Fake Claude Desktop App Distributed via Bing Ads Delivers SectopRAT
A Bing malvertising campaign is pushing a fake Claude desktop installer, hosted on a legitimate Claude.ai domain, that delivers SectopRAT malware to victims.
Detection engineering insights, threat hunting guides, and MITRE ATT&CK tutorials.
A Bing malvertising campaign is pushing a fake Claude desktop installer, hosted on a legitimate Claude.ai domain, that delivers SectopRAT malware to victims.
NSA, CISA, and partners reportedly attribute exploitation of a Zimbra webmail zero-day to a Russian espionage group that stole email, saved passwords, and 2FA recovery codes via a click-to-open payload.
CISA warns that Russian state-sponsored group Laundry Bear (Void Blizzard) is combining phishing with a patched Zimbra Collaboration vulnerability to steal email from targeted organizations.
CVE-2026-50522 is a CISA KEV-listed deserialization flaw (CWE-502) in Microsoft SharePoint enabling RCE via crafted serialized payloads, actively exploited in the wild. Our detection spans Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
CVE-2026-16232 is a KEV-listed authentication bypass in Check Point SmartConsole (CWE-287) that lets attackers access management sessions without valid credentials. We cover detection across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
CVE-2026-54052 is a critical (CVSS 9.9) authorization bypass in n8n-mcp <= 2.56.0 that lets attackers read other tenants' workflow backups, potentially exposing embedded credentials and secrets. A public PoC exists and no patch is currently available.
CVE-2026-0770 is a KEV-listed, actively exploited flaw in Langflow that lets attackers trigger execution of untrusted components. Our detection catches it via anomalous outbound connections, child process spawns, and untrusted calls to flow-execution endpoints.
CVE-2021-27137 is a KEV-listed stack-based buffer overflow in DD-WRT's web management interface enabling RCE or DoS. Our detection covers abnormal HTTP requests, httpd crashes, and post-exploitation IoT segment activity across seven SIEM platforms.
CVE-2026-60137 is a CISA KEV-listed SQL injection vulnerability in WordPress Core, actively exploited in the wild against wp-admin, wp-json, and xmlrpc.php. WordPress 7.0.2 patches the flaw; our detection ships across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
A critical (CVSS 9.9) flaw in Fission <= 1.23.0 lets attackers with Environment/Function access bypass SecurityContext hardening and deploy privileged pods, risking node or cluster compromise. PoC is public.
CVE-2026-44935 (CVSS 9.9) lets low-privileged users in Rancher Fleet exfiltrate Secrets/ConfigMaps from arbitrary namespaces via unvalidated Helm valuesFrom references. A public PoC exists; see our KQL, SPL, and other SIEM detections for exploitation attempts.
CVE-2026-52831 is a critical (CVSS 10.0) command injection flaw in Nuclio's cron trigger handling that allows unauthenticated RCE via unsanitized event headers/body. A public PoC exists; our detection covers seven SIEMs, watching for shell metacharacter injection and anomalous CronJob-spawned proces
CVE-2026-48939 is a KEV-listed unrestricted file upload flaw in Joomla's iCagenda component enabling web shell uploads and RCE; our detection covers the exploitation pattern across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
Web shells give attackers persistent, hands-on-keyboard access to compromised web servers. Learn to detect T1505.003 with practical KQL and SPL queries covering process lineage, webroot file writes, and IIS access-log anomalies.
CVE-2026-50564 (CVSS 9.9) lets Fission Environment CRD authors inject privileged, host-namespace PodSpec fields into builder/executor pods, enabling node compromise in multi-tenant clusters. A public PoC exists; df00tech ships detection across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and Cr
CVE-2026-50551 is a critical (CVSS 9.9) stored XSS-to-RCE chain in SiYuan's kernel via unsanitized attribute view asset cells, with a public PoC available. Our detection covers the injection, API abuse, and post-exploitation stages across seven SIEM platforms.
CVE-2026-25089 is a KEV-listed OS command injection flaw in Fortinet FortiSandbox enabling arbitrary command execution. We cover detection across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
CVE-2026-39808 is a KEV-listed OS command injection flaw in Fortinet FortiSandbox's management interface. Our detection catches it via anomalous process execution and shell-metacharacter requests across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
CVE-2026-58644 is a KEV-listed deserialization flaw in Microsoft SharePoint enabling remote code execution. Our detections cover post-exploitation indicators like w3wp.exe anomalies, webshell drops, and LSASS access across seven SIEM platforms.
CVE-2026-45262 is a critical (CVSS 9.9) authenticated SQL injection in FacturaScripts's REST API filter parameter, with public PoC code and potential for SSRF-driven database host compromise. We ship detection coverage across seven major SIEM platforms.
