avatar

Emiliano Mema

@Nosalva
GreeceTrusted contributorCompletionist
0 followers632 downloads576 copies6 likes1,652 views

282 detections

This rule detects two suspicious patterns: 1) DLL sideloading of 'libcef.dll' by processes like 'ClaudeDesktop.exe' or JetBrains-related tools when executed from non-standard directories like 'Downloads', 'Temp', or 'AppData'. 2) Unauthorized access to common browser credential storage files (e.g., 'Login Data', 'Cookies') by processes other than standard browsers.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
11015
This rule monitors for two distinct indicators of compromise: it detects the execution of files dropped into specific patterns within the 'AppData\Roaming' directory (associated with potential GoCaracal malware) and identifies network connections to known C2 infrastructure associated with GoCaracal and Bandook malware families.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
11012
Detects instances where a Python interpreter (python.exe or pythonw.exe) loads the 'snap7.dll' library. This library is commonly associated with the 'python-snap7' package, used for communicating with Siemens S7 PLC devices. This behavior is potentially suspicious in OT environments where Python should not be interacting with industrial control system hardware.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
3024
This rule detects outbound network connections from internal hosts to specific IP addresses associated with known AlexHost infrastructure identified as command-and-control (C2) servers for the Bandook Remote Access Trojan (RAT), which is utilized by the threat actor Dark Caracal.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
009
Detects suspicious command execution patterns commonly associated with ClickFix-style social engineering attacks. The rule identifies Terminal processes executing shell commands that retrieve remote content via curl, followed by base64 decoding and/or piping directly into a shell interpreter (zsh/sh/bash), which is a common technique for executing obfuscated malicious payloads.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
3012
Detects Microsoft Teams messages sent from an onmicrosoft.com domain that impersonate an 'IT Service Desk' and contain a link to an .msi file hosted on Azure Blob Storage, a common indicator of a phishing lure distributing malicious installers.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
2012
Detects the execution of the Windows FTP client (ftp.exe) initiated by command-line interpreters such as cmd.exe, powershell.exe, or wscript.exe, specifically when utilizing the '-s:' flag. This flag is commonly used to provide a text file containing FTP commands, which is a frequent technique for automated file transfers or exfiltration during post-exploitation activities.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
23015
Detects messages sent, chats created, or members added within Microsoft Teams that involve external participants and contain embedded HTTP or HTTPS links. This behavior is indicative of potential external spearphishing or malicious link distribution through collaborative chat platforms.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
19027
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, encoded commands using char arrays, and iex) that subsequently initiates multiple or long-running network connections. This behavior is indicative of a remote access trojan, beaconing, or fileless malware downloading additional payloads.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
5024
Detects the execution of python.exe or pythonw.exe from locations other than standard installation directories (C:\Python, C:\Program Files\Python), accompanied by the presence of associated DLLs (msvcp150/160.dll or python3xx.dll). This behavior is often indicative of portable Python environments being used for malicious script execution.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
1022
Page 1 of 29