avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,583 views

7,082 detections

Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
000
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
2 days ago
000
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
102
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
102
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
004
This rule detects the execution of the MeshAgent remote administration tool from a temporary directory followed by a network connection to known malicious infrastructure within a 15-minute window. This behavior is indicative of unauthorized remote access setup or C2 activity using a legitimate remote management utility.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
004
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
002
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
102
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
104
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003