Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
2
2
1
Contributors
5
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
2
2
1
Products / Services
2
2
1
1
1
MITRE Techniques
3
3
3
2
2
CVEs
1
1
IDS Classtypes
2
IDS Protocols
2
Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
Detects legacy RFB security-type 2 (VNC password) authentication negotiation against macOS Screen Sharing from external sources, indicating legacy-VNC administration or abuse of the CVE-2026-43760 legacy-auth path that retains root file-copy authority.
Detects the CVE-2026-65400 pre-auth bypass exploitation of macOS Screen Sharing via an oversized RFB SRP (security-type 36) authentication frame length field, correlated with the connection subsequently reaching an authenticated state.
Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
Detects an AI agent's code-execution sandbox decrypting attacker-supplied AES/PBKDF2 ciphertext immediately after fetching untrusted external content — the core trust-laundering mechanism behind Cryptographic Context Injection attacks.
