Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
8 detections
Filters
Last updated
All Time
Detection languages
8
Contributors
8
Categories
5
2
2
1
Platforms
5
3
3
3
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
2
2
1
1
1
CVEs
1
IDS Classtypes
3
3
2
IDS Protocols
4
1
1
Detects potential DGA fallback beaconing: repeated lookups (~10 per 5 days) of algorithmically-generated .com domains with a failed-resolution cadence, matching the botking implant's C2 fallback behavior.
Detects outbound connections to the known Rust supply-chain C2 infrastructure, plus a lower-confidence rule for the broader Hostwinds range on port 9089.
Detects the botking RAT's C2 beacon: HTTPS POST with the 'i am botking' registration marker and form-urlencoded action=check polling, plus associated TLS/DNS indicators.
Detects DNS, HTTP, and TLS access to the public code-hosting repositories publishing the ShieldBreak Microsoft Defender 0-day exploit (GitHub, git.projectnightcrawler.dev, git.churchofmalware.org).
Detects DNS queries and HTTP traffic to Jewelbug's known typosquatted C2 domains (fonts.chrorne[.]com, fonts.tarotfree101[.]top, robot.avbliud[.]com, www.f1ash[.]org[.]cn) via exact-match logic to avoid fuzzy-matching false positives.
Detects ClientKing's custom DNS-tunneling C2 channel via high-entropy, long subdomains in TXT-record queries at sustained volume.
Detects DNS queries to Google Ads click-tracking infrastructure followed within 60 seconds by resolution of a newly registered, previously unseen domain, consistent with the Storm-2755 AiTM redirect chain.
Detects the Payroll Pirates (Storm-2755) AiTM phishing redirect chain: Google Meet/Ads redirector, an AWS S3 intermediate hop, and final resolution of a previously-unseen domain, indicating completion of the multi-hop chain to an AiTM proxy.
