

We curate threat intelligence to provide situational awareness and actionable insights
Threat Identifier Detections
Atomic detections that serve as the foundation of our detection framework.
Threat Scenario Detections
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
Reports Hot Off the Forge
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024




All Threat Reports
German Intelligence Services warn of APT27
The German Domestic Intelligence Service (BfV) has issued an advisory on APT27 targeting German commercial organizations. The group uses the HyperBro RAT for remote access and is known for exploiting vulnerabilities in Zoho AdSelf Service Plus and Zoho ManageEngine. APT27 aims to steal business secrets and intellectual property, with the potential for supply chain attacks.
Agent Tesla & Dridex
Palo Alto Unit42's research reveals an uptick in Agent Tesla and Dridex malware distributions via phishing, using Excel macros and XLL droppers, from July to December 2021.
APT36's Malware Arsenal
TrendMicro's tracking of APT36/Earth Karkaddan reveals their use of Crimson RAT, ObliqueRat, and CapaRAT in campaigns from January 2020 to September 2021. The group employs spear-phishing and USBs for initial access, using themes like government and coronavirus to lure victims. The RATs are capable of extensive system reconnaissance, data collection, and exfiltration.
Global Affairs Canada Cyberattack
On January 19, 2022, Global Affairs Canada (GAC) detected a cyberattack causing network disruptions. While critical services remain available, some online services are still recovering. The GAC, responsible for managing Canada's foreign and consular relations, confirmed no impact on other government departments.
US Federal Government Initiative to protect Water Systems
The US government and the EPA have launched an initiative to protect the nation's water systems, focusing on enhancing cyber defense technologies. A pilot program by the EPA and CISA aims to improve ICS monitoring and cooperation among water sector entities, safeguarding over 150,000 systems serving 300 million Americans.
CVE-2021-4034 - Polkit's Pkexec - LPE
Qualys has identified CVE-2021-4034, a local privilege escalation vulnerability in the SUID-root program polkit's pkexec, present on all major Linux distributions including Ubuntu, Debian, Fedora, and CentOS. Exploiting this vulnerability is described as trivial due to the ease of execution, with various proofs-of-concept released by security researchers demonstrating the vulnerability. The impact is widespread, offering attackers high privileges across all affected Linux distributions.

About the Forge & Threat Reports
Our mission is to assess the operational behaviors of all threats to provide the community, and our customers, with actionable information and enterprise-ready detections in order to defend themselves in an ever- changing threat landscape.

Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
Whitepapers

The World's Best SOC Teams Use Anvilogic
Build Detections You Want, Where You Want






.png)