Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

8 detections

Detects curl reusing a captured cookie jar (-b /tmp/lhr_c) against a known tunnel domain, indicating session-cookie replay to hijack an authenticated session exposed via a reverse tunnel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
409
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1219
Detects curl reusing a captured cookie jar (-b /tmp/lhr_c) against a known tunnel domain, indicating session-cookie replay to hijack an authenticated session exposed via a reverse tunnel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
Detects curl liveness/health-check requests against a known tunnel domain issued repeatedly from a loop construct or a LaunchAgent/watchdog parent, indicating an automated watchdog keeping a reverse tunnel alive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
304
Detects curl liveness/health-check requests against a known tunnel domain issued repeatedly from a loop construct or a LaunchAgent/watchdog parent, indicating an automated watchdog keeping a reverse tunnel alive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects a curl request to a tunnel-exposed /api/summary endpoint piped through jq extracting a 'spend' field, indicating automated exfiltration of financial data via a coding-agent-established tunnel.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103