Skip to content

ThreatPodium

Threat Intelligence for Every Defender

  • Home
  • CVE Alerts
  • Threat Reports
  • Playbooks
  • Reports & Trends
  • Subscribe
  • About

Detection Playbooks

Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.

Detection Playbook: Gather Victim Network Information (T1590)

September 8, 2026 by ThreatPodium
T1590 · 2026-09-08

Gather Victim Network Information

Reconnaissance
PRE
MITRE ATT&CK →
Technique Gather Victim Network Information (T1590)
Tactic Reconnaissance
Platforms PRE

Read more

Categories Detection Playbooks

Detection Playbook: Employee Names (T1589.003)

September 1, 2026 by ThreatPodium
T1589.003 · 2026-09-01

Employee Names

Reconnaissance
PRE
MITRE ATT&CK →
Technique Employee Names (T1589.003)
Tactic Reconnaissance
Platforms PRE

Read more

Categories Detection Playbooks

Detection Playbook: Email Addresses (T1589.002)

August 25, 2026 by ThreatPodium
T1589.002 · 2026-08-25

Email Addresses

Reconnaissance
PRE
MITRE ATT&CK →
Technique Email Addresses (T1589.002)
Tactic Reconnaissance
Platforms PRE

Read more

Categories Detection Playbooks

Detection Playbook: Credentials (T1589.001)

August 18, 2026 by ThreatPodium
T1589.001 · 2026-08-18

Credentials

Reconnaissance
PRE
MITRE ATT&CK →
Technique Credentials (T1589.001)
Tactic Reconnaissance
Platforms PRE

Read more

Categories Detection Playbooks

Detection Playbook: Gather Victim Identity Information (T1589)

August 15, 2026 by ThreatPodium
T1589 · 2026-08-15

Gather Victim Identity Information

Reconnaissance
PRE
MITRE ATT&CK →
Technique Gather Victim Identity Information (T1589)
Tactic Reconnaissance
Platforms PRE

Read more

Categories Detection Playbooks

Detection Playbook: Virtualization/Sandbox Evasion (T1497)

August 8, 2026August 4, 2026 by ThreatPodium

Virtualization/Sandbox Evasion (T1497) describes a class of techniques where malware actively probes its execution environment to determine whether it is run…

Categories Detection Playbooks

Detection Playbook: Ingress Tool Transfer (T1105)

August 8, 2026August 3, 2026 by ThreatPodium

Ingress Tool Transfer (T1105) describes the technique where adversaries download or copy tools, scripts, or payloads from an external system they control int…

Categories Detection Playbooks

Detection Playbook: Exploit Public-Facing Application (T1190)

August 8, 2026August 2, 2026 by ThreatPodium

Exploit Public-Facing Application (T1190) describes adversaries gaining initial access by attacking a vulnerability — a software bug, misconfiguration, or un…

Categories Detection Playbooks

Detection Playbook: Drive-by Compromise (T1189)

August 8, 2026August 1, 2026 by ThreatPodium

Drive-by Compromise (T1189) is an initial access technique where an attacker causes a victim to gain code execution on their system simply by visiting a mali…

Categories Detection Playbooks

Detection Playbook: Exfiltration Over Alternative Protocol (T1048)

August 8, 2026July 31, 2026 by ThreatPodium

Exfiltration Over Alternative Protocol (T1048) describes adversaries stealing data by sending it out through a network protocol that differs from their prima…

Categories Detection Playbooks
Older posts
Page1 Page2 … Page6 Next →

Recent Posts

  • Threat Intelligence Report — September 10, 2026 | 7 New KEVs · 167 Victims
  • CVE-2026-67277 — MikroTik RouterOS: Missing Authentication | CVSS 8.8 HIGH
  • CVE-2026-86060 — MikroTik RouterOS | CVSS 9.2 CRITICAL
  • Threat Intelligence Report — September 9, 2026 | 7 New KEVs · 161 Victims
  • CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | CVSS 10.0 CRITICAL
© 2026 ThreatPodium