avatar

Disney Intel&Coffee

@Ills3C
Completionist
0 followers14 downloads12 copies0 likes109 views

4 detections

This rule establishes a daily baseline of request volumes to mail.google.com per user and per host using proxy logs. It identifies anomalous spikes in traffic or unexpected users/hosts accessing personal webmail, which may indicate data exfiltration using a legitimate web service.
avatar
Disney Intel&Coffee@Ills3C
avatar
Detections.ai Community
16 days ago
105
Detects the rare 'AssumeRoot' event in AWS STS followed by high-impact administrative or destructive API calls within a one-hour window. This behavior often indicates an adversary attempting to gain elevated, privileged access to perform unauthorized actions such as disabling logging, deleting infrastructure, or modifying IAM policies.
avatar
Disney Intel&Coffee@Ills3C
avatar
Detections.ai Community
16 days ago
102
Detects high-volume activity (BLOCK or COUNT actions) from the AWS Shield Advanced managed DDoS protection rule set within a 1-minute time window. The rule alerts on potential Layer 7 DDoS attacks by monitoring for significant spikes in event volume or the number of unique source IP addresses targeting a specific AWS WAF Web ACL.
avatar
Disney Intel&Coffee@Ills3C
avatar
Detections.ai Community
16 days ago
001
Detects the loading of the 'truesight.sys' driver from non-standard or temporary locations. This activity is associated with a campaign where threat actors use a vulnerable version of this driver to terminate security products before deploying ransomware or RATs, a technique known as Bring Your Own Vulnerable Driver (BYOVD).
avatar
Disney Intel&Coffee@Ills3C
avatar
Detections.ai Community
8 months ago
100101