
Nate Dunning
@nateosspreyCompletionist
0 followers27 downloads14 copies2 likes78 views
8 detections
Filters
Last updated
All Time
Detection languages
4
2
2
Categories
4
4
2
2
2
Platforms
4
4
2
2
Products / Services
2
2
2
2
2
MITRE Techniques
4
2
2
2
2
IDS Classtypes
2
IDS Protocols
2
Detects instances where a Gradle or Java build process invokes a shell (sh -c) containing suspicious build-related keywords such as 'preBuild', 'doLast', or 'tasks.all'. This pattern is commonly observed in supply chain compromises where malicious code is injected into build scripts to execute hidden payloads during the compilation phase.
This rule monitors for file and process events involving 'pubspec.yaml' configuration files or specific Flutter-related components such as 'universal_file_viewer' and 'surveyjs_flutter'. This detection logic is designed to track development activities or the inclusion of specific software packages within a Flutter project environment.
Detects instances where the Gradle or Gradlew build process launches a shell command, which may indicate a malicious build hook or dependency-based execution of arbitrary code within the software supply chain.
Detects outbound HTTP POST requests to suspicious .ru domains and DNS queries for these domains, indicative of C2 beaconing activity likely associated with a supply chain compromise affecting the Pub.dev ecosystem.
Detects outbound HTTP POST requests to suspicious .ru domains and DNS queries for these domains, indicative of C2 beaconing activity likely associated with a supply chain compromise affecting the Pub.dev ecosystem.
This rule monitors for file and process events involving 'pubspec.yaml' configuration files or specific Flutter-related components such as 'universal_file_viewer' and 'surveyjs_flutter'. This detection logic is designed to track development activities or the inclusion of specific software packages within a Flutter project environment.
Detects web requests containing the specific user-agent or custom secret headers used by the Moika campaign beacon to retrieve its stage 2 payload.
Detects web requests containing the specific user-agent or custom secret headers used by the Moika campaign beacon to retrieve its stage 2 payload.
