Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects known malicious stage-2 payload binaries dropped by the compromised proc-macro1/arrayref Rust supply-chain attack via hash, size, and file-type match.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects binaries embedding both the hardcoded AES-128-GCM key 'i am botking' and the embedded RSA-2048 private key used for C2 command authentication
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003