Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
Detects the Sauron Loader DLL side-loading chain: rnpkeys.exe (legitimate) side-loading malicious rnp.dll, which loads tdwp.dll to decrypt the loader in memory, all staged from C:\ProgramData\keyroll. Requires BOTH DLLs to be loaded by the same rnpkeys.exe process instance (not either/or) to eliminate single-artifact false positives, and surfaces SHA256 hashes of all three components for direct comparison against known IOCs (legitimate rnpkeys.exe: 194d7e8870ff783ce1e4e4e3015c895cc67ae52fd5e063c89dd1c069400d3991; malicious rnp.dll: 5606afdc5191d42f38d3c4f1692eda0a629c88810e29bfe78528733284ad1bf8; malicious tdwp.dll: 6551293e996d19755ba497f50b30a18c178f0d6e2a73b29ae742b8171e2985b7).
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
Detects creation of the 'keyroll' scheduled task used to relaunch the Sauron Loader DLL side-loading chain. Requires the schtasks.exe command line to both reference the 'keyroll' task name AND explicitly reference the ProgramData\keyroll path or rnpkeys.exe (ruling out unrelated tasks that happen to be named 'keyroll', e.g. legitimate key-rotation automation), and requires an INNER join corroborating an actual rnpkeys.exe relaunch from that path within 24h — a lone task-creation event with no follow-on relaunch no longer alerts.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
Page 196 of 1871
