
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,615 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
Detects a suspicious sequence of events involving NetScaler ADC or Gateway appliances: anomalous account authentication, followed by the establishment of a VPN or remote access session, and subsequent unusual outbound network activity indicating potential lateral movement or C2 communication from the appliance.
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
