Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
4
1
Contributors
5
Categories
20,015
11,427
5,755
4,979
4,812
Platforms
4
1
1
1
Products / Services
1
1
1
1
1
MITRE Techniques
1
1
1
1
1
Detects installation of unauthorized remote-access/RMM software (AnyDesk, RealVNC, Jump Desktop, Chrome Remote Desktop) outside the normal IT-provisioning window combined with a connection to an unfamiliar external IP, consistent with facilitator-maintained device access in PurpleDelta operations.
Detects BeaverTail malware deployed via PurpleDelta/PurpleBravo coordination; requires multiple occurrences of the distinctive BeaverTail string to reduce false positives
Detects a single source device or IP maintaining genuinely time-overlapping sign-in sessions under two or more distinct user identities, excluding known shared/kiosk devices and shared VPN egress points, consistent with a single PurpleDelta operator working multiple jobs simultaneously.
Detects execution of the NetProvider network-monitoring utility from a non-standard install path or in close time proximity to an active videoconferencing session, consistent with PurpleDelta operator self-monitoring of network traffic during interviews.
Detects screen-recording or AI voice-transcription applications (iTop Screen Recorder, Krisp, Caption.Ed) running within 60 minutes of an active videoconferencing session, consistent with PurpleDelta operators recording or transcribing interviews or meetings to generate scripted answers.
