Threat Intelligence Library

Threat Intelligence Library  

Actionable security intelligence from vulnerability records, advisories, ATT&CK, exploitability data, and vendor notices.

5 hunt leads from recent CISA malware and ransomware advisories. Create exactly five operational cards, each centered on one actionable hunt lead from BRICKSTORM, Medusa, Akira, Androxgh0st, and the CISA ransomware guide. Keep each card focused on what to look for, such as IOCs, detection signatures, vulnerable services, initial access patterns, or precursor activity.

Hunt DMZ web shells that precede RDP lateral movement to domain controllers and VMware vCenter. Flag PsExec activity that creates an inbound RDP rule on port 3389, especially `openrdp.bat`. Watch for VPN access without MFA, especially tied to CVE-2024-40766 or stolen VPN credentials. Alert on POSTs ...

View

How did LAUNDRY BEAR turn Zimbra webmail into a credential and mailbox collection path?. Tell the campaign as an operator-focused sequence from CVE-2025-66376 exploitation through Application Passcodes, IMAP enabling, SearchGalRequest activity, and exfiltration over DNS and HTTPS. End with a defender checklist covering patches, suspicious domains, localStorage artifacts, and revocation of Application Passcodes and 2FA scratch keys.

How did a single Zimbra phishing email turn into mailbox theft? CISA says LAUNDRY BEAR used CVE-2025-66376 so that just viewing the message could execute JavaScript in the webmail client and start mail theft[[cite:1]][[cite:2]]. The initial payload was hidden in an SVG onload field, wrapped in Base6...

View

Can you spot the identity and cloud intrusion pattern?. Frame the quiz around analyst decisions: identify whether a behavior maps to help desk social engineering, cloud valid account access, session token abuse, public facing exploitation, or cloud infrastructure discovery. Use Scattered Spider, CISA cloud hardening guidance, the GeoServer incident response report, and MITRE ATTACK cloud techniques as the answer base.

Q1. Which pattern is best described as vishing, spearphishing, or impersonation aimed at help desk staff to reset passwords or transfer MFA tokens? - Help desk social engineering - Cloud valid account access - Session token abuse - Cloud infrastructure discovery Answer: Help desk social engineering[...

View

From public facing exploit to cloud and identity cleanup. Break the incident response lesson into a sequence from public facing GeoServer exploitation of CVE-2024-36401 through web shells, cron jobs, valid accounts, brute force, PowerShell, BITS jobs, and Stowaway. End with practical response steps: prompt patching, centralized logging, incident response practice, conditional access, MFA, token revocation, and control validation.

How does a public GeoServer bug turn into full intrusion? CISA says CVE-2024-36401 was exploited on public-facing GeoServer systems, then the campaign moved through web shells, cron jobs, valid accounts, brute force, PowerShell, BITS jobs, and Stowaway.[[cite:1]] The sequence mattered: attackers use...

View

What should defenders do about Iranian-affiliated PLC targeting?. Build a multi-section brief covering the threat, affected internet-exposed PLC scope, observed access paths, ports 44818, 2222, 102, 502, and 22, ATT&CK techniques, and defender actions. Include a mitigation priority table that separates immediate exposure reduction, log review, project file validation, Rockwell AOI checks, and vendor hardening guidance.

Iranian-Affiliated Targeting of Internet-Exposed PLCs CISA warns that Iranian-affiliated cyber actors have been exploiting internet-connected PLCs across U.S. critical infrastructure, with activity observed in Government Services and Facilities, Water and Wastewater Systems, and Energy. The advisory...

View

Test your knowledge of ATT&CK mapping for detection work. Frame the quiz around practical mapping decisions, including how ATT&CK normalizes adversary behavior and how defenders use mapped techniques to organize detections. Keep the questions grounded in recurring behaviors from the evidence, such as privilege escalation, persistence, active scanning, account manipulation, and exfiltration-related activity.

Q1. How do the attached sources describe ATT&CK at a high level? - A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations - A catalog of only malware hashes and file signatures - A framework that lists only vulnerability severity scores - A patch-ma...

View
  • 1(current)