Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects processes spawned by Terraform or Go (e.g., during init, apply, or run) that exhibit suspicious access to local cloud credential files (AWS/Azure/GCP) or Terraform state files. This behavior is indicative of a malicious module attempting to exfiltrate cloud credentials from a developer's workstation or a CI/CD build host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects known Cobalt Strike default named pipe naming conventions and cross-process reflective DLL injection activities into common Windows host processes such as rundll32.exe, svchost.exe, and others. This rule monitors for suspicious named pipe creation events and process memory manipulation patterns indicative of beacon behavior and post-exploitation injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
204
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the Windows Installer service (msiexec.exe) being launched by known remote access software processes like msra.exe (Microsoft Remote Assistance) or anydesk.exe. This behavior is often associated with unauthorized software installation or payload delivery via remote support tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the creation of a scheduled task named 'keyroll' in close temporal proximity to the execution of 'rnpkeys.exe' from 'C:\ProgramData\keyroll'. This pattern mimics the persistence mechanism used by the Sauron malware (a.k.a. Strider) to execute its loader chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects execution of staged payloads within the %TEMP% directory initiated by processes associated with the Sauron Loader (rnpkeys.exe or processes running from ProgramData\keyroll). The rule monitors for common living-off-the-land binaries (rundll32.exe, regsvr32.exe, msiexec.exe, cmd.exe, powershell.exe, wscript.exe) acting as task handlers for the loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects potential vishing activity associated with the Sauron Loader threat. The rule identifies a pattern of a mailbox receiving a high volume of inbound emails (spam or subscription bombs) within a short window, followed by the user launching remote assistance tools like Quick Assist or AnyDesk on the same endpoint, indicating an attacker-guided remote session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the execution of msiexec.exe (the Windows Installer) as a child process of remote support applications such as Quick Assist, Microsoft Remote Assistance (msra.exe), or AnyDesk. This pattern is commonly associated with remote access trojans and unauthorized software deployment during social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects the creation of a scheduled task named 'keyroll' using either schtasks.exe command line arguments or Windows Event ID 4698. This specific task name is associated with the persistence mechanism of the Sauron Loader, particularly when it references 'rnpkeys.exe' or 'ProgramData\keyroll'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects various system utilities executing files or payloads staged in user-specific temporary directories (%AppData%\Local\Temp). This pattern is consistent with malware loaders (such as the Sauron Loader) that write payloads to the Temp folder before utilizing trusted Windows binaries (LOLBins) like rundll32, regsvr32, powershell, or wscript for execution. It also tracks potential driver installation or direct process memory access attempts from the same location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the embedded configuration structure within unpacked DLL samples associated with the Sauron loader, specifically targeting a fixed magic constant (0xbaadf00d) followed by a 0x40 flag byte.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the execution of the process 'rnpkeys.exe' initiated by 'msiexec.exe' from the '\ProgramData\keyroll\' directory. This activity may indicate malicious use of the Windows Installer to proxy the execution of unauthorized or potentially malicious key management software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the creation of scheduled tasks using 'schtasks.exe' where the command line arguments contain the string 'keyroll'. This pattern is often associated with automated credential management or persistence mechanisms that may be abused by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule detects the loading of a specific module named 'tdwp.dll' by the 'rnpkeys.exe' process, where both files are located within a 'keyroll' directory. This pattern is indicative of potential DLL sideloading or execution of unauthorized components where a legitimate-looking process loads a custom, possibly malicious, library from a non-standard location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects suspicious command-line patterns originating from the Windows Explorer process (explorer.exe). This rule identifies the execution of various scripting engines or utilities like PowerShell, CMD, MSHTA, and WScript/CScript when they are used with potentially malicious flags or command-line arguments, including encoded commands, hidden window styles, web-download strings, or direct HTA/scripting invocations, which are common indicators of malicious activity following potential user execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects HTTP traffic identified as Sauron Loader, characterized by specific POST requests to hardcoded domains, URI path structures, and user-agent strings indicative of automated C2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects HTTP traffic identified as Sauron Loader, characterized by specific POST requests to hardcoded domains, URI path structures, and user-agent strings indicative of automated C2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects instances where attrib.exe is executed with minimal or no command-line arguments, launched by processes other than standard Windows shell processes like cmd.exe, explorer.exe, or powershell.exe. This pattern is often indicative of potential masquerading, where malicious binaries are renamed to mimic legitimate Windows system utilities to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects instances where the rnpkeys.exe process initiates a network connection shortly after its execution. The RNP (OpenPGP) utility is generally used for local cryptographic operations; unexpected network activity from this process may indicate potential misuse, data exfiltration, or malicious use of the tool for command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
8148
Page 66 of 1870