avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,607 views

7,082 detections

Detects activity from known Storm-3168 (JADEPUFFER) campaign IP addresses across Azure control-plane, sign-in, and App Service logs. The rule monitors for malicious indicators in Azure Activity logs, Azure Sign-in logs, and Service Principal sign-ins, as well as specific sensitive URI paths (e.g., shells, admin login paths) within App Service HTTP logs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
305
Detects activity from known Storm-3168 (JADEPUFFER) campaign IP addresses across Azure control-plane, sign-in, and App Service logs. The rule monitors for malicious indicators in Azure Activity logs, Azure Sign-in logs, and Service Principal sign-ins, as well as specific sensitive URI paths (e.g., shells, admin login paths) within App Service HTTP logs.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
105
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
204
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
005
This rule monitors for indicators of compromise (IOCs) associated with the Lunex Malware-as-a-Service (MaaS) campaign. It aggregates telemetry from file creation, process execution, and network connections to identify the presence of known malicious hashes, C2 IP addresses, phishing-related domains, and specific payload URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
005
Identifies NetScaler ADC or Gateway software versions in the inventory that are known to be vulnerable to CVE-2026-88771 and CVE-2026-88772, despite having received the patch for CVE-2026-19490.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
004
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
103
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
SlimKQL
7 days ago
303
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
103
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
203