Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects known BTR.sys driver binaries via SHA-256 hash match, or the co-occurrence of the hardcoded RC4 key fragment, the FEE1DEAD magic value, and the embedded BOOTTIMETOOL resource marker in .rdata.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108
Detects hash-matched BTR.sys driver loads that are validly signed by Microsoft but not initiated by a legitimate Windows Defender platform process (MsMpEng.exe/MpCmdRun.exe or the Defender Platform folder) — indicating the driver is being loaded by an unauthorized process to abuse its kernel-level file/registry operation primitive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects the msagent.sys signed kernel-mode rootkit driver used by the CoolClient backdoor (HoneyMyte/Mustang Panda)
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005