Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
Detects network connections over port 443 initiated by a process named 'rnpkeys.exe' running from a suspicious staging directory ('\ProgramData\keyroll\'). This behavior is characteristic of side-loaded payloads establishing command-and-control communication for data exfiltration.
This rule detects the execution of 'rnpkeys.exe' from within the '\ProgramData\keyroll\' directory, specifically when it loads 'rnp.dll' from the same path. This behavior is indicative of potential malicious activity, as the ProgramData directory is a common location for adversaries to stage files, and the use of custom DLL loading from this directory may suggest an attempt to execute unauthorized code or obfuscate tool activity.
This rule detects the suspicious sequential loading of 'tdwp.dll' and 'rnp.dll' by processes related to key management or encryption (e.g., 'rnpkeys.exe' or processes from a 'keyroll' folder). The detection correlates these events within a 2-minute window and highlights if the 'tdwp.dll' has a known malicious hash.
Detects the execution of 'ClickFix' or 'fake-CAPTCHA' patterns where a user is tricked into copying and pasting a malicious command into the Windows Run dialog. The rule specifically identifies the launch of conhost.exe from explorer.exe with --headless arguments, utilizing command-line tools like curl, iex, or irm to fetch and execute external payloads.
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
Detects specific malicious Mach-O binary payloads identified as Atomic Stealer (AMOS) that are associated with Macfinger ClickFix first-stage infection campaigns. The rule uses static file signatures (Mach-O headers), specific file size ranges, and known SHA-256 hashes of the payloads.
This rule uses YARA to identify specific malicious files associated with the Sauron Loader malware, including the MSI installer and associated support DLLs (rnp.dll, tdwp.dll), based on their known SHA-256 hashes.
Detects anomalous, high-frequency outbound HTTPS POST requests from the 'rnpkeys.exe' process, characteristic of the Sauron Loader exfiltrating screenshot chunks (Message Type 3) to a Command and Control (C2) server.
Detects process injection behaviors (e.g., remote thread creation, memory allocation) targeting the attrib.exe process. Such activity is often associated with process hollowing or reflective shellcode injection, consistent with loader behavior used to execute in-memory payloads within legitimate, rarely-used system utilities.
Detects a specific social-engineering pattern known as 'ClickFix' where a user is manipulated into opening the Windows Run dialog (explorer.exe) to manually execute commands. The rule identifies suspicious command-line arguments typically associated with initial access (e.g., PowerShell hidden/encoded execution, web downloads) followed by the execution of MSI installers or related malicious binaries (e.g., rnpkeys.exe) within a 30-minute window, indicative of the Sauron Loader infection chain.
Detects reconnaissance commands related to system domain, locale, and environment settings following the execution of rnpkeys.exe from C:\ProgramData\keyroll, a behavior associated with the Sauron Loader. The rule identifies suspicious system discovery commands (nltest, whoami, etc.) or environment checks performed shortly after the loader's execution, indicating potential target verification before C2 registration.
Detects unpacked Sauron Loader DLL samples by identifying the embedded configuration structure. The rule searches for a specific 4-byte magic header (0xbaadf00d), specific configuration field strings ('group_id' and 'build_id'), and RSA key length markers consistent with the loader's known cryptographic configuration structure.
This rule detects network activity associated with the Sauron Loader malware. It monitors for TLS connections to known hardcoded C2 domains and identifies HTTP requests following a specific pattern of randomized command and control (C2) paths combined with suspicious User-Agent headers (Windows NT with Edge/Edg).
Detects DLL side-loading activity where the legitimate-looking process rnpkeys.exe, located in a non-standard ProgramData sub-directory, loads a malicious rnp.dll from the same directory, a behavior observed with the Sauron Loader malware.
Detects the creation of a remote thread targeting the native Windows utility 'attrib.exe'. This behavior is characteristic of code injection techniques, such as those used by the Sauron loader, where malicious shellcode is executed within the context of a legitimate system process to evade detection and maintain persistence.
Detects the Sauron Loader malware utilizing the process rnpkeys.exe as a parent to spawn common LOLBins (Living-off-the-Land Binaries) or execute payloads from temporary directories. This behavior is indicative of a secondary stage execution chain typical of the Sauron Loader.
Detects anomalous, high-frequency outbound network connections to port 443 initiated by the binary 'rnpkeys.exe'. This behavior is characteristic of the Sauron Loader, which uses this masqueraded process to exfiltrate collected data, such as screenshots, via an encrypted C2 channel.
Detects the execution of the Sauron Loader malware, which utilizes a DLL side-loading chain involving rnpkeys.exe loading rnp.dll or tdwp.dll from a specific ProgramData path, indicating potential malicious activity.
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.

