avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,606 views

7,082 detections

Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
902
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
106
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
006
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
002
This rule detects potential command injection attacks targeting the Zimbra 'swatchdog' service, specifically involving the abuse of SNMP trap notifications (CVE-2026-73570). The attack works by injecting malicious shell metacharacters into the 'zimbra-MIB::zmServiceName' argument, which is processed by a Perl-invoked 'swatchdog' script. The rule monitors process execution events for shell commands spawned by the swatchdog utility that contain suspicious shell operators and the targeted MIB parameter.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
002
This rule detects potential command injection attacks targeting the Zimbra 'swatchdog' service, specifically involving the abuse of SNMP trap notifications (CVE-2026-73570). The attack works by injecting malicious shell metacharacters into the 'zimbra-MIB::zmServiceName' argument, which is processed by a Perl-invoked 'swatchdog' script. The rule monitors process execution events for shell commands spawned by the swatchdog utility that contain suspicious shell operators and the targeted MIB parameter.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
002
Detects spoofed emails carrying a .patch attachment sent to a GitLab incoming-email merge-request address. Requires Microsoft's composite authentication verdict (CompAuth: fail) -- a lower-noise spoofing signal than raw SPF/DKIM/DMARC -- and excludes sender/recipient pairs already seen corresponding with that token address in the prior 30 days to suppress recurring legitimate contributors.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
6014
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
203
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
103