Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
202
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
102
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
001
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
001
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
001
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
101
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
001
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
001
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
001
Detects the loading of 'tdwp.dll' in a process that has previously loaded 'rnp.dll', which is characteristic of the Sauron loader (also known as Remsec) in-memory decryption chain performed by the 'rnpkeys.exe' executable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Detects the presence of the signed but vulnerable DCRCVDrv.sys kernel driver, which is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security processes via an unauthenticated PID-terminate IOCTL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
005
Detects instances where a process attempts to delete its own executable file image shortly after being launched. This behavior is often associated with malware attempting to minimize its forensic footprint, such as self-deleting installers or RAT (Remote Access Trojan) components that move to a different location or execute from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
205
Detects execution of rundll32.exe with suspicious command-line patterns, including paths containing 'DavWWWRoot' (indicating potential remote file execution/WebDAV abuse), specific malicious DLL function exports, or launching from PowerShell. These techniques are commonly used to execute payloads from remote locations or to bypass traditional security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
005
Flags installation of RMM tools (AnyDesk, ScreenConnect, TeamViewer, Atera, Splashtop) on an endpoint shortly after that user's account undergoes a password/MFA reset — matches the post-vishing tooling pattern CrowdStrike attributes to Mutant Spider (loaders including PrionFlaire and SocksLoader) and Scattered Spider.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
202
Detects instances where WScript or CScript (Windows Script Host) spawns PowerShell with common obfuscation and persistence flags, specifically executing in a hidden, non-interactive, headless, and encoded command mode. This pattern is commonly used by malicious scripts (e.g., VBScript or JScript) to execute secondary payloads while minimizing visual indicators on the host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
306
Detects the spawning of suspicious child processes (powershell, cmd, node, wscript, cscript) by dependency management utilities (npm, go, terraform). Attackers often leverage malicious packages or configurations during the build or install phase to execute arbitrary code. The rule also monitors for suspicious command-line execution patterns, such as detached 'go run' operations, which may indicate malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
002
Detects instances where the Terraform process initiates a 'go run' command or references specific Go-based provider source files, which may indicate an attempt to run malicious or unauthorized Go code within the infrastructure-as-code environment. This behavior is indicative of supply chain compromise where providers are leveraged to execute arbitrary logic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
002
Page 127 of 1870