Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects network communication from 'rnpkeys.exe' to external IP addresses. This behavior is indicative of the Sauron Loader malware, which utilizes a side-loaded 'rnpkeys.exe' binary to establish beaconing and C2 communication as part of its registration process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the creation of a Windows service that points to a .sys file located in common temporary directories (Temp, Windows\Temp). This behavior is characteristic of adversaries attempting to load malicious kernel drivers, often for persistence or privilege escalation, such as in Bring Your Own Vulnerable Driver (BYOVD) attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects Sauron Loader DLLs by identifying specific configuration blob magic values (0xbaadf00d), associated flags, and internal strings like 'group_id' or 'build_id' that suggest the presence of malicious configuration or RSA key material.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects unpacked Sauron Loader DLL samples by identifying specific binary structures, including the magic value 0xbaadf00d and subsequent flag bytes (0x40) often found in its embedded configuration blob.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects unpacked Sauron Loader DLL samples by identifying specific binary structures, including the magic value 0xbaadf00d and subsequent flag bytes (0x40) often found in its embedded configuration blob.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects instances where a user pastes and executes commands, specifically those containing reCAPTCHA verification strings or base64-encoded bash commands, within a macOS Terminal session. This behavior is indicative of a 'ClickFix' social engineering attack where a user is tricked into manually executing malicious commands in their shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
This rule detects potential command and control (C2) activity related to the AMOS (Atomic macOS) information stealer. It identifies a specific sequence of network requests where an initial registration beacon (POST /api/t) is followed by a shell agent request (GET /api/shell/agent) within 120 seconds, originating from the same destination IP and port.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects a sequence of events where a single user receives an unusually high volume of inbound emails (potentially vishing-related), followed shortly thereafter by the user executing common remote assistance or remote access tools (e.g., Quick Assist, AnyDesk). This pattern is consistent with social engineering tactics used in IT-support impersonation scams to facilitate the delivery of malware such as Sauron Loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects potential insider threats or departing employees by correlating abnormal bulk data downloads from cloud repositories (SharePoint/OneDrive/Box/etc.) with subsequent sensitive data access and exfiltration signals. It uses baseline behavioral profiling, requires a threshold of sensitive file interactions, and mandates high-confidence exfiltration indicators (removable media usage, suspicious external domains, or multiple combined destination events) to reduce noise. Archive/staging activity is used as an optional confidence booster.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects the MSI installer (msiexec.exe) creating files within the 'C:\ProgramData\keyroll' directory, which is characteristic of the staging phase for the Sauron Loader DLL side-loading trio (rnpkeys.exe, rnp.dll, tdwp.dll).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects a potential vishing or technical support scam scenario by identifying a burst of email traffic to a user (email bombing) followed within one hour by the execution of a remote assistance tool (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on the same user's endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the execution of bash commands containing base64 decoding instructions, often used by adversaries to decode and execute obfuscated scripts or payloads. The rule specifically looks for command lines invoking base64 along with keywords like 'echo' or 'reCAPTCHA', which are commonly associated with malicious droppers or phishing-related scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the execution of various system binaries (e.g., rundll32.exe, powershell.exe, regsvr32.exe) launched from a Temp directory where the parent or actor process is identified as rnpkeys.exe or rnp.dll. This behavior is indicative of potential malicious activity where legitimate tools or utilities (GnuPG/RNP) are being abused to proxy the execution of secondary payloads or scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
This rule detects the execution of common remote access tools (Quick Assist, AnyDesk) on a host that does not have a prior history of using those specific tools. This is intended to identify potential hands-on-keyboard activity by adversaries following initial access via social engineering, such as vishing or email-bombing, where they attempt to establish a persistent remote access foothold.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the execution of the 'rnpkeys.exe' file from the 'C:\ProgramData\keyroll\' directory. The location and filename are highly atypical and could indicate unauthorized tool usage, potential persistence, or malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects high-frequency file deletion events originating from processes with names or command-line indicators associated with AI orchestration frameworks like Semantic Kernel. This behavior may indicate an adversary abusing legitimate AI agent tools to perform unauthorized data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
203
Detects the execution of Rubeus, a common security tool used for Kerberos-based attacks including Golden/Silver Ticket forgery, AS-REP roasting, Kerberoasting, and ticket harvesting. The rule monitors command-line indicators associated with known Rubeus arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
203
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
004