avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,581 views

7,082 detections

Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
102
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
102
This rule detects potentially compromised accounts by correlating risky Entra ID sign-ins to Citrix NetScaler with subsequent VPN session establishment followed by rapid, high-volume outbound connection activity from the source IP address. This pattern is indicative of a threat actor using compromised credentials to gain access via VPN and immediately perform internal network scanning or data staging.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
002
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
102
Detects execution and network activity related to the PamStealer / Wavel malware campaign, including the JXA dropper and associated C2 infrastructure. The rule monitors for known malicious file hashes (e.g., JXA dropper, pkgunpack utility) and network connections to identified lure, distribution, and C2 domains and URLs used by the campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
107
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
002
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
002
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
002
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
002
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
204