Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects run.pyw wrapper scripts embedding RC4-encrypted RAT blob with key-schedule byte pattern and ChaCha20 decryption routine with constant signature, for EtherHiding C2 config, used by DeviceManager RAT
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects the IntelSoftwareUpdaterV8.exe installer masquerading as a legitimate updater, bundling Python 3.11 runtime and dropping to Microsoft-looking WindowsApps path used by UNC5142 DeviceManager RAT
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000