Skip to content

Threat Intelligence

  • Alerts
  • Downloads
  • Links
  • IOC Feeds

Category: Threat Intelligence

Unusual user agent VPN attempts CitrixReceiver/23.11.1.41 Windows/10.0 AuthManager/23.11.0.9 (Release) X1Class CWACapable CWA/23.11.1.41
Threat Intelligence

Unusual user agent VPN attempts CitrixReceiver/23.11.1.41 Windows/10.0 AuthManager/23.11.0.9 (Release) X1Class CWACapable CWA/23.11.1.41

threatinfoDecember 26, 2024December 26, 2024

We’re seeing unusual patterns of login attempts against our customers netscalers with the only thing in common the user-agent: CitrixReceiver/23.11.1.41…

Netscaler Credential Stuffing Attack
Threat Intelligence

Netscaler Credential Stuffing Attack

threatinfoDecember 24, 2024December 24, 2024

We have recently identified another new persistent citrix netscaler credential stuffing attack against one of our customers using recently compromised…

Credential stuffing attacks against Azure Portal from Set User Agent and Device
sentinel Threat Intelligence

Credential stuffing attacks against Azure Portal from Set User Agent and Device

threatinfoDecember 17, 2024December 17, 2024

We have recently identified a persistent credential stuffing attack against some of our customers. Credential stuffing is a cyberattack method in which…

Pushing Bulk Indicators to Multiple Sentinel Instances for a MSSP
Nifi sentinel Threat Intelligence

Pushing Bulk Indicators to Multiple Sentinel Instances for a MSSP

threatinfoNovember 29, 2024November 29, 2024

Problem We manage a MISP instance which receives over 130,000 IOCs every day from multiple sources which we need to…

Actor targeting Palo Alto VPN
Threat Intelligence

Actor targeting Palo Alto VPN

threatinfoMay 12, 2024May 13, 2024

User names used by actor seen using VPNs with Canadian source IP addresses  10/05/2024. Replace targetDomain below with the domain…

Why is the Sentinel Threat Intelligence Indicator API so full of bugs
sentinel siem Threat Intelligence

Why is the Sentinel Threat Intelligence Indicator API so full of bugs

threatinfoMarch 14, 2024December 17, 2024

Microsoft have an API to add IOCs to the threat intelligence module in sentinel which can you read about here.…

Threat Intelligence

MISP Database Size Getting Too Large

threatinfoMarch 11, 2024April 11, 2024

MISP MYSQL database growing too large and starting to get out of control?  API calls getting slower and slower?  Maybe…

MISP – An Internal Error has occured – HTTP Status code 500
Threat Intelligence

MISP – An Internal Error has occured – HTTP Status code 500

threatinfoMarch 7, 2024

If you receive a “An internal error has occured” error message when clicking on various menu functions in the MISP…

Whats a threat activity cluster?
Threat Intelligence

Whats a threat activity cluster?

threatinfoFebruary 25, 2024December 24, 2024

A threat activity cluster is a grouping of security alerts which are related to a unique or similar activity taking place in…

WSO Shell used in a Phishing-as-a-Service (PhaaS) 365 harvesting phishing campaign
Threat Intelligence

WSO Shell used in a Phishing-as-a-Service (PhaaS) 365 harvesting phishing campaign

threatinfoJanuary 13, 2024January 13, 2024

1. Initial Incident Late 2023, we observed several of our users , working in different locations with different email domains…

Posts navigation

Older posts

Copyright © 2025 Threat Intelligence | Ace News by Ascendoor | Powered by WordPress.