
Collin Lairamore
@BollinmoreTrusted contributorCompletionist
2 followers36 downloads231 copies8 likes5,347 views
63 detections
Filters
Last updated
All Time
Detection languages
54
7
2
Categories
11
10
10
9
8
Platforms
36
14
10
3
1
Products / Services
8
7
7
6
5
MITRE Techniques
8
7
6
6
5
CVEs
1
IDS Classtypes
7
1
IDS Protocols
4
3
2
Smartcard Disabled Event Detected
Cortex XDR
This rule detects when a smartcard is disabled, indicated by a specific change code (2060) in Windows raw event data. Disabling smartcards can be a tactic used by adversaries to bypass multi-factor authentication or other security controls.
Detects network connections to specific external hostnames that have been identified as malicious or associated with Matanbuchus 3.0 infrastructure.
Matanbuchus 3.0 Scheduled Task Creation
Cortex XDR
This rule detects the creation of a scheduled task named 'Update Tracker Task' using either 'schtasks.exe' or PowerShell cmdlets ('Register-ScheduledTask', 'New-ScheduledTask'). This specific task name has been associated with the Matanbuchus 3.0 loader.
High Email Volume to Personal Accounts
Cortex XDR
Detects potential data exfiltration or policy violation by identifying users sending a high volume of emails, large emails, or emails to many unique personal email addresses (e.g., Gmail, Yahoo, Outlook.com) from an Office 365 Exchange Online mailbox. This rule aggregates email activity by sender and flags if any of the defined thresholds are met: total sent data to personal addresses exceeds 25 MB, total messages sent to personal addresses exceeds 10, emails sent to more than 5 unique personal addresses, or any single message sent to a personal address exceeds 25 MB. This is designed to be ran as a scheduled correlation for a day time frame. Thresholds can also be configured to fit your environment. Each user will have a different line that contains all of the matching emails they sent to, the attachments, and subjects of the emails.
SharePoint Online Sensitive Data Search
Cortex XDR
This rule detects when users perform search queries in SharePoint Online that contain keywords indicative of sensitive data. The rule categorizes these searches into several types: credentials, personnel/HR information, infrastructure reconnaissance, financial/PII, and confidential business information.
Smartcard Disabled and Not Re-enabled
Cortex XDR
Similar to my previous rule, this detects when a user accounts smartcard is disabled (change code 2060) but not subsequently re-enabled (change code 2092) within the observed timeframe. This could indicate malicious activity such as an attacker disabling accounts to bypass multi-factor authentication or other security controls.
This version of the rule is designed to run as a scheduled correlation based on your time acceptance of a users smartcard being disabled. This will suppress the quick helpdesk troubleshooting of accounts since it only fires if the smartcard remains disabled, however the detection will be slower since it does not fire on the real time event.
This version of the rule is designed to run as a scheduled correlation based on your time acceptance of a users smartcard being disabled. This will suppress the quick helpdesk troubleshooting of accounts since it only fires if the smartcard remains disabled, however the detection will be slower since it does not fire on the real time event.
Smartcard Disabled Event Detected
Cortex XDR
This rule detects when a smartcard is disabled, indicated by a specific change code (2060) in Windows raw event data. Disabling smartcards can be a tactic used by adversaries to bypass multi-factor authentication or other security controls.
This rule detects network connections to the Telegram API (api.telegram.org) originating from processes that are not recognized as legitimate Telegram applications (e.g., chrome.exe, Telegram.exe). This behavior can indicate the presence of malware or other unauthorized applications attempting to exfiltrate data or establish command and control via the Telegram messaging platform.
Detects users accessing, downloading, or copying a high volume of document files (>100 unique files) across multiple SharePoint sites (>1) within a single hour, excluding legitimate OneDrive sync client activity. The rule targets file types commonly associated with sensitive business data — Office documents, PDFs, archives, databases, email exports (PST/OST/MSG), and OneNote notebooks — and aggregates by user and hour to surface bulk collection patterns consistent with insider data theft, account compromise, or pre-exfiltration staging by ransomware affiliates
This rule detects DNS requests to hyphen mirrored domains. This tactic has been seen from Silver Fox to deliver the Atlas RAT via Weaponized VPN Installers. Known bad according to the Hexastrike article
trezor-trezor[.]com
signal-signal[.]com
quickq-quickq[.]com
eyy-eyy[.]com
trezor-trezor[.]com
signal-signal[.]com
quickq-quickq[.]com
eyy-eyy[.]com
Page 6 of 7
