DCSync Attack via Compromised Service Account
A service account with replication rights is being abused to dump all domain hashes via DCSync. The attack branches: one path leads to Golden Ticket forgery, another to immediate l
Scenario library
362 hands-on incident-response scenarios across 12 systems, from Active Directory and Entra to AWS, Azure, GCP, Okta, and Snowflake. Drafted from live threat intelligence, published after expert review. The free set rotates monthly.
362 of 362
A service account with replication rights is being abused to dump all domain hashes via DCSync. The attack branches: one path leads to Golden Ticket forgery, another to immediate l
A Global Admin is hit with an MFA push bombing attack. Two branches emerge: the attacker either establishes OAuth app persistence OR pivots to PIM bypass - your containment decisio
A compromised Domain Admin weaponizes a domain-linked GPO - adding a Group Policy Preferences Immediate Task that runs a ransomware binary staged in SYSVOL - to detonate across the
A low-and-slow Entra ID password spray guesses weak seasonal passwords, then a valid sign-in arrives over legacy IMAP4 where the tenant's Require MFA policy never evaluates. Two br
A low-privilege domain user exploited a misconfigured certificate template (ESC1) that allows enrollee-supplied subject with a client-authentication EKU, enrolling a certificate th
An attacker with standard domain user credentials is performing a large-scale Kerberoasting attack, requesting TGS tickets for every SPN in the domain. Several weak service account
An attacker on the internal network used Responder and NTLMRelayx to coerce NTLM authentication from a Domain Controller machine account, then relayed it to a service that lacked s
A compromised partner-tenant account exploits an overly permissive cross-tenant access policy - inbound Allow all with Trust MFA from partner enabled - to sign in as a guest and re
An attacker who compromised a Global Admin used a PIM eligibility loophole to permanently assign Global Admin to a newly created account, bypassing the just-in-time activation requ
A device code phishing lure sends employees to the real microsoft.com/devicelogin to enter an attacker-generated code; three victims complete the flow and hand the attacker's first
A threat actor with a compromised Global Admin account removed corporate devices from Intune MDM management, stripping compliance policies, endpoint protection, and device configur
A threat actor used Microsoft Teams External Access (federation) to send malicious messages and files to internal employees from a lookalike external tenant. After one employee acc
A targeted phishing attack compromised the CFO's Exchange Online mailbox. The attacker created hidden inbox rules to silently forward all emails containing financial keywords to an
A ransomware group launches a Stryker-style dual extortion attack against a healthcare environment. Initial access via a compromised VPN account leads to Active Directory privilege
Friday 7:10 AM. Users across multiple regions report failed logins, device instability, and inability to access M365, VPN, and line-of-business applications. Privileged account sig
10:30 AM. A ransomware-precursor identity intrusion has been contained. Authentication has been down for two hours and executives are demanding restoration to meet the availability
10:15 AM. The identity team has finished the obvious recovery: every user password was reset and MFA was re-enrolled across the tenant, and users can sign in again. But privileged
An attacker on Kali (192.168.56.100) enumerates every SPN in sevenkingdoms.local and harvests 38 RC4 service tickets in 12 seconds, cracking them offline to recover service-account
A Domain Admin credential ([email protected]), cracked via Kerberoasting, is used to run DRSUAPI GetNCChanges (DCSync) directly against DC01 (192.168.56.10), repli
A cracked Domain Admin (robb.stark) staged a ransomware binary in SYSVOL and linked a Group Policy Immediate Task in the Default Domain Policy to launch it as SYSTEM on every host
Responder poisons LLMNR/NBT-NS on the subnet and PetitPotam coerces the DC01 machine account into authenticating to the attacker, who relays that NTLM credential to LDAP and writes
Several accounts in north.sevenkingdoms.local have DONT_REQ_PREAUTH set - an intentional misconfiguration that tells the KDC to skip Kerberos pre-authentication. From a Kali host w
An attacker with a foothold on SRV02 (192.168.56.22) runs Mimikatz against LSASS and harvests the cached NTLM hashes of logged-on accounts, including Domain Admin robb.stark. The s
An attacker on [email protected] ran SharpHound and found a standing ACL path to Domain Admins - GenericWrite on Night Watch, WriteDACL on Domain Admins. They are wal
A Tier-0 compromise dumped NTDS.dit via DCSync and the KRBTGT hash for both forest domains is in attacker hands. Forged Golden Tickets are already validating against DC01 and DC02.
A public-facing EC2 web application vulnerable to SSRF was abused to query the Instance Metadata Service (IMDSv1) and steal the EC2 instance role's temporary credentials. The attac
A user with Contributor on a resource group used 'az vm run-command' to execute on a VM whose system-assigned Managed Identity held User Access Administrator at the subscription sc
A service-account key leaked in a public Git repository let an attacker authenticate as a low-privilege service account. That SA held iam.serviceAccounts.getAccessToken on a more-p
A vendor-integration role in the production AWS account trusts a third party but its trust policy carries an over-broad Principal and no sts:ExternalId condition. An attacker who c
The SOC sees a wave of data-lake objects being overwritten so they are re-encrypted under a KMS key the organization does not control, while prior object versions are deleted and v
An over-scoped, long-lived shared access signature (SAS) - signed by the storage account key, carrying near-full permissions across all resource types with a multi-year expiry - is
A consent-phishing link gets a privileged user to grant a malicious multi-tenant app broad Microsoft Graph permissions. The consent creates a service principal that authenticates a
An attacker who lands code execution in a GKE pod (via an app SSRF/RCE) queries the node metadata server at 169.254.169.254 and retrieves the node's service-account access token. T
An over-privileged service account with broad BigQuery roles runs terabyte-scale SELECT queries across datasets it has never touched, then launches EXPORT DATA / extract jobs to a
A nation-state actor (APT29 / Midnight Blizzard) password-sprayed a legacy, non-production test account that lacked MFA, then created a malicious OAuth application and granted it b
Long-lived AWS access keys (AKIA...) for an over-privileged IAM user were committed to a code repository and found by automated secret scanners within minutes. An attacker authenti
A service-account JSON key with the broad Editor role leaked from a misconfigured world-readable Cloud Storage bucket. The attacker authenticated as sa-pipeline from an external IP
While troubleshooting, your Okta admin uploaded a browser HAR file to Okta support. That HAR contained a live admin session token. Okta's support case-management system was breache
A threat actor used valid Snowflake login credentials - harvested by infostealer malware from a contractor's machine months earlier and never rotated - to log into a Snowflake cust
An authenticated attacker exploits CVE-2023-21529, a deserialization flaw in on-prem Microsoft Exchange, to gain remote code execution on EXCH01. They drop an .aspx web shell in an
An attacker phones the help desk impersonating a Super Administrator and, with no real identity verification, gets the account's MFA factors reset. They enroll their own device, si
