Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

53 detections

Detects screen-recording or AI voice-transcription applications (iTop Screen Recorder, Krisp, Caption.Ed) running within 60 minutes of an active videoconferencing session, consistent with PurpleDelta operators recording or transcribing interviews or meetings to generate scripted answers.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects an AutoIt3.exe/OptiDrive.exe process performing WMI sandbox-fingerprinting queries (Win32_DiskDrive, Win32_VideoController) followed within 15 minutes by access to browser credential files, consistent with ACRStealer's anti-analysis check preceding data collection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects DCRCVDrv.sys driver used in ACRStealer BYOVD campaign via attacker-specific hashes, certificate serial, or atypical staging path; vendor metadata and PDB are supportive only
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects installation or execution of AnyDesk, Google Remote Desktop, or MobaXterm from user-writable directories (Downloads, Temp, AppData) outside the approved software baseline, excluding code-signed installs pushed via Intune/SCCM.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3014
Detects the unsigned/untrusted AutoIt interpreter binary OptiDrive.exe staged under the masquerade path %LOCALAPPDATA%\DriveOptimize Technologies\, mimicking legitimate 'DriveOptimize Technologies' software.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects execution of RClone from non-standard directories or outbound transfer to cloud endpoints outside an approved destination list, consistent with Gunra's pre-encryption data-exfiltration tooling.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4013
Detects Impacket-style (wmiexec, secretsdump, atexec, psexec.py, smbclient.py) and PsExec SMB admin-share lateral movement, excluding approved IT admin accounts and management servers.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5013
Detects RDP-based lateral movement, including pivots into VDI, AD, and authentication infrastructure, excluding known bastion/jump hosts and flagging sessions from atypical source workstations or off-hours timing.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5013
Detects remote process creation via wmic.exe/WmiPrvSE.exe and suspicious WMI event subscriptions, excluding known configuration-management platform service accounts (SCCM, Ansible, Puppet) and requiring the WMI connection to be the first-ever observed connection between the source/destination host pair.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6012
Detects deletion of Volume Shadow Copies and backup catalogs (vssadmin, wbadmin, wmic shadowcopy, bcdedit) consistent with Gunra ransomware's pre-encryption recovery-inhibition behavior, requiring correlated multi-command deletion sequences to reduce noise from routine backup retention.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2012
Detects OS credential dumping of the Active Directory NTDS.dit database via ntdsutil, VSS-based extraction, or Impacket's secretsdump.py, excluding approved AD backup jobs and accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5012
Detects unusually large 7-Zip/WinRAR archive creation from non-standard staging directories followed by outbound network activity, consistent with Gunra's data-staging step before double-extortion exfiltration.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8011
Detects bulk file copy to staging directories, mass file read access, mailbox-export-rule creation, and bulk PST/mailbox access, excluding DLP/eDiscovery/legal-hold exports tagged with a case ID and scheduled data-migration windows.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
109
Detects OpenSSH installation on Windows hosts, unexpected internal SSH sessions, and SSH tunnels terminating at an external (non-RFC1918) destination — particularly from SSL-VPN admin hosts — excluding documented DevOps CI/CD runners and known bastion hosts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
409
Detects pass-the-hash and pass-the-ticket lateral authentication using NTLM/Kerberos-ticket reuse across multiple hosts without a corresponding interactive logon, excluding known NTLM-by-design service accounts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108
Detects anomalous OneDrive/SharePoint bulk download activity specifically correlated with execution of the named main.exe process, excluding Microsoft-signed sync clients and known enterprise migration tools (SharePoint Migration Tool, ShareGate).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects LSASS memory access with credential-dumping-consistent access rights from unsigned or non-allowlisted processes, indicative of Mimikatz-driven credential theft used by Gunra ransomware affiliates.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects mass file rename/write events producing the distinctive .ENCRT extension used by Gunra's ChaCha20+RSA-4096 encryptor, scoped narrowly to avoid matching legitimate bulk file operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
307
Detects creation of the malicious persistent 'forticloud-sync' super-user account on FortiOS following an anomalous admin WebSocket session, consistent with post-exploitation of CVE-2024-55591/CVE-2025-24472.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
307
Network signature for the specific WebSocket/admin-API request sequence used to exploit the FortiOS/FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472, as leveraged by Gunra ransomware affiliates for initial access.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects certutil.exe -urlcache usage or PowerShell Invoke-WebRequest retrieving main.exe/cryptor.exe or similarly named payloads, followed by execution of the downloaded file, excluding downloads from an allowlist of approved internal software-distribution domains.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Page 2 of 3