Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects unpacked Sauron Loader DLL samples by identifying specific binary structures, including the magic value 0xbaadf00d and subsequent flag bytes (0x40) often found in its embedded configuration blob.
Detects unpacked Sauron Loader DLL samples by identifying specific binary structures, including the magic value 0xbaadf00d and subsequent flag bytes (0x40) often found in its embedded configuration blob.
Detects a sequence of events where a single user receives an unusually high volume of inbound emails (potentially vishing-related), followed shortly thereafter by the user executing common remote assistance or remote access tools (e.g., Quick Assist, AnyDesk). This pattern is consistent with social engineering tactics used in IT-support impersonation scams to facilitate the delivery of malware such as Sauron Loader.
Detects the MSI installer (msiexec.exe) creating files within the 'C:\ProgramData\keyroll' directory, which is characteristic of the staging phase for the Sauron Loader DLL side-loading trio (rnpkeys.exe, rnp.dll, tdwp.dll).
Detects a potential vishing or technical support scam scenario by identifying a burst of email traffic to a user (email bombing) followed within one hour by the execution of a remote assistance tool (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on the same user's endpoint.
Detects the execution of various system binaries (e.g., rundll32.exe, powershell.exe, regsvr32.exe) launched from a Temp directory where the parent or actor process is identified as rnpkeys.exe or rnp.dll. This behavior is indicative of potential malicious activity where legitimate tools or utilities (GnuPG/RNP) are being abused to proxy the execution of secondary payloads or scripts.
This rule detects the execution of common remote access tools (Quick Assist, AnyDesk) on a host that does not have a prior history of using those specific tools. This is intended to identify potential hands-on-keyboard activity by adversaries following initial access via social engineering, such as vishing or email-bombing, where they attempt to establish a persistent remote access foothold.
Detects the execution of the 'rnpkeys.exe' file from the 'C:\ProgramData\keyroll\' directory. The location and filename are highly atypical and could indicate unauthorized tool usage, potential persistence, or malicious activity.
Detects high-frequency file deletion events originating from processes with names or command-line indicators associated with AI orchestration frameworks like Semantic Kernel. This behavior may indicate an adversary abusing legitimate AI agent tools to perform unauthorized data destruction.
Detects the execution of Rubeus, a common security tool used for Kerberos-based attacks including Golden/Silver Ticket forgery, AS-REP roasting, Kerberoasting, and ticket harvesting. The rule monitors command-line indicators associated with known Rubeus arguments.
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
Detects the presence of zero-width, non-printing, or bidirectional-override Unicode characters in command lines, commonly used for obfuscation or prompt injection.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
This rule monitors for DNS queries and network connections to known infrastructure domains associated with the threat group UTA0565. It acts as an indicator of compromise (IOC) sweep to identify internal systems attempting to communicate with malicious command-and-control (C2) servers identified by typosquatting and registration-pattern analysis.
This rule detects the execution of processes that use file names mimicking legitimate security or system services, such as 'Credential Guard.exe' or 'Window Security Health Services.exe'. These names are often used by adversaries for masquerading to evade detection by blending in with legitimate system activity.
Detects a suspicious sequence of events where a process modifies a Windows Registry Run key to ensure execution at logon, followed shortly by the same executable file being copied into the current user's startup folder. This pattern is often used by malware to establish persistence.
Detects the execution of known remote access and support tools (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on a host that has recently received a high volume of emails (over 50). This behavior often aligns with social engineering campaigns where a user is instructed to download or launch a remote support tool under false pretenses.
Page 114 of 1870


