
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,963 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of manage-bde.exe with command-line arguments designed to enable encryption, disable/delete BitLocker protectors, or modify authentication keys. This pattern is indicative of ransomware abuse, specifically actors attempting to encrypt drives and destroy recovery capabilities, particularly when spawned from scripting or shell environments like PowerShell, CMD, or WMI.
Detects processes attempting to connect to the Cloud Instance Metadata Service (IMDS) IP address (169.254.169.254) or referencing it in the command line. This behavior is often associated with credential theft or reconnaissance on cloud instances.
Detects potential lateral movement activity where PowerShell or the Windows Remote Management (WinRM) host process (wsmprovhost.exe) initiates network connections to multiple distinct destination IP addresses over the WinRM default ports (5985/5986). This behavior is characteristic of an adversary using legitimate remote administration tools to pivot or spread across a network.
This rule detects attempts to acquire Windows credentials by accessing critical registry hives (SAM, SYSTEM, SECURITY) or their shadow copies. It looks for the use of 'reg save' to export hives, as well as direct file access to these hives or their shadow copy variations by non-standard system processes.
This rule detects suspicious activity related to GitHub Actions workflows, including the creation or modification of workflow configuration files, the placement of suspicious JavaScript files in the repository's .github directory, the execution of the 'Bun' runtime within an Actions runner environment, and cloud-based events indicating workflow modification containing 'Run Copilot' strings. These patterns are often associated with CI/CD pipeline compromise, malicious automation, or unauthorized code execution within build environments.
Detects instances where a guest user or an external account (identified by the #EXT# suffix) performs an operation to add a new member to a Microsoft 365 Group. This behavior can be indicative of a guest account being compromised or misused to escalate privileges or gain unauthorized access by modifying group memberships.
Detects users who modify their MFA settings (registration/update/delete) and subsequently perform privileged actions (such as adding role members or service principal credentials) within a short timeframe, while simultaneously observed active in communication applications like Teams, Zoom, or Webex. This behavior is indicative of potential account takeover where an adversary modifies authentication methods to gain persistent access, followed by privilege escalation.
Detects anomalous network activity originating from 'NearShareReceive.exe' (Windows Near Share) to public IP addresses on non-standard ports, potentially indicating unauthorized use of the Near Share feature for data staging or exfiltration.
Detects the execution of Python interpreters spawned by code editors or runtime environments (e.g., VS Code, Cursor, Node.js) with specific command-line arguments involving 'init'. This behavior may indicate an adversary attempting to leverage development tools to execute custom scripts, potentially for automated deployment, persistence, or malicious payload initialization.
This rule detects the execution of python.exe or python3.exe using the '-m init' command line flag while attempting to establish a network connection over specific, often non-standard, ports (4444, 1337, 9001, 9002, 5555, 6666, 7777, 8888). This pattern is commonly associated with reverse shells or C2 agent check-ins initiated via Python scripts.
