avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,641 views

7,082 detections

This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
003
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
2 days ago
001
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
avatar
Arnold Chan@slaz
Defender - KQL
2 days ago
001
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
101
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
2 days ago
001
Detects a suspicious sequence of events involving NetScaler ADC or Gateway appliances: anomalous account authentication, followed by the establishment of a VPN or remote access session, and subsequent unusual outbound network activity indicating potential lateral movement or C2 communication from the appliance.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
806
Detects a suspicious sequence of events involving NetScaler ADC or Gateway appliances: anomalous account authentication, followed by the establishment of a VPN or remote access session, and subsequent unusual outbound network activity indicating potential lateral movement or C2 communication from the appliance.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
006
Identifies NetScaler ADC or Gateway software versions in the inventory that are known to be vulnerable to CVE-2026-88771 and CVE-2026-88772, despite having received the patch for CVE-2026-19490.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
106
Identifies NetScaler ADC or Gateway software versions in the inventory that are known to be vulnerable to CVE-2026-88771 and CVE-2026-88772, despite having received the patch for CVE-2026-19490.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
106
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
006