logo

Courses of Action

Use this page to search and filter courses of action.

ValueExternal Ref
Alert on downloads via wget/curl to /tmp or executable drops in web directories
Alert on hidden PowerShell spawned via Shell.Application.ShellExecute
Application Developer GuidanceATT&CK Enterprise
Apply Ivanti EPMM patches immediately
Apply Microsoft Outlook patches for CVE-2023-23397 and CVE-2023-29324
Apply patches to edge devices immediately
Apply SAP Security Note #3594142
Apply Sigma rule: Script Interpreter Execution From Suspicious Folder
Apply Sigma rule: Suspicious Microsoft Office Child Process
Assess multi-cloud/hybrid architecture for continuity against physical cloud region disruption
Avoid exposing company names in SSL certificate CN/SAN
Avoid relying solely on ransom payments or insurance; prioritize backups and incident response
Block .co.com second-level domains and brand-mirroring FQDNs
Block unauthenticated public access via WAF/firewall rules
Block wscript.exe via application whitelisting
Centralize logging with sufficient retention for threat hunting
Conduct red-teaming and data-extraction testing of LLMs
Continuous configuration monitoring for unauthorised firmware and routing changes
Data Destruction Mitigation
Deploy YARA rules for ONNX detection
Detect and block ISO mounting events
Detect curl.exe use with SOCKS5/TOR (Sigma)
Detect HTTPS C2 with Base64 Parameters
Detect Office Applications Spawning LoLBins
Detect phishing kit artifacts
Detect renamed AutoIt execution (SIGMA)
Detect suspicious curl.exe downloads (SIGMA)
Detect suspicious script execution from Temp folder (SIGMA)
Detect suspicious Windows Defender exclusion additions (Sigma)
Disable browser password caching
Disable Macros
Disable unnecessary remote services and default accounts
Email filtering for cloud-shared documents
Embed rapid counter-disinformation mechanisms and synchronize intelligence sharing
Employee education on dangers of embedded QR codes in PDFs
Empower employees (training and phishing simulations)
Enable command-line process auditing for LNK execution
Enable MFA for admin accounts
Enable multi-factor authentication (MFA)
Enable two-factor authentication (2FA)
Enforce least privilege
Enforce MFA and credential hygiene
Enforce MFA for staff (especially admin/payment accounts)
Enforce PowerShell Constrained Language Mode via WDAC/AppLocker
Enforce short-lived OAuth tokens and conditional access
Enforce strict IT/OT segmentation
Enforce strong unique passwords and rotation
Exploit Protection
Harden and inventory network edge devices
Harden edge appliances and VPN gateways