
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where the legitimate Windows binary 'consent.exe' loads the library 'msimg32.dll' from a non-standard location (outside of System32 or SysWOW64). This behavior is characteristic of DLL sideloading techniques used by the BumbleBee malware loader to execute malicious code within the context of a trusted system process.
This rule detects various methods used to extract credentials protected by the Windows Data Protection API (DPAPI). It covers multiple vectors, including Mimikatz DPAPI module usage, unauthorized loading of the dpapi.dll library, suspicious access to browser or WiFi credential stores, and cross-process memory access to the LSASS process to extract DPAPI master keys.
Detects techniques associated with Golden SAML attacks, including the use of Mimikatz for ADFS token-signing certificate extraction, the execution of AADInternals PowerShell cmdlets for SAML token forgery, and unauthorized access to the ADFS configuration database (AdfsConfiguration.mdf).
This rule detects suspicious network connections originating from internal IP addresses to common service ports (DNS, SMB, RDP, WinRM) on remote, non-internal IP addresses. It flags instances where a single process on a device makes 10 or more such connections within an hour, which could indicate reconnaissance, lateral movement, or data exfiltration attempts.
This rule detects suspicious outbound DNS queries originating from a device that are not directed to common public DNS servers (Google DNS, Cloudflare DNS). The rule specifically flags queries where the remote DNS name contains keywords like 'malware', 'c2', or 'c&c', and where at least 5 such queries occur within an hour from the same device. This pattern can indicate potential malware communication or command and control (C2) activity.
This rule detects suspicious DLL injection activity by identifying multiple DLL loads from unusual folders such as 'Temp', 'AppData', or 'Windows\Temp'. Adversaries often drop malicious DLLs into these directories and then inject them into legitimate processes to achieve persistence, privilege escalation, or defense evasion. The rule counts the number of DLL loads from these suspicious locations by the same initiating process on the same device, triggering an alert if five or more such loads occur, indicating a concerted malicious effort.
This rule detects an unusual frequency of inventory-related commands being executed on a device within a one-hour window. Specifically, it looks for `tasklist.exe`, `wmic.exe`, or `Get-HotFix` being run 5 or more times in an hour. This behavior can indicate an adversary performing system information discovery.
Detects the creation of processes where the command line contains keywords such as 'cve' or 'vulnerability'. This could indicate attempts to exploit known vulnerabilities, perform vulnerability research, or execute tools related to vulnerability assessment.
This rule detects devices making a high volume of successful network connections to GitHub's API endpoints (api.github.com or api.releases). A count of 5 or more successful connections within an hour from a single device is considered suspicious and could indicate data exfiltration, automated tooling, or unusual development activity.
Detects failed attempts to change the system audit policy. This could indicate an adversary attempting to disable or modify security monitoring to evade detection.
