Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where the rnpkeys process (likely used for GPG-related operations) spawns common Windows living-off-the-land binaries such as rundll32, regsvr32, msiexec, cmd, powershell, or wscript. It specifically monitors for patterns indicating potential script execution from temporary folders, the bypass of PowerShell execution policies, or the installation of products via msiexec, which may indicate malicious activity following initial compromise or delivery of a malicious payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of rnpkeys.exe from a specific path, followed by the loading of expected DLLs (rnp.dll or tdwp.dll) from the same directory, and a subsequent network connection on port 443. This behavior pattern is consistent with DLL side-loading used to establish a network-based command and control channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the presence of an unpacked Sauron Loader DLL by identifying a specific embedded configuration header (magic value 0xbaadf00d followed by flags 0x40) in conjunction with configuration fields like 'group_id' or 'build_id'. This rule is intended for static analysis of file samples.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution or presence of a malicious MSI installer file used by the Sauron Loader. This rule identifies files that exhibit the MSI OLE compound file structure in conjunction with specific file paths (C:\ProgramData\keyroll) and the presence of identified malicious components (rnpkeys.exe, rnp.dll, and tdwp.dll), or matches known SHA256 file hashes associated with this loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects periodic outbound network connections from rnpkeys.exe characteristic of the Sauron Loader C2 beaconing. The rule identifies a consistent heartbeat pattern (approx. 600 seconds) between successful C2 polls to the same remote host, distinguishing it from typical user-driven browser traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the presence or execution of a specific file hash associated with a known malicious campaign (KREMLIN/REF9334) that leverages a signed SentinelOne binary. This indicates potential abuse of trusted code-signing to bypass security controls.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
23 days ago
509
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
19 days ago
003
Detects the execution of mshta.exe with a command line involving remote HTTP connections or suspicious file extensions (.dat), which are often used by adversaries to proxy the execution of malicious scripts or HTA files.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
19 days ago
003
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
004
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
104
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
004
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
000
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
000
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
000
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
13 days ago
000
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
000
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
13 days ago
000
Detects the execution of known Python scripts (CES_Enroll.py, ntlm_ces_relay.py, ces_negotiate_ntlm.py) often associated with NTLM relay attacks or forced authentication techniques. These scripts leverage Python to interact with authentication protocols or relay requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
000
Detects Kerberos TGT requests (AS-REQ, Event ID 4768) where authentication is performed using a certificate (PKINIT) instead of a password. This pattern is commonly associated with Pass-the-Certificate attacks, often utilized by tools like Certipy following certificate enrollment or relaying to obtain a TGT as part of a credential access chain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
000
Detects the execution of known NTLM Certificate Enrollment Service (CES) relay tools alongside subsequent outbound network connections to Active Directory Certificate Services (AD CS) CES enrollment endpoints. This behavioral pattern indicates an adversary attempting to relay NTLM authentication to an AD CS server to request a certificate, typically for privilege escalation or persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
000
Detects the execution of potentially malicious utilities (curl, finger, cmd, powershell) that are launched by the Windows Explorer process (explorer.exe). This pattern is often indicative of malicious activity where an adversary uses legitimate OS processes to spawn command shells or network tools for further exploitation or file retrieval.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
004
Page 185 of 1871