Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects the 12KB RtkNGUI64.exe backdoor built without a C runtime, using GCC (tdm64-1) 4.9.2 and custom CRC/table-based string obfuscation
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects a fake desktop.ini file combining a legitimate-looking ShellClassInfo/LocalizedResourceName lure (shell32.dll,-21781) with a C2 domain hidden as unary-encoded trailing whitespace after byte offset 174 -- consolidates the lure-content and whitespace-encoding indicators into one high-fidelity rule
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002