
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,972 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects HTTP traffic patterns consistent with data exfiltration to major cloud storage providers (AWS S3, Azure Blob Storage, Google Cloud Storage) using common command-line interface tools like rclone, aws-cli, and AzCopy.
This rule detects potential misuse of the legitimate Windows utility InstallUtil.exe (a .NET component installer) to proxy the execution of malicious code. It identifies two specific suspicious patterns: first, the execution of InstallUtil with command-line arguments indicative of bypass attempts (e.g., /logfile, /LogToConsole, or /U) or loading files from user-writable directories (Temp, AppData, Downloads, ProgramData); second, instances where InstallUtil spawns potentially malicious child processes such as PowerShell, cmd, or various system binaries often used for persistence or lateral movement.
This rule detects potentially malicious activity involving the Windows binaries Regasm.exe and Regsvcs.exe, which can be abused to proxy the execution of arbitrary code. It specifically identifies three suspicious behaviors: spawning of common command shells or script engines by these binaries, execution of these binaries when located in or loading assemblies from user-writable directories (e.g., Temp, AppData, Downloads), and module loading of DLLs from those same writable locations, especially when the binary is not Microsoft-signed.
Detects potential lateral movement activity involving Windows Remote Management (WinRM). The rule monitors for common WinRM-related tools (winrs.exe), PowerShell WinRM cmdlets (e.g., Invoke-Command) targeting non-local systems, and the spawning of suspicious processes by the WinRM host process (wsmprovhost.exe).
Detects outbound WebSocket connections from endpoints to known infrastructure associated with the Turla group's STOCKSTAY malware. The rule monitors DeviceNetworkEvents for successful connections or attempts to specific domains (glitch.me, onrender.com, theworkpc.com) or connections containing WebSocket-related headers in the metadata, which indicate C2 activity.
Detects mshta.exe spawning from archive utilities (winrar.exe, 7z.exe) or Windows Explorer, or executing HTA files directly from common user-writable temporary or download directories. This pattern is commonly associated with the execution of malicious payloads delivered via compressed archives, a technique observed in campaigns attributed to the Turla threat group.
This rule monitors for potentially malicious use of the Windows Certutil utility, specifically targeting the -urlcache (often used to download remote files) and -decode (used to decode hidden or obfuscated payloads) command-line arguments. It filters out common trusted processes like Microsoft's msiexec.exe to reduce noise.
Detects potential DCOM-based lateral movement by monitoring for suspicious process spawns from COM surrogates (dllhost.exe), WMI provider hosts (wmiprvse.exe), or remote invocation of office/management applications (mmc.exe, excel.exe, outlook.exe) that subsequently execute command shells or scripting interpreters.
Detects evidence of file timestomping, a technique used by attackers to modify file system timestamps (Create, Access, Modify, Change) to evade forensic detection or masquerade malicious files. The rule monitors for explicit usage of timestomping tools (e.g., Invoke-TimeStomp), abuse of system utilities like fsutil.exe for timestamp modification by suspicious parent processes, and unauthorized or unsigned processes performing timestamp modification on sensitive file types.
Detects the use of common archive utilities (7-Zip, WinRAR) to perform file archiving operations within sensitive user-profile directories (Desktop, Documents, Downloads, etc.). This pattern is often used by adversaries to stage or bundle sensitive data prior to exfiltration.
