Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects command-line activity indicative of attempts to dump LSASS memory after performing in-memory unhooking or bypassing of security monitoring DLLs (ntdll.dll, amsi.dll, win32kbase.sys). This behavior is characteristic of adversaries attempting to harvest credentials while evading EDR/AV visibility.
Detects a process initiating a memory dump of lsass.exe (using --dump arguments) followed within 15 minutes by the creation of a hexadecimal-named .tmp file in the Windows\Temp directory. This behavioral pattern is characteristic of credential dumping using reflected cloning or similar techniques, followed by the staging of obfuscated or encrypted minidump data for exfiltration.
This rule detects LSASS credential dumping attempts by correlating the execution of a dump command (via process command line) with the subsequent creation of a temporary file in the Windows Temp directory. The rule is specifically designed to bypass evasion techniques that introduce randomized delays between the LSASS process access and the file write operation by utilizing a 30-minute join window.
Detects outbound HTTP POST requests associated with the Telepuz modular loader. The rule monitors for specific URI patterns, request body parameters, and suspicious User-Agent strings indicative of PowerShell or MSHTA command-and-control communication.
Detects web traffic containing indicators of 'ClickFix' social engineering attacks. These attacks present a fake 'CAPTCHA' or verification prompt to the user and instruct them to copy and paste a malicious script (involving PowerShell or mshta) into their system terminal.
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
This rule detects potential post-exploitation activity following a SharePoint XamlServices.Parse() deserialization attack. It monitors the w3wp.exe (IIS worker process) for the loading of suspicious .NET deserialization-related assemblies (e.g., System.Xaml.dll) followed by the execution of a shell process (cmd.exe, powershell.exe, etc.) within a short window, which is indicative of fileless web shell activity.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects periodic outbound network connections (beaconing) to rare remote destinations initiated by processes running from non-standard or user-writable locations. The rule calculates the interval coefficient of variation (CV) between successful connections to identify regular, consistent patterns indicative of command and control communication while excluding known legitimate update and service traffic.
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
This rule detects potentially malicious command execution initiated by web browsers (Chrome, Edge, Firefox, Safari, Opera). It identifies scenarios where browsers spawn PowerShell on Windows with encoded command arguments or spawn shells (zsh, bash, sh) on macOS while piping commands retrieved via curl or wget, which is a common pattern for dropper and fileless malware delivery.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
Detects an outbound network connection initiated by 'rnpkeys.exe' when executing from a non-standard 'ProgramData\keyroll' directory. This behavior is associated with the early stages of a Command and Control (C2) registration sequence, where an encrypted loader initiates network contact before subsequent staged communication.
Detects known components of the Sauron malware, including MSI installers, side-loaded executables (rnpkeys.exe), and malicious DLLs (rnp.dll, tdwp.dll) by matching known SHA-256 file hashes. It also includes a YARA rule for detecting PE binaries containing the string 'Sauron'.
Detects the presence of MSI installer packages associated with the Sauron Loader malware, which stage malicious files (rnpkeys.exe, rnp.dll, and tdwp.dll) into the C:\ProgramData\keyroll directory to facilitate DLL side-loading.
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
Detects network connections over port 443 initiated by a process named 'rnpkeys.exe' running from a suspicious staging directory ('\ProgramData\keyroll\'). This behavior is characteristic of side-loaded payloads establishing command-and-control communication for data exfiltration.
This rule detects the execution of 'rnpkeys.exe' from within the '\ProgramData\keyroll\' directory, specifically when it loads 'rnp.dll' from the same path. This behavior is indicative of potential malicious activity, as the ProgramData directory is a common location for adversaries to stage files, and the use of custom DLL loading from this directory may suggest an attempt to execute unauthorized code or obfuscate tool activity.
This rule detects the suspicious sequential loading of 'tdwp.dll' and 'rnp.dll' by processes related to key management or encryption (e.g., 'rnpkeys.exe' or processes from a 'keyroll' folder). The detection correlates these events within a 2-minute window and highlights if the 'tdwp.dll' has a known malicious hash.
Page 112 of 1870


