avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,618 views

7,082 detections

Detects Heartbleed (CVE-2014-0160) exploitation attempts by monitoring for malformed TLS heartbeat requests (undersized payload) followed by oversized responses from the server that indicate potential memory disclosure.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
003
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
10020
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
13035
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
305
Detects the multi-stage Microsoft cloud identity compromise chain reported by Microsoft Security Research (September 2026): a victim completes a successful Entra ID device-code sign-in (often induced by passkey-themed device-code phishing), the same identity's authentication/security info is registered or changed (MFA/passkey persistence) within 60 minutes (deduplicated to the earliest such event per sign-in), followed within 120 minutes by a burst of at least 25 successful, delegated-context Microsoft Graph API calls (Scopes claim populated, i.e. user-delegated permissions rather than pure application/client-credential access) spanning at least 3 distinct resource paths, exhibiting reconnaissance (>=5 requests against /users, /groups, /directoryRoles, /roleManagement, /applications, /servicePrincipals, /organization) and/or collection (>=10 requests against /messages, /mailFolders, /attachments, /drive, /drives, /sites, /lists, /search) patterns. Restricting to delegated (Scopes-bearing) Graph calls and requiring resource-path breadth removes the two largest false-positive sources: service-principal/application-only automation jobs (Roles-only tokens) and single-endpoint polling tools. Pure behavioral correlation across SigninLogs, AuditLogs, and MicrosoftGraphActivityLogs - no static IOCs. Flags whether Graph activity originated from an IP different from the original device-code sign-in IP as a strong pivot/session-reuse indicator.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
105
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
207
Detects a suspicious sequence of events where a host performs multiple reconnaissance-style probes (health checks, documentation, or OpenAPI definitions) followed within 10 minutes by access to sensitive artifact-related URLs on the same remote host. This pattern is indicative of an attacker profiling a target server for metadata and then proceeding to exfiltrate files or sensitive artifacts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
003
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
209
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
003
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
003