avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,565 views

7,082 detections

Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
002
Detects NeedyMantis' initial C2 beacon: an HTTP GET to /library/zip/ on port 443, anchored to the URI root, carrying a client-originated 'Set-Cookie:' header (clients normally send 'Cookie:', never 'Set-Cookie:' -- this direction reversal is the core anomaly and is near-impossible for legitimate traffic) alongside an explicit 'Upgrade: websocket' header. Matching the literal header text (not just header-name presence) and anchoring the URI removes generic WebSocket apps and any unrelated path containing '/library/zip/' as a substring.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
002
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
002
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
002
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
4018
Detects the specific TCP handshake pattern characteristic of the Fast Reverse Proxy (FRP) client (frpc) initiating a connection to a command-and-control server. The rule inspects established traffic for specific metadata strings ('privilege_key', 'run_id', 'pool_count') within the initial handshake payload.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
002
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
205
This rule detects established TLS connections to external domains that exhibit characteristics often associated with phishing campaigns. Specifically, it looks for domain names in the SNI field that contain common brand names (e.g., microsoft, google, paypal) combined with typical login-related keywords (e.g., login, verify, auth) on high-churn or suspicious Top-Level Domains (TLDs) such as .top, .xyz, or .icu.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
Detects the installation of unauthorized AI-related browser extensions followed by outbound network communication from the browser process to known external AI service API endpoints within one hour. This behavior is indicative of potential data exfiltration via shadow AI tools, bypassing standard enterprise DLP controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
501