Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

13 detections

Detects an AI agent sandbox exfiltrating harvested PII/session context by embedding it as an x-auth-token query parameter in an outbound HTTP request to an external host — the network-observable exfiltration stage of Cryptographic Context Injection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1007
Detects ACRStealer C2 data-transfer bursts (outbound credential-data exfiltration >100KB, inbound follow-on payload >1MB) correlated with prior credential-sweep and process-injection-stage flowbits, rather than raw transfer size alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects HTTP traffic to StopAndProtect's compromised-WordPress C2 operational endpoints, heartbeat beaconing, encrypted-archive exfiltration, and victim data directory access.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects HTTP requests to the JWR phishing framework's REST-based alternate C2 API surface, covering beaconing, exfiltration POSTs, CVV capture, instruction polling/acknowledgment, and device/IP fingerprint sync across five distinct endpoints.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
202
Detects SilentDataCollector uploading AES-CBC encrypted, specifically-named archives (desktop_files, pass_V, wallet_V, filelist.zip.encrypted, documents<n>.zip) to the compromised WordPress C2.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects the UNC5142 DeviceManager RAT's DNS-based C2 channel: raw malformed/non-resolver UDP/53 packets and Base64-chunked o-/e-/r- prefixed query names to 91.92.240.100, plus microsoft.com-suffixed decoy queries.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Correlates Abyssos file-collection/archival commands (GRABBER_START/FM_GET/FM_ARCHIVE/FM_ADDTOARCHIVE) — requiring at least 5 collected files before an archive — with a subsequent non-standard-port outbound connection within 30 minutes, consistent with staged exfiltration over the AES-GCM C2 channel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects likely exfiltration of encrypted synced passkey (WebauthnCredentialSpecifics) blobs to external C2 infrastructure, correlated with a prior non-browser read of Chrome's Sync Data LevelDB store, consistent with the collection-and-exfiltration stage of a Pass-ta-key credential-theft chain. Excludes traffic destined to Google's own domains.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects a process running from a path ending in svchost32.exe performing an unusually high volume of file open/read/rename/write operations or transferring a large total byte volume within a 1-hour window, consistent with CornFlake bulk file collection/exfiltration nearing its documented throttle limits.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001