
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,592 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
This rule monitors for network communication with a specific known malicious IP address and URL path, as well as the execution or presence of associated malicious file hashes. Additionally, it flags emails involving specific indicators identified as potentially associated with malicious activity.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
