avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,575 views

7,082 detections

Detects potential consent phishing attempts by identifying when a user grants high-risk, persistent-access OAuth scopes (such as Mail or Files) to a new third-party application. The rule specifically excludes known first-party Microsoft apps and utilizes a lookback period to avoid alerting on applications that have already been consented to within the tenant, reducing noise from routine enterprise app usage.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
102
Detects network traffic associated with Adversary-in-the-Middle (AiTM) phishing kits that impersonate Microsoft and Google login pages. The rules identify the presence of specific HTML elements (like Cloudflare Turnstile anti-bot gates) and authentication session cookie headers served from non-authorized/non-official domains, indicating a reverse-proxy phishing attack.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
002
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
SlimKQL
5 days ago
002
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
002
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
002