
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,585 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
Detects unauthorized exfiltration of sensitive information, such as camera credentials or location data, directed to the Telegram Bot API as part of the 'Operation CameraSwarm' campaign.
This rule detects established TLS connections to external domains that exhibit characteristics often associated with phishing campaigns. Specifically, it looks for domain names in the SNI field that contain common brand names (e.g., microsoft, google, paypal) combined with typical login-related keywords (e.g., login, verify, auth) on high-churn or suspicious Top-Level Domains (TLDs) such as .top, .xyz, or .icu.
This rule detects established TLS connections to external domains that exhibit characteristics often associated with phishing campaigns. Specifically, it looks for domain names in the SNI field that contain common brand names (e.g., microsoft, google, paypal) combined with typical login-related keywords (e.g., login, verify, auth) on high-churn or suspicious Top-Level Domains (TLDs) such as .top, .xyz, or .icu.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
