
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,606 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
This rule detects potential command injection attacks targeting the Zimbra 'swatchdog' service, specifically involving the abuse of SNMP trap notifications (CVE-2026-73570). The attack works by injecting malicious shell metacharacters into the 'zimbra-MIB::zmServiceName' argument, which is processed by a Perl-invoked 'swatchdog' script. The rule monitors process execution events for shell commands spawned by the swatchdog utility that contain suspicious shell operators and the targeted MIB parameter.
This rule detects potential command injection attacks targeting the Zimbra 'swatchdog' service, specifically involving the abuse of SNMP trap notifications (CVE-2026-73570). The attack works by injecting malicious shell metacharacters into the 'zimbra-MIB::zmServiceName' argument, which is processed by a Perl-invoked 'swatchdog' script. The rule monitors process execution events for shell commands spawned by the swatchdog utility that contain suspicious shell operators and the targeted MIB parameter.
Detects spoofed emails carrying a .patch attachment sent to a GitLab incoming-email merge-request address. Requires Microsoft's composite authentication verdict (CompAuth: fail) -- a lower-noise spoofing signal than raw SPF/DKIM/DMARC -- and excludes sender/recipient pairs already seen corresponding with that token address in the prior 30 days to suppress recurring legitimate contributors.
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