CVE-2026-56291 is a KEV-listed unrestricted file upload flaw in Balbooa Forms for Joomla, letting attackers upload web shells for RCE. Our detection ships across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
CVE-2023-4346, a CISA KEV-listed flaw in KNX's connection authorization lockout, lets attackers brute-force building automation access keys. Our KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike detections flag the repeated failed auth attempts that reveal it.
CVE-2026-15409 is a KEV-listed SSRF flaw in SonicWall SMA1000 appliances letting attackers pivot into internal networks and cloud metadata. Our detection catches it via SIEM correlation of anomalous outbound requests across seven platforms.
CVE-2026-46817, a CISA KEV-listed privilege escalation flaw in Oracle E-Business Suite, enables authentication bypass and escalation to APPS/SYSADMIN roles. df00tech ships detections across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.
CVE-2026-56155 is a KEV-listed access control flaw in Microsoft AD FS that lets limited-privilege actors obtain unauthorized federated access. Our detection tracks anomalous token issuance, claims rule changes, and AD FS admin activity across seven SIEM platforms.
CVE-2026-56164 is a KEV-listed unauthenticated access flaw in Microsoft SharePoint Server enabling RCE and webshell deployment; our detection covers anonymous endpoint access, anomalous IIS child processes, and webshell drops across seven SIEM platforms.
Bring Your Own Vulnerable Driver (BYOVD) attacks let adversaries kill EDR from kernel space before your detections ever fire. This guide gives SOC analysts concrete KQL and SPL queries to catch driver loads, service creation, and kernel tampering mapped to MITRE ATT&CK T1068.
Production KQL (Microsoft Sentinel) and SPL (Splunk) detections for MITRE ATT&CK T1558 — Kerberoasting, AS-REP Roasting, Golden and Silver Tickets — with Event 4769/4768 logic and tuning guidance for SOC teams.
How threat actors weaponize legitimate remote access software like AnyDesk, ScreenConnect, and Atera — and the production KQL and SPL detection rules SOC teams need to catch T1219 abuse before ransomware lands.
Production KQL and SPL detection rules for MITRE ATT&CK T1055 process injection — DLL injection, process hollowing, thread hijacking, PE injection, and Early Bird APC — with tuning guidance for SOC teams.
Production-grade KQL and SPL detection queries for five critical vulnerabilities in the CISA Known Exploited Vulnerabilities catalog. Map KEV to MITRE ATT&CK, prioritise alerts, and close the gap between patch lag and detection coverage.
Every ransomware deployment starts with killing the AV. KQL queries for Microsoft Sentinel and SPL for Splunk to catch Defender disablement, service stops, taskkill abuse, and unauthorized exclusion additions before encryption begins.
Real KQL and SPL detection rules for catching LOLBin abuse — mshta, regsvr32, rundll32, WMI, and BITS Jobs — using MITRE ATT&CK T1218, T1047, and T1197 mapped queries from the df00tech library.
A practical guide to building your first SOC detection library: required logs, MITRE ATT&CK prioritisation, starter KQL and SPL queries, and a development loop that works.
A practical C2 detection rule guide for SOCs: beaconing analysis, DNS tunneling, Cobalt Strike, Sliver, and protocol tunneling with KQL and SPL queries.
Credential dumping detection for T1003.001 LSASS, SAM, and NTDS extraction. KQL and SPL queries to catch Mimikatz, ProcDump, comsvcs.dll, and DCSync in your environment.
Production-tested lateral movement detection KQL queries for Microsoft Sentinel and Defender for Endpoint covering T1021 — RDP, SMB admin shares, and WinRM.
A practical phishing detection rule guide for T1566 covering spearphishing attachments, links, and service-based phishing with KQL queries for Microsoft Defender and Sentinel.
Build a PowerShell detection rule for T1059.001 with production KQL for Microsoft Sentinel and SPL for Splunk. Covers encoded commands, AMSI bypass, and tuning.
A ransomware detection rule playbook for 2026: TTPs, KQL queries, and LockBit, BlackCat, Akira tells — catch mass file encryption and shadow copy deletion pre-detonation.
Scheduled task detection for T1053.005 with production KQL and SPL queries for Microsoft Sentinel and Splunk — covering schtasks.exe, at.exe, cron, 4698/4700/4702 events, and hidden task persistence.
SPL vs KQL for detection engineering — side-by-side Splunk and Microsoft Sentinel syntax with real queries for PowerShell, LSASS, and scheduled task detections.
The most important MITRE ATT&CK techniques every SOC analyst must detect, prioritized by real-world frequency with KQL detection coverage for each.
df00tech provides 704 production-ready KQL and SPL detection rules mapped to the MITRE ATT&CK framework. Learn how comprehensive detection coverage protects your environment.
A practical guide for SOC teams on using the MITRE ATT&CK framework to identify detection gaps, prioritise rule development, and measure coverage improvements over time.
Hands-on KQL threat hunting queries for Microsoft Sentinel, covering credential dumping, UAC bypass, log tampering, ingress tool transfer, and password spraying detection.