
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,607 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects activity from known Storm-3168 (JADEPUFFER) campaign IP addresses across Azure control-plane, sign-in, and App Service logs. The rule monitors for malicious indicators in Azure Activity logs, Azure Sign-in logs, and Service Principal sign-ins, as well as specific sensitive URI paths (e.g., shells, admin login paths) within App Service HTTP logs.
Detects activity from known Storm-3168 (JADEPUFFER) campaign IP addresses across Azure control-plane, sign-in, and App Service logs. The rule monitors for malicious indicators in Azure Activity logs, Azure Sign-in logs, and Service Principal sign-ins, as well as specific sensitive URI paths (e.g., shells, admin login paths) within App Service HTTP logs.
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
Identifies NetScaler ADC or Gateway software versions in the inventory that are known to be vulnerable to CVE-2026-88771 and CVE-2026-88772, despite having received the patch for CVE-2026-19490.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
