Skip to content

ThreatPodium

Threat Intelligence for Every Defender

  • Home
  • CVE Alerts
  • Threat Reports
  • Playbooks
  • Reports & Trends
  • Subscribe
  • About

Detection Playbooks

Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.

Detection Playbook: Process Discovery (T1057)

August 8, 2026July 20, 2026 by ThreatPodium

Process Discovery (T1057) is a reconnaissance technique where adversaries enumerate running processes on a compromised system to understand what software is …

Categories Detection Playbooks

Detection Playbook: System Owner/User Discovery (T1033)

August 8, 2026July 19, 2026 by ThreatPodium

System Owner/User Discovery (T1033) is a reconnaissance technique where adversaries enumerate the current user, active sessions, and account listings on a co…

Categories Detection Playbooks

Detection Playbook: System Network Configuration Discovery (T1016)

August 8, 2026July 18, 2026 by ThreatPodium

System Network Configuration Discovery (T1016) is a technique where adversaries enumerate network settings on a compromised host — collecting IP addresses, M…

Categories Detection Playbooks

Detection Playbook: Disable Windows Event Logging (T1562.002)

August 8, 2026July 17, 2026 by ThreatPodium

Disable Windows Event Logging (T1562.002) covers attacker actions that stop, corrupt, or suppress the Windows event logging pipeline — most commonly by tampe…

Categories Detection Playbooks

Detection Playbook: Disable or Modify Security Tools (T1562.001)

August 8, 2026July 16, 2026 by ThreatPodium

Disable or Modify Security Tools (T1562.001) describes attacker actions taken to impair, stop, or tamper with defensive software — including antivirus engine…

Categories Detection Playbooks

Detection Playbook: Clear Windows Event Logs (T1070.001)

August 8, 2026July 15, 2026 by ThreatPodium

Clear Windows Event Logs (T1070.001) is a defense evasion technique where attackers delete or wipe Windows event log channels — such as Security, System, App…

Categories Detection Playbooks

Detection Playbook: Process Injection (T1055)

August 8, 2026July 14, 2026 by ThreatPodium

Process injection (T1055) is a technique where adversaries insert and execute arbitrary code within the address space of a running, legitimate process. By hi…

Categories Detection Playbooks

Detection Playbook: Token Impersonation/Theft (T1134.001)

August 8, 2026July 13, 2026 by ThreatPodium

Token Impersonation/Theft (T1134.001) is a Windows privilege escalation technique in which an adversary duplicates an existing access token belonging to anot…

Categories Detection Playbooks

Detection Playbook: DNS (T1071.004)

August 8, 2026July 12, 2026 by ThreatPodium

DNS tunneling (T1071.004) is a command-and-control technique where adversaries embed data — including commands and exfiltrated output — inside DNS query and …

Categories Detection Playbooks

Detection Playbook: Web Protocols (T1071.001)

August 8, 2026July 11, 2026 by ThreatPodium

Web Protocols (T1071.001) describes adversaries using HTTP, HTTPS, and WebSocket as the transport layer for command-and-control (C2) communication. Rather th…

Categories Detection Playbooks
Older posts
Newer posts
← Previous Page1 Page2 Page3 Page4 … Page6 Next →

Recent Posts

  • CVE-2026-42018 — JFrog Artifactory: Improper Authentication | CVSS 7.5 HIGH
  • CVE-2026-42016 — JFrog Artifactory | CVSS 8.1 HIGH
  • CVE-2026-84869 — ConnectWise ScreenConnect: Privilege Mismanagement | CVSS 9.9 CRITICAL
  • Threat Intelligence Report — September 10, 2026 | 7 New KEVs · 167 Victims
  • CVE-2026-67277 — MikroTik RouterOS: Missing Authentication | CVSS 8.8 HIGH
© 2026 ThreatPodium