Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects C2Looper sideloading a malicious wtsapi32.dll from a non-System32 path by terminating and relaunching the legitimate OneDrive.exe process to load it.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
309
Detects C2Looper sideloading a malicious wtsapi32.dll from a non-System32 path by terminating and relaunching the legitimate OneDrive.exe process to load it.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
504
Detects anomalous OneDrive/SharePoint bulk download activity specifically correlated with execution of the named main.exe process, excluding Microsoft-signed sync clients and known enterprise migration tools (SharePoint Migration Tool, ShareGate).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107