Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a specific staging and execution pattern where a payload file with a 6-16 character random filename is written to a temporary directory and subsequently executed by a common Windows handler process (such as rundll32, regsvr32, or powershell) within a 60-second window. This behavior is indicative of the Sauron Loader task-execution workflow.
Detects the creation of a scheduled task named 'keyroll', which is associated with the persistence mechanism of Sauron Loader. The task is used to launch a DLL side-loading chain involving rnpkeys.exe and tdwp.dll.
Detects the execution of rnpkeys.exe from the path C:\ProgramData\keyroll\, which performs DLL side-loading by loading rnp.dll followed by tdwp.dll. This sequence is indicative of the Sauron Loader malware attempting to perform in-memory payload decryption.
Detects the Sauron Loader malware pattern where a payload is downloaded or retrieved and written to a randomly named file within a temporary directory, followed by the immediate execution of that staged file. This behavior is indicative of C2 tasking involving payload staging.
Detects the execution of staged scripts (.cmd, .ps1, .vbs, .js) from user temporary directories using cmd.exe, powershell.exe, or wscript.exe. This behavior is consistent with the Sauron Loader malware family, which utilizes these interpreters to execute secondary C2-tasked payloads.
Detects instances of process injection targeting the 'attrib.exe' process. This behavior is associated with the Sauron Loader, which performs in-memory shellcode execution by allocating memory and creating a remote thread within a legitimate process, such as 'attrib.exe', to avoid writing payloads to disk.
Detects the execution of staged payloads from the Windows %TEMP% directory. This rule monitors for suspicious activity often associated with loader-style C2 execution, including direct execution of randomly named files, proxy execution via rundll32 or regsvr32, silent MSI installations, and the execution of payloads extracted from archives in temporary locations.
Detects the execution of staged payloads from the Windows %TEMP% directory. This rule monitors for suspicious activity often associated with loader-style C2 execution, including direct execution of randomly named files, proxy execution via rundll32 or regsvr32, silent MSI installations, and the execution of payloads extracted from archives in temporary locations.
Detects unpacked Sauron Loader DLL samples by identifying a specific embedded configuration header (magic 0xbaadf00d) followed by RSA key material length fields. This indicates the presence of malicious configuration structures associated with the Sauron Loader malware.
Detects activity associated with the Sauron Loader malware, specifically monitoring for the execution of rnpkeys.exe or loading of tdwp.dll, followed by a high volume of HTTPS POST requests to the same destination host, which is characteristic of chunked screenshot exfiltration.
Detects execution of rnpkeys.exe from the C:\ProgramData\keyroll\ directory, which is indicative of Sauron Loader side-loading activity, followed by an outbound network connection on port 443 within a 5-minute window. This behavior is consistent with the initial bot registration beaconing phase of the malware.
Detects instances where critical system processes (such as svchost.exe, lsass.exe, or w3wp.exe) spawn known command-line interpreters or script execution utilities (e.g., cmd.exe, powershell.exe, certutil.exe) which then initiate outbound network connections to common ports (445, 3389, 135, 5985, 5986, 1433, 80, 443) that are external to the local network. This behavior is often associated with lateral movement, command and control (C2) communication, or reconnaissance.
Detects the presence of Sauron Loader by matching known SHA-256 hashes of the MSI installer and associated side-loaded DLLs, or by identifying malicious PE files containing the 'Sauron' string.
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
This rule detects potentially malicious child processes (cmd.exe or powershell.exe) spawned by PaperCut application processes (pc-app.exe, PCClient.exe, or java.exe), which may indicate exploitation attempts such as RCE following an authentication bypass.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
Detects endpoint DNS resolution for the 'mysignins.microsoft.com' domain. This domain is frequently used in Adversary-in-the-Middle (AiTM) phishing attacks to facilitate user interaction with legitimate Microsoft portals while the attacker intercepts session tokens.
Detects instances where the rnpkeys process (likely used for GPG-related operations) spawns common Windows living-off-the-land binaries such as rundll32, regsvr32, msiexec, cmd, powershell, or wscript. It specifically monitors for patterns indicating potential script execution from temporary folders, the bypass of PowerShell execution policies, or the installation of products via msiexec, which may indicate malicious activity following initial compromise or delivery of a malicious payload.
Detects the execution of suspected Sauron Loader components staged in C:\ProgramData\keyroll\ (rnpkeys.exe or tdwp.dll) followed by an outbound network connection from the same host within a 2-minute window. This behavior correlates the staging of malicious binaries with the loader's automated outbound registration attempt.
Detects the execution of attrib.exe spawned by known Sauron Loader process names (rnpkeys.exe, rnp.exe, or tdwp.exe). The rule flags instances where attrib.exe is executed without its typical command-line arguments (file attribute flags), suggesting it is being used as a surrogate process for injected C2-tasked shellcode.
Page 184 of 1871



