T1590: T1590
Essential information
- MITRE technique ID
T1590- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
Gather Victim Network Information
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | reconnaissance |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (39)
-
UNC6040, UNC6240 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:00 · Modified 21/12/2025 17:00
-
BreachForums usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 30/03/2026 12:12 · Modified 30/03/2026 12:12
-
Worok usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:03 · Modified 20/12/2025 22:03
-
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:05 · Modified 21/12/2025 07:05
-
Silence group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:03 · Modified 20/12/2025 23:03
-
LuoYu usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 20:00 · Modified 20/12/2025 20:00
-
Cavalry Werewolf usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:09 · Modified 21/12/2025 18:09
-
IMPERIAL KITTEN usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:51 · Modified 21/12/2025 01:51
-
The MITRE Corporation Confidence 100
[Transparent Tribe](https://attack.mitre.org/groups/G0134) is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
darcula usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 10:12 · Modified 21/12/2025 10:12
-
The MITRE Corporation Confidence 100
[HAFNIUM](https://attack.mitre.org/groups/G0125) is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. [HAFNIUM](https://attack.mitre.org/groups/G0125) primarily targets entities in the US …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Void Dokkaebi usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:52 · Modified 21/12/2025 13:52
-
The MITRE Corporation Confidence 100
[Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384) banking Trojan, and then by 2017 …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Void Blizzard usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:54 · Modified 21/12/2025 13:54
-
Earth Lamia usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:26 · Modified 21/12/2025 14:26
-
LummaC2 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:49 · Modified 21/12/2025 14:49
-
Funnull usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:41 · Modified 03/03/2026 18:14
-
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:51 · Modified 04/05/2026 16:33 -
TA428 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:51 · Modified 20/12/2025 21:51
-
Salt Typhoon usesThe MITRE Corporation Confidence 100
[Salt Typhoon](https://attack.mitre.org/groups/G1045) is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
I-SOON usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:48 · Modified 21/12/2025 15:48
-
The MITRE Corporation Confidence 100
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
VexTrio usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:40 · Modified 21/12/2025 02:54
-
Knownsec usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 12/01/2026 13:14 · Modified 12/01/2026 13:14
-
The MITRE Corporation Confidence 100
[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
ShinyHunters usesAlienVault Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 02/02/2026 12:05 · Modified 20/03/2026 09:17 -
Diplomatic Orbiter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:13 · Modified 21/12/2025 02:13
-
LockBit usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:28 · Modified 21/12/2025 12:28
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:55 · Modified 21/12/2025 14:55
-
Androxgh0st usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:24 · Modified 21/12/2025 08:21
-
The MITRE Corporation Confidence 100
[Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
Socks5Systemz usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:18 · Modified 21/12/2025 08:18
-
Smishing Triad usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:45 · Modified 21/12/2025 04:45
