avatar

Syed Usfar Wasim

@nCD24
DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views

38 detections

ARTokenC2NetworkTraffic - fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
24052
Detects high-frequency failed logon attempts (>= 6) against accounts with administrative naming conventions within a 3-minute window. The rule specifically flags activity targeting multiple distinct destination hosts, which is a strong indicator of lateral movement or account brute-forcing/spraying attempts across an enterprise network.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
10013
This rule detects when common Windows LOLBins (Living-off-the-Land Binaries) or scripting hosts attempt to read, create, modify, or rename sensitive credential storage files (such as login databases and cookies) associated with popular web browsers like Chrome, Edge, and Firefox. Such behavior is a common indicator of credential theft activity by information-stealing malware.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
15025
Detects potential Microsoft Teams impersonation or social-engineering activity where accounts use IT, admin, support, or security-themed display names, especially when associated with external users or impersonation indicators.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
46058
Detects potential zero-click LLM prompt injection attacks against Microsoft 365 Copilot. The rule correlates Microsoft 365 Copilot activity involving external/untrusted URLs or domains with recent inbound email activity to the same user. This pattern is designed to identify scenarios where an attacker leverages an inbound email to trigger a Copilot interaction with malicious external content, potentially leading to unauthorized data access or exfiltration.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
9023
This rule detects scenarios where Microsoft Office applications (Word, Excel, Outlook, PowerPoint, OneNote) spawn known suspicious child processes (LOLBAS) that exhibit command-line flags indicative of remote content retrieval or script execution (e.g., download strings, encoded commands) and subsequently initiate network connections to public IP addresses or URLs within a 15-minute window.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
6013
This rule detects a multi-stage phishing campaign involving Gmail-hosted emails containing 'short.gy' URLs. It monitors for three distinct signals: (1) Outbound network connections to 'chongdaotang.net', (2) User clicks on 'short.gy' links arriving from Gmail addresses, and (3) Inbound or BCC-delivered emails from Gmail senders containing 'short.gy' links. This combination is highly indicative of a phishing operation attempting to redirect users to a malicious infrastructure.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
7010
This rule detects potentially malicious use of libcurl or curl.exe involving mTLS-related flags (e.g., --cert, --key, --cacert) in non-browser processes. It specifically flags instances where such processes perform repeated HTTPS connections to remote hosts, which may indicate exploitation of CVE-2026-8932 related to mTLS connection reuse and authentication bypass.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
204
Page 4 of 4