
Emiliano Mema
@NosalvaGreeceTrusted contributorCompletionist
0 followers632 downloads576 copies6 likes1,652 views
282 detections
Filters
Last updated
All Time
Detection languages
159
62
43
18
Categories
95
52
49
34
29
Platforms
156
52
34
25
17
Products / Services
74
55
40
40
19
MITRE Techniques
81
76
34
31
22
CVEs
2
2
1
IDS Classtypes
22
14
4
3
IDS Protocols
22
9
5
5
1
This rule detects two suspicious patterns: 1) DLL sideloading of 'libcef.dll' by processes like 'ClaudeDesktop.exe' or JetBrains-related tools when executed from non-standard directories like 'Downloads', 'Temp', or 'AppData'. 2) Unauthorized access to common browser credential storage files (e.g., 'Login Data', 'Cookies') by processes other than standard browsers.
This rule monitors for two distinct indicators of compromise: it detects the execution of files dropped into specific patterns within the 'AppData\Roaming' directory (associated with potential GoCaracal malware) and identifies network connections to known C2 infrastructure associated with GoCaracal and Bandook malware families.
Detects instances where a Python interpreter (python.exe or pythonw.exe) loads the 'snap7.dll' library. This library is commonly associated with the 'python-snap7' package, used for communicating with Siemens S7 PLC devices. This behavior is potentially suspicious in OT environments where Python should not be interacting with industrial control system hardware.
This rule detects outbound network connections from internal hosts to specific IP addresses associated with known AlexHost infrastructure identified as command-and-control (C2) servers for the Bandook Remote Access Trojan (RAT), which is utilized by the threat actor Dark Caracal.
Detects suspicious command execution patterns commonly associated with ClickFix-style social engineering attacks. The rule identifies Terminal processes executing shell commands that retrieve remote content via curl, followed by base64 decoding and/or piping directly into a shell interpreter (zsh/sh/bash), which is a common technique for executing obfuscated malicious payloads.
Detects Microsoft Teams messages sent from an onmicrosoft.com domain that impersonate an 'IT Service Desk' and contain a link to an .msi file hosted on Azure Blob Storage, a common indicator of a phishing lure distributing malicious installers.
Detects the execution of the Windows FTP client (ftp.exe) initiated by command-line interpreters such as cmd.exe, powershell.exe, or wscript.exe, specifically when utilizing the '-s:' flag. This flag is commonly used to provide a text file containing FTP commands, which is a frequent technique for automated file transfers or exfiltration during post-exploitation activities.
Detects messages sent, chats created, or members added within Microsoft Teams that involve external participants and contain embedded HTTP or HTTPS links. This behavior is indicative of potential external spearphishing or malicious link distribution through collaborative chat platforms.
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, encoded commands using char arrays, and iex) that subsequently initiates multiple or long-running network connections. This behavior is indicative of a remote access trojan, beaconing, or fileless malware downloading additional payloads.
Detects the execution of python.exe or pythonw.exe from locations other than standard installation directories (C:\Python, C:\Program Files\Python), accompanied by the presence of associated DLLs (msvcp150/160.dll or python3xx.dll). This behavior is often indicative of portable Python environments being used for malicious script execution.
Page 1 of 29
