Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a specific staging and execution pattern where a payload file with a 6-16 character random filename is written to a temporary directory and subsequently executed by a common Windows handler process (such as rundll32, regsvr32, or powershell) within a 60-second window. This behavior is indicative of the Sauron Loader task-execution workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the creation of a scheduled task named 'keyroll', which is associated with the persistence mechanism of Sauron Loader. The task is used to launch a DLL side-loading chain involving rnpkeys.exe and tdwp.dll.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of rnpkeys.exe from the path C:\ProgramData\keyroll\, which performs DLL side-loading by loading rnp.dll followed by tdwp.dll. This sequence is indicative of the Sauron Loader malware attempting to perform in-memory payload decryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the Sauron Loader malware pattern where a payload is downloaded or retrieved and written to a randomly named file within a temporary directory, followed by the immediate execution of that staged file. This behavior is indicative of C2 tasking involving payload staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of staged scripts (.cmd, .ps1, .vbs, .js) from user temporary directories using cmd.exe, powershell.exe, or wscript.exe. This behavior is consistent with the Sauron Loader malware family, which utilizes these interpreters to execute secondary C2-tasked payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects instances of process injection targeting the 'attrib.exe' process. This behavior is associated with the Sauron Loader, which performs in-memory shellcode execution by allocating memory and creating a remote thread within a legitimate process, such as 'attrib.exe', to avoid writing payloads to disk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of staged payloads from the Windows %TEMP% directory. This rule monitors for suspicious activity often associated with loader-style C2 execution, including direct execution of randomly named files, proxy execution via rundll32 or regsvr32, silent MSI installations, and the execution of payloads extracted from archives in temporary locations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of staged payloads from the Windows %TEMP% directory. This rule monitors for suspicious activity often associated with loader-style C2 execution, including direct execution of randomly named files, proxy execution via rundll32 or regsvr32, silent MSI installations, and the execution of payloads extracted from archives in temporary locations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects unpacked Sauron Loader DLL samples by identifying a specific embedded configuration header (magic 0xbaadf00d) followed by RSA key material length fields. This indicates the presence of malicious configuration structures associated with the Sauron Loader malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects activity associated with the Sauron Loader malware, specifically monitoring for the execution of rnpkeys.exe or loading of tdwp.dll, followed by a high volume of HTTPS POST requests to the same destination host, which is characteristic of chunked screenshot exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects execution of rnpkeys.exe from the C:\ProgramData\keyroll\ directory, which is indicative of Sauron Loader side-loading activity, followed by an outbound network connection on port 443 within a 5-minute window. This behavior is consistent with the initial bot registration beaconing phase of the malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects instances where critical system processes (such as svchost.exe, lsass.exe, or w3wp.exe) spawn known command-line interpreters or script execution utilities (e.g., cmd.exe, powershell.exe, certutil.exe) which then initiate outbound network connections to common ports (445, 3389, 135, 5985, 5986, 1433, 80, 443) that are external to the local network. This behavior is often associated with lateral movement, command and control (C2) communication, or reconnaissance.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
25 days ago
8014
Detects the presence of Sauron Loader by matching known SHA-256 hashes of the MSI installer and associated side-loaded DLLs, or by identifying malicious PE files containing the 'Sauron' string.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
006
This rule detects potentially malicious child processes (cmd.exe or powershell.exe) spawned by PaperCut application processes (pc-app.exe, PCClient.exe, or java.exe), which may indicate exploitation attempts such as RCE following an authentication bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
1307
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
107
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
107
Detects endpoint DNS resolution for the 'mysignins.microsoft.com' domain. This domain is frequently used in Adversary-in-the-Middle (AiTM) phishing attacks to facilitate user interaction with legitimate Microsoft portals while the attacker intercepts session tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
206
Detects instances where the rnpkeys process (likely used for GPG-related operations) spawns common Windows living-off-the-land binaries such as rundll32, regsvr32, msiexec, cmd, powershell, or wscript. It specifically monitors for patterns indicating potential script execution from temporary folders, the bypass of PowerShell execution policies, or the installation of products via msiexec, which may indicate malicious activity following initial compromise or delivery of a malicious payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of suspected Sauron Loader components staged in C:\ProgramData\keyroll\ (rnpkeys.exe or tdwp.dll) followed by an outbound network connection from the same host within a 2-minute window. This behavior correlates the staging of malicious binaries with the loader's automated outbound registration attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of attrib.exe spawned by known Sauron Loader process names (rnpkeys.exe, rnp.exe, or tdwp.exe). The rule flags instances where attrib.exe is executed without its typical command-line arguments (file attribute flags), suggesting it is being used as a surrogate process for injected C2-tasked shellcode.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Page 184 of 1871