Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
5
Contributors
5
Categories
3
1
1
1
1
Platforms
5
Products / Services
10,371
9,516
6,509
4,371
3,687
MITRE Techniques
1
1
1
1
1
Detects Abyssos RECOVERY and RECOVERY_GECKO modules used to harvest Chrome/Firefox credentials, requiring an unsigned executable freshly dropped in the Windows temp folder using the rcv/rvg naming pattern that references browser credential stores (Chrome Login Data, Firefox key4.db) alongside the module's hardcoded XOR decryption key
Detects binaries containing hardcoded VM tooling process names alongside a CPUID hypervisor-detection instruction immediately followed by evasive conditional branching or a process-termination call, consistent with Abyssos hypervisor fingerprinting and sandbox evasion.
Detects the Abyssos RAT main executable via known sample hashes, or by requiring a minimum weight/threshold of co-occurring structural PE traits (obfuscated single-executable-section layout, minimal static import table consistent with CRC32-based dynamic API hashing, and absence of a valid certificate), rather than any single trait alone.
Detects Abyssos RAT modules (DCFINDER, VULNSCAN, ELEVATE_SYS_TOKEN, RDPWRAP) by requiring a shared XOR/AES-CBC key alongside a temp-folder write using a module-specific short prefix (dcf, vul, plg, rdp) that is followed by execution via an anomalous export function name (abyss or the module-specific Get*Text/Json exports)
Detects Abyssos RAT KEYLOGGER module by requiring SetWindowsHookEx-style capture strings to co-occur with the klog-prefixed drop artifact or windows_update_cache.json log file, reducing false positives from generic hook installers; also flags XOR key, export function abyss, and KEYLOGGER_GETLOGS command