A user is consent-phished into authorizing a malicious, over-scoped connected app in the company's Salesforce CRM, granting it broad API access via an OAuth refresh token. The atta
An attacker who reaches administrative access in the AWS Organization management account uses IAM Identity Center (AWS SSO) to grant itself durable, cross-account admin. It creates
An attacker with Lambda management permissions reads a production function's configuration to harvest the secrets teams commonly store in environment variables - database credentia
An IAM principal that can call ssm:SendCommand uses AWS Systems Manager Run Command to run a script as root across the managed EC2 fleet - no SSH, no RDP, no security-group change,
An attacker who lands code execution in an Amazon EKS pod reaches the EC2 Instance Metadata Service on the worker node and steals the node IAM role's temporary credentials, abusing
An actor with AWS Organizations management access goes after the org-wide guardrails. From the management account they detach a restrictive Service Control Policy from a production
A principal with rights over an Azure Automation Account imports a runbook that authenticates as the account's system-assigned managed identity via Connect-AzAccount -Identity. Tha
An attacker holding rights over a Key Vault's authorization model rewrites it to grant themselves Get and List on secrets, keys, and certificates, then bulk-reads the vault. A Key
The Entra Connect (formerly Azure AD Connect) server bridges on-prem Active Directory and Entra ID, and it runs with the most dangerous account pair in a hybrid estate: an on-prem
An attacker lures a user into completing a device-code authentication flow on the legitimate Microsoft endpoint and walks away with the user's access and refresh tokens. The same s
An attacker who holds a privileged Entra role, or who has phished a Global or Application Administrator, adds a new client secret to an existing, highly privileged application regi
A workload identity pool provider is configured with an overly broad attribute condition that trusts any external token from a given issuer instead of a specific repository or acco
An identity with deploy rights uses run.services.create to deploy a malicious Cloud Run service and attaches a privileged runtime service account. The workload then runs continuous
A compromised internal principal holding resourcemanager.projects.setIamPolicy rewrites the project IAM policy to grant roles/owner to an attacker-controlled service account, then
An attacker with project access creates an HMAC key for a service account - the S3-interoperable access mechanism for Cloud Storage - giving stealthy, long-lived, key-based read ac
After reaching admin access, an attacker mints an Okta SSWS API token tied to a Super Administrator rather than living in the browser session. The token inherits that admin's full
An attacker controls an Entra application whose service principal holds broad Microsoft Graph application permissions such as Sites.Read.All and Files.Read.All, obtained through ad
An attacker holding a leaked personal access token (PAT) or an over-scoped authorized OAuth/GitHub App reaches the private repositories of a GitHub organization. The token clones s
An attacker abuses domain-wide delegation (DWD) in Google Workspace. A GCP service account is authorized in the Workspace Admin console with broad OAuth scopes, which lets it imper
A leaked Databricks personal access token (PAT) gives an attacker programmatic access to the workspace REST API. From an unfamiliar IP and outside business hours, they enumerate Un
An attacker registers a malicious application in Entra ID and sends a user a genuine Microsoft consent link requesting delegated Graph scopes such as Chat.Read, ChannelMessage.Read
A public repository runs a CI workflow triggered on pull_request_target, which executes in the base repository's context with access to its secrets. The workflow also checks out an
An infostealer on an employee laptop copied the browser's saved cookies, including a live, MFA-satisfied SaaS session and refresh token. The attacker imported those tokens into the
A leaked long-lived AWS access key is replayed from an unfamiliar IP to abuse Amazon Bedrock. The attacker probes which foundation models are enabled, disables Bedrock invocation l
A Terraform state file in an S3 backend holds plaintext secrets, because Terraform records every resource attribute - including a generated RDS master password, an IAM access key,
A compromised AWS credential with Amazon SES send permissions is used to send phishing from the victim's own verified, DKIM-signed domain. Because the mail carries the domain's rea
A developer runs npm install and pulls a version of a popular package whose maintainer account was taken over. The package's postinstall script executes on the workstation, reads c
A public web application uses an Amazon Cognito identity pool to hand browser clients temporary AWS credentials. The authenticated identity-pool role was written with broad IAM per
An over-permissioned application role - granted secretsmanager:GetSecretValue and ssm:GetParameter across all resources instead of the few it needs - has its temporary credentials
An attacker with a foothold on an over-privileged role moves to blind the account before acting further. In under two minutes a single principal calls StopLogging then DeleteTrail
External resolution monitoring flags a trusted login subdomain answering with an attacker-controlled host, and Route 53 change history shows a ChangeResourceRecordSets that no chan
A compromised IAM principal with EC2 permissions snapshots the EBS volume backing a production database, then calls ModifySnapshotAttribute to add an external 12-digit AWS account
A compromised CI push credential overwrites a production image tag (app:latest) in an ECR repository whose tags are mutable, repointing the trusted tag to a new digest that carries
An attacker who compromised a low-privilege role in a peripheral account is walking a chain of permissive trust relationships toward a sensitive production account. Each hop is a l
An internal API behind API Gateway is guarded by a custom Lambda REQUEST authorizer that returns an IAM policy deciding whether a request is allowed. The authorizer is broken two w
A service principal holds the User Access Administrator role on a production subscription, which grants the ability to create role assignments but not to use resources directly. An
An Azure DevOps pipeline reads its build steps from a YAML file in the repository and runs them on a self-hosted agent that holds an ARM service connection to a production Azure su
A virtual machine runs a web application whose system-assigned managed identity holds Get and List on a production Key Vault. An attacker with code execution on the VM mints a mana
An attacker with rights to deploy to a Function App drops a new function into a production app whose system-assigned managed identity holds read access to a customer-data storage a
A Cloud Build trigger runs on every push to a build repository and executes the steps in the repo's cloudbuild.yaml as the default Cloud Build service account, which carries broad
A production GKE deployment pulls its container image from an Artifact Registry repository by the mutable tag :prod. An over-permissioned writer service account, whose downloadable
An application service account holds the broad Cloud SQL Admin role rather than the narrow connect permission it actually needs, and its key leaked outside the workload. Authentica
A user on an Entra-joined Windows endpoint is compromised by malware running with local privileges. The Primary Refresh Token (PRT) is a long-lived credential bound to the device t
An attacker who has reached a privileged Entra role abuses cross-tenant synchronization, a B2B feature that automatically provisions and updates users from one tenant into another.
