Back to list

Incident Overview

Incident ID CINC-20251221-220A3DB9
Severity Medium (70)
Status new
Alert Count 28
Host Count 1

Timeline

First Seen 2025-12-21 23:47:31
Last Seen 2025-12-22 07:51:06
Duration 0d 8h 3m
Created 2025-12-22 00:41
Updated 2026-01-13 15:14

Kill Chain Analysis

Rec... Ini... Exe... Per... Pri... Def... Cre... Dis... Lat... Col... Com... Exf... Imp...
Observed Tactics:
Machine Learning
Techniques:
Sensor-based ML

Affected Hosts (1)

BOOK-R0BE6S1NC3

Related Alerts (28)

Severity Status Hostname Description Tactic Command Line Time
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 07:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 06:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 05:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 04:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 03:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 02:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 01:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 01:07
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 01:03
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:59
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:55
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:47
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:43
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:39
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:35
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:31
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:27
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:23
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:19
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:15
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:11
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:07
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-22 00:03
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-21 23:59
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-21 23:55
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-21 23:51
High new BOOK-R0BE6S1NC3 A file written to the file system meets the on-sensor machine learning high confidence threshold for malicious files. Detection is based on a high degree of entropy, packing, anti-malware evasion, or other similarity to known malware. Machine Learning "C:\Program Files\dotnet\dotnet.exe" exec "C:\Program Files\dotnet\sdk\9.0.201\Roslyn\bincore\VBCSCompiler.dll" "-pipename:TDGwX3Acbe8Vn1VPJ84NuZVCw6abR8+_THshQ4OwCv0" 12-21 23:47