Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a potential brute force or password spraying attempt by identifying instances where a single IP address targets 8 or more distinct user accounts with failed authentication attempts (Event ID 4625) within a 30-minute window.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
16 days ago
106
Detects attempts to bypass Vite development server file access restrictions by appending query parameters such as ?raw, ?import&raw, or ?import&url&inline to request paths for sensitive files like .env, cloud credentials, and terraform state files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
006
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
406
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
202
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
202
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
202
Detects the execution chain of the Sauron Loader malware. The rule identifies the side-loading of 'rnp.dll' by 'rnpkeys.exe' originating from the 'C:\ProgramData\keyroll' directory, followed by the loading of 'tdwp.dll' which facilitates in-memory decryption and execution. Persistence is confirmed by the creation or update of a scheduled task named 'keyroll'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
102
Detects the creation or modification of a scheduled task utilizing 'tdwp.dll' and containing the 'keyroll' argument in the command line. This pattern is indicative of a specific persistent mechanism often associated with unauthorized activity or potential malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
102
Detects known Sauron Loader MSI installer/DLL samples by SHA-256 or the rnpkeys.exe/rnp.dll/tdwp.dll side-load pairing referenced together in a file
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
102
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
406
This rule detects unscheduled modifications to federation, application, or service principal credentials, including ADFS token-signing certificates, in both Azure AD (via O365 management activity logs) and local Windows environments (via Security Event Logs). It filters these events against a known rotation schedule to highlight suspicious, non-routine changes that may indicate persistence establishment or identity provider tampering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential lateral movement by users who have recently been flagged for credential theft or infostealer activity. The rule correlates initial security alerts with subsequent Windows logon events (RDP, network/WinRM) or SMB share access, identifying users connecting to multiple distinct destinations within a 48-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 70 of 1870