
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,606 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Detects exploitation attempts against Microsoft SharePoint leveraging the ToolShell exploit chain, as well as subsequent post-exploitation webshell activity involving anomalous 'layoutNsp.aspx' naming conventions. This covers initial exploitation of vulnerabilities such as CVE-2025-49704 and associated variants, followed by the deployment of webshells associated with the ToolShell campaign.
