• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    US-First RMM phishing campaign domains/IP/payload URL IOC hunt

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 27 days ago•8•0•14

    This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.

    Microsoft Sentinel (KQL)

    Tags

    T1566 - PhishingT1204 - User ExecutionT1071 - Application Layer ProtocolT1105 - Ingress Tool TransferTA0002 - ExecutionNetwork ConnectionNetwork Connection OutboundProcess CreationFile DownloadWindowsWindows Defender Atpkql

    Found in

    • US-First RMM Phishing Campaign Using Vercel InfrastructureLast updated 27 days ago
    • US-First RMM Phishing Campaign Using Vercel InfrastructureLast updated 27 days ago
    • US-First RMM Phishing Campaign Using Vercel InfrastructureLast updated 27 days ago
    • US-First RMM Phishing Campaign Using Vercel InfrastructureLast updated 27 days ago
    • US-First RMM Phishing Campaign Using Vercel InfrastructureLast updated 27 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?