avatar

Min Sakka

@AlphaOmega
Completionist
0 followers80 downloads43 copies0 likes177 views

15 detections

Enumerates installed Chrome extensions, cross-references against public blocklists, and flags suspicious permissions.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
103
This rule detects anomalies in outbound network data transfer by comparing the current daily volume of data sent to external, non-private IP addresses against the historical average for those specific sources. It alerts when the daily volume exceeds 500MB and shows a significant spike (3x or more) compared to historical baseline data or when no historical data is available for a new source connection.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
202
Detects the forged Next.js Server Action invocation used to deliver the
RCE payload after the encryption key has been disclosed. The request is
a multipart/form-data POST containing a "$ACTION_REF_*" field together
with the numbered "$ACTION_<ref>:0/1/2" descriptor fields (action id,
argument list, base64-encoded AES-GCM ciphertext for the closure-bound
args) plus one additional attacker-controlled form field carrying the
payload. Legitimate Server Action calls originate only from the app's
own client bundle and do not normally arrive as raw multipart posts
crafted with a generic HTTP client / no browser fingerprint, especially
shortly after a manifest-disclosure request from the same source (see
companion rule "Next.js Server-Reference-Manifest Disclosure via
Backslash Path Traversal").
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
001
Detects potential JWT algorithm-confusion or authentication-bypass attempts
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
001
Enumerates installed Chrome extensions, cross-references against public blocklists, and flags suspicious permissions.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
4 months ago
2011