
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,566 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
Detects emails from free-mail domains (@mail.com or @outlook.com) that contain a specific malicious infrastructure indicator in the InternetMessageId or originate from a known suspicious IP address associated with TA419-style spoofing campaigns. This indicates the email was relayed through unauthorized infrastructure rather than the expected legitimate mail providers.
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
