
Lewis Weedon
@LewisWeedonCompletionist
1 follower11 downloads420 copies30 likes2,572 views
5 detections
Filters
Last updated
All Time
Detection languages
5
Categories
2
2
2
1
1
Platforms
4
1
Products / Services
3
1
1
MITRE Techniques
3
2
2
2
2
This rule detects potential phishing activity by correlating email delivery of Excel attachments with subsequent network connections to known malicious domains initiated by common browser or office processes. It identifies cases where a user may have opened a suspicious Excel file and initiated an outbound network request to a flagged domain within 24 hours of receiving the email.
EvilAi Campaign
This rule detects file and network indicators of compromise (IOCs) associated with the fake 'ClawdBot Agent' VS Code extension malware campaign. It looks for known malicious file hashes and network connections to C2 infrastructure, including specific C2 checks for ScreenConnect relay on port 8041.
This rule detects network connections to domains known to host and distribute malicious file converter applications that install Remote Access Trojans (RATs).
This rule detects outbound network connections to command and control (C2) domains and identifies files by name or hash associated with malicious PDF editor campaigns (e.g., ConvertMate, PDFClick, PDFSkills). These campaigns use malicious PDF editors for C2 communication, to download additional payloads, and for initial execution.
