Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the execution of 'ClickFix' or 'fake-CAPTCHA' patterns where a user is tricked into copying and pasting a malicious command into the Windows Run dialog. The rule specifically identifies the launch of conhost.exe from explorer.exe with --headless arguments, utilizing command-line tools like curl, iex, or irm to fetch and execute external payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
303
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
103
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule uses YARA to identify specific malicious files associated with the Sauron Loader malware, including the MSI installer and associated support DLLs (rnp.dll, tdwp.dll), based on their known SHA-256 hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects anomalous, high-frequency outbound HTTPS POST requests from the 'rnpkeys.exe' process, characteristic of the Sauron Loader exfiltrating screenshot chunks (Message Type 3) to a Command and Control (C2) server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects process injection behaviors (e.g., remote thread creation, memory allocation) targeting the attrib.exe process. Such activity is often associated with process hollowing or reflective shellcode injection, consistent with loader behavior used to execute in-memory payloads within legitimate, rarely-used system utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a specific social-engineering pattern known as 'ClickFix' where a user is manipulated into opening the Windows Run dialog (explorer.exe) to manually execute commands. The rule identifies suspicious command-line arguments typically associated with initial access (e.g., PowerShell hidden/encoded execution, web downloads) followed by the execution of MSI installers or related malicious binaries (e.g., rnpkeys.exe) within a 30-minute window, indicative of the Sauron Loader infection chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects reconnaissance commands related to system domain, locale, and environment settings following the execution of rnpkeys.exe from C:\ProgramData\keyroll, a behavior associated with the Sauron Loader. The rule identifies suspicious system discovery commands (nltest, whoami, etc.) or environment checks performed shortly after the loader's execution, indicating potential target verification before C2 registration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects unpacked Sauron Loader DLL samples by identifying the embedded configuration structure. The rule searches for a specific 4-byte magic header (0xbaadf00d), specific configuration field strings ('group_id' and 'build_id'), and RSA key length markers consistent with the loader's known cryptographic configuration structure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects network activity associated with the Sauron Loader malware. It monitors for TLS connections to known hardcoded C2 domains and identifies HTTP requests following a specific pattern of randomized command and control (C2) paths combined with suspicious User-Agent headers (Windows NT with Edge/Edg).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects DLL side-loading activity where the legitimate-looking process rnpkeys.exe, located in a non-standard ProgramData sub-directory, loads a malicious rnp.dll from the same directory, a behavior observed with the Sauron Loader malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the creation of a remote thread targeting the native Windows utility 'attrib.exe'. This behavior is characteristic of code injection techniques, such as those used by the Sauron loader, where malicious shellcode is executed within the context of a legitimate system process to evade detection and maintain persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the Sauron Loader malware utilizing the process rnpkeys.exe as a parent to spawn common LOLBins (Living-off-the-Land Binaries) or execute payloads from temporary directories. This behavior is indicative of a secondary stage execution chain typical of the Sauron Loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects anomalous, high-frequency outbound network connections to port 443 initiated by the binary 'rnpkeys.exe'. This behavior is characteristic of the Sauron Loader, which uses this masqueraded process to exfiltrate collected data, such as screenshots, via an encrypted C2 channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the execution of the Sauron Loader malware, which utilizes a DLL side-loading chain involving rnpkeys.exe loading rnp.dll or tdwp.dll from a specific ProgramData path, indicating potential malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the execution of msiexec.exe performing the installation or staging of specific binary files (rnpkeys.exe, rnp.dll, and tdwp.dll) into the C:\ProgramData\keyroll\ directory, which is a known behavior associated with the Sauron Loader malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects network communication from 'rnpkeys.exe' to external IP addresses. This behavior is indicative of the Sauron Loader malware, which utilizes a side-loaded 'rnpkeys.exe' binary to establish beaconing and C2 communication as part of its registration process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the creation of a Windows service that points to a .sys file located in common temporary directories (Temp, Windows\Temp). This behavior is characteristic of adversaries attempting to load malicious kernel drivers, often for persistence or privilege escalation, such as in Bring Your Own Vulnerable Driver (BYOVD) attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects Sauron Loader DLLs by identifying specific configuration blob magic values (0xbaadf00d), associated flags, and internal strings like 'group_id' or 'build_id' that suggest the presence of malicious configuration or RSA key material.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Page 113 of 1870