
Syed Usfar Wasim
@nCD24DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views
38 detections
Filters
Last updated
All Time
Detection languages
38
Categories
4
2
2
2
2
Platforms
18
8
3
2
2
Products / Services
4
3
3
1
1
MITRE Techniques
7
6
6
6
6
CVEs
1
1
1
1
1
IDS Classtypes
2
1
ARTokenC2NetworkTraffic - fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform.
Detects high-frequency failed logon attempts (>= 6) against accounts with administrative naming conventions within a 3-minute window. The rule specifically flags activity targeting multiple distinct destination hosts, which is a strong indicator of lateral movement or account brute-forcing/spraying attempts across an enterprise network.
This rule detects when common Windows LOLBins (Living-off-the-Land Binaries) or scripting hosts attempt to read, create, modify, or rename sensitive credential storage files (such as login databases and cookies) associated with popular web browsers like Chrome, Edge, and Firefox. Such behavior is a common indicator of credential theft activity by information-stealing malware.
Detects potential Microsoft Teams impersonation or social-engineering activity where accounts use IT, admin, support, or security-themed display names, especially when associated with external users or impersonation indicators.
Detects potential zero-click LLM prompt injection attacks against Microsoft 365 Copilot. The rule correlates Microsoft 365 Copilot activity involving external/untrusted URLs or domains with recent inbound email activity to the same user. This pattern is designed to identify scenarios where an attacker leverages an inbound email to trigger a Copilot interaction with malicious external content, potentially leading to unauthorized data access or exfiltration.
This rule detects scenarios where Microsoft Office applications (Word, Excel, Outlook, PowerPoint, OneNote) spawn known suspicious child processes (LOLBAS) that exhibit command-line flags indicative of remote content retrieval or script execution (e.g., download strings, encoded commands) and subsequently initiate network connections to public IP addresses or URLs within a 15-minute window.
This rule detects a multi-stage phishing campaign involving Gmail-hosted emails containing 'short.gy' URLs. It monitors for three distinct signals: (1) Outbound network connections to 'chongdaotang.net', (2) User clicks on 'short.gy' links arriving from Gmail addresses, and (3) Inbound or BCC-delivered emails from Gmail senders containing 'short.gy' links. This combination is highly indicative of a phishing operation attempting to redirect users to a malicious infrastructure.
This rule detects potentially malicious use of libcurl or curl.exe involving mTLS-related flags (e.g., --cert, --key, --cacert) in non-browser processes. It specifically flags instances where such processes perform repeated HTTPS connections to remote hosts, which may indicate exploitation of CVE-2026-8932 related to mTLS connection reuse and authentication bypass.
Page 4 of 4
