Detection Playbook: File and Directory Discovery (T1083)

T1083 · 2026-07-21 File and Directory Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique File and Directory Discovery (T1083) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview File and Directory Discovery (T1083) refers to adversaries actively enumerating the file system — listing directories, searching for specific file types, and mapping … Read more

Threat Intelligence Report — July 20, 2026 | 7 New KEVs · 170 Victims

Report Date: 2026-07-20

New KEVs: 7  — unchanged vs last weekRansomware Victims: 170  ▼ -51 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 170 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Detection Playbook: Process Discovery (T1057)

T1057 · 2026-07-20 Process Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique Process Discovery (T1057) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview Process Discovery (T1057) is a reconnaissance technique where adversaries enumerate running processes on a compromised system to understand what software is active, what security tools are present, … Read more

Threat Intelligence Report — July 19, 2026 | 7 New KEVs · 169 Victims

Report Date: 2026-07-19

New KEVs: 7  ▲ +1 vs last weekRansomware Victims: 169  ▼ -50 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 169 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Detection Playbook: System Owner/User Discovery (T1033)

T1033 · 2026-07-19 System Owner/User Discovery Discovery Linux macOS Network Devices Windows MITRE ATT&CK → Technique System Owner/User Discovery (T1033) Tactic Discovery Platforms Linux, macOS, Network Devices, Windows Overview System Owner/User Discovery (T1033) is a reconnaissance technique where adversaries enumerate the current user, active sessions, and account listings on a compromised host. Attackers use this … Read more

Threat Intelligence Report — July 18, 2026 | 7 New KEVs · 160 Victims

Report Date: 2026-07-18

New KEVs: 7  ▲ +1 vs last weekRansomware Victims: 160  ▼ -62 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 160 new victims posted to leak sites over the last 7 days, with Dragonforce posting the most victims.

Read more

Detection Playbook: System Network Configuration Discovery (T1016)

T1016 · 2026-07-18 System Network Configuration Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique System Network Configuration Discovery (T1016) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview System Network Configuration Discovery (T1016) is a technique where adversaries enumerate network settings on a compromised host — collecting IP addresses, MAC addresses, … Read more

Threat Intelligence Report — July 17, 2026 | 7 New KEVs · 171 Victims

Report Date: 2026-07-17

New KEVs: 7  ▲ +1 vs last weekRansomware Victims: 171  ▼ -26 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 171 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: Disable Windows Event Logging (T1562.002)

T1562.002 · 2026-07-17 Disable Windows Event Logging Defense Evasion MITRE ATT&CK → Technique Disable Windows Event Logging (T1562.002) Tactic Defense Evasion Platforms Windows, Linux, macOS Overview Disable Windows Event Logging (T1562.002) covers attacker actions that stop, corrupt, or suppress the Windows event logging pipeline — most commonly by tampering with the Windows Event Log service, … Read more

Threat Intelligence Report — July 16, 2026 | 7 New KEVs · 231 Victims

Report Date: 2026-07-16

New KEVs: 7  ▲ +3 vs last weekRansomware Victims: 231  ▲ +104 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Fortinet products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Sandworm (Russia) and Scattered Spider. Ransomware activity is moderate with 231 new victims posted to leak sites over the last 7 days, with Deadlock posting the most victims.

Read more