
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,583 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