An attacker who has reached Okta administrative access abuses inbound federation - the feature that lets an external identity provider assert who a user is. They add an attacker-co
An organization believes MFA is enforced everywhere, but its Conditional Access posture has a gap: a policy excludes a set of accounts, does not cover a legacy authentication proto
A compromised session holding the Exchange Administrator role creates a single org-wide transport (mail-flow) rule that blind-copies every inbound and outbound message to an attack
After phishing a user, an attacker uses that user's identity to build a Power Automate cloud flow that triggers on new mail and on OneDrive or SharePoint file changes and POSTs eve
An attacker with a compromised Intune Administrator session creates a malicious PowerShell platform script (Intune Scripts feature) and assigns it to the All Devices group with run
An attacker is invited as a guest into a Microsoft Teams team, either through a compromised insider or a social-engineering pretext, and that team is connected to a SharePoint site
An attacker phishes a sales-operations user into authorizing a malicious OAuth connected app that requests the api and refresh_token scopes. The user clicks Allow, and the app rece
A persistent self-hosted GitHub Actions runner inside the corporate network picked up an untrusted fork pull request. Because the runner is non-ephemeral, the attacker's job steps
A Slack bot token (xoxb) and an incoming webhook URL are committed to a public repository in a deleted-but-still-in-history commit. An external scanner scrapes the leaked credentia
A developer's Atlassian API token is leaked in a build log pasted into a support ticket. An attacker pairs it with the developer's email for HTTP Basic authentication against the A
A ServiceNow middleware integration identity, svc_integration_mw, was granted a broad admin role months ago for a job that only needs to sync one CMDB table. Its OAuth credential l
A production storage account access key for an Azure Blob container is leaked, giving the holder full data-plane control over every blob without touching Azure RBAC or Entra. An at
A user was tricked into authorizing an over-scoped Google Apps Script project that requested broad Gmail and Drive read scopes plus script.external_request. The script runs on an I
A compromised scoped help-desk admin account is used to escalate privilege in Okta - granting Super Administrator to an attacker-controlled account directly, and ALSO adding that a
An attacker who reached the on-prem AD FS server exports its token-signing certificate and private key. With that key they forge SAML responses (a Golden SAML) that assert any user
A lower-privileged CI/CD IAM principal holds a broad, unconstrained iam:PassRole together with permission to create and invoke Lambda functions. On its own the principal is limited
A data-science team stages a pre-trained model pulled from a public model hub into the Vertex AI Model Registry, and a recurring Vertex AI pipeline is scheduled to load it. The mod
An employee is phished with a link to a reverse-proxy site that sits between them and the real Okta login. They type their password and complete the genuine MFA challenge, but the
AD CS web enrollment (certsrv) accepts NTLM and, by default, enforces neither channel signing nor Extended Protection for Authentication over its HTTP endpoint, so an attacker can
The certificate authority has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set in its policy configuration. With that flag, the CA honors a subject alternative name supplied by the requ
A non-administrative principal holds the ManageCA right on the enterprise certificate authority. That right lets it grant itself the ManageCertificates (CA officer) right, enable t
A certificate template object has an over-permissive access-control list: a low-privileged principal holds write rights (WriteDacl/WriteProperty/WriteOwner) over it. The template i
A certificate template carries the Certificate Request Agent EKU and is enrollable by ordinary users. An enrollment-agent certificate lets its holder co-sign certificate requests o
Certificate-based authentication maps a certificate to an account. Strong mapping uses the SID security extension (szOID_NTDS_CA_SECURITY_EXT) that the CA embeds; weak mapping fall
A certificate template carries an issuance policy whose OID is linked to an Active Directory group via msDS-OIDToGroupLink. When a user authenticates with a certificate issued from
A low-privileged user enrolls on a broadly enrollable schema version 1 certificate template (a Supplies-in-Request web-server template) but embeds a Client Authentication applicati
An attacker who compromised the certificate authority server exports the CA's own private key and certificate. With the CA private key they forge certificates for any principal ent
A non-DC server is configured for Kerberos unconstrained delegation (the TRUSTED_FOR_DELEGATION flag). Any account that authenticates to that server has its full, forwardable Kerbe
Windows Hello for Business key-trust authentication lets an account hold key credentials in its msDS-KeyCredentialLink attribute; a certificate-like key in that attribute can be us
Every workstation shares the same built-in local Administrator password because LAPS was never deployed. An attacker with admin on one endpoint dumps the local SAM and recovers the
After compromising a child domain, an attacker abuses the intra-forest trust to reach the parent domain. They inject the SID of a parent-domain privileged group (for example Enterp
The tenant requires MFA for all users, so leadership believes account takeover is handled. But legacy authentication protocols (IMAP, POP, SMTP AUTH, older Exchange ActiveSync, and
A service account (svc_web) is configured for constrained delegation with protocol transition - msDS-AllowedToDelegateTo is set and TRUSTED_TO_AUTH_FOR_DELEGATION (the 'use any aut
A standard domain user chains two 2021 flaws to impersonate a domain controller. CVE-2021-42278 let a machine account's sAMAccountName be renamed to match a DC (dropping the traili
Older Group Policy Preferences (GPP) that set local account passwords store the password as a cpassword attribute in an XML file in SYSVOL, AES-encrypted with a 32-byte static key
Entra ID Seamless Single Sign-On uses an on-prem computer account named AZUREADSSOACC whose Kerberos key signs the tickets that log domain-joined users into the cloud silently. An
Pass-Through Authentication (PTA) lets Entra ID validate cloud sign-in passwords against on-prem AD by handing them to a PTA agent running on a server in the environment. The agent
The tenant has many permanent (standing) Global Administrators and does not use Privileged Identity Management (PIM) to make privileged roles just-in-time. Every standing Global Ad
The domain carries privileged-account hygiene debt that any authenticated user can enumerate from readable AD attributes: a Domain Admin (backup_admin) flagged PASSWD_NOTREQD - exe
An end-of-life Windows Server domain controller (DC-LEGACY01) is still a full read-write replication partner. It receives no security updates and carries weak legacy defaults - SMB
The tenant accumulated enterprise applications and service principals that nobody owns anymore: long-lived client secrets set years ago, broad application (app-only) Graph permissi
A dynamic security group in Entra ID, SG-AppAdmins-Dyn, computes its membership from a rule over user attributes - (user.department -eq "Billing-Admins") - and that group confers r
Self-service password reset is configured weakly: it requires only one verification method, accepts methods an attacker can satisfy or spoof (such as a mobile number or secondary e
ADCS trust does not live only in templates and the CA service - it lives in AD objects in the Configuration partition: the CA host's computer account, the Enrollment Services and C
ESC11 is the RPC counterpart to ESC8: instead of relaying NTLM to the CA's HTTP web enrollment page, the attacker relays it to the CA's RPC certificate-enrollment interface (MS-ICP
