Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
10 days ago
001
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
10 days ago
001
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
10 days ago
001
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
101
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
10 days ago
001
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
001
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
10 days ago
001
Detects the loading of 'tdwp.dll' in a process that has previously loaded 'rnp.dll', which is characteristic of the Sauron loader (also known as Remsec) in-memory decryption chain performed by the 'rnpkeys.exe' executable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects the presence of the signed but vulnerable DCRCVDrv.sys kernel driver, which is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security processes via an unauthenticated PID-terminate IOCTL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
005
Detects network activity associated with NetSupport Manager remote access software, specifically monitoring for connections to known malicious domains and infrastructure, as well as recurring beaconing patterns indicative of command-and-control behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
005
Detects instances where a process attempts to delete its own executable file image shortly after being launched. This behavior is often associated with malware attempting to minimize its forensic footprint, such as self-deleting installers or RAT (Remote Access Trojan) components that move to a different location or execute from memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
205
Detects suspicious force push events to the 'main' branch in GitHub repositories. The rule flags pushes that include hardcoded commit hashes associated with known malicious activity, pushes where the author and committer identities do not match, or pushes containing specific indicators such as 'indexe.cjs' or 'preinstall' scripts which are common in software supply chain attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
105
This rule detects unauthorized access, creation, or modification of Git credential files (.git-credentials, .netrc) by processes other than standard Git credential management utilities. It also monitors command-line activity that references these credential stores to identify potential attempts to exfiltrate or manipulate stored credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
205
Detects execution of rundll32.exe with suspicious command-line patterns, including paths containing 'DavWWWRoot' (indicating potential remote file execution/WebDAV abuse), specific malicious DLL function exports, or launching from PowerShell. These techniques are commonly used to execute payloads from remote locations or to bypass traditional security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
005
Detects suspicious PowerShell process execution initiated by Windows Explorer, specifically involving WebDAV-related commands or network share mounting indicators. This pattern is commonly associated with attackers attempting to download and execute remote payloads from WebDAV shares to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
505
Detects instances where PowerShell processes initiate outbound WebDAV connections, potentially to download or stage malicious DLLs. The detection rule correlates network activity involving WebDAV indicators (e.g., DavWWWRoot) with subsequent local file creation events for DLL files within WebDAV-related folders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
005
Flags anomalous volume of Entra ID sign-ins using the device-code authorization grant, matching the Kali365 phishing-as-a-service technique (sold on Telegram, ~$250/month per FBI PSA) that captures Microsoft 365 OAuth tokens through the legitimate device-code flow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
502