
Disney Intel&Coffee
@Ills3CCompletionist
0 followers14 downloads12 copies0 likes109 views
4 detections
Filters
Last updated
All Time
Detection languages
3
1
Categories
2
1
1
1
1
Platforms
2
1
1
Products / Services
1
1
1
1
1
MITRE Techniques
2
2
1
1
1
This rule establishes a daily baseline of request volumes to mail.google.com per user and per host using proxy logs. It identifies anomalous spikes in traffic or unexpected users/hosts accessing personal webmail, which may indicate data exfiltration using a legitimate web service.
Detects the rare 'AssumeRoot' event in AWS STS followed by high-impact administrative or destructive API calls within a one-hour window. This behavior often indicates an adversary attempting to gain elevated, privileged access to perform unauthorized actions such as disabling logging, deleting infrastructure, or modifying IAM policies.
Detects high-volume activity (BLOCK or COUNT actions) from the AWS Shield Advanced managed DDoS protection rule set within a 1-minute time window. The rule alerts on potential Layer 7 DDoS attacks by monitoring for significant spikes in event volume or the number of unique source IP addresses targeting a specific AWS WAF Web ACL.
Detects the loading of the 'truesight.sys' driver from non-standard or temporary locations. This activity is associated with a campaign where threat actors use a vulnerable version of this driver to terminate security products before deploying ransomware or RATs, a technique known as Bring Your Own Vulnerable Driver (BYOVD).
