Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects an unsigned/unexpected PAM module written into the su/sudo authentication stack, correlated with non-package-manager modification of /etc/pam.d/ configuration and subsequent su/sudo activity — the technique Jewelbug's Linux tooling uses to steal credentials.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects ELF binaries embedding the ClientKing implant name alongside structural indicators (Rust runtime markers or C2 configuration patterns), associated with Jewelbug espionage tooling targeting Linux servers and routers
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103