Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects StopAndProtect malware binaries via the hardcoded developer source path string, validated against PE format or a known sample hash.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects StopAndProtect campaign base64-encoded payload files staged in WordPress upload directories, requiring multiple named .b64 filenames or a base64 blob in a wp-content/uploads path context
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000