
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,964 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where the legitimate Windows utility 'Fondue.exe' (Features on Demand) loads the control panel library 'APPWIZ.cpl' from non-standard locations such as C:\Users\Public or AppData directories. It also identifies the staging phase where 'APPWIZ.cpl' is written to 'C:\Users\Public', which is indicative of a DLL side-loading attack sequence, often associated with the Elephant malware dropper.
Detects suspected malicious activity associated with the Dropping Elephant threat group. The rule monitors for two behaviors: 1) IP address geolocation fingerprinting by identifying non-browser processes communicating with ipify.org and ip2c.org within a 60-second window, and 2) Direct network connections to known Dropping Elephant C2 domains, specifically gcl-power.org and chinagreenenergy.org.
This rule detects the creation or registration of scheduled tasks that involve the 'PerfWatson2.exe' utility or execution paths originating from within the local AppData directory. These patterns are often associated with persistence mechanisms used by malware or malicious scripts to maintain execution after reboots.
Detects high-frequency ICMP Echo Requests (Type 8) directed from internal networks to external destinations with oversized payloads (greater than 200 bytes). This pattern is indicative of ICMP tunneling, which is often used by adversaries for covert command-and-control (C2) communications or data exfiltration, bypassing standard filtering or monitoring.
Detects network traffic indicative of the EternalBlue (MS17-010) exploit attempt against SMBv1 services. The rule specifically looks for SMB packets with transaction command patterns associated with this exploit, which was commonly used by the WannaCry ransomware.
Detects the execution of VS Code Tunnel processes (code-tunnel.exe or code.exe with tunnel arguments) initiated by processes other than standard development-related parent processes (e.g., explorer, terminal, IDEs). This behavior may indicate an adversary attempting to establish persistent unauthorized remote access to a compromised host using the VS Code Tunnel functionality.
This rule detects DNS queries containing an exceptionally long subdomain label (50 or more characters). Such patterns are often indicative of DNS tunneling techniques where data is encoded within the subdomain portion of a DNS query to bypass network security controls or establish command-and-control channels.
Detects clear-text attempts to clear Windows Event Logs using 'wevtutil' or 'Clear-EventLog' command patterns within network traffic, indicating a potential attempt to remove evidence of malicious activity on a host.
Detects anomalous, high-volume data transfers to Telegram API endpoints (api.telegram.org, specific IP ranges), which is indicative of data exfiltration by malware such as KuinaExtractor. The rule monitors for cumulative outbound traffic exceeding 500MB within a 1-hour session window per process.
Detects anomalous SMB NTLM authentication traffic indicative of relay attacks, where an attacker intercepts an authentication request and relays it to another SMB service.
