Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
12 detections
Filters
Last updated
All Time
Detection languages
12
Contributors
12
Categories
10
4
2
1
1
Platforms
8
4
1
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
3
2
1
1
1
IDS Classtypes
7
5
IDS Protocols
4
3
3
2
Detects outbound C2 connections to known ACRStealer infrastructure IPs specifically from a process already flagged as hollowed/injected (wab.exe, MSBuild.exe, dllhost.exe) via a companion flowbit, rather than flagging all egress from these processes.
Detects ACRStealer C2 data-transfer bursts (outbound credential-data exfiltration >100KB, inbound follow-on payload >1MB) correlated with prior credential-sweep and process-injection-stage flowbits, rather than raw transfer size alone.
Detects a malformed/high-entropy repeated-label DNS query pattern used by ACRStealer as a connectivity canary check prior to establishing C2.
Detects the ACRStealer Telegram Dead Drop Resolver handoff: a non-Telegram-client TLS/SNI contact into Telegram's IP range immediately followed by a DNS/TLS/HTTP connection to the resolved C2 domain res.explicittweak.cc.
Detects the fake Adobe Flash update download from microsoft-flash[.]com/download/Adobeinstall.exe, served only after Jewelbug's 'flash' module validates the victim's targeted domain, account status, and OS.
Detects XG-Web implant check-in beacons — DNS lookups and HTTP config_*.js fetches — against Jewelbug's typosquatted C2 domain set, the unified panel reported to have logged over one million implant check-ins.
Detects a ClientKing-style beacon abusing internal proxy CONNECT authentication to reach known Jewelbug C2 infrastructure (tarotfree101.top), reusing a compromised organization's own proxy the way Jewelbug reused a major aerospace manufacturer's internal proxy.
Detects Antino's abuse of trusted cloud services — Microsoft Graph API and Google Docs — as C2 channels, gated on non-standard TLS ports, missing browser User-Agent, and non-HTML response bodies to reduce false positives from the very high volume of legitimate traffic to these domains.
Detects the exact watering-hole script fetch (fonts.chrorne[.]com /dist/js/*.chunk.js) injected into shared government webmail installations, which opens a WebSocket back to Jewelbug C2 and exfiltrates session cookies and usernames.
Detects DNS queries and HTTP traffic to Jewelbug's known typosquatted C2 domains (fonts.chrorne[.]com, fonts.tarotfree101[.]top, robot.avbliud[.]com, www.f1ash[.]org[.]cn) via exact-match logic to avoid fuzzy-matching false positives.
Detects ClientKing's custom DNS-tunneling C2 channel via high-entropy, long subdomains in TXT-record queries at sustained volume.
Detects TLS SNI and HTTP Host values matching Jewelbug's typosquatted-domain pattern impersonating the OKX and Binance cryptocurrency exchanges, used to drive traffic to cloaked phishing pages.
