avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,578 views

7,082 detections

This rule detects potential command injection attacks targeting the Zimbra 'swatchdog' service, specifically involving the abuse of SNMP trap notifications (CVE-2026-73570). The attack works by injecting malicious shell metacharacters into the 'zimbra-MIB::zmServiceName' argument, which is processed by a Perl-invoked 'swatchdog' script. The rule monitors process execution events for shell commands spawned by the swatchdog utility that contain suspicious shell operators and the targeted MIB parameter.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
101
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
2 days ago
000
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
000
Detects inbound phishing emails containing brand mentions for Signal, WhatsApp, or Telegram alongside lure phrases related to verification, 2FA, or device linking. The rule specifically filters for emails containing URLs while excluding messages originating from official domains associated with these services.
avatar
Arnold Chan@slaz
avatar
Hunters
2 days ago
000
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
2 days ago
000
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
SlimKQL
13 days ago
4012
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
2010
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
102
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
102
This rule detects potentially malicious Command and Control (C2) traffic utilizing DNS over HTTPS (DoH) to interact with public resolvers like Cloudflare, Google, and Quad9. It identifies both high-frequency, repeated direct-to-resolver TLS sessions and specific HTTP requests to these resolvers that resolve domains associated with known C2 infrastructure, such as the ClickFix campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
002