Skip to content

ThreatPodium

Threat Intelligence for Every Defender

  • Home
  • CVE Alerts
  • Threat Reports
  • Playbooks
  • Reports & Trends
  • Subscribe
  • About

Detection Playbooks

Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.

Detection Playbook: Service Stop (T1489)

August 8, 2026July 10, 2026 by ThreatPodium

Service Stop (T1489) is a technique where adversaries deliberately halt or disable running services on a target system to prevent legitimate users from acces…

Categories Detection Playbooks

Detection Playbook: Inhibit System Recovery (T1490)

August 8, 2026July 9, 2026 by ThreatPodium

Inhibit System Recovery (T1490) describes adversary actions taken to delete, disable, or corrupt the built-in recovery mechanisms of an operating system or p…

Categories Detection Playbooks

Detection Playbook: Data Encrypted for Impact (T1486)

August 8, 2026July 8, 2026 by ThreatPodium

Data Encrypted for Impact (T1486) describes adversary activity where files, drives, or entire systems are encrypted to deny the victim access to their own da…

Categories Detection Playbooks

Detection Playbook: Valid Accounts (T1078)

August 8, 2026July 7, 2026 by ThreatPodium

Valid Accounts (T1078) describes adversaries using legitimate, existing credentials — stolen, purchased, phished, or brute-forced — to access systems and ser…

Categories Detection Playbooks

Detection Playbook: Spearphishing Link (T1566.002)

August 8, 2026July 6, 2026 by ThreatPodium

Spearphishing Link (T1566.002) is a targeted email attack where adversaries send carefully crafted messages containing malicious URLs to specific individuals…

Categories Detection Playbooks

Detection Playbook: Spearphishing Attachment (T1566.001)

August 8, 2026July 5, 2026 by ThreatPodium

Spearphishing Attachment (T1566.001) is a targeted email-based attack where an adversary sends a crafted email to a specific individual, company, or industry…

Categories Detection Playbooks

Detection Playbook: Service Execution (T1569.002)

August 8, 2026July 4, 2026 by ThreatPodium

Service Execution (T1569.002) describes how adversaries abuse the Windows Service Control Manager (SCM) to run malicious commands or payloads — either by cre…

Categories Detection Playbooks

Detection Playbook: SMB/Windows Admin Shares (T1021.002)

August 8, 2026July 3, 2026 by ThreatPodium

SMB/Windows Admin Shares (T1021.002) is a lateral movement technique where attackers use valid credentials — stolen, brute-forced, or obtained through creden…

Categories Detection Playbooks

Detection Playbook: Remote Desktop Protocol (T1021.001)

August 8, 2026July 2, 2026 by ThreatPodium

Remote Desktop Protocol (RDP) lateral movement occurs when an adversary uses valid credentials to interactively log into a remote Windows system via port 338…

Categories Detection Playbooks

Detection Playbook: System Information Discovery (T1082)

August 8, 2026July 1, 2026 by ThreatPodium

System Information Discovery (T1082) is a technique where adversaries enumerate detailed information about a target system — including OS version, patch leve…

Categories Detection Playbooks
Older posts
Newer posts
← Previous Page1 … Page3 Page4 Page5 Page6 Next →

Recent Posts

  • CVE-2026-42018 — JFrog Artifactory: Improper Authentication | CVSS 7.5 HIGH
  • CVE-2026-42016 — JFrog Artifactory | CVSS 8.1 HIGH
  • CVE-2026-84869 — ConnectWise ScreenConnect: Privilege Mismanagement | CVSS 9.9 CRITICAL
  • Threat Intelligence Report — September 10, 2026 | 7 New KEVs · 167 Victims
  • CVE-2026-67277 — MikroTik RouterOS: Missing Authentication | CVSS 8.8 HIGH
© 2026 ThreatPodium