ESC16 is the CA-wide version of ESC9. The certificate authority is configured to omit the SID security extension (szOID_NTDS_CA_SECURITY_EXT) from every certificate it issues, by a
An unauthenticated host on the network forged a Netlogon secure channel against a domain controller (the Zerologon all-zeros-IV flaw), set the DC's own machine-account password to
An attacker with AWS access turns a production Lambda function into durable, credential-less persistence by widening the function's resource-based (function) policy. Using lambda:A
An attacker holding an over-permissioned principal with AWS Systems Manager access needs no SSH, no key pair, and no open inbound port to move through a fleet. With ssm:SendCommand
An Azure Function App that has a managed identity exposes a local identity endpoint that returns a token for that identity. If an attacker can run code in the Function, by exploiti
The invoice-renderer Cloud Run service in proj-checkout runs as the runtime service account sa-invoice-run, and code inside the container can ask the metadata server for that accou
A Databricks service principal authenticates to the account and workspace REST APIs via OAuth machine-to-machine credentials - a client id plus a long-lived client secret that mint
A user is social-engineered into installing and consenting to a malicious Slack app - 'ChannelSync Pro' - that requests broad OAuth scopes (channels:history, groups:history, im:his
A container in the prod-ecs cluster is compromised through a vulnerable app. With no key on disk, the attacker reads the task role's temporary credentials from the container creden
A public web application uses an Amazon Cognito identity pool to hand signed-in app users temporary AWS credentials by assuming an IAM authenticated role. That role was written wit
An attacker with RDS and KMS permissions does not query a production database row by row to steal it. They create a manual snapshot of the encrypted orders-prod database, then call
An attacker adds a hidden client secret to an Entra ID application whose service principal already holds RoleManagement.ReadWrite.Directory and Application.ReadWrite.All - Microsof
An Azure storage account has two account keys that each grant full control of everything in it - all blobs, files, queues, and tables. The keys never expire, and shared-key authent
GCP organization policies are the org-wide preventive guardrails: they block service-account key creation, prevent public IAM and public buckets, restrict VM external IPs and resou
Inside a GKE cluster, Kubernetes RBAC decides who can do what. A namespace-scoped workload identity - a compromised pod or a stolen ServiceAccount token - was granted the RBAC bind
ServiceNow is the system of record for IT and often the business: incidents, the CMDB, user and employee records, and the sensitive details and occasional credentials people put in
Notion holds a company's documents, wikis, runbooks, plans, and the secrets and personal data that end up in pages and databases. An internal integration token, leaked in code or p
A cloud content-management tenant (Box) holds the company's documents. An attacker gets an over-scoped third-party app authorized (consent phishing, or a stolen app config with ent
A support platform (Zendesk) holds customer tickets, contact records, and the secrets customers sometimes paste into tickets while troubleshooting. An attacker obtains a long-lived
An observability platform (Datadog) ingests the organization's logs, metrics, and infrastructure inventory. An attacker who finds a leaked API key plus application key (committed t
An attacker with AWS access plants durable persistence using serverless orchestration instead of a host. An EventBridge rule on a schedule (or an event pattern) triggers a Step Fun
An Azure Logic App runs a workflow as a managed identity that was over-granted a broad subscription role. An attacker who can edit the workflow (Logic App Contributor) adds an acti
GCP Pub/Sub carries the organization's event stream - app events, audit data, sometimes records with PII. An attacker with Pub/Sub permissions attaches a new subscription to a busy
CVE-2024-21410 is an Exchange Server elevation-of-privilege via NTLM relay: an attacker coerces a victim's NTLM authentication and relays it to an on-prem Exchange Server that does
An e-signature platform (DocuSign) is a system of record for executed contracts and signer PII and a trusted channel recipients are conditioned to open and sign. An attacker with a
AWS IAM Roles Anywhere lets on-prem and non-AWS workloads obtain temporary role credentials by presenting an X.509 client certificate that chains to a registered trust anchor. An a
An over-privileged analytics role (analytics-etl) is used to run a Glue job and Athena CTAS queries that read across the S3 data lake and redirect the results to an S3 location in
An attacker abused an over-broad grant on an assumed role to loosen a sensitive SNS topic's access policy and attach their own external HTTPS endpoint as a confirmed subscriber, si
An actor with kms:PutKeyPolicy on a customer-managed CMK rewrites the key policy to grant their own AWS account kms:Decrypt (or issues a standalone kms:CreateGrant to an external g
An attacker who can edit a buildspec or a CodePipeline stage pushed a commit that alters buildspec.yml for the deploy-prod CodeBuild project. The injected step reads the build cont
A compromised analytics principal uses redshift:GetClusterCredentials to obtain temporary database credentials, connects to the prod-warehouse cluster, and runs UNLOAD to dump whol
The SOC sees AWS Backup recovery points being deleted in bursts and a backup vault targeted for deletion - an attempt to destroy the organization's ability to recover before a dest
An attacker who controls the AWS account's registered root email inbox and recovery phone drives the 'forgot password' and 'sign in using alternative factors' flows to seize the ro
An identity holding the Azure Virtual Machine Contributor role pushes a CustomScriptExtension to a production virtual machine. The extension runs the attacker's payload as SYSTEM o
An attacker who has reached Security Admin / Owner scope methodically blinds the SOC before acting: Microsoft Defender for Cloud plans are downgraded to Free, Sentinel analytics ru
An actor with Resource Policy Contributor at subscription scope deleted the deny-public-blob-access policy assignment and set the audit-untagged-resources assignment effect to Disa
The SOC observes an attacker with Backup Contributor scope disabling soft delete on a production Recovery Services vault, then running stop-protection-with-delete-data against the
A web application's managed identity was granted db_datareader (and in practice read of everything) on an Azure SQL database that holds regulated customer records. After compromisi
A foreign managing tenant (a rogue managed-services offer, or an over-broad MSP delegation) holds an Azure Lighthouse delegation over the customer's subscription that grants far mo
An attacker with Contributor on the front-door and WAF resources weakens the edge protections: the Front Door WAF policy is switched from Prevention to Detection (or the managed ru
A shared access signature (SAS) key with the Listen claim for an Event Hub (or Service Bus topic) leaks from a config file. The attacker uses the key to register a new consumer gro
An attacker onboarded an on-prem server to Azure Arc (Microsoft.HybridCompute) and used the Arc Connected Machine agent plus extensions (Custom Script / Run Command over Arc) to ga
A VPC Service Controls perimeter protects a GCS bucket and a BigQuery dataset holding customer exports. An actor with valid service-account credentials did not attack the data dire
An attacker who impersonated a service account holding logging admin and project IAM-policy rights moved to blind detection before the main objective. They broke the audit-log expo
An attacker who gained IAM rights over Compute resources granted their principal roles/compute.osAdminLogin and wrote an attacker SSH public key to project-wide instance metadata,
An internal application is published behind Identity-Aware Proxy so only a specific access group should reach it without a VPN. An over-broad IAM binding grants roles/iap.httpsReso
