
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,578 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
This rule detects potential command injection attacks targeting the Zimbra 'swatchdog' service, specifically involving the abuse of SNMP trap notifications (CVE-2026-73570). The attack works by injecting malicious shell metacharacters into the 'zimbra-MIB::zmServiceName' argument, which is processed by a Perl-invoked 'swatchdog' script. The rule monitors process execution events for shell commands spawned by the swatchdog utility that contain suspicious shell operators and the targeted MIB parameter.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects potentially malicious Command and Control (C2) traffic utilizing DNS over HTTPS (DoH) to interact with public resolvers like Cloudflare, Google, and Quad9. It identifies both high-frequency, repeated direct-to-resolver TLS sessions and specific HTTP requests to these resolvers that resolve domains associated with known C2 infrastructure, such as the ClickFix campaign.
