
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,618 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects Heartbleed (CVE-2014-0160) exploitation attempts by monitoring for malformed TLS heartbeat requests (undersized payload) followed by oversized responses from the server that indicate potential memory disclosure.
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
Detects the multi-stage Microsoft cloud identity compromise chain reported by Microsoft Security Research (September 2026): a victim completes a successful Entra ID device-code sign-in (often induced by passkey-themed device-code phishing), the same identity's authentication/security info is registered or changed (MFA/passkey persistence) within 60 minutes (deduplicated to the earliest such event per sign-in), followed within 120 minutes by a burst of at least 25 successful, delegated-context Microsoft Graph API calls (Scopes claim populated, i.e. user-delegated permissions rather than pure application/client-credential access) spanning at least 3 distinct resource paths, exhibiting reconnaissance (>=5 requests against /users, /groups, /directoryRoles, /roleManagement, /applications, /servicePrincipals, /organization) and/or collection (>=10 requests against /messages, /mailFolders, /attachments, /drive, /drives, /sites, /lists, /search) patterns. Restricting to delegated (Scopes-bearing) Graph calls and requiring resource-path breadth removes the two largest false-positive sources: service-principal/application-only automation jobs (Roles-only tokens) and single-endpoint polling tools. Pure behavioral correlation across SigninLogs, AuditLogs, and MicrosoftGraphActivityLogs - no static IOCs. Flags whether Graph activity originated from an IP different from the original device-code sign-in IP as a strong pivot/session-reuse indicator.
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
Detects a suspicious sequence of events where a host performs multiple reconnaissance-style probes (health checks, documentation, or OpenAPI definitions) followed within 10 minutes by access to sensitive artifact-related URLs on the same remote host. This pattern is indicative of an attacker profiling a target server for metadata and then proceeding to exfiltrate files or sensitive artifacts.
Detects execution of encoded commands in macOS terminal environments that originate from clipboard content mimicking a reCAPTCHA verification process. This pattern often involves users being social-engineered into pasting a malicious string that decodes a payload and pipes it directly into a shell interpreter (sh/bash/zsh). The rule monitors for the co-occurrence of base64/openssl decoding commands and shell execution pipes, while filtering out known legitimate software installation patterns.
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
