Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the pidclone-style LSASS credential dumper that clones the target process into a suspended state, mirrors its memory, generates a minidump, and writes an XOR-encrypted copy of the dump to a randomized filename under Windows\Temp
Detects a sequence of events indicative of LSASS memory dumping where a process opens a handle to lsass.exe and subsequently creates a uniquely named temporary file (16-character hexadecimal filename) in the Windows Temp directory within a short timeframe. This behavior is often associated with the obfuscated flushing of a stolen memory dump to disk to evade signature-based detection.
Detects compiled LSASS credential-dumper binaries that clone the target process in a suspended state, patch ntdll/amsi/win32kbase hooking regions, and write an in-memory minidump, even when debug/console strings and process ancestry have been scrubbed to evade static and lineage detections
Detects msiexec.exe being executed with a remote HTTP(S) URL argument that includes a token-based query parameter. This pattern is characteristic of ClickFix-style social engineering attacks where a user is tricked into manually executing a command to download and run a malicious MSI file.
Detects the use of PowerShell cmdlets (Add-MpPreference or Set-MpPreference) to modify Microsoft Defender exclusions (paths, processes, or extensions). This behavior is often associated with adversaries attempting to evade security detection by excluding malicious files or processes from being scanned by Microsoft Defender.
Detects instances where Node.js, Python, or Go processes spawn command shell interpreters (cmd.exe, powershell.exe, etc.). This behavior is often indicative of C2 command execution by malware, such as the Graphalgo RAT, which may use these languages to execute shell-level commands after initial infection or payload execution.
Detects processes spawned by Terraform or Go (e.g., during init, apply, or run) that exhibit suspicious access to local cloud credential files (AWS/Azure/GCP) or Terraform state files. This behavior is indicative of a malicious module attempting to exfiltrate cloud credentials from a developer's workstation or a CI/CD build host.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
Detects the Windows Installer service (msiexec.exe) being launched by known remote access software processes like msra.exe (Microsoft Remote Assistance) or anydesk.exe. This behavior is often associated with unauthorized software installation or payload delivery via remote support tools.
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
Detects potential vishing activity associated with the Sauron Loader threat. The rule identifies a pattern of a mailbox receiving a high volume of inbound emails (spam or subscription bombs) within a short window, followed by the user launching remote assistance tools like Quick Assist or AnyDesk on the same endpoint, indicating an attacker-guided remote session.
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
Detects various system utilities executing files or payloads staged in user-specific temporary directories (%AppData%\Local\Temp). This pattern is consistent with malware loaders (such as the Sauron Loader) that write payloads to the Temp folder before utilizing trusted Windows binaries (LOLBins) like rundll32, regsvr32, powershell, or wscript for execution. It also tracks potential driver installation or direct process memory access attempts from the same location.
Detects the embedded configuration structure within unpacked DLL samples associated with the Sauron loader, specifically targeting a fixed magic constant (0xbaadf00d) followed by a 0x40 flag byte.
Detects the execution of the process 'rnpkeys.exe' initiated by 'msiexec.exe' from the '\ProgramData\keyroll\' directory. This activity may indicate malicious use of the Windows Installer to proxy the execution of unauthorized or potentially malicious key management software.
Detects the creation of scheduled tasks using 'schtasks.exe' where the command line arguments contain the string 'keyroll'. This pattern is often associated with automated credential management or persistence mechanisms that may be abused by adversaries.
This rule detects the loading of a specific module named 'tdwp.dll' by the 'rnpkeys.exe' process, where both files are located within a 'keyroll' directory. This pattern is indicative of potential DLL sideloading or execution of unauthorized components where a legitimate-looking process loads a custom, possibly malicious, library from a non-standard location.
Detects suspicious command-line patterns originating from the Windows Explorer process (explorer.exe). This rule identifies the execution of various scripting engines or utilities like PowerShell, CMD, MSHTA, and WScript/CScript when they are used with potentially malicious flags or command-line arguments, including encoded commands, hidden window styles, web-download strings, or direct HTA/scripting invocations, which are common indicators of malicious activity following potential user execution.
Page 60 of 1866

