
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,957 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects attempts by a Chrome web browser process to create, modify, or rename files associated with sensitive user credentials or application data, such as AWS credentials, browser logins, or environment configuration files. This behavior is indicative of credential theft or staging of sensitive information.
This rule detects the use of 'net.exe' or 'net1.exe' to configure a non-standard SMB port, which is a technique often used for NTLM reflection and relay attacks. By specifying an arbitrary port for SMB traffic, an attacker may attempt to bypass standard network filtering or establish a listener to intercept authentication requests.
Detects execution of Python interpreters used as an SMB server, specifically where the implementation is not using the standard SMB port (445). This behavior is often associated with the use of tools like Impacket's smbserver.py for lateral movement, staging, or data exfiltration, attempting to blend in by using non-standard ports.
Detects Microsoft Excel application crashes (Event ID 1000) characterized by an access violation exception code (c0000005). This pattern can indicate an attempt to exploit vulnerabilities in office applications or memory corruption issues, potentially signaling a malicious document exploitation attempt.
Detects SMTP traffic containing XLSX file attachments, specifically looking for base64 encoded content that matches the criteria for CVE-2025-60727. This rule monitors network traffic for the delivery of potential malicious Office documents.
This rule detects potential privilege escalation activity associated with the abuse of CTFMON related objects (named pipes, symlinks, junctions) which may be used in conjunction with high-privilege operations (like SeDebugPrivilege or SeImpersonatePrivilege) to elevate access to SYSTEM. It correlates access events for CTF objects by processes (other than the legitimate ctfmon.exe) with subsequent sensitive privilege assignments within a short time window.
Detects anomalous activity where a single user or service principal downloads more than 5 Microsoft Teams meeting recordings within a 1-hour window. This behavior potentially indicates an insider threat or compromised account performing bulk harvesting of sensitive meeting content.
This rule detects outbound HTTP traffic generated by the WinHTTP library, specifically when the User-Agent identifies as WinHttp.WinHttpRequest. This pattern is indicative of potential post-exploitation activity, such as command-and-control communication or data exfiltration, originating from a process associated with an exploited Excel document (CVE-2025-60727).
Detects SMTP traffic containing XLSX file attachments, specifically looking for base64 encoded content that matches the criteria for CVE-2025-60727. This rule monitors network traffic for the delivery of potential malicious Office documents.
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
