Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

22 detections

Detects access to the AWS CLI credentials file (~/.aws/credentials) in a user's home directory, used by CISA's red team to harvest long-lived static IAM access keys.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
5014
Detects access to files containing cleartext credentials on an administrative workstation, followed by their use to authenticate to a sensitive business system — the initial-access path CISA's red team used against SBS 1.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
33011
Detects process execution shortly after a user clicks a malicious link delivered via spearphishing email, indicating successful initial-access payload execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
409
Detects an executable loading an unexpected DLL, indicative of DLL side-loading used to execute a payload while evading static EDR signatures, as observed in CISA's red team engagement.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
306
Detects access to SQL developer tool configuration files (connections.json, product-preferences.xml) followed by a decryption utility, used by CISA's red team to recover cleartext database credentials from a targeted workstation.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
203
Detects the BYOVD kill chain for the DCRCVDrv.sys driver: drop to C:\Windows\Temp\, DCRCVDRV_U/LEGACY_DCRCVDRV_U service installation, device open, and IOCTL 0x2205c0 invocation used to terminate security/EDR processes from kernel context.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
909
Detects the full process-hollowing sequence (suspended process creation, SetThreadContext, ResumeThread) executed against the same target PID for wab.exe or MSBuild.exe within a short window — the ACRStealer campaign's injection technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects a concentrated sweep of multiple browser credential/cookie artifacts (Local State, Login Data, Cookies, History) by a single non-browser process (OptiDrive.exe) within a one-minute window — the ACRStealer credential-theft stage.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects APC injection into dllhost.exe unbacked/private memory via NtQueueApcThread correlated with a subsequent outbound network connection from the same process — the ACRStealer injection-and-C2 pattern.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects Run key persistence for follow-on ACRStealer payloads (creator-ws.exe under ProgramData\Rapid, pgocvt.exe under ProgramData\TIEmounter) launched via a cmd /c start wrapper.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
507
Detects wscript.exe executing OptiDrive.vbs from the %LOCALAPPDATA%\DriveOptimize Technologies\ masquerade directory to invoke the renamed AutoIt interpreter OptiDrive.exe — the ACRStealer staging/masquerade technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
Detects sandbox/VM fingerprinting via combined Win32_DiskDrive and Win32_VideoController WMI queries from the same process/host within a short window — anti-analysis behavior observed in the ACRStealer AutoIt payload prior to execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects rapid self-deletion of the initial ACRStealer payload artifacts (Proper.a3x, BrowserMetrics) within 5 minutes of their creation by the setup_patched.exe/AutoIt execution chain — an indicator-removal behavior.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects non-interactive PowerShell launched via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command - reading commands from stdin — the ACRStealer payload's command-execution technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Static file-based detection of the ACRStealer dropper, encrypted AutoIt payload, and DCRCVDrv.sys BYOVD driver via filenames, service/device names, signer names, and certificate serial. Certificate/signer matches only fire in combination with the driver file or service artifacts to avoid flagging the legitimate vendor certificate alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects DLL side-loading of the unsigned tbbmalloc.dll by the signed binary pgocvt.exe from the C:\ProgramData\TIEmounter\ staging directory — a second-stage follow-on payload technique in the ACRStealer campaign.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects an unsigned/unexpected PAM module written into the su/sudo authentication stack, correlated with non-package-manager modification of /etc/pam.d/ configuration and subsequent su/sudo activity — the technique Jewelbug's Linux tooling uses to steal credentials.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Detects execution of AutoIt3.exe running the Proper.a3x payload following extraction by the IExpress self-extractor setup_patched.exe (or from its IXP000.TMP staging path) — the initial infection chain observed in the ACRStealer/Amatera BYOVD campaign.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects ELF binaries embedding the ClientKing implant name alongside structural indicators (Rust runtime markers or C2 configuration patterns), associated with Jewelbug espionage tooling targeting Linux servers and routers
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects mshta.exe execution combined with CSIS geopolitical lure content or the known TEST.hta downloader artifact used to deliver the Antino backdoor
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects ClientKing's technique of loading Linux kernel modules directly from memory (via memfd/init_module) without a corresponding on-disk .ko file, used to deploy rootkit functionality.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Page 1 of 2