Sunturai
Vendor advisory

www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a
Published on
www.cisa.gov
Sources in this catalogue
2

ATT&CK techniques those detections carry

  • T1059Command and Scripting Interpreter
  • T1059.009Cloud API
  • T1112Modify Registry
  • T1190Exploit Public-Facing Application
  • T1218.011Rundll32
  • T1530Data from Cloud Storage
  • T1567Exfiltration Over Web Service
  • T1567.002Exfiltration to Cloud Storage
Open the original

4 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
AzCopy or Azure Storage Explorer Usage on Unusual HostMedium
Detect Zerologon via ZeekMedium
Windows Rundll32 Apply User Settings ChangesInformational
Windows Modify Registry NoChangingWallPaperMedium

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice