Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

53 detections

Detects SSFileCopySender/SSFileCopyReceiver helpers running as uid=0 reading or writing sensitive system paths during Screen Sharing sessions using legacy VNC auth or lacking a preceding valid local logon — abuse of the root file-copy primitive underlying CVE-2026-65400.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
22046
Detects creation of LaunchAgent/LaunchDaemon plists, /etc/zshenv, or SSH authorized_keys attributed to screensharingd/helpers or occurring within a Screen Sharing session window — persistence via the root file-write primitive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5026
Detects installation of unauthorized remote-access/RMM software (AnyDesk, RealVNC, Jump Desktop, Chrome Remote Desktop) outside the normal IT-provisioning window combined with a connection to an unfamiliar external IP, consistent with facilitator-maintained device access in PurpleDelta operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2012
Detects wscript.exe executing the VBScript launcher OptiDrive.vbs from the ACRStealer masquerade staging path (%LOCALAPPDATA%\DriveOptimize Technologies\), used to invoke the persistent compiled AutoIt payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
16013
Detects a process other than screensharingd binding to macOS Screen Sharing port 5900 shortly after being newly spawned, indicating potential exploitation of the CVE-2026-43779 connection-interception logic flaw.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6015
Detects sudoers.d writes attributed to screensharingd/helper followed within minutes by passwordless (sudo -n) execution for a previously-unprivileged account, optionally correlated with a dropped callback script.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1014
Detects AutoIt3.exe launched with a .a3x script argument from a %TEMP%\IXP* self-extraction directory, spawned by WEXTRACT.EXE — the ACRStealer first-stage execution chain (setup_patched.exe IExpress self-extractor deploying an encrypted AutoIt payload).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6010
Detects self-deletion of ACRStealer's first-stage payload artifacts (Proper.a3x / BrowserMetrics) by the same process that recently created a persistence Run key or dropped follow-on files, indicating anti-forensic cleanup after installation.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010
Detects OptiDrive.exe sweeping multiple browser credential/cookie store files (Local State, Login Data, Cookies, History) across at least 3 distinct files within a 2-minute window, consistent with ACRStealer's browser credential harvesting.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4010
Detects the ACRStealer BYOVD driver's ungated IOCTL 0x2205c0 being sent to \\.\DCRCVDRV_U by a non-management process, correlated within 2 minutes with termination of a security/EDR process, indicating kernel-level defense evasion via the vulnerable driver.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
809
Detects persistence established via a Run registry key named 'Rapid' or 'TIEmounter' pointing to C:\ProgramData\Rapid\creator-ws.exe, correlated with the corresponding process launch, matching ACRStealer's second-stage payload persistence mechanism.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
308
Detects process hollowing/injection into wab.exe, MSBuild.exe, dllhost.exe, or rundll32.exe — suspended process creation combined with SetThreadContext or NtQueueApcThread on the same process within a 5-minute window, followed by an outbound connection to known ACRStealer C2 (49.13.169.214) or renewed browser credential-store access.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
307
Detects non-interactive PowerShell invoked via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -, reading attacker commands from standard input, spawned by a process that is not a known RMM/patch-management agent and is unsigned, low-integrity, or itself suspicious — matching ACRStealer's follow-on command execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects the unsigned/untrusted DLL tbbmalloc.dll being side-loaded by pgocvt.exe from C:\ProgramData\TIEmounter\, matching ACRStealer's second payload-set DLL side-loading technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
306
Detects installation/loading of the DCRCVDrv.sys BYOVD driver at the atypical staging path C:\Windows\Temp\DCRCVDrv.sys — including SCM service registration, \Device\DCRCVDRV_U device/symlink creation, and named kernel share-event objects — distinguishing attacker deployment from a legitimate DLP install.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects repeated screensharingd crash/restart cycles tightly time-correlated with file-copy helper activity, indicating CVE-2026-43777 DoS exploitation alongside its secondary file-copy abuse potential.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects command-history clearing and log-deletion events (history -c, PowerShell history wipe, Clear-EventLog, wevtutil cl) co-occurring with another suspicious indicator (credential access or lateral movement) on the same host within a 1-hour window, excluding scheduled group-policy retention jobs.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
13035
Detects presence of persona-fabrication and identity-fraud enablement software (Wavebox, MEmu, eSIM Plus, Blacktel, insertFace, TrustID Card) via process, network, or file-system artifacts on an endpoint, consistent with PurpleDelta identity-fraud tradecraft.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects execution of face-swapping or deepfake software, excluding known legitimate virtual-background/video-filter tools, consistent with PurpleDelta operators disguising their identity during video interviews.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects screensharingd or its child helper processes accessing TCC-protected data categories on hosts with no prior TCC grant recorded for screensharingd, indicating a TCC bypass via the Screen Sharing exploit chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects execution of the NetProvider network-monitoring utility from a non-standard install path or in close time proximity to an active videoconferencing session, consistent with PurpleDelta operator self-monitoring of network traffic during interviews.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Page 1 of 3