Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Contributors
2
Categories
20,015
11,427
5,755
4,979
4,812
Platforms
2
1
Products / Services
2
1
1
MITRE Techniques
1
Detects an unsigned/unexpected PAM module written into the su/sudo authentication stack, correlated with non-package-manager modification of /etc/pam.d/ configuration and subsequent su/sudo activity — the technique Jewelbug's Linux tooling uses to steal credentials.
Detects ELF binaries embedding the ClientKing implant name alongside structural indicators (Rust runtime markers or C2 configuration patterns), associated with Jewelbug espionage tooling targeting Linux servers and routers