Binary Authorization is supposed to admit only signed, attested container images to GKE and Cloud Run. A compromised CI/CD deploy identity weakened the Binary Authorization policy
An attacker who has gained access to a developer's Cloud Shell session harvests the gcloud Application Default Credentials and cached OAuth tokens that grant the developer's GCP ac
An identity with rights over Cloud KMS scheduled destruction of the CryptoKey versions used to encrypt production backups and data (CMEK). Destroying a key version erases the mater
Workday Integration System Users (ISUs) are non-human service accounts that authenticate integrations to the tenant with a standing key. An attacker obtains the credential for an o
A malicious or over-scoped OAuth app installed in the Zoom account holds a recording:read scope and a long-lived app token. An attacker drives that token through the Zoom recording
An Asana Personal Access Token (PAT) leaks - committed to a public repo or pasted into a CI log - and an attacker replays it against the API. The token carries one project lead's f
A HubSpot private-app access token is leaked, for example exposed in a frontend bundle or a shared script. The attacker drives the CRM API with that token to bulk-export contacts,
A PagerDuty REST API key is stolen. Rather than steal data, the attacker uses it to blind the responders: they create broad maintenance windows and suppress/auto-resolve alerts so
An attacker with push or merge-request access to a GitLab project edits .gitlab-ci.yml (or adds a job) to echo and exfiltrate the project's masked CI/CD variables, which hold cloud
An attacker with job-configure or pipeline-edit access in Jenkins runs a build (or a Script Console Groovy snippet) that binds and decrypts the entire stored credential store - clo
An attacker obtains an Auth0 Management API token (a machine-to-machine credential with tenant-admin scopes) and uses it to plant persistence in the identity provider itself: a rog
A leaked Twilio API key (SID + secret) is used by an attacker to send SMS phishing from the organization's own trusted sender numbers and to rewrite messaging-service routing so th
A stolen SendGrid API key is used to send phishing through the organization's own verified sending domain, so the messages pass SPF, DKIM, and DMARC and arrive in inboxes looking f
A leaked Stripe restricted API key that was scoped too broadly - carrying both refund-write and customer-read - is being abused from an unfamiliar IP to issue a wave of fraudulent
A hijacked admin session on the organization's SaaS password manager abuses SCIM/admin capability to widen its access and bulk-reveals shared vaults full of long-lived static secre
An attacker with a stolen CI session/token runs a job that dumps CircleCI context and project environment variables, then uses the cloud OIDC credentials and provider keys those va
A credential-stuffed PyPI maintainer account is taken over and used to publish a backdoored release of a popular package, which downstream consumers then pull during normal install
A stolen Terraform Cloud / HCP API token is used to read state outputs (which often contain plaintext secrets) and to queue applies that change real infrastructure. The acting prin
A leaked Cloudflare API token is used to edit DNS records (repointing a proxied login subdomain to attacker infrastructure) and to disable WAF and firewall rules so the protected o
An attacker who replicated the KRBTGT account hash from a domain controller (via DCSync) now forges Kerberos ticket-granting tickets offline for any user and SID with an arbitrary
An attacker with sufficient rights writes a malicious access control entry - for example GenericAll for a low-privileged principal they control - onto the AdminSDHolder object in t
A certificate template on the enterprise CA grants enrollment to a broad, low-privileged group and carries the Any Purpose EKU (or no EKU at all), with no manager approval and no e
An attacker with effectively domain-level rights briefly registers a rogue domain controller - creating server and nTDSDSA objects in the configuration partition and adding DRS/GC
An attacker gained local administrator and an interactive shell on the ADCS certificate authority host CA01, reaching the CA's signing-key context. Whether the key lives on a YubiH
An attacker with write access to a Tier-0 account's altSecurityIdentities attribute adds an explicit X509 certificate mapping pointing to a certificate they control. Because the do
An attacker holds a delegated GenericWrite (or WriteProperty on the delegation attribute) over the computer object SQL01$ through an over-broad object ACL. Using that write - not a
An attacker who already holds Domain Admin injects the Skeleton Key patch into the LSASS process on domain controllers. The patch adds a single master password that authenticates a
An attacker abuses Microsoft Configuration Manager (SCCM) two ways at once: they recover the Network Access Account (NAA) credential, which is distributed in machine policy and rec
An attacker pivots across Microsoft SQL Server linked servers, hopping from a low-value instance to a privileged one through trusted linked-server logins. On a reachable instance t
An operator holding the Authentication Administrator role issues a Temporary Access Pass (TAP) for a target user, signs in with that TAP, and uses the bootstrap session to register
A regional helpdesk operator holds a role scoped to an Administrative Unit, but the AU quietly contains privileged accounts - so the delegated admin can reach a Tier-0 target. Two
An attacker with rights to manage an app registration adds a federated identity credential (FIC) to it - an external OIDC issuer plus a subject claim - and then mints tokens for th
A delegated Entitlement Management catalog owner tampers with an access-package assignment policy: they switch an approval-required policy to auto-assign, add a privileged director
After a phishing alert, the team disables a user and resets the password, believing access is cut. But the attacker had already stolen an access token, and against resources that d
An attacker who briefly held Okta Super Admin builds an Okta Workflows flow - Okta's low-code automation engine that runs inside the IdP - wired to an event trigger and a 15-minute
An attacker with Okta admin reach weaponizes Okta's outbound SCIM provisioning. By creating a user with no HR source, binding it to a group mapped to a dozen SCIM-provisioned SaaS
An attacker compromises the on-prem Windows host running the Okta AD agent - the connector that brokers delegated authentication between Okta and Active Directory. In delegated aut
An attacker who has reached Okta admin registers a token inline hook - an external HTTPS endpoint Okta calls during OIDC/SAML token minting - that returns JSON Patch commands addin
An admin-level attacker does not attack a user - they quietly rewrite Okta's defenses. In one admin session they widen a trusted network zone to include an undocumented attacker ra
An Okta OAuth 2.0 service app authenticates with the client-credentials grant using a private key (private_key_jwt) or client secret - no user, no interactive sign-in, no MFA. An a
An attacker with Intune policy-edit rights loosens a device compliance policy so an attacker-controlled, non-compliant device is reported compliant. Because Entra Conditional Acces
An attacker holding Intune administrative rights queues bulk Wipe and Retire device actions across the entire managed fleet, weaponizing a legitimate management capability as endpo
An attacker imports rogue Windows Autopilot device identities (hardware hashes) and abuses a stolen bulk enrollment token so attacker-controlled hardware provisions through Autopil
An attacker who can edit an Intune SCEP or PKCS certificate profile retargets it so the certificate connector mints authentication certificates for arbitrary subjects - executives,
A scoped Intune operator - provisioned to manage only a small Site-3 device group via a scope tag - exploits an RBAC misconfiguration to widen their own reach to the entire fleet.
