Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
1
Products / Services
1
1
MITRE Techniques
1
1
IDS Classtypes
1
IDS Protocols
1
Detects outbound TCP traffic to known PurpleDelta-associated infrastructure IP addresses on common remote-access/web ports (80, 443, 3389), indicating potential communication with North Korean IT-worker facilitator infrastructure. Scope is limited to static IP indicators from Appendix A; does not cover Astrill VPN egress ranges or shell-company recruitment domains (minicursor[.]com), which would require separate signatures.
