Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Static file-based detection of the ACRStealer dropper, encrypted AutoIt payload, and DCRCVDrv.sys BYOVD driver via filenames, service/device names, signer names, and certificate serial. Certificate/signer matches only fire in combination with the driver file or service artifacts to avoid flagging the legitimate vendor certificate alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103