An attacker with Intune configuration rights creates a device configuration profile that bundles a rogue proxy (PAC/manual proxy pointing at 198.51.100.237) with an attacker-contro
A Microsoft Teams incoming-webhook (Office 365 connector) URL leaks from a public code repo and an attacker POSTs messages straight into a channel that look like trusted internal a
A registered application holds broad mailbox-impersonation power in Microsoft 365 - either the legacy ApplicationImpersonation RBAC role or the application-wide full_access_as_app
An actor holding an eDiscovery Manager role uses Microsoft Purview to run a content search spanning every mailbox plus SharePoint and OneDrive, then exports the matching results at
After compromising an admin session the attacker runs Add-MailboxPermission to grant a FullAccess delegate right on executive mailboxes to an account they control. FullAccess lets
An over-permissioned role stops and deletes the AWS Config configuration recorder and disables Amazon Inspector to blind compliance drift detection and vulnerability scanning, the
An over-permissioned application role carrying wildcard dynamodb actions is caught mid-exfiltration: it is either running paginated full-table Scans against a customer-records tabl
The SOC sees an SQS queue's access policy rewritten to add an external AWS account as an authorized consumer with sqs:ReceiveMessage and sqs:DeleteMessage - a silent cross-account
A Cognito user pool app client is misconfigured - it is a public client with no secret, the plaintext USER_PASSWORD_AUTH and ADMIN_USER_PASSWORD_AUTH flows are enabled, self-servic
From the management account (or a registered delegated administrator), an attacker creates a service-managed CloudFormation StackSet with auto-deployment enabled whose template pro
A Cosmos DB account primary key (embedded in a connection string) leaks from an app-config repo. The key is a data-plane master credential: it grants full NoSQL read/write directly
An internet-facing workload (vm-batch-worker) was compromised and its system-assigned Managed Identity, which was over-granted Reader at the Tenant Root management group scope, is
An attacker with VM contributor-style RBAC uses Azure Bastion for browser-based access and the VM Run Command extension to execute scripts on VMs through the control plane - agentl
A developer's Azure DevOps personal access token (PAT) leaks. The PAT is a long-lived bearer credential scoped to the developer's permissions: from an unfamiliar IP the attacker cl
An attacker with Data Factory contributor-style access reads or reuses the linked-service credentials that connect a data factory to its data stores - or simply rides the factory's
An identity holds an over-broad datastore role (roles/datastore.owner, carrying datastore.databases.export and full read) - or a leaked service-account key carries it - and an atta
A principal holding an over-broad compute.securityAdmin silently edited the Cloud Armor security policy in front of a production backend service - removing the preconfigured WAF de
An attacker with a compromised internal account created a BigQuery Data Transfer scheduled query that runs as a service account and, on a recurring interval, exports new rows from
An attacker who controls a service account with broad Compute permissions created a snapshot of a sensitive persistent disk (the data volume of a regulated-database VM) and then mo
A NetSuite token-based-authentication (TBA) integration role - meant for a nightly finance sync - has its consumer key and token secret leaked. An attacker replays the token from a
A personal access token (PAT) issued for a BI embed integration - Tableau or Power BI serving dashboards into a customer portal - is leaked from an embedding application's config.
A leaked, over-privileged MongoDB Atlas project API key is used to add 0.0.0.0/0 to the project IP access list - opening the cluster to the entire internet - and a leaked applicati
An attacker who stole a Docker Hub push credential for a widely-used published base image logged in from an unfamiliar location and repointed the :stable tag to a poisoned digest w
A cloud IAM role's OIDC trust policy for GitHub Actions is too broad: it validates the GitHub issuer and audience but does not pin the subject claim, so a workflow from a foreign r
A Vault token attached to an over-broad policy is leaked from an application environment. Because the policy grants read on a wide path glob, the token reads many secret paths in a
An attacker with ArgoCD admin access (or leaked Git repo credentials) commits malicious manifests to the GitOps source of truth, and the ArgoCD controller faithfully syncs them int
An attacker with author/deploy permissions plants an Apex trigger (or a record-triggered Flow) that quietly exfiltrates records to an external endpoint every time a row is written.
An attacker with script-author rights planted a malicious server-side Business Rule (backed by a Script Include) that fires on record operations and silently posts record data to a
On a Windows Server 2025 domain, an attacker with only create/write permission over an OU creates a delegated Managed Service Account (dMSA) and sets its migration attributes - msD
Having stolen the KRBTGT key, an attacker requests a real TGT for a low-privileged user through the normal AS-REQ flow, then decrypts that legitimate ticket with the KRBTGT key, ed
A Domain Admin session extracts the domain DPAPI backup key from a domain controller. That single RSA key is the recovery key DPAPI uses to protect every domain user's master keys,
A DnsAdmins member sets the ServerLevelPluginDll value on a domain controller's DNS service, pointing dns.exe at an attacker DLL staged on a share. Because DNS runs as SYSTEM on th
A member of the Backup Operators group uses SeBackupPrivilege on a domain controller to snapshot the volume and read the locked NTDS.dit database and the SYSTEM registry hive off t
An attacker who controls the WSUS server (or can man-in-the-middle its HTTP client traffic) approves a malicious 'update': a Microsoft-signed LOLBin wrapped with an attacker comman
A service principal in the tenant holds AppRoleAssignment.ReadWrite.All - the Graph permission that lets an app assign app roles to any service principal. Controlling that app's cr
An attacker holding directory-write (Global Administrator) tampers with a custom domain's federation settings - converting a managed domain to federated and registering a rogue Iss
A user is phished into consenting to a malicious OAuth app and the attacker captures a long-lived refresh token. The help desk resets the user's password and closes the ticket - bu
An attacker with sufficient rights abuses Entra Application Proxy and its on-prem connector to publish an internal application to the internet - or hijacks an existing published ap
An attacker steals a service principal's client secret (from a leaked pipeline variable or config file) and uses it to authenticate to the tenant. Because Conditional Access is sco
An attacker enrolls a rogue, unmanaged endpoint into Okta and binds an Okta Verify / FastPass authenticator to it, then gets device assurance to evaluate it as Managed by asserting
An attacker with lambda:PublishLayerVersion publishes a new, backdoored version of a shared Lambda layer that dozens of functions import, then widens its share with AddLayerVersion
An attacker with ram:CreateResourceShare quietly shares production VPC subnets and a Route 53 Resolver rule from your account to an attacker-controlled account, creating a stealthy
An attacker with ec2-instance-connect:SendSSHPublicKey calls the API to push an ephemeral, roughly 60-second SSH public key to a running production instance and then connects, gett
A document planted in an Amazon Bedrock agent's knowledge base carries hidden instructions, and when a normal user question causes the agent to retrieve that document it follows th
An AppSync GraphQL API resolver is missing field-level authorization: the listOrders / getOrder resolvers read the backing DynamoDB data source with no condition tied to the caller
An attacker holding App Service publish (deployment) credentials for a production web app opens the Kudu/SCM advanced-tools debug console at the scm.azurewebsites.net endpoint and
An attacker with an APIM subscription key makes an out-of-band edit to the gateway policy on a production customer API: they delete the inbound validate-jwt element that authentica
An attacker with access to an Azure Machine Learning workspace runs a notebook on a compute instance and uses it to call the instance metadata endpoint, minting the workspace/compu
An attacker with write access to Event Grid added a new event subscription on a production storage system topic and pointed its delivery webhook at an attacker-controlled endpoint,
An attacker who holds the RBAC to manage Azure Update Manager edits a maintenance configuration and attaches a malicious pre-task that pulls a script from an external source and ru
An attacker with write access to a Cloud Composer environment's DAGs bucket uploads a malicious Python DAG. Airflow's scheduler parses the new file and the workers execute its task
An attacker with project-level access created a Cloud Scheduler job that fires attacker-controlled code on a recurring cron - an HTTP target, a Pub/Sub publish, or a Cloud Function
An attacker using a stolen automation identity (deploy-bot) with standing Apigee deploy rights authored and deployed a tampered revision of the payments-api proxy from outside the
An attacker with Pub/Sub or Eventarc edit rights changed a push subscription's endpoint (or created an Eventarc trigger) so the event stream is delivered to an attacker-controlled
A role binding meant to be fenced in by an IAM Condition is walked straight through because the CEL expression is written loosely: a resource.name.startsWith prefix has no boundary
An attacker obtains Jamf Pro administrator and API credentials and turns the MDM server itself into a deployment weapon. From an unfamiliar ASN outside business hours they mint an
A leaked Shopify Admin API access token, belonging to an over-scoped custom app, is used to page through customers and orders and pull customer PII, order history, and limited paym
A stolen JFrog Artifactory access token is used to publish a poisoned artifact into a shared repository that every downstream build resolves from. The principal is the token, and t
An attacker with access to a Zapier workspace builds a new Zap that pipes records out of a connected app (CRM, email, or cloud storage) to an attacker-controlled webhook sink. The
A stolen Vercel deploy token is used to push a malicious production deployment that ships a client-side skimmer (injected loader posting visitor form fields to an external endpoint
A leaked Sentry auth token lets an attacker download the project's uploaded source maps to de-minify and reverse-engineer the production front-end, and read error events that inadv
Leaked Plaid access tokens - and possibly the app's client_secret - let an attacker call the Plaid API and harvest end-users' linked bank-account balances and transaction history.
