Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where the rnpkeys process (likely used for GPG-related operations) spawns common Windows living-off-the-land binaries such as rundll32, regsvr32, msiexec, cmd, powershell, or wscript. It specifically monitors for patterns indicating potential script execution from temporary folders, the bypass of PowerShell execution policies, or the installation of products via msiexec, which may indicate malicious activity following initial compromise or delivery of a malicious payload.
Detects the execution of rnpkeys.exe from a specific path, followed by the loading of expected DLLs (rnp.dll or tdwp.dll) from the same directory, and a subsequent network connection on port 443. This behavior pattern is consistent with DLL side-loading used to establish a network-based command and control channel.
Detects the presence of an unpacked Sauron Loader DLL by identifying a specific embedded configuration header (magic value 0xbaadf00d followed by flags 0x40) in conjunction with configuration fields like 'group_id' or 'build_id'. This rule is intended for static analysis of file samples.
Detects the execution or presence of a malicious MSI installer file used by the Sauron Loader. This rule identifies files that exhibit the MSI OLE compound file structure in conjunction with specific file paths (C:\ProgramData\keyroll) and the presence of identified malicious components (rnpkeys.exe, rnp.dll, and tdwp.dll), or matches known SHA256 file hashes associated with this loader.
Detects periodic outbound network connections from rnpkeys.exe characteristic of the Sauron Loader C2 beaconing. The rule identifies a consistent heartbeat pattern (approx. 600 seconds) between successful C2 polls to the same remote host, distinguishing it from typical user-driven browser traffic.
Detects the presence or execution of a specific file hash associated with a known malicious campaign (KREMLIN/REF9334) that leverages a signed SentinelOne binary. This indicates potential abuse of trusted code-signing to bypass security controls.
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
Detects the execution of mshta.exe with a command line involving remote HTTP connections or suspicious file extensions (.dat), which are often used by adversaries to proxy the execution of malicious scripts or HTA files.
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
Detects the execution of potentially malicious utilities (curl, finger, cmd, powershell) that are launched by the Windows Explorer process (explorer.exe). This pattern is often indicative of malicious activity where an adversary uses legitimate OS processes to spawn command shells or network tools for further exploitation or file retrieval.
Page 185 of 1871


