Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects rockstargames.exe dropping a batch script or executing binaries directly from C:\Users\Default\Local Settings, specifically targeting the execution pattern associated with DCRAT (UserOOBEBroker.exe masquerading).
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
9 hours ago
000
Detects DNS queries, HTTP requests, TLS SNI requests, and direct IP traffic associated with DCRAT command and control infrastructure using the domain a0700877.xsph.ru or IP 141.8.197.42 during a GTA VI lure campaign.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
9 hours ago
000