A developer installs a typosquatted VS Code extension - a lookalike of a popular formatter - that on activation reads the workspace and the OS for credentials (.env, cloud config,
A leaked Grafana service-account token gives an attacker read access to dashboards and data sources, but the distinct danger is what they do next: they create broad silences, delet
Fivetran connectors hold standing credentials to read source systems and write to the warehouse, which makes the data-movement layer itself a path to the data. An attacker who cont
A stolen Duo Admin API key lets an attacker reach into the MFA system itself: it can generate a bypass code for a target user, enroll an attacker-controlled device, or weaken an au
A stolen or rogue Ping (PingOne or PingFederate) OAuth client secret sits at the identity provider, so it can mint client-credentials access tokens and reach every app federated be
A leaked LaunchDarkly API access token is used to flip a feature flag that gates a server-side security control - an authorization check - turning it OFF in production for all user
A Postman workspace, collection, or environment that was left public exposes the secrets developers embedded in it: API keys, bearer tokens, and connection strings the attacker the
Retool internal-tool apps connect to resources (databases and APIs) using stored, privileged credentials, so the app itself holds standing access to production. An attacker who rea
A leaked but valid Confluent Cloud (Kafka) API key lets an attacker join the streaming platform and subscribe a rogue consumer group to sensitive topics, intercepting the live even
A developer opens a Codespace for a repo whose devcontainer was tampered with by a malicious pull request. The postCreateCommand runs attacker code inside the cloud dev environment
A dbt Cloud service token leaks from a misconfigured CI variable. The attacker uses it to trigger a job that runs attacker-authored models and macros, which execute arbitrary SQL i
OneLogin admin API credentials leak from an automation host. Because OneLogin is the single sign-on IdP, those credentials are effectively Tier-0: the attacker uses the admin API t
A leaked Amplitude project API key and secret key - found in a public client bundle and a config repo - are replayed against the Amplitude Export API from an off-pipeline source. T
A leaked Segment access token and source write key let an attacker do two things at once: bulk-read unified customer identity profiles through the Profiles API, and add a rogue Web
A Webflow site publish token leaks from a build pipeline. Because the token controls the live public website, the attacker does two things visitors can feel: injects a malicious ex
A read-only Wiz API token leaks from a SOAR integration. Wiz is the cloud security posture tool, so its findings are a curated, prioritized map of the organization's most exploitab
A finance analyst at Northwind Robotics receives an urgent Teams video call from someone who looks and sounds exactly like the CFO. The audio and video are AI-generated. The 'CFO'
An attacker shares a finance manager at Meridian Freight an ordinary-looking vendor reconciliation document that hides instructions for the company AI assistant inside its text. Wh
A retailer runs a public customer-facing support and sales chatbot built on an LLM and wired to real refund, promo, and order tools. An attacker crafts prompts that jailbreak it, o
The internal AI help assistant at Northwind Robotics answers employee questions using retrieval-augmented generation over indexed company sources: the wiki, ticket threads, and sha
An autonomous AI agent runs in Azure with its own managed identity and a set of tools it can call: read support tickets, query internal databases, call internal APIs, and send mess
A remote candidate applies to Meridian Logistics for an IT support role. During the video interview and the remote onboarding identity-proofing check, the candidate presents an AI-
Lacking a sanctioned AI tool, a backend engineer at Northwind Robotics pastes production source code - a config file carrying a live AWS access key, a production database connectio
An attacker with write access to the training dataset and feature store for a production fraud-detection model on Azure ML injected poisoned samples into a new data asset version s
A company serves a proprietary ML model through a hosted inference API on AWS (a SageMaker-style endpoint) that has weak authentication, no meaningful per-principal rate limiting,
A customer-facing LLM chatbot at a SaaS company carries a hidden system prompt that holds both its guardrails and, through a developer anti-pattern, an embedded API key plus an int
An employee at Northwind Robotics gets an external Microsoft Teams call from someone presenting as the internal IT help desk, claiming an urgent security fix is needed. The caller
Info-stealer malware on an employee's endpoint harvests the Microsoft Teams desktop client's cached authentication and session tokens, along with browser session cookies, from loca
Teams Shared Channels (Teams Connect / B2B direct connect) let an internal channel be shared directly with an external organization's tenant, so their users collaborate in-place wi
An operator with Exchange administrative footing self-assigns the Exchange RBAC 'Mailbox Import Export' management role - a role not granted by default even to Organization Managem
An attacker with stolen mailbox credentials plants a client-side Outlook rule with a start-application action and backs it with a malicious custom form and a folder Home Page. When
An external attacker abuses Exchange Online's Direct Send path - the tenant smart host contoso-com.mail.protection.outlook.com - to relay UNAUTHENTICATED mail that spoofs internal
An abused Exchange admin account creates an inbound connector in Exchange Online that maps a range of attacker-controlled IPs to a trusted partner. Mail from attacker infrastructur
BitLocker recovery keys for managed Windows devices at Meridian Logistics are escrowed to Intune and Entra so the help desk can recover locked-out machines. An account that picks u
An attacker who has gained Intune configuration rights creates a custom OMA-URI device configuration profile and assigns it to all devices. The profile pushes arbitrary Configurati
An attacker who holds Intune application-management rights packages malware as a Win32 app, a .intunewin package, and uploads it as a line-of-business app. They assign it as REQUIR
An operator matching the Scattered Spider (UNC3944 / Octo Tempest) playbook phones your IT help desk impersonating a named privileged employee, passes knowledge-based verification
A state-linked actor matching APT29 / Midnight Blizzard tradecraft runs a coordinated device-code lure against several executives at once - a trusted-looking Teams chat and email a
A developer is approached by a fake recruiter and runs a malicious 'coding test' package on their workstation. It harvests browser session cookies, cloud CLI credentials, the git c
A state-linked actor matching Volt Typhoon's playbook operates almost entirely with built-in tools and stolen valid accounts to stay invisible. After entering via an exposed edge a
