Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects C2Looper v1 HTTP beaconing and result reporting to hardcoded C2 IP addresses over port 8888 via the /api/beacon and /api/result endpoints.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects DNS, HTTP, and TLS access to the public code-hosting repositories publishing the ShieldBreak Microsoft Defender 0-day exploit (GitHub, git.projectnightcrawler.dev, git.churchofmalware.org).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010