avatar

Montaser Ismail

@M0nt3x
Trusted contributorCompletionist
0 followers4 downloads306 copies1 like797 views

40 detections

This rule monitors for indicators of compromise (IOCs) and behavioral patterns associated with the Lazarus Group's 'Operation Dream Job' campaign. It tracks known malicious hashes, domains, and IP addresses, alongside suspicious activities such as PDF viewer abuse, DLL side-loading, process injection, persistence mechanism creation (Registry/Scheduled Tasks), and recruitment-themed phishing lures.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
37083
This rule detects potential malicious activity related to the 'gh-token-monitor' toolkit by aggregating suspicious signals across file, process, and network data sources on an individual host. It looks for the presence of specific configuration files or scripts, execution of commands associated with the toolkit or setup processes, and network connections to known command-and-control domains or IP addresses. A host is flagged if it exhibits two or more of these distinct signal categories, suggesting a high-confidence indicator of compromise.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
2014
Detects network connections to known suspicious infrastructure, including specific domains associated with Session, catbox.moe, or targeted npm registry and GitHub API queries initiated by common command-line utilities. This behavior often suggests adversary communication, data staging, or potential tool/malware delivery.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
406
This rule performs a comprehensive hunt for activities associated with the MuddyWater (also known as Boggy Serpens) threat group, specifically relating to their 'Operation Olalampo' campaign. It monitors for spearphishing artifacts (lure documents and attachments), execution of specific malware and drop artifacts, the use of LOLBins by Office applications, unauthorized remote access via AnyDesk, Telegram-based C2 communication, and persistence mechanisms such as registry run keys and specific file extensions (.wdlp).
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
290141
This rule detects file-based activity associated with a tool named 'gh-token-monitor', which is likely used for the monitoring or exfiltration of GitHub access tokens from a compromised host. The rule monitors for the creation or presence of specific scripts, configuration files, and directory paths associated with this activity, including files related to a 'claude' configuration.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
305
Detects package installation activities involving potentially compromised TanStack packages during the defined malicious publish window (2026-05-11 to 2026-05-12). The rule monitors common Node.js package managers (npm, pnpm, yarn, bun) and CLI tools for commands attempting to fetch identified affected versions of @tanstack/* libraries.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
103
Identifies devices with software versions affected by CVE-2026-45321 or devices running TanStack related packages identified via vulnerability management and software inventory data.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
1 month ago
001
Detects inbound emails containing password-protected archives (rar, zip, 7z) from either common freemail providers or domains matching known social engineering themes (e.g., webinar, interview, research). The rule specifically flags emails where the subject or body includes password hints (e.g., 'pwd', 'extract', 'unzip') indicating an attempt to deliver malicious payloads while evading email gateway inspection.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
2014
Detects attempts to impair Windows Defender protection by modifying preferences via PowerShell (Set-MpPreference/Add-MpPreference), stopping the WinDefend service using sc.exe, or altering sensitive Windows Defender registry keys. This rule monitors process execution and registry modification events, excluding known legitimate management tools like Intune and SCCM.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
5011
This rule detects user interaction with potentially malicious URLs from known Dynamic DNS (DDNS) providers or URLs containing suspicious keywords frequently associated with phishing lures (e.g., login, auth, verify, mfa). It filters out known legitimate Microsoft domains to reduce noise.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
10011