-
Storm-1747 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:19 · Modified 21/12/2025 19:19
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 04/03/2026 16:46 · Modified 04/03/2026 16:46
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:56 · Modified 21/12/2025 15:56
-
Static Tundra relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:47 · Modified 21/12/2025 15:47
Malware (103)
-
Socks5Systemz usesFamilyPublished 16/12/2024 23:06 · Modified 16/12/2024 23:06
-
mimikatz usesFamilyPublished 11/05/2026 16:15 · Modified 11/05/2026 16:15
-
Androxgh0st usesFamilyPublished 19/05/2026 17:52 · Modified 19/05/2026 17:52
-
nccTrojan usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:35 · Modified 20/12/2025 21:51
-
PULSEPACK usesFamilyPublished 28/01/2026 13:31 · Modified 28/01/2026 13:31
-
Tycoon2FA usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
GhostFetch usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
StallionRAT usesFamilyPublished 02/10/2025 09:42 · Modified 02/10/2025 09:42
- IMAPLoader
-
DodgeBox usesFamilyPublished 12/07/2024 16:11 · Modified 12/07/2024 16:11
-
Brute Ratel usesFamilyPublished 27/05/2025 10:35 · Modified 27/05/2025 10:35
-
Warlock ransomware usesFamilyPublished 02/08/2025 10:18 · Modified 02/08/2025 10:18
-
DollyWay usesFamilyPublished 13/06/2025 07:59 · Modified 13/06/2025 07:59
-
IOCONTROL usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
SHAPESHIFT usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
GhostX usesFamilyPublished 10/01/2026 13:29 · Modified 10/01/2026 13:29
-
Tonnerre usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
ZeroCleare usesFamily The MITRE Corporation Confidence 100
[ZeroCleare](https://attack.mitre.org/software/S1151) is a wiper malware that has been used in conjunction with the [RawDisk](https://attack.mitre.org/software/S0364) driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:37 · Modified 27/03/2026 01:05 -
Tycoon 2FA usesFamilyPublished 14/05/2026 11:16 · Modified 14/05/2026 11:16
- Truebot
-
MegaCortex - S0576 usesFamilyPublished 12/09/2025 00:05 · Modified 12/09/2025 00:05
-
Ladon usesFamilyPublished 24/06/2024 08:16 · Modified 24/06/2024 08:16
-
TraderTraitor usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
CoGUI usesFamilyPublished 06/05/2025 20:37 · Modified 06/05/2025 20:37
-
ShadowPad - S0596 usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
Tsundere usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
WhisperGate usesFamilyPublished 09/09/2024 08:02 · Modified 09/09/2024 08:02
-
SmokeLoader usesFamilyPublished 16/09/2025 08:02 · Modified 16/09/2025 08:02
- Shamoon
-
Araneida Scanner usesFamilyPublished 20/12/2024 08:49 · Modified 20/12/2024 08:49
- Cotx
-
Tickler usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
LimeRAT usesFamilyPublished 26/08/2025 15:21 · Modified 26/08/2025 15:21
- WinDealer
-
Remcos usesFamilyPublished 05/05/2026 18:45 · Modified 05/05/2026 18:45
-
PrivateLoader usesFamilyPublished 14/01/2025 15:22 · Modified 14/01/2025 15:22
- GraphicalProton
-
Foudre usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
LockerGoga - S0372 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:58 · Modified 21/12/2025 16:05
- S.A.S
-
POISONPLUG.SHADOW usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
LockBit usesFamilyPublished 06/05/2026 10:26 · Modified 06/05/2026 10:26
-
LummaC2 usesFamilyPublished 16/01/2026 20:33 · Modified 16/01/2026 20:33
-
Balada usesFamilyPublished 13/06/2025 07:59 · Modified 13/06/2025 07:59
-
FMAPP.exe usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
- CotSam
-
GoldKefu usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
- MoonBounce
-
SugarGh0st RAT usesFamilyPublished 14/10/2024 10:23 · Modified 14/10/2024 10:23
-
Shamoon - S0140 usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
