Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

This rule detects the presence of known malicious browser extensions, specifically "Zoom Stealer Extension" and "Shady Panda Extension", by looking for their unique Extension IDs within file paths or file names on devices. It identifies the first and last seen timestamps, the names of the extensions, their IDs, associated campaigns, and the browsers they target, summarizing this information per device.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
9 months ago
1176862
Original Sigma Rule: https://github.com/Neo23x0/sigma/blob/master/rules/apt/apt_hurricane_panda.yml.
Questions via Twitter: @janvonkirchheim.
Azure Sentinel@AzureSentinel
avatar
AzureSentinel
1 year ago
008