
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects high-volume file writes or the use of common command-line copy utilities (xcopy, robocopy, copy) targeting removable drive paths (E-G:). This behavior is often indicative of data staging or exfiltration activities.
Detects the execution and network activity of known reverse tunneling and proxy tools such as Chisel, Ngrok, and FRP. These tools are commonly abused by adversaries to establish persistence, bypass firewalls, and facilitate command and control (C2) communication. The rule monitors for specific process names, command-line arguments, and DNS requests related to these services.
Detects processes attempting to connect to the Cloud Instance Metadata Service (IMDS) IP address (169.254.169.254) or referencing it in the command line. This behavior is often associated with credential theft or reconnaissance on cloud instances.
Detects behaviors associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, including the dropping of .sys driver files into non-canonical directories, the registration and execution of kernel services via sc.exe, the use of fltMC to load filter drivers, and the loading of driver modules from non-standard locations.
Detects common productivity applications (e.g., Word, Excel, Acrobat Reader) spawning typical command-line interpreters or scripting hosts. This behavior is a frequent indicator of malicious macro execution or exploit-based payload delivery often seen in phishing campaigns.
Detects attempts to access or exfiltrate the Windows Security Account Manager (SAM) or SYSTEM registry hives, which are primary targets for extracting credential hashes. This rule identifies common attack vectors including native Windows registry utilities (reg.exe), PowerShell-based volume shadow copy techniques (Invoke-NinjaCopy), and known credential dumping tools like secretsdump (from the Impacket suite) executed via command line or interpreted through Python.
Detects the abuse of the legitimate Windows binary regsvr32.exe for malicious purposes. This rule monitors for two common attack patterns: 1) The use of regsvr32.exe with specific command-line arguments (/i, /s, /u, /n) to load remote scripts (SCT files) or libraries from the internet, a technique known as 'Squiblydoo'. 2) Suspicious child processes spawned by regsvr32.exe, which often indicates follow-on malicious activity such as command shell execution or lateral movement tools.
Detects potential DCOM-based lateral movement by monitoring for suspicious process spawns from COM surrogates (dllhost.exe), WMI provider hosts (wmiprvse.exe), or remote invocation of office/management applications (mmc.exe, excel.exe, outlook.exe) that subsequently execute command shells or scripting interpreters.
This rule detects potential misuse of the legitimate Windows utility 'InstallUtil.exe' for proxy execution. It flags instances where InstallUtil is executed with suspicious command-line parameters often used for bypass techniques (e.g., logging flags or loading code from user-writable directories like Temp, AppData, or Downloads), or when InstallUtil acts as a parent process to suspicious child processes typically associated with post-exploitation activities.
Detects unauthorized modifications to SSH 'authorized_keys' files or the '/etc/ssh/sshd_config' configuration file on Linux systems. These actions can be used for persistent access (key injection) or to weaken SSH security controls (e.g., enabling root login) and are typical indicators of account manipulation or compromise.
