
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,955 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the use of PsExec or the Service Control Manager (sc.exe) to execute code remotely, which is a common technique used by attackers for lateral movement and remote code execution.
Detects instances where the Windows Management Instrumentation service (WmiPrvSE.exe) spawns a command shell (cmd.exe) with command-line arguments involving standard output redirection (2>&1), often used to capture error and output streams in remote command execution scenarios. This pattern is commonly observed during lateral movement or remote administration activity.
Detects the use of administrative tools like wmic.exe, powershell.exe, or pwsh.exe to invoke WMI event subscription components such as ActiveScriptEventConsumer, CommandLineEventConsumer, or FilterToConsumerBinding. This behavior is a common technique for establishing persistence or elevating privileges by executing malicious code when specific system events occur.
Detects outbound TCP traffic originating from the internal network to external hosts on TCP port 45588, which is associated with Interlock ransomware beaconing behavior. This rule monitors for initial TCP SYN packets, characteristic of an outbound connection attempt potentially related to command-and-control activity following the exploitation of CVE-2026-20131.
This rule detects network connections to known cloud storage, file hosting, and webhook services (Discord, Pastebin, Dropbox, Telegram, AnonFiles) initiated by processes other than standard web browsers. Such behavior is often indicative of data exfiltration or C2 activity using legitimate web services to blend in with normal traffic.
This rule detects high-frequency file renaming or creation activities within a short timeframe (60 seconds) that involve uncommon file extensions. This behavior is highly characteristic of the encryption phase of ransomware attacks, where malicious processes quickly rename or encrypt files across the system.
Detects the execution of rundll32.exe or regsvr32.exe as a child process of script interpreters like wscript.exe, cscript.exe, or mshta.exe. The command line parameters often involve potentially malicious paths (e.g., Temp, AppData, ProgramData, Users\Public) or the presence of DLL extensions, indicating potential proxy execution of malicious scripts or side-loaded libraries.
Detects artifacts related to the ValleyRAT malware family, specifically identifying markers such as 'Phantom Persistence Module', 'RegisterApplicationRestart', and specific 'RSL_' strings within process command lines, image paths, or module loads using Windows Event Logs and Sysmon data.
This rule detects high-frequency file renaming or creation activities within a short timeframe (60 seconds) that involve uncommon file extensions. This behavior is highly characteristic of the encryption phase of ransomware attacks, where malicious processes quickly rename or encrypt files across the system.
This rule detects network connections to known cloud storage, file hosting, and webhook services (Discord, Pastebin, Dropbox, Telegram, AnonFiles) initiated by processes other than standard web browsers. Such behavior is often indicative of data exfiltration or C2 activity using legitimate web services to blend in with normal traffic.
