avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,566 views

7,082 detections

Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
002
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
002
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
104
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
203
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
2 days ago
000
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
000
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
000
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
2 days ago
000
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
000
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
000