avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,592 views

7,082 detections

This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
101
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
001
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
003
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
005
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
003
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
403
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
003
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
103
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
103
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
103