Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

9 detections

Detects potential DGA fallback beaconing: repeated lookups (~10 per 5 days) of algorithmically-generated .com domains with a failed-resolution cadence, matching the botking implant's C2 fallback behavior.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects outbound connections to the known Rust supply-chain C2 infrastructure, plus a lower-confidence rule for the broader Hostwinds range on port 9089.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
203
Detects the botking RAT's C2 beacon: HTTPS POST with the 'i am botking' registration marker and form-urlencoded action=check polling, plus associated TLS/DNS indicators.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects encapsulated C2 traffic over non-standard ports and DNS/HTTP tunneling patterns using entropy/volume thresholds and sustained-pattern requirements to avoid matching ordinary long DNS queries, excluding known legitimate tunneling tools/VPN endpoints.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3012
Detects TLS sessions to Sapphire Sleet/UNC1069 Hostwinds C2 infrastructure presenting the exact self-signed certificate issuer string linked to the Mastra/axios campaigns.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000
Detects large-volume outbound TLS transfers scoped to mega.nz/mega.io SNI/destination, tuned against a typical daily-use baseline so routine small file-sharing does not trigger, consistent with Gunra's confirmed exfiltration of up to tens of terabytes to Mega.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108
Network detection for Sliver C2 framework beaconing, tightened to require JA3/JA3S fingerprints and certificate-field patterns characteristic of Sliver's default TLS templates rather than generic self-signed certificates.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects FileZilla FTP client traffic patterns and large single-session outbound FTP transfers to external hosts above a tuned threshold, weighted more heavily outside business hours, excluding known internal FTP servers/vendors and approved data-transfer partners.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Network signature matching known Gunra C2 IP addresses, the datapub.news leak/paste domain, and Gunra-associated .onion leak/negotiation sites.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004