Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
2
Contributors
2
Categories
2
1
Platforms
2
Products / Services
10,371
9,516
6,509
4,371
3,687
MITRE Techniques
2
2
1
Detects the 12KB RtkNGUI64.exe backdoor built without a C runtime, using GCC (tdm64-1) 4.9.2 and custom CRC/table-based string obfuscation
Detects a fake desktop.ini file combining a legitimate-looking ShellClassInfo/LocalizedResourceName lure (shell32.dll,-21781) with a C2 domain hidden as unary-encoded trailing whitespace after byte offset 174 -- consolidates the lure-content and whitespace-encoding indicators into one high-fidelity rule
