Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
2
Contributors
1
1
Categories
1
1
1
1
Platforms
2
Products / Services
2
1
MITRE Techniques
17,957
15,455
12,307
8,184
6,031
This rule detects the presence of known malicious browser extensions, specifically "Zoom Stealer Extension" and "Shady Panda Extension", by looking for their unique Extension IDs within file paths or file names on devices. It identifies the first and last seen timestamps, the names of the extensions, their IDs, associated campaigns, and the browsers they target, summarizing this information per device.
Original Sigma Rule: https://github.com/Neo23x0/sigma/blob/master/rules/apt/apt_hurricane_panda.yml.
Questions via Twitter: @janvonkirchheim.
Questions via Twitter: @janvonkirchheim.
