
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,565 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects a suspected device-code phishing attack where a user visits a known malicious lure domain and shortly thereafter completes a successful Microsoft 365 device-code authentication. This rule correlates network events with sign-in logs within a 10-minute window to identify session hijacking attempts that bypass traditional MFA.
Detects a suspected device-code phishing attack where a user visits a known malicious lure domain and shortly thereafter completes a successful Microsoft 365 device-code authentication. This rule correlates network events with sign-in logs within a 10-minute window to identify session hijacking attempts that bypass traditional MFA.
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
