Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Contributors
2
Categories
1
1
1
1
1
Platforms
1
1
Products / Services
1
1
1
1
MITRE Techniques
17,957
15,455
12,307
8,184
6,031
IDS Classtypes
1
IDS Protocols
1
Detects rockstargames.exe dropping a batch script or executing binaries directly from C:\Users\Default\Local Settings, specifically targeting the execution pattern associated with DCRAT (UserOOBEBroker.exe masquerading).
Detects DNS queries, HTTP requests, TLS SNI requests, and direct IP traffic associated with DCRAT command and control infrastructure using the domain a0700877.xsph.ru or IP 141.8.197.42 during a GTA VI lure campaign.
