Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects processes spawned by Terraform or Go (e.g., during init, apply, or run) that exhibit suspicious access to local cloud credential files (AWS/Azure/GCP) or Terraform state files. This behavior is indicative of a malicious module attempting to exfiltrate cloud credentials from a developer's workstation or a CI/CD build host.
Detects known Cobalt Strike default named pipe naming conventions and cross-process reflective DLL injection activities into common Windows host processes such as rundll32.exe, svchost.exe, and others. This rule monitors for suspicious named pipe creation events and process memory manipulation patterns indicative of beacon behavior and post-exploitation injection.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
Detects the Windows Installer service (msiexec.exe) being launched by known remote access software processes like msra.exe (Microsoft Remote Assistance) or anydesk.exe. This behavior is often associated with unauthorized software installation or payload delivery via remote support tools.
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
Detects potential vishing activity associated with the Sauron Loader threat. The rule identifies a pattern of a mailbox receiving a high volume of inbound emails (spam or subscription bombs) within a short window, followed by the user launching remote assistance tools like Quick Assist or AnyDesk on the same endpoint, indicating an attacker-guided remote session.
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
Detects various system utilities executing files or payloads staged in user-specific temporary directories (%AppData%\Local\Temp). This pattern is consistent with malware loaders (such as the Sauron Loader) that write payloads to the Temp folder before utilizing trusted Windows binaries (LOLBins) like rundll32, regsvr32, powershell, or wscript for execution. It also tracks potential driver installation or direct process memory access attempts from the same location.
Detects the embedded configuration structure within unpacked DLL samples associated with the Sauron loader, specifically targeting a fixed magic constant (0xbaadf00d) followed by a 0x40 flag byte.
Detects the execution of the process 'rnpkeys.exe' initiated by 'msiexec.exe' from the '\ProgramData\keyroll\' directory. This activity may indicate malicious use of the Windows Installer to proxy the execution of unauthorized or potentially malicious key management software.
Detects the creation of scheduled tasks using 'schtasks.exe' where the command line arguments contain the string 'keyroll'. This pattern is often associated with automated credential management or persistence mechanisms that may be abused by adversaries.
This rule detects the loading of a specific module named 'tdwp.dll' by the 'rnpkeys.exe' process, where both files are located within a 'keyroll' directory. This pattern is indicative of potential DLL sideloading or execution of unauthorized components where a legitimate-looking process loads a custom, possibly malicious, library from a non-standard location.
Detects suspicious command-line patterns originating from the Windows Explorer process (explorer.exe). This rule identifies the execution of various scripting engines or utilities like PowerShell, CMD, MSHTA, and WScript/CScript when they are used with potentially malicious flags or command-line arguments, including encoded commands, hidden window styles, web-download strings, or direct HTA/scripting invocations, which are common indicators of malicious activity following potential user execution.
Detects HTTP traffic identified as Sauron Loader, characterized by specific POST requests to hardcoded domains, URI path structures, and user-agent strings indicative of automated C2 activity.
Detects HTTP traffic identified as Sauron Loader, characterized by specific POST requests to hardcoded domains, URI path structures, and user-agent strings indicative of automated C2 activity.
Detects instances where attrib.exe is executed with minimal or no command-line arguments, launched by processes other than standard Windows shell processes like cmd.exe, explorer.exe, or powershell.exe. This pattern is often indicative of potential masquerading, where malicious binaries are renamed to mimic legitimate Windows system utilities to evade detection.
Detects instances where the rnpkeys.exe process initiates a network connection shortly after its execution. The RNP (OpenPGP) utility is generally used for local cryptographic operations; unexpected network activity from this process may indicate potential misuse, data exfiltration, or malicious use of the tool for command-and-control communication.
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
Page 66 of 1870

