avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,585 views

7,082 detections

Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
003
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
1013
Detects unauthorized exfiltration of sensitive information, such as camera credentials or location data, directed to the Telegram Bot API as part of the 'Operation CameraSwarm' campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
2149
This rule detects established TLS connections to external domains that exhibit characteristics often associated with phishing campaigns. Specifically, it looks for domain names in the SNI field that contain common brand names (e.g., microsoft, google, paypal) combined with typical login-related keywords (e.g., login, verify, auth) on high-churn or suspicious Top-Level Domains (TLDs) such as .top, .xyz, or .icu.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
002
This rule detects established TLS connections to external domains that exhibit characteristics often associated with phishing campaigns. Specifically, it looks for domain names in the SNI field that contain common brand names (e.g., microsoft, google, paypal) combined with typical login-related keywords (e.g., login, verify, auth) on high-churn or suspicious Top-Level Domains (TLDs) such as .top, .xyz, or .icu.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
002
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
002
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
202
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
202
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
002
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
102