Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Detects the presence of known malicious Rust crate archive files (arrayref-0.3.10.crate, proc-macro1-*, and related typosquatted package names) in a host's local Cargo registry cache, indicating the compromised dependency was fetched.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010
Detects process activity referencing the typosquatted proc-macro1 crate or build-script-build.exe spawning a child process — the build-time execution chain used to trigger the malicious proc-macro1 payload on Windows build hosts.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
308
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108
Detects a new build-dependencies entry adding a networking crate (ureq/reqwest/rustls) to a Cargo.toml that previously had no such dependency, correlated with a recent Cargo.lock modification, flagging a package gaining unexpected build-time network capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects a build process (cargo/rustc/build-script-build) that drops an executable to /tmp/rust-setup and launches it detached so it persists after the build completes — the payload-delivery mechanism used by the compromised proc-macro1 Rust crate.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102