Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the pidclone-style LSASS credential dumper that clones the target process into a suspended state, mirrors its memory, generates a minidump, and writes an XOR-encrypted copy of the dump to a randomized filename under Windows\Temp
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects a sequence of events indicative of LSASS memory dumping where a process opens a handle to lsass.exe and subsequently creates a uniquely named temporary file (16-character hexadecimal filename) in the Windows Temp directory within a short timeframe. This behavior is often associated with the obfuscated flushing of a stolen memory dump to disk to evade signature-based detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects compiled LSASS credential-dumper binaries that clone the target process in a suspended state, patch ntdll/amsi/win32kbase hooking regions, and write an in-memory minidump, even when debug/console strings and process ancestry have been scrubbed to evade static and lineage detections
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects msiexec.exe being executed with a remote HTTP(S) URL argument that includes a token-based query parameter. This pattern is characteristic of ClickFix-style social engineering attacks where a user is tricked into manually executing a command to download and run a malicious MSI file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
107
Detects the use of PowerShell cmdlets (Add-MpPreference or Set-MpPreference) to modify Microsoft Defender exclusions (paths, processes, or extensions). This behavior is often associated with adversaries attempting to evade security detection by excluding malicious files or processes from being scanned by Microsoft Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
007
Detects instances where Node.js, Python, or Go processes spawn command shell interpreters (cmd.exe, powershell.exe, etc.). This behavior is often indicative of C2 command execution by malware, such as the Graphalgo RAT, which may use these languages to execute shell-level commands after initial infection or payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects processes spawned by Terraform or Go (e.g., during init, apply, or run) that exhibit suspicious access to local cloud credential files (AWS/Azure/GCP) or Terraform state files. This behavior is indicative of a malicious module attempting to exfiltrate cloud credentials from a developer's workstation or a CI/CD build host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the Windows Installer service (msiexec.exe) being launched by known remote access software processes like msra.exe (Microsoft Remote Assistance) or anydesk.exe. This behavior is often associated with unauthorized software installation or payload delivery via remote support tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects potential vishing activity associated with the Sauron Loader threat. The rule identifies a pattern of a mailbox receiving a high volume of inbound emails (spam or subscription bombs) within a short window, followed by the user launching remote assistance tools like Quick Assist or AnyDesk on the same endpoint, indicating an attacker-guided remote session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects various system utilities executing files or payloads staged in user-specific temporary directories (%AppData%\Local\Temp). This pattern is consistent with malware loaders (such as the Sauron Loader) that write payloads to the Temp folder before utilizing trusted Windows binaries (LOLBins) like rundll32, regsvr32, powershell, or wscript for execution. It also tracks potential driver installation or direct process memory access attempts from the same location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the embedded configuration structure within unpacked DLL samples associated with the Sauron loader, specifically targeting a fixed magic constant (0xbaadf00d) followed by a 0x40 flag byte.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the execution of the process 'rnpkeys.exe' initiated by 'msiexec.exe' from the '\ProgramData\keyroll\' directory. This activity may indicate malicious use of the Windows Installer to proxy the execution of unauthorized or potentially malicious key management software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the creation of scheduled tasks using 'schtasks.exe' where the command line arguments contain the string 'keyroll'. This pattern is often associated with automated credential management or persistence mechanisms that may be abused by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule detects the loading of a specific module named 'tdwp.dll' by the 'rnpkeys.exe' process, where both files are located within a 'keyroll' directory. This pattern is indicative of potential DLL sideloading or execution of unauthorized components where a legitimate-looking process loads a custom, possibly malicious, library from a non-standard location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects suspicious command-line patterns originating from the Windows Explorer process (explorer.exe). This rule identifies the execution of various scripting engines or utilities like PowerShell, CMD, MSHTA, and WScript/CScript when they are used with potentially malicious flags or command-line arguments, including encoded commands, hidden window styles, web-download strings, or direct HTA/scripting invocations, which are common indicators of malicious activity following potential user execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Page 60 of 1866