Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
4 detections
Filters
Last updated
All Time
Detection languages
4
Contributors
4
Categories
2
2
1
1
1
Platforms
4
Products / Services
10,366
9,516
6,509
4,363
3,686
MITRE Techniques
2
2
2
1
1
IDS Classtypes
2
1
1
IDS Protocols
3
Detects HTTP requests to the attacker's WebApp-Form-Host operator panel managing compromised WordPress sites at scale (wp-uploading.php/wp-verifyup.php with activator parameters).
Detects HTTP requests to StopAndProtect's WordPress webshells and malicious MU-plugin backdoor endpoints.
Detects HTTP traffic to StopAndProtect's compromised-WordPress C2 operational endpoints, heartbeat beaconing, encrypted-archive exfiltration, and victim data directory access.
Detects SilentDataCollector uploading AES-CBC encrypted, specifically-named archives (desktop_files, pass_V, wallet_V, filelist.zip.encrypted, documents<n>.zip) to the compromised WordPress C2.
