Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
001
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
001
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
24 days ago
6012
Detects the execution of PowerShell from a shortcut (.lnk) file, particularly when suspicious command-line arguments such as hidden windows, encoded commands, or bypass flags are utilized. This pattern is commonly associated with initial access via malicious attachments or shortcut files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
107
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
006
This rule monitors for suspicious process execution (e.g., cmd, powershell) spawned from PaperCut service processes (pc-app.exe, tomcat.exe) followed by a Domain Admin group membership change on the same device within a 30-minute window. This behavior is indicative of privilege escalation attempts following the exploitation of PaperCut vulnerabilities (CVE-2026-81578/CVE-2026-82078).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
307
This rule detects potentially malicious command execution by monitoring additions to the Windows Explorer RunMRU registry key. It specifically triggers when the registry data contains references to 'powershell', 'curl', or appears to be encoded/base64 strings, which are often used by adversaries to execute malicious scripts or download payloads via the Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
106
Detects the loading of the Restart Manager DLL (rstrtmgr.dll) by suspicious processes, such as those running from writable user paths (e.g., Temp, AppData) or masquerading as numeric-only named executables. Adversaries may abuse this library for process termination or interaction to facilitate malicious operations, such as clearing file locks during deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
006
This rule detects the creation of Windows scheduled tasks using the 'schtasks.exe' utility or events generated when a task is registered. This technique is commonly used for persistence and execution by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
006
Detects the execution of ADExplorer64.exe, a legitimate but potentially misused Sysinternals tool often utilized by attackers for Active Directory reconnaissance and enumeration of domain objects.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
206
This rule detects the use of PowerShell to download common Remote Monitoring and Management (RMM) or remote access tools from the internet. This behavior is frequently associated with malicious actors attempting to establish persistent remote access to a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
306
Detects the use of the net.exe or net1.exe utility to add a local user account with the specific password string 'Numlock!123'. This pattern is frequently used by attackers or malicious scripts to establish persistence or secondary access on a system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
106
Detects the clearing of the Windows Security Event Log. This activity is a common indicator of an adversary attempting to remove evidence of their presence or actions on a compromised host.
avatar
F S@Fsdr
avatar
Detections.ai Community
24 days ago
2013
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
17030
Detects the execution of rnpkeys.exe dropped by an MSI installer (msiexec.exe) from the C:\ProgramData\keyroll directory. The rule specifically monitors for side-loading of the rnp.dll or tdwp.dll libraries by rnpkeys.exe, a technique associated with the Sauron loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects anomalous network traffic patterns from the legitimate 'rnpkeys.exe' process when side-loaded from the 'ProgramData\keyroll' directory. The rule specifically looks for a sequence of connections matching initial C2 registration (TLV 0x01) followed by consistent, periodic beaconing (TLV 0x02) at an interval indicating automated task polling, rather than single-connection legitimate activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
This rule detects the creation of Windows Scheduled Tasks by monitoring for Event ID 4698 (Windows Security Log) or Sysmon Event ID 1 (Process Creation) that involves task name parameters. Adversaries frequently use the Windows Task Scheduler to establish persistence, execute malicious code, or run tasks at system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
This rule monitors the rnpkeys.exe process for suspicious environmental reconnaissance activity, specifically targeting locale/keyboard-layout registry queries or domain enumeration via command-line tools. These activities are identified as occurring in a strict temporal sequence (pre-registration check) shortly before an initial outbound network connection, consistent with the behavior of the Sauron loader malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects a specific staging and execution pattern where a payload file with a 6-16 character random filename is written to a temporary directory and subsequently executed by a common Windows handler process (such as rundll32, regsvr32, or powershell) within a 60-second window. This behavior is indicative of the Sauron Loader task-execution workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects a specific staging and execution pattern where a payload file with a 6-16 character random filename is written to a temporary directory and subsequently executed by a common Windows handler process (such as rundll32, regsvr32, or powershell) within a 60-second window. This behavior is indicative of the Sauron Loader task-execution workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the creation of a scheduled task named 'keyroll', which is associated with the persistence mechanism of Sauron Loader. The task is used to launch a DLL side-loading chain involving rnpkeys.exe and tdwp.dll.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Page 183 of 1871