Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

53 detections

Network detection for Sliver C2 framework beaconing, tightened to require JA3/JA3S fingerprints and certificate-field patterns characteristic of Sliver's default TLS templates rather than generic self-signed certificates.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects unusually high-volume recursive file/directory enumeration (dir /s, tree, Get-ChildItem -Recurse) spanning multiple distinct user-profile directories or department shares in a short window, excluding known AV/EDR scanning engines and backup-agent processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects browser session-cookie database access followed by session reuse under impossible-travel or concurrent-session conditions, consistent with Gunra's VDI session-hijacking technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
305
Detects repeated netstat.exe execution or net use enumeration across multiple distinct hosts in a short window, excluding known network-monitoring (NPM) tools and helpdesk remote-support sessions.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects FileZilla FTP client traffic patterns and large single-session outbound FTP transfers to external hosts above a tuned threshold, weighted more heavily outside business hours, excluding known internal FTP servers/vendors and approved data-transfer partners.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects Gunra ransomware components (main.exe, cryptor.exe, msmp.exe) via known file hashes, or via a clustered combination of embedded exclusion-logic strings referencing C:\Windows and .exe/.dll/.sys extensions used by the ChaCha20+RSA-4096 encryptor to skip system files; requires all exclusion strings present, in the expected order, and tightly clustered together to avoid matching unrelated installers that merely reference these common substrings individually
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects SSH access to the Hiware system access-control server from accounts/source IPs outside the approved PAM admin allowlist, followed by bulk password-database export, consistent with Gunra's symmetric-key theft and mass credential decryption.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects cmd.exe /c spawned by an unusual parent process combined with native-API execution patterns outside normal application behavior, excluding common benign parent-child chains, and requires co-occurrence with at least one other flagged detection before surfacing given its low specificity.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102
Detects unauthorized modification of VDI/authentication-portal files implementing a hard-coded OTP-acceptance bypass, a specific Gunra MFA-tampering technique distinguished from routine MFA policy changes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102
Detects SSL-VPN traffic-control/promiscuous-mode changes triggered by unexpected or unsigned processes outside approved maintenance windows, consistent with Gunra's interception of VDI authentication traffic.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102
Detects binaries importing both IsDebuggerPresent and CheckRemoteDebuggerPresent combined with anti-debug timing-check code patterns (rdtsc instruction and/or GetTickCount/QueryPerformanceCounter timing APIs), requiring multiple corroborating indicators to reduce false positives on legitimate software. Excludes binaries carrying a verified digital signature to avoid flagging legitimately signed software using these APIs for license-protection or anti-tamper purposes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000
Page 3 of 3