avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,565 views

7,082 detections

Detects a suspected device-code phishing attack where a user visits a known malicious lure domain and shortly thereafter completes a successful Microsoft 365 device-code authentication. This rule correlates network events with sign-in logs within a 10-minute window to identify session hijacking attempts that bypass traditional MFA.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
001
Detects a suspected device-code phishing attack where a user visits a known malicious lure domain and shortly thereafter completes a successful Microsoft 365 device-code authentication. This rule correlates network events with sign-in logs within a 10-minute window to identify session hijacking attempts that bypass traditional MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
001
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
001
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
001
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
3 days ago
000