting to blockchain RPC endpoint
high
HUNT

Hunt TALOSQ2-HUNT-010

OmniStealer Python payload execution — python.exe reading browser credential DBs, SSH keys, and connecting to api.telegram.org or g.api.mega.co.nz
high
HUNT

Hunt TALOSQ2-HUNT-013

Check Point CVE-2026-16232 exploitation artifacts — SmartConsole API calls from non-admin subnet; token generation without preceding cert auth
critical
HUNT

Hunt TALOSQ2-HUNT-014

PureRAT blockchain dead-drop C2 — non-browser process connecting to infura.io/alchemyapi.io/trongrid.io/tronscan.org; especially from hollowed explorer.exe/svchost.exe
high
HUNT

Hunt TALOSQ2-HUNT-016

TeleShim ASUS/GoPro ISO staging (cross-case) — RegSchdTask.exe or GoProAlertService.exe executing from non-C drive after ISO mount
high
IMPERSONATION

ibeg.com on operator hosting

Lookalike of CIB Egypt on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.
high
IMPERSONATION

adnoc.click on operator hosting

Lookalike of ADNOC on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.
high
IMPERSONATION

raamco.com on operator hosting

Lookalike of Saudi Aramco on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.
high
IMPERSONATION

cibeg.online on operator hosting

Lookalike of CIB Egypt on non-parking hosting with a live SSH service — actively provisioned, not a parked domain.
high