avatar

Aaron Mog

@amog
1 follower76 downloads34 copies2 likes2,030 views

5 detections

Detects the execution of commands used to disable the algif_aead module to mitigate CVE-2026-31431 (Copy Fail). This rule monitors for dynamic unloading of the module using 'rmmod' or persistent configuration changes via 'modprobe.d' to disable the module. While this is a mitigation step, monitoring for it ensures compliance and tracks remediation efforts.
avatar
Aaron Mog@amog
avatar
Detections.ai Community
5 months ago
1211,225
Detects the use of a PowerShell download cradle, a technique observed in the PhantomCaptcha campaign to download and execute a next-stage payload. This pattern often involves stealthy flags to evade detection.
avatar
Aaron Mog@amog
avatar
Detections.ai Community
11 months ago
20119
Detects the crash of lsass.exe caused by WLDAP32.dll, which is a strong indicator of exploitation of the LDAPNightmare vulnerability (CVE-2024-49113). This exploit causes a denial of service on unpatched Windows Servers.
avatar
Aaron Mog@amog
avatar
Detections.ai Community
11 months ago
2184
Detects potential exploitation of CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools and Aria Operations.
An attacker can stage a malicious binary in a world-writable directory (e.g., /tmp) which is then executed with root privileges by the VMware service discovery mechanism when it attempts to determine the binary's version.
avatar
Aaron Mog@amog
avatar
Detections.ai Community
1 year ago
80426
Detects a high number of failed or denied Multi-Factor Authentication (MFA) attempts followed by a success for the same user account within a short time frame. This pattern, known as MFA fatigue or push bombing, is a technique actively used by threat actors like Scattered Spider to overwhelm a user with push notifications until they approve one, granting the attacker access.
avatar
Aaron Mog@amog
avatar
Detections.ai Community
1 year ago
100176