Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects outbound TCP traffic to known PurpleDelta-associated infrastructure IP addresses on common remote-access/web ports (80, 443, 3389), indicating potential communication with North Korean IT-worker facilitator infrastructure. Scope is limited to static IP indicators from Appendix A; does not cover Astrill VPN egress ranges or shell-company recruitment domains (minicursor[.]com), which would require separate signatures.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102