Defensive Intelligence PlatformOutsmart Threats
Outsmart Threats
Before They Strike.
Analyze, detect, and respondbefore they become breaches.
Streamline Your Defense with an Intelligence Edge.
Alert Management
23 threats found
| Timestamp | Mitre Technique | Description | Severity |
|---|---|---|---|
| 14:20:05 | T1530 | S3 Data Exfiltration · Anomalous GetObject volume from unknown IP · bucketclient-financial-records | Critical |
| 14:18:22 | T1562.001 | CloudTrail Logging Disabled · StopLogging event detected from root account · regionus-east-1 | Critical |
| 14:15:10 | T1078.004 | Unusual Access Pattern · Successful login from geographically improbable location · userdev-ops-svc | High |
| 13:58:19 | T1530 | S3 Bucket Public Discovery · Enumeration attempt detected via ListBuckets API · src94.232.x.x | Medium |
| 13:42:07 | T1098 | IAM Privilege Escalation · AttachUserPolicy granted AdministratorAccess to · principalsvc-build-bot | Critical |
| 13:31:48 | T1110.003 | Password Spray Detected · 412 failed logins across accounts38 from a single source · src185.143.x.x | High |
| 13:14:55 | T1059.001 | Suspicious PowerShell Execution · Base64 encoded command launched by · processwinword.exe · host=corp-fin-ws-04 | High |
| 12:58:32 | T1071.001 | C2 Beacon Pattern · Periodic HTTPS callouts to domaincdn-static-asset.xyz every 58s | Critical |
| 12:41:19 | T1027 | Obfuscated Payload Uploaded · High-entropy archive dropped to path/tmp/.cache/.sys | Medium |
| 12:27:04 | T1486 | Mass File Modification · 2,184 files renamed with extension ext.locked within 90s | Critical |
| 12:09:51 | T1190 | Public-Facing Service Exploit · CVE-2024-1086 exploitation attempt on serviceedge-gateway-03 | High |
| 11:54:38 | T1003.001 | LSASS Memory Dump · comsvcs.dll MiniDump invoked on hostfin-dc-01 | Critical |
| 11:37:12 | T1219 | Remote Access Tool Launched · AnyDesk.exe spawned from user temp directory · userjdoe | High |
| 11:21:48 | T1018 | Internal Network Discovery · nltest enumerated 47 domain controllers in 8s | Medium |
| 10:58:22 | T1547.001 | Registry Run Key Modified · Persistence written to keyHKCU\...\Run\UpdateSvc | High |
| 10:42:09 | T1567.002 | Exfil via Cloud Storage · 1.2 GB pushed to destinationtransfer.sh over 6 min | Critical |
| 10:26:51 | T1136.001 | Local Account Created · net user added svc-helper to local admins on hostcorp-ws-22 | High |
| 10:11:34 | T1083 | File and Directory Discovery · Recursive listing of pathC:\Users\Public | Medium |
| 09:54:17 | T1055 | Process Injection Detected · rundll32.exe injected into explorer.exe | Critical |
| 09:38:02 | T1574.002 | DLL Side-Loading · Unsigned version.dll loaded next to trusted binary | High |
| 09:21:46 | T1496 | Cryptominer Activity · Sustained 96% CPU on hostrender-node-07 beaconing to known mining pool | Medium |
Welcome Back
Sign In to your Aletheia account
Protected by Aletheia Security. By signing in, you agree to our
Terms of Service
Don't have an account? Sign up