AsyncRAT usesFamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
- Grace
- PortDoor
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
GoldDiggerPlus usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
BiBi wiper usesFamilyPublished 02/06/2026 14:38 · Modified 02/06/2026 14:38
-
BypassBoss usesFamilyPublished 27/05/2025 10:35 · Modified 27/05/2025 10:35
-
Vidar usesFamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
TameCat usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
XWorm usesFamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
- Ransom:Win32/Snatch
- Clop
-
Latrodectus usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
JSOutProx usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
Cobalt Strike usesFamilyPublished 16/12/2024 14:25 · Modified 16/12/2024 14:25
-
RedAlert usesFamilyPublished 03/03/2026 15:42 · Modified 03/03/2026 15:42
-
RansomHub usesFamilyPublished 07/08/2025 18:57 · Modified 07/08/2025 18:57
-
Filerase usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
- SVR Cyber
-
Cactus usesFamilyPublished 17/04/2026 08:36 · Modified 17/04/2026 08:36
-
EDRKillShifter usesFamilyPublished 19/03/2026 15:28 · Modified 19/03/2026 15:28
- Tykit
-
DcRAT usesFamilyPublished 01/03/2026 05:26 · Modified 01/03/2026 05:26
-
LAGTOY usesFamilyPublished 24/04/2025 23:27 · Modified 24/04/2025 23:27
-
RustBucket usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
Raspberry Robin usesFamilyPublished 08/08/2025 07:53 · Modified 08/08/2025 07:53
-
FoalShell usesFamilyPublished 02/10/2025 09:42 · Modified 02/10/2025 09:42
-
Mozi usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
RustyWater usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Sneaky 2FA usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
- Logtu
- DNSep
-
DarkNimbus usesFamilyPublished 05/02/2026 20:16 · Modified 05/02/2026 20:16
-
TheMoon usesFamilyPublished 11/03/2026 10:02 · Modified 11/03/2026 10:02
-
VSHELL usesFamilyPublished 05/05/2026 14:07 · Modified 05/05/2026 14:07
-
ZeroCleare - S1151 usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
PS1Bot usesFamilyPublished 05/09/2025 02:14 · Modified 05/09/2025 02:14
- IceXLoader
-
Nefilim usesFamilyPublished 12/09/2025 00:05 · Modified 12/09/2025 00:05
- StandardKeyboard
-
GoldDigger usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
Swiss Army Suite usesFamilyPublished 02/10/2024 01:12 · Modified 02/10/2024 01:12
-
KadNap usesFamilyPublished 11/03/2026 10:02 · Modified 11/03/2026 10:02
-
Un-Mail usesFamilyPublished 10/01/2026 13:29 · Modified 10/01/2026 13:29
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
DNSChanger usesFamilyPublished 04/02/2026 15:26 · Modified 04/02/2026 15:26
-
MoonWalk usesFamilyPublished 12/07/2024 16:11 · Modified 12/07/2024 16:11
-
Meterpreter usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
GoldPickaxe usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
Sign1 usesFamilyPublished 13/06/2025 07:59 · Modified 13/06/2025 07:59
-
Amadey - S1025 usesFamilyPublished 29/09/2025 08:06 · Modified 29/09/2025 08:06
-
WizardNet usesFamilyPublished 05/02/2026 20:16 · Modified 05/02/2026 20:16
Reports (38)
-
AlienVault Confidence 100 3 CVEs 20 MITREs 1 Malware 23 IOCs 23 ObservablesPublished 18/06/2026 00:48 · threat-report
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 Observables 1 APTPublished 11/06/2026 23:09 · Modified 15/06/2026 19:16 · threat-report
-
AlienVault Confidence 100 20 MITREs 13 IOCs 13 ObservablesPublished 11/06/2026 18:31 · Modified 15/06/2026 19:16 · threat-report
-
20 MITREs 39 ObservablesPublished 11/06/2026 16:31 · Modified 15/06/2026 19:46
-
20 MITREs 1 Malware 1 APTPublished 02/06/2026 14:38 · Modified 03/06/2026 09:34
-
20 MITREs 2 Observables 1 APTPublished 09/05/2026 11:15 · Modified 11/05/2026 09:56
-
AlienVault Confidence 100 20 MITREs 23 IOCs 23 ObservablesPublished 23/04/2026 21:25 · Modified 27/04/2026 14:39 · threat-report
-
