Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects the botking RAT issuing Shell/ShellX/runscript commands that spawn powershell.exe from an implant-named parent process, matching the backdoor's remote command-execution capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
10014
Detects C2Looper's remote interactive shell and ShellExecuteW run-and-self-delete command execution, correlated with the c2_out.txt output-capture artifact.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects C2Looper's remote interactive shell and ShellExecuteW run-and-self-delete command execution, correlated with the c2_out.txt output-capture artifact.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207