Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
2
1
1
1
Platforms
3
1
1
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
1
1
1
1
1
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
Detects run.pyw wrapper scripts embedding RC4-encrypted RAT blob with key-schedule byte pattern and ChaCha20 decryption routine with constant signature, for EtherHiding C2 config, used by DeviceManager RAT
Detects the IntelSoftwareUpdaterV8.exe installer masquerading as a legitimate updater, bundling Python 3.11 runtime and dropping to Microsoft-looking WindowsApps path used by UNC5142 DeviceManager RAT
