Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
002
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
002
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
002
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
000
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
000
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
000
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
000
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
000
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
000
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
000
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
000
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
000
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
000
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
000
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
000
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Page 196 of 1871