Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
5
Contributors
5
Categories
5
2
Platforms
5
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
3
2
1
1
1
IDS Classtypes
4
1
Detects HTTP requests to known Storm-2755 Payroll Pirates AiTM lookalike proxy domains that also reference Microsoft authentication infrastructure in the URI, indicating a reverse-proxy phishing kit relaying to real Microsoft login endpoints.
Detects DNS queries to Google Ads click-tracking infrastructure followed within 60 seconds by resolution of a newly registered, previously unseen domain, consistent with the Storm-2755 AiTM redirect chain.
Detects POST requests to the Storm-2755 Payroll Pirates AiTM toolkit fingerprinting endpoint URI pattern co-occurring with the distinctive openresty/PHP response header combination.
Detects the Payroll Pirates (Storm-2755) AiTM phishing redirect chain: Google Meet/Ads redirector, an AWS S3 intermediate hop, and final resolution of a previously-unseen domain, indicating completion of the multi-hop chain to an AiTM proxy.
Detects AiTM phishing page geolocation fingerprint script referencing api.country.is, setting an rcfh_country cookie, and redirecting via oauth2/v2.0/authorize.
