
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,599 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects process/file hashes associated with the ChatGPT Custom GPT ClickFix
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
