
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potentially malicious DNS traffic where queries contain exceptionally long, encoded, or randomized subdomains. Attackers often use these patterns to exfiltrate data from a target network, bypassing traditional security controls by encapsulating information within DNS requests (DNS tunneling). The detection looks for DNS queries exceeding 100 bytes in length with specific character patterns indicative of Base64 or similar encoding.
Detects suspicious WinRM SOAPAction headers indicating potential lateral movement or remote command execution (e.g., shell command, process creation, or WMI operations) over WinRM HTTP ports 5985 and 5986.
This rule detects potential Cobalt Strike Beacon check-in activity over HTTP. It identifies incoming GET requests where the URI is abnormally short and the HTTP Referer header is missing, which are common indicators of default Cobalt Strike malleable C2 profiles.
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
This rule detects potential ransomware lateral movement patterns by correlating specific network connection attempts (SMB/RDP/RPC) with the observed creation of files having the '.prinzeugen' extension on the same host within a 2-hour window. This behavior is indicative of a ransomware strain propagating across the network and performing encryption.
Detects suspicious usage of the Bun runtime, specifically when it is spawned by common Node.js development processes (like npm or node-gyp) or downloaded from non-official sources using command-line tools or browsers. This behavior is associated with the Miasma malware campaign, which abuses the Bun runtime for malicious operations.
This rule detects suspicious activity related to GitHub Actions workflows, including the creation or modification of workflow configuration files, the placement of suspicious JavaScript files in the repository's .github directory, the execution of the 'Bun' runtime within an Actions runner environment, and cloud-based events indicating workflow modification containing 'Run Copilot' strings. These patterns are often associated with CI/CD pipeline compromise, malicious automation, or unauthorized code execution within build environments.
This rule detects file creation or modification events associated with the Miasma campaign. It identifies specific payload files (e.g., .claude/setup.mjs, .vscode/tasks.json), the use of specific marker strings in file metadata or origin URLs, and obfuscated task configurations in VS Code directories that leverage bun or node to execute base64-encoded or character-encoded commands.
This rule detects attempts to modify Windows Defender exclusions using PowerShell cmdlets (Add-MpPreference, Set-MpPreference) or direct Registry manipulation. Adversaries often modify these exclusions to hide malicious files or directories from antivirus scanning, a technique used to impair defensive security tools.
