
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,581 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
This rule detects potentially compromised accounts by correlating risky Entra ID sign-ins to Citrix NetScaler with subsequent VPN session establishment followed by rapid, high-volume outbound connection activity from the source IP address. This pattern is indicative of a threat actor using compromised credentials to gain access via VPN and immediately perform internal network scanning or data staging.
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
Detects execution and network activity related to the PamStealer / Wavel malware campaign, including the JXA dropper and associated C2 infrastructure. The rule monitors for known malicious file hashes (e.g., JXA dropper, pkgunpack utility) and network connections to identified lure, distribution, and C2 domains and URLs used by the campaign.
Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
