Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
13 detections
Filters
Last updated
All Time
Detection languages
7
2
2
2
Contributors
13
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
5
4
3
2
Products / Services
2
2
2
2
2
MITRE Techniques
9
5
5
4
4
CVEs
1
IDS Classtypes
5
1
IDS Protocols
3
1
1
Detects an AI agent sandbox exfiltrating harvested PII/session context by embedding it as an x-auth-token query parameter in an outbound HTTP request to an external host — the network-observable exfiltration stage of Cryptographic Context Injection.
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
Detects ACRStealer C2 data-transfer bursts (outbound credential-data exfiltration >100KB, inbound follow-on payload >1MB) correlated with prior credential-sweep and process-injection-stage flowbits, rather than raw transfer size alone.
Detects HTTP traffic to StopAndProtect's compromised-WordPress C2 operational endpoints, heartbeat beaconing, encrypted-archive exfiltration, and victim data directory access.
Detects HTTP requests to the JWR phishing framework's REST-based alternate C2 API surface, covering beaconing, exfiltration POSTs, CVV capture, instruction polling/acknowledgment, and device/IP fingerprint sync across five distinct endpoints.
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
Detects SilentDataCollector uploading AES-CBC encrypted, specifically-named archives (desktop_files, pass_V, wallet_V, filelist.zip.encrypted, documents<n>.zip) to the compromised WordPress C2.
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
Detects the UNC5142 DeviceManager RAT's DNS-based C2 channel: raw malformed/non-resolver UDP/53 packets and Base64-chunked o-/e-/r- prefixed query names to 91.92.240.100, plus microsoft.com-suffixed decoy queries.
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
Correlates Abyssos file-collection/archival commands (GRABBER_START/FM_GET/FM_ARCHIVE/FM_ADDTOARCHIVE) — requiring at least 5 collected files before an archive — with a subsequent non-standard-port outbound connection within 30 minutes, consistent with staged exfiltration over the AES-GCM C2 channel.
Detects likely exfiltration of encrypted synced passkey (WebauthnCredentialSpecifics) blobs to external C2 infrastructure, correlated with a prior non-browser read of Chrome's Sync Data LevelDB store, consistent with the collection-and-exfiltration stage of a Pass-ta-key credential-theft chain. Excludes traffic destined to Google's own domains.
Detects a process running from a path ending in svchost32.exe performing an unusually high volume of file open/read/rename/write operations or transferring a large total byte volume within a 1-hour window, consistent with CornFlake bulk file collection/exfiltration nearing its documented throttle limits.
