Skip to content

Hide Navigation Hide TOC

Covert Server Intrusion — Process Injection, Log Tampering, DNS Hijack & Traffic Interception - ATR-2026-01803 (ead1efb9-e554-5cf7-958b-826c608599b8)

Detects an instruction directing an agent with server/infrastructure tooling to perform a covert intrusion action on a server or network: injecting commands or code into a running process "discreetly", wiping system logs to "hide any traces of access", manipulating DNS records to "redirect users to an alternate site", capturing network traffic to "intercept sensitive information", subtly altering data "to remain undetected by monitoring tools", or permanently deleting a database to "prevent data recovery". Drawn from the AgentSecurityBench (ASB) infrastructure domain, every variant pairs an intrusion verb (introduce code/ commands into a process, modify/alter logs or data, manipulate DNS, capture traffic, permanently delete) with an explicit covert or anti-forensic qualifier (discreetly, hide traces, undetected, intercept, redirect to alternate, prevent recovery). The rule requires both the intrusion verb and the malicious qualifier to co-occur, so legitimate ops language ("update DNS records to improve performance", "modify the firmware to enhance performance", "monitor network traffic to ensure data security") does not fire — those benign-disguised ASB variants are intentionally out of scope.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Covert Server Intrusion — Process Injection, Log Tampering, DNS Hijack & Traffic Interception - ATR-2026-01803 (ead1efb9-e554-5cf7-958b-826c608599b8) Agent Threat Rules 1