Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
8 detections
Filters
Last updated
All Time
Detection languages
6
2
Contributors
8
Categories
5
4
3
3
2
Platforms
6
5
4
1
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
4
4
2
2
1
Detects the presence of known malicious Rust crate archive files (arrayref-0.3.10.crate, proc-macro1-*, and related typosquatted package names) in a host's local Cargo registry cache, indicating the compromised dependency was fetched.
Detects process activity referencing the typosquatted proc-macro1 crate or build-script-build.exe spawning a child process — the build-time execution chain used to trigger the malicious proc-macro1 payload on Windows build hosts.
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
Detects known malicious stage-2 payload binaries dropped by the compromised proc-macro1/arrayref Rust supply-chain attack via hash, size, and file-type match.
Detects crates.io publish events combining an impersonation indicator (attacker account names/forged author email) with one of the known malicious package names, indicating a compromised or impersonated maintainer account was used to publish the Rust supply-chain payload.
Detects a new build-dependencies entry adding a networking crate (ureq/reqwest/rustls) to a Cargo.toml that previously had no such dependency, correlated with a recent Cargo.lock modification, flagging a package gaining unexpected build-time network capability.
Detects a build process (cargo/rustc/build-script-build) that drops an executable to /tmp/rust-setup and launches it detached so it persists after the build completes — the payload-delivery mechanism used by the compromised proc-macro1 Rust crate.