3 CVEs 20 MITREs 2 Malwares 2 ObservablesPublished 21/04/2026 16:20 · Modified 22/04/2026 08:59
-
8 MITREs 3 Observables 1 APTPublished 28/03/2026 07:39 · Modified 30/03/2026 10:12
-
14 MITREs 1 APTPublished 19/03/2026 14:23 · Modified 20/03/2026 08:17
-
15 MITREs 2 Malwares 11 ObservablesPublished 11/03/2026 10:02 · Modified 11/03/2026 10:05
-
17 MITREs 1 Malware 9 Observables 1 APTPublished 04/03/2026 19:42 · Modified 05/03/2026 09:48
-
19 MITREs 6 Malwares 5 Observables 1 APTPublished 04/03/2026 19:42 · Modified 05/03/2026 09:48
-
1 CVE 20 MITREs 10 Malwares 1 Observable 1 APTPublished 04/03/2026 15:30 · Modified 04/03/2026 15:46
-
15 MITREs 1 Malware 1 ObservablePublished 03/03/2026 06:39 · Modified 03/03/2026 17:14
-
9 MITREs 1 Malware 10 ObservablesPublished 04/02/2026 15:26 · Modified 04/02/2026 21:20
-
2 CVEs 8 MITREs 6 ObservablesPublished 28/11/2025 02:45 · Modified 21/12/2025 18:16
-
6 CVEs 31 MITREs 92 Observables 1 APTPublished 28/08/2025 15:03 · Modified 28/08/2025 15:31
-
10 MITREs 28 Observables 1 APTPublished 12/08/2025 18:54 · Modified 12/08/2025 19:55
-
16 MITREs 1 Malware 1 APTPublished 02/08/2025 10:18 · Modified 04/08/2025 09:19
-
5 MITREs 4 Malwares 54 ObservablesPublished 11/06/2025 09:40 · Modified 11/06/2025 10:15
-
Illuminating Transparent Tribe related5 MITREs 3 Observables 1 APTPublished 03/06/2025 18:25 · Modified 03/06/2025 21:13
-
14 MITREs 1 Malware 3 Observables 1 APTPublished 15/05/2025 22:59 · Modified 21/05/2025 20:42
-
5 MITREs 1 MalwarePublished 25/03/2025 23:57 · Modified 26/03/2025 13:20
-
11 MITREs 1 APTPublished 20/02/2025 20:48 · Modified 21/02/2025 15:29
-
20 MITREs 12 MalwaresPublished 20/02/2025 20:48 · Modified 21/02/2025 15:30
-
10 MITREs 9 Observables 1 APTPublished 31/01/2025 13:44 · Modified 31/01/2025 14:07
-
11 MITREs 29 ObservablesPublished 20/01/2025 11:08 · Modified 20/01/2025 11:13
-
10 MITREs 1 Malware 13 ObservablesPublished 20/12/2024 08:49 · Modified 20/12/2024 11:42
-
16 MITREs 1 Malware 3 ObservablesPublished 17/12/2024 00:24 · Modified 17/12/2024 10:04
-
9 MITREs 4 Malwares 2 Observables 1 APTPublished 09/12/2024 13:12 · Modified 09/12/2024 18:02
-
13 CVEs 20 MITREs 2 Malwares 10 Observables 1 APTPublished 12/11/2024 08:47 · Modified 12/11/2024 09:28
-
19 MITREs 1 Malware 1 Observable 1 APTPublished 14/10/2024 10:23 · Modified 14/10/2024 10:47
-
10 MITREs 1 Malware 8 ObservablesPublished 02/10/2024 01:12 · Modified 02/10/2024 10:52
-
10 CVEs 25 MITREs 1 Malware 50 ObservablesPublished 09/09/2024 08:02 · Modified 09/09/2024 08:30
-
6 MITREs 5 ObservablesPublished 09/09/2024 07:38 · Modified 09/09/2024 07:50
-
19 MITREs 2 Malwares 21 ObservablesPublished 26/07/2024 08:25 · Modified 26/07/2024 09:00
-
MoonWalk related7 MITREs 2 Malwares 3 Observables 1 APTPublished 12/07/2024 16:11 · Modified 12/07/2024 16:20
Vulnerabilities (CVE) (52)
Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
- Published
- 12/11/2024
- Modified
- 21/12/2025
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 04/03/2024
- Modified
- 22/04/2026
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways …
- Attack vector
- Network
- Published
- 30/05/2024
- Modified
- 04/03/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing …
- Attack vector
- NETWORK
- Published
- 21/07/2025
- Modified
- 21/12/2025
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus …
- Attack vector
- Network
- Published
- 07/11/2024
- Modified
- 21/12/2025
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute …
- Attack vector
- Network
- Published
- 19/05/2025
- Modified
- 21/12/2025
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware …
- Attack vector
- Network
- Published
- 20/07/2025
- Modified
- 21/12/2025
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could …
- Attack vector
- Network
- Published
- 22/07/2025
- Modified
- 21/12/2025
Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to …
- Attack vector
- NETWORK
