Skip to content

ThreatPodium

Threat Intelligence for Every Defender

  • Home
  • CVE Alerts
  • Threat Reports
  • Playbooks
  • Reports & Trends
  • Subscribe
  • About

Detection Playbooks

Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.

Detection Playbook: DLL Side-Loading (T1574.002)

August 8, 2026June 20, 2026 by ThreatPodium

DLL Side-Loading (T1574.002) is a technique where an attacker places a malicious DLL with a specific filename into a directory that a legitimate, often signe…

Categories Detection Playbooks

Detection Playbook: Windows Service (T1543.003)

August 8, 2026June 19, 2026 by ThreatPodium

Windows Service persistence (T1543.003) allows adversaries to register a malicious executable as a Windows service so it automatically launches every time th…

Categories Detection Playbooks

Detection Playbook: Registry Run Keys / Startup Folder (T1547.001)

August 8, 2026June 18, 2026 by ThreatPodium

Registry Run Keys and Startup Folder persistence (T1547.001) is a technique where adversaries write entries to specific Windows registry keys or drop files i…

Categories Detection Playbooks

Detection Playbook: Visual Basic (T1059.005)

August 8, 2026June 17, 2026 by ThreatPodium

Visual Basic (VB) and its derivatives — Visual Basic for Applications (VBA) and VBScript — are scripting and programming languages that adversaries abuse to …

Categories Detection Playbooks

Detection Playbook: Scheduled Task (T1053.005)

August 8, 2026June 16, 2026 by ThreatPodium

Windows Scheduled Tasks (T1053.005) allow adversaries to register code to run automatically at a specified time, interval, or system event. Attackers use thi…

Categories Detection Playbooks

Detection Playbook: Windows Management Instrumentation (T1047)

August 8, 2026June 15, 2026 by ThreatPodium

Windows Management Instrumentation (WMI) is a built-in Windows administration framework that allows querying system state, executing commands, and managing c…

Categories Detection Playbooks

Detection Playbook: Windows Command Shell (T1059.003)

August 8, 2026June 14, 2026 by ThreatPodium

Windows Command Shell (T1059.003) refers to adversary abuse of cmd.exe — the native Windows command interpreter — to execute commands, run batch scripts (.ba…

Categories Detection Playbooks

Detection Playbook: PowerShell (T1059.001)

August 8, 2026June 13, 2026 by ThreatPodium

PowerShell (T1059.001) refers to adversary abuse of Windows PowerShell — Microsoft’s built-in scripting language and interactive shell — to execute commands,…

Categories Detection Playbooks
Newer posts
← Previous Page1 … Page5 Page6

Recent Posts

  • CVE-2026-42018 — JFrog Artifactory: Improper Authentication | CVSS 7.5 HIGH
  • CVE-2026-42016 — JFrog Artifactory | CVSS 8.1 HIGH
  • CVE-2026-84869 — ConnectWise ScreenConnect: Privilege Mismanagement | CVSS 9.9 CRITICAL
  • Threat Intelligence Report — September 10, 2026 | 7 New KEVs · 167 Victims
  • CVE-2026-67277 — MikroTik RouterOS: Missing Authentication | CVSS 8.8 HIGH
© 2026 ThreatPodium