avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,101 copies41 likes15,589 views

7,082 detections

This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
003
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
003
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
003
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
006
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
001
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
101
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
101
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
001