Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
11 detections
Filters
Last updated
All Time
Detection languages
6
2
2
1
Contributors
11
Categories
20,015
11,427
5,755
4,979
4,812
Platforms
7
6
4
2
1
Products / Services
3
3
2
2
2
MITRE Techniques
2
2
1
1
1
IDS Classtypes
1
IDS Protocols
1
Detects Linux persistence and removal activity by the botking implant, systemd user-service creation with the 'System Config User Service' description marker, secondary symlink persistence, or systemctl --user enable/disable for install/removal.
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
Detects known malicious stage-2 payload binaries dropped by the compromised proc-macro1/arrayref Rust supply-chain attack via hash, size, and file-type match.
Detects binaries embedding both the hardcoded AES-128-GCM key 'i am botking' and the embedded RSA-2048 private key used for C2 command authentication
Detects Antino's abuse of trusted cloud services — Microsoft Graph API and Google Docs — as C2 channels, gated on non-standard TLS ports, missing browser User-Agent, and non-HTML response bodies to reduce false positives from the very high volume of legitimate traffic to these domains.
Detects mshta.exe execution combined with CSIS geopolitical lure content or the known TEST.hta downloader artifact used to deliver the Antino backdoor
Detects cmd.exe spawned by the Jewelbug native-messaging helper registered under the Microsoft-masquerading name com.microsoft.runedge, correlated with creation of the corresponding Chrome NativeMessagingHosts registry key — the mechanism the group uses to bridge its malicious 'PDF Viewer' browser extension to an interactive remote shell.
Detects ClientKing's technique of loading Linux kernel modules directly from memory (via memfd/init_module) without a corresponding on-disk .ko file, used to deploy rootkit functionality.
Detects obfuscated JavaScript payload generated via the XG-Web code-generation platform and hosted on typosquatted fonts.tarotfree101.top domain, used by Jewelbug
Detects fake Adobe Flash/Adobe installer executables used by Jewelbug to drop the Antino backdoor, sideload slc.dll, install the 'PDF Viewer' extension, and register the com.microsoft.runedge native-messaging helper. Requires known filenames combined with known hashes or slc.dll/indicator strings, and excludes files carrying a valid Adobe code-signing certificate.
