Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of 'ClickFix' or 'fake-CAPTCHA' patterns where a user is tricked into copying and pasting a malicious command into the Windows Run dialog. The rule specifically identifies the launch of conhost.exe from explorer.exe with --headless arguments, utilizing command-line tools like curl, iex, or irm to fetch and execute external payloads.
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
This rule uses YARA to identify specific malicious files associated with the Sauron Loader malware, including the MSI installer and associated support DLLs (rnp.dll, tdwp.dll), based on their known SHA-256 hashes.
Detects anomalous, high-frequency outbound HTTPS POST requests from the 'rnpkeys.exe' process, characteristic of the Sauron Loader exfiltrating screenshot chunks (Message Type 3) to a Command and Control (C2) server.
Detects process injection behaviors (e.g., remote thread creation, memory allocation) targeting the attrib.exe process. Such activity is often associated with process hollowing or reflective shellcode injection, consistent with loader behavior used to execute in-memory payloads within legitimate, rarely-used system utilities.
Detects a specific social-engineering pattern known as 'ClickFix' where a user is manipulated into opening the Windows Run dialog (explorer.exe) to manually execute commands. The rule identifies suspicious command-line arguments typically associated with initial access (e.g., PowerShell hidden/encoded execution, web downloads) followed by the execution of MSI installers or related malicious binaries (e.g., rnpkeys.exe) within a 30-minute window, indicative of the Sauron Loader infection chain.
Detects reconnaissance commands related to system domain, locale, and environment settings following the execution of rnpkeys.exe from C:\ProgramData\keyroll, a behavior associated with the Sauron Loader. The rule identifies suspicious system discovery commands (nltest, whoami, etc.) or environment checks performed shortly after the loader's execution, indicating potential target verification before C2 registration.
Detects unpacked Sauron Loader DLL samples by identifying the embedded configuration structure. The rule searches for a specific 4-byte magic header (0xbaadf00d), specific configuration field strings ('group_id' and 'build_id'), and RSA key length markers consistent with the loader's known cryptographic configuration structure.
This rule detects network activity associated with the Sauron Loader malware. It monitors for TLS connections to known hardcoded C2 domains and identifies HTTP requests following a specific pattern of randomized command and control (C2) paths combined with suspicious User-Agent headers (Windows NT with Edge/Edg).
Detects DLL side-loading activity where the legitimate-looking process rnpkeys.exe, located in a non-standard ProgramData sub-directory, loads a malicious rnp.dll from the same directory, a behavior observed with the Sauron Loader malware.
Detects the creation of a remote thread targeting the native Windows utility 'attrib.exe'. This behavior is characteristic of code injection techniques, such as those used by the Sauron loader, where malicious shellcode is executed within the context of a legitimate system process to evade detection and maintain persistence.
Detects the Sauron Loader malware utilizing the process rnpkeys.exe as a parent to spawn common LOLBins (Living-off-the-Land Binaries) or execute payloads from temporary directories. This behavior is indicative of a secondary stage execution chain typical of the Sauron Loader.
Detects anomalous, high-frequency outbound network connections to port 443 initiated by the binary 'rnpkeys.exe'. This behavior is characteristic of the Sauron Loader, which uses this masqueraded process to exfiltrate collected data, such as screenshots, via an encrypted C2 channel.
Detects the execution of the Sauron Loader malware, which utilizes a DLL side-loading chain involving rnpkeys.exe loading rnp.dll or tdwp.dll from a specific ProgramData path, indicating potential malicious activity.
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
Detects the execution of msiexec.exe performing the installation or staging of specific binary files (rnpkeys.exe, rnp.dll, and tdwp.dll) into the C:\ProgramData\keyroll\ directory, which is a known behavior associated with the Sauron Loader malware.
Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
Detects network communication from 'rnpkeys.exe' to external IP addresses. This behavior is indicative of the Sauron Loader malware, which utilizes a side-loaded 'rnpkeys.exe' binary to establish beaconing and C2 communication as part of its registration process.
Detects the creation of a Windows service that points to a .sys file located in common temporary directories (Temp, Windows\Temp). This behavior is characteristic of adversaries attempting to load malicious kernel drivers, often for persistence or privilege escalation, such as in Bring Your Own Vulnerable Driver (BYOVD) attacks.
Detects Sauron Loader DLLs by identifying specific configuration blob magic values (0xbaadf00d), associated flags, and internal strings like 'group_id' or 'build_id' that suggest the presence of malicious configuration or RSA key material.
Page 113 of 1870

