Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the loading of 'tdwp.dll' in a process that has previously loaded 'rnp.dll', which is characteristic of the Sauron loader (also known as Remsec) in-memory decryption chain performed by the 'rnpkeys.exe' executable.
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the presence of the signed but vulnerable DCRCVDrv.sys kernel driver, which is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security processes via an unauthenticated PID-terminate IOCTL.
Detects instances where a process attempts to delete its own executable file image shortly after being launched. This behavior is often associated with malware attempting to minimize its forensic footprint, such as self-deleting installers or RAT (Remote Access Trojan) components that move to a different location or execute from memory.
Detects execution of rundll32.exe with suspicious command-line patterns, including paths containing 'DavWWWRoot' (indicating potential remote file execution/WebDAV abuse), specific malicious DLL function exports, or launching from PowerShell. These techniques are commonly used to execute payloads from remote locations or to bypass traditional security controls.
Flags installation of RMM tools (AnyDesk, ScreenConnect, TeamViewer, Atera, Splashtop) on an endpoint shortly after that user's account undergoes a password/MFA reset — matches the post-vishing tooling pattern CrowdStrike attributes to Mutant Spider (loaders including PrionFlaire and SocksLoader) and Scattered Spider.
Detects instances where WScript or CScript (Windows Script Host) spawns PowerShell with common obfuscation and persistence flags, specifically executing in a hidden, non-interactive, headless, and encoded command mode. This pattern is commonly used by malicious scripts (e.g., VBScript or JScript) to execute secondary payloads while minimizing visual indicators on the host.
Detects the spawning of suspicious child processes (powershell, cmd, node, wscript, cscript) by dependency management utilities (npm, go, terraform). Attackers often leverage malicious packages or configurations during the build or install phase to execute arbitrary code. The rule also monitors for suspicious command-line execution patterns, such as detached 'go run' operations, which may indicate malicious activity.
Detects instances where the Terraform process initiates a 'go run' command or references specific Go-based provider source files, which may indicate an attempt to run malicious or unauthorized Go code within the infrastructure-as-code environment. This behavior is indicative of supply chain compromise where providers are leveraged to execute arbitrary logic.
Page 127 of 1870


