Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of 'rnpkeys.exe' originating from the 'C:\ProgramData\keyroll' directory, which is a non-standard location for executable files and may indicate malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
003
Detects the execution of legitimate remote-access software commonly used in social engineering attacks, such as Quick Assist and AnyDesk. These tools are frequently abused as an initial access or persistence mechanism by threat actors following initial contact via methods like vishing or email-based social engineering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
103
Detects instances where 'rnpkeys.exe', residing within a 'keyroll' directory, initiates suspicious child processes or executes suspicious command lines. This includes triggering common scripting engines like PowerShell or cmd.exe, using execution policy bypass flags, or executing binaries from Temp directories, which are characteristic of malicious post-exploitation or persistence activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
103
Detects unpacked Sauron Loader malware samples by identifying specific embedded configuration artifacts, including a fixed magic header value (0xbaadf00d), internal marker strings, and associated test identifiers for group and build IDs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
003
This rule detects two suspicious behaviors: 1) Execution of common system binaries (e.g., rundll32.exe, powershell.exe) from a directory pattern resembling a temporary folder or droppers, and 2) Network connections initiated by the 'attrib.exe' binary, which is atypical for this utility and may indicate malicious activity or staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
203
Detects the execution of various system binaries (e.g., rundll32.exe, powershell.exe, regsvr32.exe) launched from a Temp directory where the parent or actor process is identified as rnpkeys.exe or rnp.dll. This behavior is indicative of potential malicious activity where legitimate tools or utilities (GnuPG/RNP) are being abused to proxy the execution of secondary payloads or scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
003
This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects various process injection techniques (such as CreateRemoteThread, QueueUserAPC, and remote memory writes) initiated by external processes targeting high-value, commonly abused Windows system processes like svchost.exe, lsass.exe, and explorer.exe. These techniques are often used by ransomware and other malware to hide malicious code execution within trusted system memory space.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects various methods used by adversaries to perform credential dumping from the Local Security Authority Subsystem Service (LSASS) process. It monitors for direct process access with suspicious handle permissions, the use of comsvcs.dll via rundll32.exe for MiniDump creation, the execution of memory dumping tools like procdump, and the creation of LSASS memory dump files by Task Manager.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the use of PsExec or SC.exe to create services on multiple remote endpoints within a short time window. This pattern is characteristic of adversary-driven mass deployment of ransomware or other malicious payloads where remote execution via Windows service control is used to move laterally across a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects potential lateral movement by identifying processes spawned via WMI (e.g., wmic.exe, WmiPrvSE.exe) or PowerShell Remoting (WinRM, Invoke-Command, Enter-PSSession) that occur shortly after a successful network or remote interactive logon on the same host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects attempts to inhibit system recovery by deleting the Windows backup catalog or modifying boot configuration data to disable automatic repair features using built-in utilities like wbadmin.exe and bcdedit.exe. This activity is commonly associated with ransomware or destructive attacks attempting to prevent system restoration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the creation of password-protected archives using 7-Zip or WinRAR command-line utilities. Adversaries often use these tools to compress and encrypt data prior to exfiltration to bypass security controls and prevent inspection of contents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects suspicious command-line execution patterns originating from explorer.exe, characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and pasting malicious commands into a terminal or Run dialog. The rule monitors for the usage of system binaries (mshta, powershell, rundll32, etc.) combined with network-fetching arguments or suspicious execution flags (hidden windows, encoded commands).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
301
Detects the execution of rclone, a command-line tool for synchronizing files to and from cloud storage services. The rule identifies suspicious command-line usage patterns, specifically looking for common transfer operations (copy, sync, copyto), usage of configuration files, transfer tuning flags, or direct remote cloud storage identifiers, which are characteristic of unauthorized data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
201
Detects the execution of known Remote Monitoring and Management (RMM) tools from common staging directories (e.g., Temp, Downloads, AppData) or using command-line arguments indicative of a silent or hidden installation, which is a common pattern for initial access and persistence by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the execution of known portable network scanning utilities such as SoftPerfect NetScan and Advanced IP Scanner. These tools are frequently abused by threat actors for network enumeration and service discovery to facilitate lateral movement within a compromised environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
This rule detects the creation of new Windows services that are characteristic of lateral movement tools like PsExec. It looks for services with names typical of PsExec/PAExec, the use of administrative shares (ADMIN$) in image paths, or services with randomly generated names executing from temporary directories (e.g., Windows\Temp, Users\Public). Legitimate administrative tools such as svchost.exe or those within Program Files are excluded.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects attempts to clear Windows event logs using built-in utilities like wevtutil.exe, PowerShell commands (Clear-EventLog, Remove-EventLog), or the detection of Event ID 1102 (Log cleared). This activity is commonly used by adversaries, including ransomware affiliates, to obfuscate their tracks during or after an attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the use of legitimate Windows administrative utilities (vssadmin, wmic, bcdedit, wbadmin) to delete volume shadow copies, clear backup catalogs, or modify boot configuration to prevent automatic system recovery. This behavior is a common indicator of ransomware preparing for encryption by removing local recovery options.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Page 53 of 1870