Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the loading of 'tdwp.dll' in a process that has previously loaded 'rnp.dll', which is characteristic of the Sauron loader (also known as Remsec) in-memory decryption chain performed by the 'rnpkeys.exe' executable.
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the presence of the signed but vulnerable DCRCVDrv.sys kernel driver, which is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security processes via an unauthenticated PID-terminate IOCTL.
Detects network activity associated with NetSupport Manager remote access software, specifically monitoring for connections to known malicious domains and infrastructure, as well as recurring beaconing patterns indicative of command-and-control behavior.
Detects instances where a process attempts to delete its own executable file image shortly after being launched. This behavior is often associated with malware attempting to minimize its forensic footprint, such as self-deleting installers or RAT (Remote Access Trojan) components that move to a different location or execute from memory.
Detects suspicious force push events to the 'main' branch in GitHub repositories. The rule flags pushes that include hardcoded commit hashes associated with known malicious activity, pushes where the author and committer identities do not match, or pushes containing specific indicators such as 'indexe.cjs' or 'preinstall' scripts which are common in software supply chain attacks.
This rule detects unauthorized access, creation, or modification of Git credential files (.git-credentials, .netrc) by processes other than standard Git credential management utilities. It also monitors command-line activity that references these credential stores to identify potential attempts to exfiltrate or manipulate stored credentials.
Detects execution of rundll32.exe with suspicious command-line patterns, including paths containing 'DavWWWRoot' (indicating potential remote file execution/WebDAV abuse), specific malicious DLL function exports, or launching from PowerShell. These techniques are commonly used to execute payloads from remote locations or to bypass traditional security controls.
Detects suspicious PowerShell process execution initiated by Windows Explorer, specifically involving WebDAV-related commands or network share mounting indicators. This pattern is commonly associated with attackers attempting to download and execute remote payloads from WebDAV shares to bypass security controls.
Detects instances where PowerShell processes initiate outbound WebDAV connections, potentially to download or stage malicious DLLs. The detection rule correlates network activity involving WebDAV indicators (e.g., DavWWWRoot) with subsequent local file creation events for DLL files within WebDAV-related folders.
Flags anomalous volume of Entra ID sign-ins using the device-code authorization grant, matching the Kali365 phishing-as-a-service technique (sold on Telegram, ~$250/month per FBI PSA) that captures Microsoft 365 OAuth tokens through the legitimate device-code flow.

