Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
53 detections
Filters
Last updated
All Time
Detection languages
47
3
3
Contributors
53
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
42
6
5
3
Products / Services
22
12
6
3
2
MITRE Techniques
8
8
7
6
4
CVEs
3
2
2
2
1
IDS Classtypes
1
1
1
IDS Protocols
1
1
1
Network detection for Sliver C2 framework beaconing, tightened to require JA3/JA3S fingerprints and certificate-field patterns characteristic of Sliver's default TLS templates rather than generic self-signed certificates.
Detects unusually high-volume recursive file/directory enumeration (dir /s, tree, Get-ChildItem -Recurse) spanning multiple distinct user-profile directories or department shares in a short window, excluding known AV/EDR scanning engines and backup-agent processes.
Detects browser session-cookie database access followed by session reuse under impossible-travel or concurrent-session conditions, consistent with Gunra's VDI session-hijacking technique.
Detects repeated netstat.exe execution or net use enumeration across multiple distinct hosts in a short window, excluding known network-monitoring (NPM) tools and helpdesk remote-support sessions.
Detects FileZilla FTP client traffic patterns and large single-session outbound FTP transfers to external hosts above a tuned threshold, weighted more heavily outside business hours, excluding known internal FTP servers/vendors and approved data-transfer partners.
Detects Gunra ransomware components (main.exe, cryptor.exe, msmp.exe) via known file hashes, or via a clustered combination of embedded exclusion-logic strings referencing C:\Windows and .exe/.dll/.sys extensions used by the ChaCha20+RSA-4096 encryptor to skip system files; requires all exclusion strings present, in the expected order, and tightly clustered together to avoid matching unrelated installers that merely reference these common substrings individually
Detects SSH access to the Hiware system access-control server from accounts/source IPs outside the approved PAM admin allowlist, followed by bulk password-database export, consistent with Gunra's symmetric-key theft and mass credential decryption.
Detects cmd.exe /c spawned by an unusual parent process combined with native-API execution patterns outside normal application behavior, excluding common benign parent-child chains, and requires co-occurrence with at least one other flagged detection before surfacing given its low specificity.
Detects unauthorized modification of VDI/authentication-portal files implementing a hard-coded OTP-acceptance bypass, a specific Gunra MFA-tampering technique distinguished from routine MFA policy changes.
Detects SSL-VPN traffic-control/promiscuous-mode changes triggered by unexpected or unsigned processes outside approved maintenance windows, consistent with Gunra's interception of VDI authentication traffic.
Detects binaries importing both IsDebuggerPresent and CheckRemoteDebuggerPresent combined with anti-debug timing-check code patterns (rdtsc instruction and/or GetTickCount/QueryPerformanceCounter timing APIs), requiring multiple corroborating indicators to reduce false positives on legitimate software. Excludes binaries carrying a verified digital signature to avoid flagging legitimately signed software using these APIs for license-protection or anti-tamper purposes.
Page 3 of 3