A phishing email delivers a loader that beacons to a Cobalt Strike C2. The actor harvests credentials and moves laterally, climbing toward Tier-0 to reach domain dominance and pre-
A state-linked actor matching Sandworm's playbook reaches Domain Admin and turns Group Policy into a distribution channel for a destructive wiper - the technique seen in their atta
Your tenant already federates a small partner population through a trusted inbound identity provider. That IdP's subject/NameID mapping is too permissive - just-in-time matching re
A user is lured by a ClickFix fake-CAPTCHA into pasting and running hidden PowerShell (Win+R, Ctrl+V, Enter) that drops an infostealer and lifts their Microsoft 365 session token -
A password-protected lure on a trusted sharing platform leads the user to what looks like a normal Microsoft 365 sign-in, which they complete legitimately including MFA. They are t
A LockBit ransomware-as-a-service affiliate lands on an internet-facing server by abusing a valid account over RDP/VPN after a brute-force run, dumps LSASS to harvest credentials,
ALPHV (aka BlackCat, Noberus) gets in through a public-facing app and a reused valid account, escalates by bypassing UAC and manipulating access tokens toward Domain Admin, disable
Play (aka PlayCrypt) breaks in through an exploited public-facing edge appliance, pivots into AD, dumps credentials, and reaches Domain Admin. Their signature is deployment: instea
8base runs a Phobos-based encryptor delivered by a SmokeLoader loader. The actor phished in, stole credentials, escalated through token impersonation to Domain Admin, and is now in
An infostealer on an employee's laptop harvested that person's corporate logins and live SaaS/IdP session cookies and shipped the log to a marketplace, where an access broker has n
A LAPSUS$-style extortion crew starts with a valid account: credentials bought from an infostealer log let them sign in but MFA blocks them. They prompt-bomb the user with push not
A China-nexus actor tracked as Storm-0558 obtained a stolen identity-provider token-signing key and, exploiting a token-validation gap, minted authentication tokens for targeted us
A state-sponsored actor modeled on APT28 (Fancy Bear, GRU) runs a low-and-slow password spray from rotating anonymized infrastructure - Tor exit nodes and residential proxies - aga
A Kimsuky (APT43) operator sends a tailored spear-phishing message to a policy analyst and harvests the credential through a fake login page that mirrors the real Entra sign-in. Us
A Charming Kitten (APT35) operator spends days building rapport through a fake conference-organizer persona before ever sending a link, then funnels the target through an adversary
Scattered Spider (UNC3944) targets a privileged cloud identity, ports the user's mobile number to a SIM they control (or social-engineers the carrier/help desk), and uses the inter
An unauthenticated attacker sends a crafted deserialization payload to an internet-facing on-prem SharePoint server (the ToolShell class of attack) and gets code execution as the S
An internet-reachable enterprise unified-communications server ships with a static, vendor-set root-level account whose password is hardcoded and cannot be changed by the admin. An
An internet-facing mobile-access gateway that brokers connections between managed devices and back-end systems (mail, file, and directory) exposes an unauthenticated management end
A user searches for a common IT utility on a mainstream search engine and clicks the top result, which is a poisoned/malvertised page that serves a trojanized installer instead of
A phishing lure delivers a commodity RAT loader onto a workstation, which spawns a scripting-interpreter stager that opens a persistent C2 beacon over ordinary web traffic. Hours b
An operator runs an AI-assisted, modular platform that scans the internet at scale, exploits whatever answers, and pipes harvested credentials into a collection channel. There is n
A public-facing Apache ActiveMQ message broker is reachable from the internet and vulnerable to an unauthenticated deserialization RCE that loads an attacker-controlled Spring clas
A Lynx ransomware intrusion opens with a single successful RDP logon to an internet-exposed host, with no preceding brute force, credential stuffing, or failed authentication from
A loader from a single phishing click sat dormant for roughly fifty days, then the actor resumed: C2 re-activated, a Day-0-harvested credential was replayed over remote services, a
A single AD intrusion carries tooling and tradecraft that map to three different ransomware brands at once: a phishing-delivered loader, a commodity RAT beaconing to attacker infra
A user is redirected through a traffic-distribution service to a convincing fake-fix page (a ClickFix/FileFix-style lure) that shows a fabricated error and coaches them to open the
An RDP server is published straight to the internet with no gateway and no MFA. An attacker sprays a large list of usernames against it with a small set of common passwords, and af
A senior infrastructure engineer serving out a resignation shows anomalous bulk access and personal-cloud egress. Intent is genuinely ambiguous - the same pattern fits legitimate a
A trusted cloud platform engineer, mid-maintenance, applies a destructive change to production instead of staging - wrong profile, right ticket. A security control is disabled and
A well-meaning nurse exports a panel of patient records to her personal drive to finish charting from home. It is a real HIPAA data-handling incident and a policy violation - and i
A trader on the Frankfurt desk is quietly feeding pre-release deal flow to a competitor fund that pays him through an encrypted channel. He is not a victim and not careless - he wa
A cleared engineer is quietly moving controlled program data to a foreign party - but the evidence says he is being coerced, not paid. A threat against his family abroad is forcing
An engineer pastes proprietary source code and a slice of customer data into a public AI chatbot to debug faster. No malice, no sanctioned tool - just someone trying to get their w
An autonomous build agent ingests a poisoned dependency doc, and an injected instruction turns it against you - it is now reading secrets and staging exfiltration with its own prod
Your ops agent runs dangerous shell commands only behind a human 'approve this action?' gate - the control the whole team trusts. Then a destructive command runs with the gate show
Your data agent uses an MCP tool server to fetch documents. A crafted tool call makes that server reach the cloud metadata endpoint, read files outside its allowed path, and hand b
Your knowledge agent acted on a 'memory' it never truly stored - a planted instruction sitting in its vector store - and its memory tool handed back another tenant's saved credenti
Your SOC's AI triage marked a clearly malicious sample benign, and its summary quietly echoed reassurance the attacker wrote into the malware's own strings. The adversary is not at
No scenarios match that search. Try a different term or system.
Looking for what is new? See the library updates. Start training free in the quickstart.