Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
2
1
Contributors
3
Categories
2
2
1
1
1
Platforms
3
Products / Services
10,371
9,516
6,509
4,371
3,687
MITRE Techniques
2
2
2
Detects C2Looper sideloading a malicious wtsapi32.dll from a non-System32 path by terminating and relaunching the legitimate OneDrive.exe process to load it.
Detects C2Looper sideloading a malicious wtsapi32.dll from a non-System32 path by terminating and relaunching the legitimate OneDrive.exe process to load it.
Detects anomalous OneDrive/SharePoint bulk download activity specifically correlated with execution of the named main.exe process, excluding Microsoft-signed sync clients and known enterprise migration tools (SharePoint Migration Tool, ShareGate).
