Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Detects installation of unauthorized remote-access/RMM software (AnyDesk, RealVNC, Jump Desktop, Chrome Remote Desktop) outside the normal IT-provisioning window combined with a connection to an unfamiliar external IP, consistent with facilitator-maintained device access in PurpleDelta operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2012
Detects BeaverTail malware deployed via PurpleDelta/PurpleBravo coordination; requires multiple occurrences of the distinctive BeaverTail string to reduce false positives
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
007
Detects a single source device or IP maintaining genuinely time-overlapping sign-in sessions under two or more distinct user identities, excluding known shared/kiosk devices and shared VPN egress points, consistent with a single PurpleDelta operator working multiple jobs simultaneously.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects execution of the NetProvider network-monitoring utility from a non-standard install path or in close time proximity to an active videoconferencing session, consistent with PurpleDelta operator self-monitoring of network traffic during interviews.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects screen-recording or AI voice-transcription applications (iTop Screen Recorder, Krisp, Caption.Ed) running within 60 minutes of an active videoconferencing session, consistent with PurpleDelta operators recording or transcribing interviews or meetings to generate scripted answers.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103