Detection Pipeline
Real-time tracking of AI analysis phases
Live Feed Active
๐ฅ New Ingest
0
๐ Enriching
0
๐ง AI Triaging
6
service.NIX-Host_Based_Firewall_Disabled
๐ฅ๏ธ fusionserver
00326-NIX-Host_Based_Firewall_Disabled
service.NIX-Host_Based_Firewall_Disabled
๐ฅ๏ธ fusionserver
00326-NIX-Host_Based_Firewall_Disabled
service.NIX-Host_Based_Firewall_Disabled
๐ฅ๏ธ fusionserver
00326-NIX-Host_Based_Firewall_Disabled
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
โ
Triaged & Cased
176
service.NIX-Host_Based_Firewall_Disabled
๐ฅ๏ธ fusionserver
00326-NIX-Host_Based_Firewall_Disabled
service.NIX-Host_Based_Firewall_Disabled
๐ฅ๏ธ fusionserver
00326-NIX-Host_Based_Firewall_Disabled
service.NIX-Host_Based_Firewall_Disabled
๐ฅ๏ธ fusionserver
00326-NIX-Host_Based_Firewall_Disabled
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.YARA Detection in Memory
๐ฅ๏ธ desktop-atsepsk
YARA Detection in Memory - Windows_Trojan_Generic_9997489c
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ win-91lccq536b4
New Code Atypical Path
service.windows_process_creation/proc_creation_win_cmd_rmdir_execution
๐ฅ๏ธ win-91lccq536b4
Directory Removal Via Rmdir
service.windows_process_creation/proc_creation_win_cmd_rmdir_execution
๐ฅ๏ธ win-91lccq536b4
Directory Removal Via Rmdir
service.windows_process_creation/proc_creation_win_cmd_dir_execution
๐ฅ๏ธ win-91lccq536b4
File And SubFolder Enumeration Via Dir Command
service.windows_process_creation/proc_creation_win_cmd_rmdir_execution
๐ฅ๏ธ win-91lccq536b4
Directory Removal Via Rmdir
service.windows_process_creation/proc_creation_win_cmd_dir_execution
๐ฅ๏ธ win-91lccq536b4
File And SubFolder Enumeration Via Dir Command
service.windows_process_creation/proc_creation_win_cmd_dir_execution
๐ฅ๏ธ win-91lccq536b4
File And SubFolder Enumeration Via Dir Command
service.windows_process_creation/proc_creation_win_cmd_dir_execution
๐ฅ๏ธ win-91lccq536b4
File And SubFolder Enumeration Via Dir Command
service.windows_process_creation/proc_creation_win_cmd_rmdir_execution
๐ฅ๏ธ win-91lccq536b4
Directory Removal Via Rmdir
service.windows_process_creation/proc_creation_win_svchost_masqueraded_execution
๐ฅ๏ธ win-91lccq536b4
Suspicious Process Masquerading As SvcHost.EXE
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.New Process From Atypical Path
๐ฅ๏ธ df-labsdc01.dflabs.local
New Process from Atypical Path
managed.Malicious PowerShell Commandlets - ProcessCreation
๐ฅ๏ธ df-labsdc01.dflabs.local
Malicious PowerShell Commandlets - ProcessCreation
service.windows_process_creation/proc_creation_win_whoami_execution_from_high_priv_process
๐ฅ๏ธ df-labsdc01.dflabs.local
Whoami.EXE Execution From Privileged Process
service.windows_process_creation/proc_creation_win_susp_local_system_owner_account_discovery
๐ฅ๏ธ df-labsdc01.dflabs.local
Local Accounts Discovery
managed.Malicious PowerShell Commandlets - ProcessCreation
๐ฅ๏ธ df-labsdc01.dflabs.local
Malicious PowerShell Commandlets - ProcessCreation
managed.Malicious PowerShell Commandlets - ProcessCreation
๐ฅ๏ธ df-labsdc01.dflabs.local
Malicious PowerShell Commandlets - ProcessCreation
service.windows_process_creation/proc_creation_win_powershell_malicious_cmdlets
๐ฅ๏ธ df-labsdc01.dflabs.local
Malicious PowerShell Commandlets - ProcessCreation
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 9164
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 3600
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 8396
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 8460
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.windows_process_creation/proc_creation_win_hostname_execution
๐ฅ๏ธ df-labsdc01.dflabs.local
Suspicious Execution of Hostname
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 644
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 2440
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 7784
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Process Killed PID 7640
general.RealTime Monitoring Tampering
๐ฅ๏ธ df-labsdc01.dflabs.local
Realtime Monitoring Tampering
service.WIN-Set-MpPreference_Disabled
๐ฅ๏ธ df-labsdc01.dflabs.local
00088-WIN-Set-MpPreference_Disabled
service.WIN-PS_Invoke_Expression_Usage
๐ฅ๏ธ df-labsdc01.dflabs.local
00023-WIN-PS_Invoke_Expression_Usage
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ df-labsdc01.dflabs.local
