Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
8 detections
Filters
Last updated
All Time
Detection languages
4
4
Contributors
8
Categories
8
4
4
2
2
Platforms
8
Products / Services
10,411
9,526
6,520
4,398
3,688
MITRE Techniques
4
2
2
2
2
Detects curl reusing a captured cookie jar (-b /tmp/lhr_c) against a known tunnel domain, indicating session-cookie replay to hijack an authenticated session exposed via a reverse tunnel.
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
Detects curl reusing a captured cookie jar (-b /tmp/lhr_c) against a known tunnel domain, indicating session-cookie replay to hijack an authenticated session exposed via a reverse tunnel.
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
Detects curl liveness/health-check requests against a known tunnel domain issued repeatedly from a loop construct or a LaunchAgent/watchdog parent, indicating an automated watchdog keeping a reverse tunnel alive.
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
Detects curl liveness/health-check requests against a known tunnel domain issued repeatedly from a loop construct or a LaunchAgent/watchdog parent, indicating an automated watchdog keeping a reverse tunnel alive.
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
