Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
8 detections
Filters
Last updated
All Time
Detection languages
8
Contributors
8
Categories
2
2
1
1
1
Platforms
6
2
2
1
Products / Services
10,366
9,516
6,509
4,363
3,686
MITRE Techniques
2
2
1
1
1
Detects PureLogs Stealer payload binaries by identifying specific artifacts including a hardcoded nibble-decoding alphabet, minimal PE imports, and high-entropy sections containing obfuscated Windows API strings like GetProcAddress, kernel32.dll, and ntdll.dll.
Detects DCRCVDrv.sys driver used in ACRStealer BYOVD campaign via attacker-specific hashes, certificate serial, or atypical staging path; vendor metadata and PDB are supportive only
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
Detects ELF binaries embedding the ClientKing implant name alongside structural indicators (Rust runtime markers or C2 configuration patterns), associated with Jewelbug espionage tooling targeting Linux servers and routers
Detects mshta.exe execution combined with CSIS geopolitical lure content or the known TEST.hta downloader artifact used to deliver the Antino backdoor
Detects run.pyw wrapper scripts embedding RC4-encrypted RAT blob with key-schedule byte pattern and ChaCha20 decryption routine with constant signature, for EtherHiding C2 config, used by DeviceManager RAT
Detects obfuscated JavaScript payload generated via the XG-Web code-generation platform and hosted on typosquatted fonts.tarotfree101.top domain, used by Jewelbug
Detects the IntelSoftwareUpdaterV8.exe installer masquerading as a legitimate updater, bundling Python 3.11 runtime and dropping to Microsoft-looking WindowsApps path used by UNC5142 DeviceManager RAT
