Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
14 detections
Filters
Last updated
All Time
Detection languages
7
4
2
1
Contributors
8
5
1
Categories
10
4
4
4
4
Platforms
10
8
7
4
Products / Services
4
4
4
3
1
MITRE Techniques
17,933
15,412
12,289
8,184
6,030
IDS Classtypes
4
IDS Protocols
4
This rule detects artifacts and behaviors associated with the WaterPlum/Contagious Interview (also known as DeceptiveDevelopment) malware suite, including BeaverTail, InvisibleFerret, and related payloads. The rule specifically targets the presence of embedded family-name strings, as well as the execution of suspicious npm package installations triggered by VS Code task automation (tasks.json) or trust prompts, common in fake technical interview attack scenarios.
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
Detects Node.js or Python processes exhibiting suspicious behavior consistent with information-stealing malware (such as BeaverTail or InvisibleFerret). The rule monitors for these processes accessing sensitive files, including browser credentials, cookies, browser extension wallet settings, cryptocurrency wallet files, and various identification document image types, followed by the execution of archiving utilities (e.g., zip, rar, 7z) to stage the collected data for exfiltration.
Detects malicious software bundles consistent with the Contagious Interview (G1052) threat group's multi-stage infection chain. The rule identifies the presence of multiple malware family identifiers (such as BeaverTail, InvisibleFerret, and others) within the context of npm or VS Code task configuration files, which are commonly used in job-assessment themed social engineering campaigns.
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects BeaverTail malware deployed via PurpleDelta/PurpleBravo coordination; requires multiple occurrences of the distinctive BeaverTail string to reduce false positives


