Skip to content

Commit 1e16650

Browse files
hazcodgithub-actions[bot]
authored andcommitted
sync: update community detections
1 parent 3aa2b5e commit 1e16650

2 files changed

Lines changed: 30 additions & 0 deletions

File tree

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
id: 019cefa0-b817-7778-9422-7ef2d5c20090
2+
name: ShinyHunters Phishing Infrastructure Detection
3+
description: This rule detects network connections or email URLs that contain domains associated with the 'ShinyHunters' threat group's infrastructure. The rule specifically looks for a predefined list of domains known to be used by ShinyHunters for phishing or other malicious activities. It correlates email URL information with device network events to identify potential compromise attempts.
4+
query: "let ShinyHuntersInfra = dynamic([\".acess-terms.com\",\".okta.guide\",\".sso.guide\",\r\n\".okta.domains\",\".setup-okta.com\",\".help-okta.com\",\".desk-okta.com\",\".safe-okta.com\",\r\n\".prod-okta.com\",\".lock-okta.com\",\".passkeysetup.com\"]);\r\nlet EmailUrlThreat =\r\nEmailUrlInfo\r\n| where Timestamp > ago(1h)\r\n| where Url has_any(ShinyHuntersInfra);\r\nDeviceNetworkEvents\r\n| where Timestamp > ago(1h)\r\n| where RemoteUrl has_any(ShinyHuntersInfra)\r\n| union EmailUrlThreat"
5+
query_type: kql
6+
severity: medium
7+
tactics:
8+
- TA0001
9+
techniques:
10+
- T1566
11+
- T1566.002
12+
tags:
13+
- kql
14+
author: Steven Lim
15+
version: "4"

‎library.index.yaml‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45004,6 +45004,21 @@ entries:
4500445004
- kql
4500545005
version: "1"
4500645006
file: entries/kql/019cec23-b321-741d-952c-7e08548a2986.yaml
45007+
- id: 019cefa0-b817-7778-9422-7ef2d5c20090
45008+
name: ShinyHunters Phishing Infrastructure Detection
45009+
description: This rule detects network connections or email URLs that contain domains associated with the 'ShinyHunters' threat group's infrastructure. The rule specifically looks for a predefined list of domains known to be used by ShinyHunters for phishing or other malicious activities. It correlates email URL information with device network events to identify potential compromise attempts.
45010+
query_type: kql
45011+
severity: medium
45012+
tactics:
45013+
- TA0001
45014+
techniques:
45015+
- T1566
45016+
- T1566.002
45017+
tags:
45018+
- kql
45019+
author: Steven Lim
45020+
version: "4"
45021+
file: entries/kql/019cefa0-b817-7778-9422-7ef2d5c20090.yaml
4500745022
- id: 01bc2aa2-98db-4217-951d-727eacf33034
4500845023
name: Exposure Management + Defender for Office 365
4500945024
description: 'KQL Query from file: Exposure Management + Defender for Office 365'

0 commit comments

Comments
 (0)