
Montaser Ismail
@M0nt3xTrusted contributorCompletionist
0 followers4 downloads306 copies1 like797 views
40 detections
Filters
Last updated
All Time
Detection languages
40
Categories
20
10
8
6
5
Platforms
30
7
6
2
1
Products / Services
19
6
4
3
2
MITRE Techniques
14
11
7
6
6
CVEs
2
1
1
1
This rule monitors for indicators of compromise (IOCs) and behavioral patterns associated with the Lazarus Group's 'Operation Dream Job' campaign. It tracks known malicious hashes, domains, and IP addresses, alongside suspicious activities such as PDF viewer abuse, DLL side-loading, process injection, persistence mechanism creation (Registry/Scheduled Tasks), and recruitment-themed phishing lures.
This rule detects potential malicious activity related to the 'gh-token-monitor' toolkit by aggregating suspicious signals across file, process, and network data sources on an individual host. It looks for the presence of specific configuration files or scripts, execution of commands associated with the toolkit or setup processes, and network connections to known command-and-control domains or IP addresses. A host is flagged if it exhibits two or more of these distinct signal categories, suggesting a high-confidence indicator of compromise.
Detects network connections to known suspicious infrastructure, including specific domains associated with Session, catbox.moe, or targeted npm registry and GitHub API queries initiated by common command-line utilities. This behavior often suggests adversary communication, data staging, or potential tool/malware delivery.
This rule performs a comprehensive hunt for activities associated with the MuddyWater (also known as Boggy Serpens) threat group, specifically relating to their 'Operation Olalampo' campaign. It monitors for spearphishing artifacts (lure documents and attachments), execution of specific malware and drop artifacts, the use of LOLBins by Office applications, unauthorized remote access via AnyDesk, Telegram-based C2 communication, and persistence mechanisms such as registry run keys and specific file extensions (.wdlp).
This rule detects file-based activity associated with a tool named 'gh-token-monitor', which is likely used for the monitoring or exfiltration of GitHub access tokens from a compromised host. The rule monitors for the creation or presence of specific scripts, configuration files, and directory paths associated with this activity, including files related to a 'claude' configuration.
Detects package installation activities involving potentially compromised TanStack packages during the defined malicious publish window (2026-05-11 to 2026-05-12). The rule monitors common Node.js package managers (npm, pnpm, yarn, bun) and CLI tools for commands attempting to fetch identified affected versions of @tanstack/* libraries.
Identifies devices with software versions affected by CVE-2026-45321 or devices running TanStack related packages identified via vulnerability management and software inventory data.
Detects inbound emails containing password-protected archives (rar, zip, 7z) from either common freemail providers or domains matching known social engineering themes (e.g., webinar, interview, research). The rule specifically flags emails where the subject or body includes password hints (e.g., 'pwd', 'extract', 'unzip') indicating an attempt to deliver malicious payloads while evading email gateway inspection.
Detects attempts to impair Windows Defender protection by modifying preferences via PowerShell (Set-MpPreference/Add-MpPreference), stopping the WinDefend service using sc.exe, or altering sensitive Windows Defender registry keys. This rule monitors process execution and registry modification events, excluding known legitimate management tools like Intune and SCCM.
This rule detects user interaction with potentially malicious URLs from known Dynamic DNS (DDNS) providers or URLs containing suspicious keywords frequently associated with phishing lures (e.g., login, auth, verify, mfa). It filters out known legitimate Microsoft domains to reduce noise.
