Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
2
1
Contributors
3
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
3
Products / Services
1
1
1
MITRE Techniques
2
2
1
1
1
Detects known BTR.sys driver binaries via SHA-256 hash match, or the co-occurrence of the hardcoded RC4 key fragment, the FEE1DEAD magic value, and the embedded BOOTTIMETOOL resource marker in .rdata.
Detects hash-matched BTR.sys driver loads that are validly signed by Microsoft but not initiated by a legitimate Windows Defender platform process (MsMpEng.exe/MpCmdRun.exe or the Defender Platform folder) — indicating the driver is being loaded by an unauthorized process to abuse its kernel-level file/registry operation primitive.
Detects the msagent.sys signed kernel-mode rootkit driver used by the CoolClient backdoor (HoneyMyte/Mustang Panda)
