
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,583 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
Detects outbound HTTPS traffic to domains using file-sharing or cloud-sync themed keywords in combination with specific top-level domains (TLD) often associated with suspicious infrastructure. The rule specifically excludes well-known legitimate services such as OneDrive, SharePoint, Dropbox, Box, iCloud, and Google, and includes a detection threshold to minimize alerts for incidental traffic.
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
This rule performs a retrospective search across device file and network events for indicators of compromise associated with the UNC6240/ShinyHunters actor's activity against PeopleSoft, specifically linked to CVE-2026-35273. It monitors for known malicious file hashes (JSP webshells and executables), connections to known C2 infrastructure, and DNS lookups for specific malicious domains.
This rule detects the execution of the MeshAgent remote administration tool from a temporary directory followed by a network connection to known malicious infrastructure within a 15-minute window. This behavior is indicative of unauthorized remote access setup or C2 activity using a legitimate remote management utility.
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
