Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
703
Detects network connections over port 443 initiated by a process named 'rnpkeys.exe' running from a suspicious staging directory ('\ProgramData\keyroll\'). This behavior is characteristic of side-loaded payloads establishing command-and-control communication for data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
This rule detects the execution of 'rnpkeys.exe' from within the '\ProgramData\keyroll\' directory, specifically when it loads 'rnp.dll' from the same path. This behavior is indicative of potential malicious activity, as the ProgramData directory is a common location for adversaries to stage files, and the use of custom DLL loading from this directory may suggest an attempt to execute unauthorized code or obfuscate tool activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
This rule detects the suspicious sequential loading of 'tdwp.dll' and 'rnp.dll' by processes related to key management or encryption (e.g., 'rnpkeys.exe' or processes from a 'keyroll' folder). The detection correlates these events within a 2-minute window and highlights if the 'tdwp.dll' has a known malicious hash.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the execution of 'ClickFix' or 'fake-CAPTCHA' patterns where a user is tricked into copying and pasting a malicious command into the Windows Run dialog. The rule specifically identifies the launch of conhost.exe from explorer.exe with --headless arguments, utilizing command-line tools like curl, iex, or irm to fetch and execute external payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
303
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
103
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects specific malicious Mach-O binary payloads identified as Atomic Stealer (AMOS) that are associated with Macfinger ClickFix first-stage infection campaigns. The rule uses static file signatures (Mach-O headers), specific file size ranges, and known SHA-256 hashes of the payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
This rule uses YARA to identify specific malicious files associated with the Sauron Loader malware, including the MSI installer and associated support DLLs (rnp.dll, tdwp.dll), based on their known SHA-256 hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects anomalous, high-frequency outbound HTTPS POST requests from the 'rnpkeys.exe' process, characteristic of the Sauron Loader exfiltrating screenshot chunks (Message Type 3) to a Command and Control (C2) server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects process injection behaviors (e.g., remote thread creation, memory allocation) targeting the attrib.exe process. Such activity is often associated with process hollowing or reflective shellcode injection, consistent with loader behavior used to execute in-memory payloads within legitimate, rarely-used system utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects a specific social-engineering pattern known as 'ClickFix' where a user is manipulated into opening the Windows Run dialog (explorer.exe) to manually execute commands. The rule identifies suspicious command-line arguments typically associated with initial access (e.g., PowerShell hidden/encoded execution, web downloads) followed by the execution of MSI installers or related malicious binaries (e.g., rnpkeys.exe) within a 30-minute window, indicative of the Sauron Loader infection chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects reconnaissance commands related to system domain, locale, and environment settings following the execution of rnpkeys.exe from C:\ProgramData\keyroll, a behavior associated with the Sauron Loader. The rule identifies suspicious system discovery commands (nltest, whoami, etc.) or environment checks performed shortly after the loader's execution, indicating potential target verification before C2 registration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects unpacked Sauron Loader DLL samples by identifying the embedded configuration structure. The rule searches for a specific 4-byte magic header (0xbaadf00d), specific configuration field strings ('group_id' and 'build_id'), and RSA key length markers consistent with the loader's known cryptographic configuration structure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
This rule detects network activity associated with the Sauron Loader malware. It monitors for TLS connections to known hardcoded C2 domains and identifies HTTP requests following a specific pattern of randomized command and control (C2) paths combined with suspicious User-Agent headers (Windows NT with Edge/Edg).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects DLL side-loading activity where the legitimate-looking process rnpkeys.exe, located in a non-standard ProgramData sub-directory, loads a malicious rnp.dll from the same directory, a behavior observed with the Sauron Loader malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the creation of a remote thread targeting the native Windows utility 'attrib.exe'. This behavior is characteristic of code injection techniques, such as those used by the Sauron loader, where malicious shellcode is executed within the context of a legitimate system process to evade detection and maintain persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the Sauron Loader malware utilizing the process rnpkeys.exe as a parent to spawn common LOLBins (Living-off-the-Land Binaries) or execute payloads from temporary directories. This behavior is indicative of a secondary stage execution chain typical of the Sauron Loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects anomalous, high-frequency outbound network connections to port 443 initiated by the binary 'rnpkeys.exe'. This behavior is characteristic of the Sauron Loader, which uses this masqueraded process to exfiltrate collected data, such as screenshots, via an encrypted C2 channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the execution of the Sauron Loader malware, which utilizes a DLL side-loading chain involving rnpkeys.exe loading rnp.dll or tdwp.dll from a specific ProgramData path, indicating potential malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101