Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
4
1
Contributors
5
Categories
3
3
2
2
2
Platforms
4
3
2
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
3
3
2
1
1
Detects the presence of known malicious Rust crate archive files (arrayref-0.3.10.crate, proc-macro1-*, and related typosquatted package names) in a host's local Cargo registry cache, indicating the compromised dependency was fetched.
Detects process activity referencing the typosquatted proc-macro1 crate or build-script-build.exe spawning a child process — the build-time execution chain used to trigger the malicious proc-macro1 payload on Windows build hosts.
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
Detects a new build-dependencies entry adding a networking crate (ureq/reqwest/rustls) to a Cargo.toml that previously had no such dependency, correlated with a recent Cargo.lock modification, flagging a package gaining unexpected build-time network capability.
Detects a build process (cargo/rustc/build-script-build) that drops an executable to /tmp/rust-setup and launches it detached so it persists after the build completes — the payload-delivery mechanism used by the compromised proc-macro1 Rust crate.
