Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects unpacked Sauron Loader DLL samples by identifying specific binary structures, including the magic value 0xbaadf00d and subsequent flag bytes (0x40) often found in its embedded configuration blob.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects unpacked Sauron Loader DLL samples by identifying specific binary structures, including the magic value 0xbaadf00d and subsequent flag bytes (0x40) often found in its embedded configuration blob.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a sequence of events where a single user receives an unusually high volume of inbound emails (potentially vishing-related), followed shortly thereafter by the user executing common remote assistance or remote access tools (e.g., Quick Assist, AnyDesk). This pattern is consistent with social engineering tactics used in IT-support impersonation scams to facilitate the delivery of malware such as Sauron Loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the MSI installer (msiexec.exe) creating files within the 'C:\ProgramData\keyroll' directory, which is characteristic of the staging phase for the Sauron Loader DLL side-loading trio (rnpkeys.exe, rnp.dll, tdwp.dll).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a potential vishing or technical support scam scenario by identifying a burst of email traffic to a user (email bombing) followed within one hour by the execution of a remote assistance tool (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on the same user's endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the execution of various system binaries (e.g., rundll32.exe, powershell.exe, regsvr32.exe) launched from a Temp directory where the parent or actor process is identified as rnpkeys.exe or rnp.dll. This behavior is indicative of potential malicious activity where legitimate tools or utilities (GnuPG/RNP) are being abused to proxy the execution of secondary payloads or scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects the execution of common remote access tools (Quick Assist, AnyDesk) on a host that does not have a prior history of using those specific tools. This is intended to identify potential hands-on-keyboard activity by adversaries following initial access via social engineering, such as vishing or email-bombing, where they attempt to establish a persistent remote access foothold.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects the execution of the 'rnpkeys.exe' file from the 'C:\ProgramData\keyroll\' directory. The location and filename are highly atypical and could indicate unauthorized tool usage, potential persistence, or malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects high-frequency file deletion events originating from processes with names or command-line indicators associated with AI orchestration frameworks like Semantic Kernel. This behavior may indicate an adversary abusing legitimate AI agent tools to perform unauthorized data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
203
Detects the execution of Rubeus, a common security tool used for Kerberos-based attacks including Golden/Silver Ticket forgery, AS-REP roasting, Kerberoasting, and ticket harvesting. The rule monitors command-line indicators associated with known Rubeus arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
203
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
004
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
004
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
006
Detects the presence of zero-width, non-printing, or bidirectional-override Unicode characters in command lines, commonly used for obfuscation or prompt injection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
003
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
203
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
203
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
003
This rule monitors for DNS queries and network connections to known infrastructure domains associated with the threat group UTA0565. It acts as an indicator of compromise (IOC) sweep to identify internal systems attempting to communicate with malicious command-and-control (C2) servers identified by typosquatting and registration-pattern analysis.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
17 days ago
104
This rule detects the execution of processes that use file names mimicking legitimate security or system services, such as 'Credential Guard.exe' or 'Window Security Health Services.exe'. These names are often used by adversaries for masquerading to evade detection by blending in with legitimate system activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
100
Detects a suspicious sequence of events where a process modifies a Windows Registry Run key to ensure execution at logon, followed shortly by the same executable file being copied into the current user's startup folder. This pattern is often used by malware to establish persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
103
Detects the execution of known remote access and support tools (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on a host that has recently received a high volume of emails (over 50). This behavior often aligns with social engineering campaigns where a user is instructed to download or launch a remote support tool under false pretenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
001
Page 114 of 1870