avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,615 views

7,082 detections

Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
001
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
001
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
Defender - KQL
3 days ago
101
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
001
This rule detects the execution of common remote access and management (RMM) tools from non-standard directories such as user profiles, temp folders, or other locations outside of standard application installation paths (e.g., Program Files or ProgramData). Such activity is often indicative of unauthorized remote access setup or the use of portable RMM binaries by an adversary to maintain persistent access.
avatar
Arnold Chan@slaz
Defender - KQL
3 days ago
201
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
102
Detects a suspicious sequence of events involving NetScaler ADC or Gateway appliances: anomalous account authentication, followed by the establishment of a VPN or remote access session, and subsequent unusual outbound network activity indicating potential lateral movement or C2 communication from the appliance.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
105
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
105
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
102
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
102