Tags

Browse and search all threat intelligence tags

Admin Panel Hunt

Activity

IP addresses searching for administrative login interfaces and control panels

CGI Script Hunt

Activity

IP addresses scanning for CGI scripts and vulnerable CGI directories like /cgi-bin/

CMS Enumeration

Activity

IP addresses probing for CMS platforms like Drupal, Joomla, and admin panels

Config File Hunt

Activity

IP addresses searching for configuration files and sensitive application data

Database Admin Hunt

Activity

IP addresses searching for database administration interfaces like phpMyAdmin

Directory Traversal Attempt

Activity

IP addresses attempting path traversal attacks to access system files

Enterprise Software Probe

Activity

IP addresses targeting enterprise software like VMware, Citrix, and Exchange servers

File Upload Attempt

Activity

IP addresses probing for file upload endpoints and upload functionality

Router Exploit

Activity

IP addresses targeting router firmware vulnerabilities and IoT devices

SharePoint Active Exploitation

Activity

CVE-2025-53770 active SharePoint exploitation attempts targeting ToolPane.aspx endpoints. These represent live attacks attempting to deploy webshells and extract MachineKey secrets for persistent access.

SharePoint ToolShell Exploit

Activity

Detects exploitation attempts against CVE-2025-53770, a critical zero-day SharePoint RCE vulnerability. Attackers use ASPX payloads to steal MachineKey configuration and achieve remote code execution. Primary IOC: /_layouts/15/spinstall0.aspx

SharePoint Webshell Scanning

Activity

Scanning for CVE-2025-53770 SharePoint webshells (spinstall*.aspx). These requests typically indicate threat actors probing for already compromised SharePoint servers rather than active exploitation attempts.

SIP REGISTER Scanner

Activity

IP addresses with this tag have been observed scanning the Internet for SIP devices and attempting to query or modify address bindings using REGISTER requests.

SolarWinds Probe

Activity

IP addresses targeting SolarWinds Orion network monitoring platforms

SSH Bruteforcer

Worm

IP addresses with this tag have been observed making repeated SSH connections in a short timeframe.

SSH Connection Attempt

Activity

IP addresses with this tag have been observed attempting to negotiate an SSH session.

Telnet Bruteforcer

Activity

IP addresses with this tag have been observed attempting to bruteforce Telnet server credentials.

Telnet Login Attempt

Activity

IP addresses with this tag have been observed attempting to authenticate to a Telnet server.

TLS/SSL Crawler

Activity

IP addresses with this tag have been observed attempting to opportunistically crawl the Internet and establish TLS/SSL connections.

VNC Login Attempt

Activity

IP addresses with this tag have been observed attempting to authenticate to a VNC server.

Web Command Injection

Activity

IP addresses attempting to execute system commands through web applications

Web Crawler

Activity

IP addresses with this tag have been seen crawling HTTP(S) servers around the Internet.

Web Shell Hunt

Activity

IP addresses searching for web shells and backdoors on web servers

WordPress Enumeration

Activity

IP addresses enumerating WordPress users and admin interfaces