Browse Rules

Search and filter across all detection sources

80 rules

reversinglabs unknown yara

Linux_Rootkit_Pumakit [rootkit]

Yara rule that detects Pumakit rootkit.

signature-base unknown yara

Venom_Rootkit [yara]

Venom Linux Rootkit

sagan medium other

[CISCO-SECUREENDPOINT] Rootkit Detection

[CISCO-SECUREENDPOINT] Rootkit Detection

sekoia unknown yara

rootkit_lin_winnti [yara_rules]

Rootkit used by Winnti

signature-base unknown yara

MAL_LNX_LinaDoor_Rootkit_May22 [yara]

Detects LinaDoor Linux Rootkit

panther medium python

OSSEC Rootkit Detected via Osquery

Checks if any results are returned for the Osquery OSSEC Rootkit pack.

sekoia unknown yara

apt_gelsemium_wolfsbane_rootkit [yara_rules]

Detects Gelsemium's WolfsBane rootkit

sekoia unknown yara

rootkit_diamorphine_strings [yara_rules]

Detects Diamorphine linux rootkit based on strings

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Ossec rootkit file $(osquery.columns.path) detected

osquery: $(osquery.pack) $(osquery.subquery): Ossec rootkit file $(osquery.columns.path) detected

yara unknown yara

rootkit [malware]

loldrivers low sigma

Driver Load - Chaos-Rootkit.sys

Detects loading of driver Chaos-Rootkit.sys via name. Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes, work on the latest Windows versions.

loldrivers high sigma

Driver Load - Chaos-Rootkit.sys

Detects loading of driver Chaos-Rootkit.sys via hash. Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes, work on the latest Windows versions.

signature-base unknown yara

CN_Honker_Webshell_ASP_rootkit [yara]

Webshell from CN Honker Pentest Toolset - file rootkit.txt

hayabusa critical sigma

Moriya Rootkit - System

Detects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report

sigma critical sigma

Moriya Rootkit - System

Detects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report

sigma high sigma

Triple Cross eBPF Rootkit Install Commands

Detects default install commands of the Triple Cross eBPF rootkit based on the "deployer.sh" script

splunk unknown spl

Linux Medusa Rootkit

This detection identifies file creation events associated with the installation of the Medusa rootkit, a userland LD_PRELOAD-based rootkit known for deploying shared objects, loader binaries, and configuration files into specific system directories. These files typically facilitate process hiding, credential theft, and backdoor access. Monitoring for such file creation patterns enables early detection of rootkit deployment before full compromise.

signature-base unknown yara

MAL_UNC2891_Caketap [yara]

Detects UNC2891 Rootkit Caketap

signature-base unknown yara

Winnti_malware_Nsiproxy [yara]

Detects a Winnti rootkit

yara unknown yara

Winnti_malware_Nsiproxy [malware]

Detects a Winnti rootkit

sagan critical other

[CROWDSTRIKE] A command was run that is indicative of a Jynx Rootkit installation.

[CROWDSTRIKE] A command was run that is indicative of a Jynx Rootkit installation.

sigma high sigma

Triple Cross eBPF Rootkit Execve Hijack

Detects execution of a the file "execve_hijack" which is used by the Triple Cross rootkit as a way to elevate privileges

signature-base unknown yara

MAL_Netfilter_May_2021_1 [yara]

Detects Netfilter rootkit

sigma high sigma

Triple Cross eBPF Rootkit Default LockFile

Detects the creation of the file "rootlog" which is used by the TripleCross rootkit as a way to check if the backdoor is already running.

sekoia unknown yara

rootkit_win_purplefox_kernel_driver [yara_rules]

Detect the Purple Fox trojan