
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,641 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
Detects a suspicious sequence of events involving NetScaler ADC or Gateway appliances: anomalous account authentication, followed by the establishment of a VPN or remote access session, and subsequent unusual outbound network activity indicating potential lateral movement or C2 communication from the appliance.
Detects a suspicious sequence of events involving NetScaler ADC or Gateway appliances: anomalous account authentication, followed by the establishment of a VPN or remote access session, and subsequent unusual outbound network activity indicating potential lateral movement or C2 communication from the appliance.
Identifies NetScaler ADC or Gateway software versions in the inventory that are known to be vulnerable to CVE-2026-88771 and CVE-2026-88772, despite having received the patch for CVE-2026-19490.
Identifies NetScaler ADC or Gateway software versions in the inventory that are known to be vulnerable to CVE-2026-88771 and CVE-2026-88772, despite having received the patch for CVE-2026-19490.
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