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_csc_susp_dynamic_compilation
๐ฅ๏ธ df-labsdc01.dflabs.local
Dynamic .NET Compilation Via Csc.EXE
service.windows_process_creation/proc_creation_win_powershell_download_iex
๐ฅ๏ธ df-labsdc01.dflabs.local
PowerShell Download and Execution Cradles
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ df-labsdc01.dflabs.local
Non Interactive PowerShell Process Spawned
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
service.windows_process_creation/proc_creation_win_netsh_fw_add_rule
๐ฅ๏ธ desktop-atsepsk
New Firewall Rule Added Via Netsh.EXE
service.windows_process_creation/proc_creation_win_msiexec_embedding
๐ฅ๏ธ desktop-atsepsk
Suspicious MsiExec Embedding Parent
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
service.windows_process_creation/proc_creation_win_susp_web_request_cmd_and_cmdlets
๐ฅ๏ธ df-labsdc01.dflabs.local
Usage Of Web Request Commands And Cmdlets
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
service.windows_process_creation/proc_creation_win_svchost_masqueraded_execution
๐ฅ๏ธ df-labsdc01.dflabs.local
Suspicious Process Masquerading As SvcHost.EXE
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
service.windows_process_creation/proc_creation_win_msiexec_execute_dll
๐ฅ๏ธ desktop-atsepsk
Suspicious Msiexec Execute Arbitrary DLL
general.New Process from Atypical Path
๐ฅ๏ธ desktop-atsepsk
New Process from Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
service.windows_process_creation/proc_creation_win_powershell_non_interactive_execution
๐ฅ๏ธ desktop-atsepsk
Non Interactive PowerShell Process Spawned
service.windows_process_creation/proc_creation_win_powershell_set_policies_to_unsecure_level
๐ฅ๏ธ desktop-atsepsk
Change PowerShell Policies to an Insecure Level
general.YARA Detection on Disk
๐ฅ๏ธ desktop-atsepsk
YARA Detection on Disk - Macos_Infostealer_Wallets_8e469ea0
general.YARA Detection in Memory
๐ฅ๏ธ desktop-atsepsk
YARA Detection in Memory - Windows_Trojan_Generic_9997489c
service.NIX-Touch_Timestomping
๐ฅ๏ธ fusionserver
00087-NIX-Touch_Timestomping
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
general.YARA Detection in Memory
๐ฅ๏ธ desktop-atsepsk
YARA Detection in Memory - Windows_Trojan_Generic_9997489c
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
service.NIX-Touch_Timestomping
๐ฅ๏ธ fusionserver
00087-NIX-Touch_Timestomping
general.New Process From Atypical Path
๐ฅ๏ธ df-labsdc01.dflabs.local
New Process from Atypical Path
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
service.windows_process_creation/proc_creation_win_susp_web_request_cmd_and_cmdlets
๐ฅ๏ธ df-labsdc01.dflabs.local
Usage Of Web Request Commands And Cmdlets
service.windows_process_creation/proc_creation_win_svchost_masqueraded_execution
๐ฅ๏ธ df-labsdc01.dflabs.local
Suspicious Process Masquerading As SvcHost.EXE
general.YARA Detection in Memory
๐ฅ๏ธ desktop-atsepsk
YARA Detection in Memory - Windows_Trojan_Generic_9997489c
general.YARA Detection in Memory
๐ฅ๏ธ desktop-atsepsk
YARA Detection in Memory - Windows_Trojan_Generic_9997489c
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
service.windows_process_creation/proc_creation_win_expand_cabinet_files
๐ฅ๏ธ desktop-3nfb237
Potentially Suspicious Cabinet File Expansion
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
general.Sensitive Process Accessed
๐ฅ๏ธ df-labsdc01.dflabs.local
Sensitive Process Accessed
service.windows_process_creation/proc_creation_win_susp_web_request_cmd_and_cmdlets
๐ฅ๏ธ df-labsdc01.dflabs.local
Usage Of Web Request Commands And Cmdlets
service.windows_process_creation/proc_creation_win_svchost_masqueraded_execution
๐ฅ๏ธ df-labsdc01.dflabs.local
Suspicious Process Masquerading As SvcHost.EXE
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
general.YARA Detection on Disk
๐ฅ๏ธ desktop-atsepsk
YARA Detection on Disk - Macos_Infostealer_Wallets_8e469ea0
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
general.YARA Detection on Disk
๐ฅ๏ธ desktop-atsepsk
YARA Detection on Disk - Macos_Infostealer_Wallets_8e469ea0
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path
general.Sensitive Process Accessed
๐ฅ๏ธ desktop-3nfb237
Sensitive Process Accessed
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-atsepsk
New Code Atypical Path
general.NEW FILE WRITE BYTES SAMPLE GRAB
๐ฅ๏ธ desktop-3nfb237
New Code Atypical Path