Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
9 detections
Filters
Last updated
All Time
Detection languages
9
Contributors
9
Categories
5
4
2
1
1
Platforms
5
4
4
4
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
3
2
2
1
1
IDS Classtypes
4
3
2
IDS Protocols
3
2
1
1
1
Detects potential DGA fallback beaconing: repeated lookups (~10 per 5 days) of algorithmically-generated .com domains with a failed-resolution cadence, matching the botking implant's C2 fallback behavior.
Detects outbound connections to the known Rust supply-chain C2 infrastructure, plus a lower-confidence rule for the broader Hostwinds range on port 9089.
Detects the botking RAT's C2 beacon: HTTPS POST with the 'i am botking' registration marker and form-urlencoded action=check polling, plus associated TLS/DNS indicators.
Detects encapsulated C2 traffic over non-standard ports and DNS/HTTP tunneling patterns using entropy/volume thresholds and sustained-pattern requirements to avoid matching ordinary long DNS queries, excluding known legitimate tunneling tools/VPN endpoints.
Detects TLS sessions to Sapphire Sleet/UNC1069 Hostwinds C2 infrastructure presenting the exact self-signed certificate issuer string linked to the Mastra/axios campaigns.
Detects large-volume outbound TLS transfers scoped to mega.nz/mega.io SNI/destination, tuned against a typical daily-use baseline so routine small file-sharing does not trigger, consistent with Gunra's confirmed exfiltration of up to tens of terabytes to Mega.
Network detection for Sliver C2 framework beaconing, tightened to require JA3/JA3S fingerprints and certificate-field patterns characteristic of Sliver's default TLS templates rather than generic self-signed certificates.
Detects FileZilla FTP client traffic patterns and large single-session outbound FTP transfers to external hosts above a tuned threshold, weighted more heavily outside business hours, excluding known internal FTP servers/vendors and approved data-transfer partners.
Network signature matching known Gunra C2 IP addresses, the datapub.news leak/paste domain, and Gunra-associated .onion leak/negotiation sites.
