Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects rockstargames.exe dropping a batch script or executing binaries directly from C:\Users\Default\Local Settings, specifically targeting the execution pattern associated with DCRAT (UserOOBEBroker.exe masquerading).
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
10 hours ago
000
Detects DNS queries, HTTP requests, TLS SNI requests, and direct IP traffic associated with DCRAT command and control infrastructure using the domain a0700877.xsph.ru or IP 141.8.197.42 during a GTA VI lure campaign.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
10 hours ago
000