
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to Azure AD/Entra ID application configurations, specifically updating the 'RedirectUri' or 'ReplyUrls' to point to potentially external or unauthorized domains. This technique is often used in OAuth-based application-consent phishing campaigns to redirect authorization codes to adversary-controlled servers.
Detects network connections from common web browser processes (Chrome, Edge, Brave, Electron) to loopback addresses (127.0.0.1 or Localhost) where the URL path contains sensitive keywords like /code, /textbox, /credentials, or /secrets. This behavior is often associated with browser-based exploitation attempts, such as targeting local development servers or internal browser automation interfaces to extract sensitive information.
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
Detects web browsers and browser-related applications (e.g., Chrome, Edge, ChatGPT, Electron apps) spawning suspicious child processes that are commonly used for command-line execution or script interpretation. This behavior is often indicative of malicious extensions, browser exploits, or attempts to leverage browser processes for initial execution or lateral movement.
Detects high frequency inbound network connection attempts or accepted connections initiated by common file sharing processes (e.g., NearShare.exe, NearbySharing.exe, quickshare.exe, sharingd, airplayd). A high volume of inbound connection attempts may indicate brute force, discovery, or malicious scanning behavior using legitimate file sharing tools as a conduit.
Detects the use of the 'net.exe' or 'net1.exe' command-line utilities to mount a local SMB share using loopback addresses (127.0.0.1 or localhost) with the '/tcpport' argument. This pattern is indicative of attempts to exploit CVE-2026-24294 to bypass NTLM authentication protections through local reflection or relay attacks.
Detects the execution of known Impacket relay tools such as ntlmrelayx and smbrelayx, which are commonly used by adversaries to perform NTLM relay attacks to gain unauthorized access or execute code on remote systems.
Detects web browsers and browser-related applications (e.g., Chrome, Edge, ChatGPT, Electron apps) spawning suspicious child processes that are commonly used for command-line execution or script interpretation. This behavior is often indicative of malicious extensions, browser exploits, or attempts to leverage browser processes for initial execution or lateral movement.
Detects the execution of known Impacket relay tools such as ntlmrelayx and smbrelayx, which are commonly used by adversaries to perform NTLM relay attacks to gain unauthorized access or execute code on remote systems.
Detects GhostBackdoor malware execution via known file hash.
