Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a potential brute force or password spraying attempt by identifying instances where a single IP address targets 8 or more distinct user accounts with failed authentication attempts (Event ID 4625) within a 30-minute window.
Detects attempts to bypass Vite development server file access restrictions by appending query parameters such as ?raw, ?import&raw, or ?import&url&inline to request paths for sensitive files like .env, cloud credentials, and terraform state files.
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
Detects a potential ClickFix social engineering attack pattern where a user manually launches a script interpreter (e.g., PowerShell, cmd, mshta) from Windows Explorer followed within 30 minutes by the execution of 'rnpkeys.exe', a known indicator in installer side-load chains.
Detects anomalous network traffic patterns from 'rnpkeys.exe', a known loader associated with the Sauron malware, communicating with predefined command-and-control (C2) domains or over HTTPS. The rule identifies high volumes of short-lived, frequent connections indicative of fragmented exfiltration (e.g., screenshots) blended into regular beaconing activity.
Detects the Sauron Loader execution chain, which involves a specific process (rnpkeys.exe, rnp.dll, or tdwp.dll) performing a network request (beacon), followed by the creation of a new file (executable, script, or library), and the subsequent execution of that same file. This pattern is characteristic of operator-issued download-and-run tasking.
Detects the execution chain of the Sauron Loader malware. The rule identifies the side-loading of 'rnp.dll' by 'rnpkeys.exe' originating from the 'C:\ProgramData\keyroll' directory, followed by the loading of 'tdwp.dll' which facilitates in-memory decryption and execution. Persistence is confirmed by the creation or update of a scheduled task named 'keyroll'.
Detects the creation or modification of a scheduled task utilizing 'tdwp.dll' and containing the 'keyroll' argument in the command line. This pattern is indicative of a specific persistent mechanism often associated with unauthorized activity or potential malware.
Detects known Sauron Loader MSI installer/DLL samples by SHA-256 or the rnpkeys.exe/rnp.dll/tdwp.dll side-load pairing referenced together in a file
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
This rule detects unscheduled modifications to federation, application, or service principal credentials, including ADFS token-signing certificates, in both Azure AD (via O365 management activity logs) and local Windows environments (via Security Event Logs). It filters these events against a known rotation schedule to highlight suspicious, non-routine changes that may indicate persistence establishment or identity provider tampering.
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
Detects potential lateral movement by users who have recently been flagged for credential theft or infostealer activity. The rule correlates initial security alerts with subsequent Windows logon events (RDP, network/WinRM) or SMB share access, identifying users connecting to multiple distinct destinations within a 48-hour window.
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
Page 70 of 1870



