
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,953 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects URLs that contain common redirection or link parameters (u=, url=, redirect=, r=, link=, target=, dest=) where the value of the parameter is a long, alphanumeric string that appears to be an encoded domain. This pattern can indicate attempts to obfuscate the true destination of a link, often seen in phishing campaigns or malicious redirection attempts. The rule specifically looks for encoded parameters containing common top-level domains like .com, .net, or .org.
Detects the use of the rclone tool with data transfer commands (copy, move, sync, copyto, moveto) originating from a GoAnywhere server process or common interactive shell processes (cmd.exe, powershell.exe). This activity is highly suspicious and could indicate data exfiltration.
Detects when a web browser (Chrome, Edge, Firefox, Brave, Opera) initiates a process that is not another instance of itself. This could indicate a drive-by download, execution of malicious code, or other suspicious activity originating from a browser.
Detects the use of npm to install known malicious npm packages, which is indicative of a supply chain compromise attempt via typosquatting or malicious dependency injection.
Detects the addition of users to specific high-value or sensitive groups in Microsoft Entra ID (Azure AD), which could indicate potential unauthorized privilege escalation or persistence attempts by an attacker.
Detects instances where a process running under the NT AUTHORITY\SYSTEM user context spawns a common execution utility (like cmd, powershell, or wscript) on a host that has recently engaged in network communication over port 445 (SMB). This behavior is highly indicative of lateral movement using SMB, such as service-based execution or remote command execution via tools like PsExec or WMI.
Detects network connection attempts directed toward RFC 1918 private IP address spaces (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost (127.0.0.0/8) that do not involve common Windows file sharing ports (TCP/445 and TCP/139). This behavior may indicate lateral movement, internal reconnaissance, or the use of non-standard protocols for internal communication.
Detects unexpected network connections initiated by the Local Security Authority Subsystem Service (lsass.exe) to the localhost (127.0.0.1) on ports other than standard SMB ports (445 or 139). LSASS should typically only communicate locally via RPC or LPC for authentication services, and anomalous network activity from this process may indicate credential theft attempts, process injection, or unauthorized memory access activities.
Detects the execution of net.exe or net1.exe with the 'tcpport' argument, which is typically used for querying network port connectivity or information on a host.
Detects instances where a process running under the NT AUTHORITY\SYSTEM user context spawns a common execution utility (like cmd, powershell, or wscript) on a host that has recently engaged in network communication over port 445 (SMB). This behavior is highly indicative of lateral movement using SMB, such as service-based execution or remote command execution via tools like PsExec or WMI.
