Intelligence View
Metro Exodus 'Sam's Story' DLC releases on Xbox One
Metro Exodus' second DLC is here, offering players a new story to enjoy. What you need to know The next Metro Exodus DLC, Sam's Story, has released on Xbox One. The DLC is coming out on PC at 12 PM ET. The DLC follows the character Sam…
What you need to know
The next Metro Exodus DLC, Sam's Story, has released on Xbox One.
The DLC is coming out on PC at 12 PM ET.
The DLC follows the character Sam as he attempts to journey back to the USA.
The majority of the expansion takes place in the port city of Vladivostok.
The second DLC for Metro Exodus, Sam's Story, has been released on Xbox One by developer 4A Games. You'll need the base game in order to play it, and if you happen to own the Metro Exodus Expansion Pass, you'll unlock access to it immediately. The expansion is coming out shortly on PC at 12 PM ET.
The DLC follows the character Sam as attempts to find a way to get back to the USA from Russia after he starts to believe there's a chance his family survived the nuclear war that originally ravaged the world. Most of the narrative occurs in the port city of Vladivostok as Sam tries to find a way to sail back to the USA with. Like the ot...
1. Sofort-Triage & Abwehrmaßnahmen
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - Metro Exodus 'Sam's Story' DLC releases on Xbox One
id: ee414f58-504b-486f-be6f-d02f8ef8a556
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-27"
description = "YARA Signature for "
strings:
$str = "Metro Exodus \'Sam\'s Story\' DLC" ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Metro Exodus Sams Story DLC releases on ")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countmessage: "*Metro Exodus Sams Story DLC releases on *"CommonSecurityLog
| where Message has "Metro Exodus Sams Story DLC releases on "
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc2. Cyber Threat Intelligence & Forensik
MITRE ATT&CK Matrix Navigator 14 Taktiken
tsecurity.de Cognitive Threat RAG
Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.