- Complexity
- HIGH
- Published
- 15/09/2017
- Modified
- 22/04/2026
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie …
- Published
- 20/12/2025
- Modified
- 21/12/2025
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code …
- Published
- 02/06/2022
- Modified
- 27/05/2026
Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured …
- Attack vector
- Network
- Published
- 03/11/2021
- Modified
- 18/02/2026
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries …
- Attack vector
- Network
- Published
- 29/04/2025
- Modified
- 21/12/2025
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
- Attack vector
- Adjacent
- Published
- 01/05/2023
- Modified
- 21/12/2025
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources …
- Attack vector
- Network
- Published
- 19/05/2025
- Modified
- 21/12/2025
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath …
- Attack vector
- Network
- Published
- 15/07/2024
- Modified
- 21/12/2025
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code …
- Attack vector
- Network
- Published
- 11/07/2023
- Modified
- 20/12/2025
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. …
- Attack vector
- NETWORK
- Published
- 12/10/2024
- Modified
- 21/12/2025
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the …
- Published
- 12/11/2024
- Modified
- 21/12/2025
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 19/03/2014
- Modified
- 22/04/2026
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within …
- Attack vector
- Network
- Published
- 22/08/2023
- Modified
- 27/05/2026
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
- Attack vector
- Network
- Published
- 23/09/2022
- Modified
- 27/05/2026
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute …
- Published
- 03/11/2021
- Modified
- 21/12/2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands …
- Attack vector
- Network
- Published
- 04/12/2024
- Modified
- 21/12/2025
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
- Published
- 27/06/2022
- Modified
- 20/12/2025
Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a …
- Published
- 16/01/2024
- Modified
- 21/12/2025
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system …
- Attack vector
- Network
- Published
- 12/06/2024
- Modified
- 21/12/2025
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected …
- Attack vector
- NETWORK
- Published
- 03/11/2021
- Modified
- 14/01/2026
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
- Attack vector
- Network
- Published
- 17/10/2024
- Modified
- 21/12/2025
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications …
- Attack vector
- Network
- Published
- 02/02/2023
- Modified
- 21/12/2025
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
- Attack vector
- Network
- Published
- 15/03/2023
- Modified
- 21/12/2025
An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
- Published
- 31/03/2022
- Modified
- 21/12/2025
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected …
- Attack vector
- Network
- Published
- 02/06/2025
- Modified
- 21/12/2025
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow …
- Attack vector
- Network
- Published
- 22/07/2025
- Modified
- 21/12/2025
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
- Attack vector
- Network
- Published
- 07/03/2024
- Modified
- 21/12/2025
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/06/2017
- Modified
- 22/04/2026
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the …
- Attack vector
- Network
- Published
- 23/10/2023
- Modified
- 21/12/2025
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Attack patterns (MITRE) (6)
-
Network Topology subtechnique-ofT1590.004
-
T1590.005 subtechnique-ofIP Addresses
-
Network Trust Dependencies subtechnique-of
-
DNS subtechnique-ofT1590.002
-
Network Security Appliances subtechnique-ofT1590.006
-
T1590.001 subtechnique-ofDomain Properties
Course Of Action (1)
- Pre-compromise mitigates