Skip to content

ThreatPodium

Threat Intelligence for Every Defender

  • Home
  • CVE Alerts
  • Threat Reports
  • Playbooks
  • Reports & Trends
  • Subscribe
  • About

Detection Playbooks

Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.

Detection Playbook: Domain Groups (T1069.002)

August 8, 2026June 30, 2026 by ThreatPodium

Domain Groups enumeration (T1069.002) is the act of querying Active Directory or a domain controller to map out domain-level groups and their memberships. At…

Categories Detection Playbooks

Detection Playbook: Domain Account (T1087.002)

August 8, 2026June 29, 2026 by ThreatPodium

Domain Account Discovery (T1087.002) is a technique where adversaries enumerate domain user accounts and groups to map out the Active Directory environment. …

Categories Detection Playbooks

Detection Playbook: Network Service Discovery (T1046)

August 8, 2026June 28, 2026 by ThreatPodium

Network Service Discovery (T1046) is a reconnaissance technique where adversaries scan local and remote systems to enumerate running services, open ports, an…

Categories Detection Playbooks

Detection Playbook: Obfuscated Files or Information (T1027)

August 8, 2026June 27, 2026 by ThreatPodium

Obfuscated Files or Information (T1027) describes the practice of encoding, encrypting, compressing, or otherwise obscuring malicious content to make it hard…

Categories Detection Playbooks

Detection Playbook: Regsvr32 (T1218.010)

August 8, 2026June 26, 2026 by ThreatPodium

Regsvr32.exe is a legitimate Windows utility designed to register and unregister COM objects and DLLs. Attackers abuse it to execute malicious scripts or DLL…

Categories Detection Playbooks

Detection Playbook: Rundll32 (T1218.011)

August 8, 2026June 25, 2026 by ThreatPodium

Rundll32.exe is a legitimate Windows utility designed to load and execute functions exported from DLL files. Attackers abuse it to execute malicious payloads…

Categories Detection Playbooks

Detection Playbook: Pass the Hash (T1550.002)

August 8, 2026June 24, 2026 by ThreatPodium

Pass the Hash (PtH) is a credential-based lateral movement technique where an attacker uses a captured NTLM password hash — rather than the plaintext passwor…

Categories Detection Playbooks

Detection Playbook: Kerberoasting (T1558.003)

August 8, 2026June 23, 2026 by ThreatPodium

Kerberoasting is a credential theft technique in which an attacker with any valid domain account requests Kerberos Ticket-Granting Service (TGS) tickets for …

Categories Detection Playbooks

Detection Playbook: Password Spraying (T1110.003)

August 8, 2026June 22, 2026 by ThreatPodium

Password spraying is a credential access technique where an adversary attempts a single commonly used password — or a very short list — across a large number…

Categories Detection Playbooks

Detection Playbook: LSASS Memory (T1003.001)

August 8, 2026June 21, 2026 by ThreatPodium

LSASS Memory dumping (T1003.001) is a credential theft technique where attackers extract authentication material — including NTLM hashes, Kerberos tickets, a…

Categories Detection Playbooks
Older posts
Newer posts
← Previous Page1 … Page4 Page5 Page6 Next →

Recent Posts

  • CVE-2026-42018 — JFrog Artifactory: Improper Authentication | CVSS 7.5 HIGH
  • CVE-2026-42016 — JFrog Artifactory | CVSS 8.1 HIGH
  • CVE-2026-84869 — ConnectWise ScreenConnect: Privilege Mismanagement | CVSS 9.9 CRITICAL
  • Threat Intelligence Report — September 10, 2026 | 7 New KEVs · 167 Victims
  • CVE-2026-67277 — MikroTik RouterOS: Missing Authentication | CVSS 8.8 HIGH
© 2026 ThreatPodium