Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
60037
Detects legacy RFB security-type 2 (VNC password) authentication negotiation against macOS Screen Sharing from external sources, indicating legacy-VNC administration or abuse of the CVE-2026-43760 legacy-auth path that retains root file-copy authority.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1022
Detects the CVE-2026-65400 pre-auth bypass exploitation of macOS Screen Sharing via an oversized RFB SRP (security-type 36) authentication frame length field, correlated with the connection subsequently reaching an authenticated state.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
0013
Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
408
Detects an AI agent's code-execution sandbox decrypting attacker-supplied AES/PBKDF2 ciphertext immediately after fetching untrusted external content — the core trust-laundering mechanism behind Cryptographic Context Injection attacks.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000