
Amit Ambekar
@Amit007Completionist
0 followers14 downloads48 copies0 likes137 views
21 detections
Filters
Last updated
All Time
Detection languages
18
3
Categories
11
4
3
3
3
Platforms
21
Products / Services
15
1
1
1
1
MITRE Techniques
10
6
5
5
4
Detects the creation or modification of a scheduled task named 'Maps Performance Task' using schtasks.exe or reg.exe. This task is often associated with legitimate Windows system maintenance related to map data but may be monitored as it involves persistence mechanisms.
Detects the presence of the Docro Hijacker browser hijacker component (Adblock.dll) designed to tamper with Chrome's 'Secure Preferences' file. It specifically looks for indicators of HMAC-SHA256 integrity check bypass mechanisms used to force-install malicious browser extensions.
This rule detects the creation of Windows services with specific, potentially suspicious names (wscl-13, msvcsrvc) configured to start automatically on system startup. The detection logic monitors command-line activity from sc.exe or services.exe to identify these specific service registrations.
Detects the use of PowerShell to modify Microsoft Defender Antivirus configurations, specifically adding file exclusions or disabling protection features like Real-time or IOAV monitoring. These actions are common indicators of an adversary attempting to disable security controls to evade detection.
Detects the modification or creation of scheduled tasks using OOBETaskScheduler or referencing Windows Servicing paths, combined with network connections to known malicious domains identified in threat intelligence.
Detects the execution of command-line shells (cmd, powershell, pwsh) running under the SYSTEM context that were initiated by or associated with a process containing 'ShieldBreak' in its filename. This behavior is indicative of a suspicious or potentially malicious process (e.g., a security bypass tool) attempting to spawn elevated shells.
Detects the loading of 'Adblock.dll' by the executable 'eld2.exe', specifically when 'eld2.exe' is executed as a child process of 'windirstat.exe'. This behavior is indicative of DLL side-loading where a legitimate or potentially malicious application is used to load a secondary library.
Detects instances where multiple executables named 'eld0.exe', 'eld1.exe', or 'eld2.exe' are executed on the same device within a short time window, all containing a 'CID=' argument in the command line. This behavior is often indicative of automated deployment, staging, or modular malware execution patterns.
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
Detects the presence of known artifacts associated with the GreenSection proof-of-concept exploit, including the source code file 'GreenSection.cpp', a specific driver crash dump 'nvoglv64.dmp', and a associated unique GUID. These files are indicators that an actor has staged exploit materials on the system.
Page 1 of 3
