• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    High Fidelity ARToken Detection

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Syed Usfar Wasim@nCD24
    •updated Jul 6, 2026•24•0•52

    ARTokenC2NetworkTraffic - fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform.

    Microsoft Sentinel (KQL)

    Tags

    T1566.002 - Spearphishing LinkT1528 - Steal Application Access TokenT1098.001 - Additional Cloud CredentialsT1114.002 - Remote Email CollectionT1550.001 - Application Access TokenT1531 - Account Access RemovalT1583.006 - Web ServicesT1027 - Obfuscated Files or InformationT1497.001 - System Checkskql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?