
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,963 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects when a single computer executes 5 or more process termination commands (taskkill or Stop-Process) within a one-hour window. This behavior can be indicative of an adversary attempting to disrupt system operations or evade defenses by stopping security tools or critical services.
This rule detects a high volume of remote desktop session changes (logon/logoff) for a single user within a one-hour window. Event IDs 4778 and 4779 indicate a session reconnected or disconnected, respectively. A high count (>=10) could suggest suspicious activity such as session hijacking, rapid reconnections by an attacker, or automated tools interacting with remote sessions.
This rule detects successful network connections to known paste sites like Pastebin or Gist. Adversaries often use these services to host malicious code, exfiltrate data, or for command and control (C2) communications. Monitoring such connections can help identify potential data exfiltration attempts or the download of malicious content.
This rule detects potential information disclosure attempts by monitoring W3C IIS logs for repeated queries containing keywords like 'version', 'build', or 'debug'. A high frequency (5 or more attempts within an hour) from a single IP address suggests an adversary is trying to enumerate software versions or debug information, which can be used for further reconnaissance or exploit development.
Detects multiple attempts at command injection through IIS web server URI queries. The rule looks for common command execution functions like 'eval(', 'system(', or 'exec(' within the 'csUriQuery' field of W3C IIS logs. A threshold of 3 or more attempts from the same IP within an hour triggers the alert.
This rule detects multiple attempts (10 or more within an hour) from a single IP address to access administrative interfaces on a web server. It specifically looks for URI queries containing keywords like 'admin', 'wp-admin', or 'administrator' in W3CIISLog data. Such activity often indicates a brute-force attack or scanning for administrative login pages.
Detects repeated 'git clone' or 'git fetch' commands executed on a system within a short timeframe. This activity could indicate an adversary attempting to exfiltrate data from a code repository or staging environment, or rapidly pull down multiple repositories.
Detects when a single user account performs 5 or more account creations (EventID 4720) or account enables (EventID 4722) within a one-hour period. This activity could indicate malicious behavior, such as an attacker establishing persistence or expanding access, or it could be a sign of automated account provisioning.
This rule identifies when a single account creates three or more files containing 'backup', 'export', or 'dump' in their filenames within a one-hour period. This activity could be indicative of data staging for exfiltration or an attempt to back up sensitive information prior to a malicious action.
This rule detects repeated successful operations related to public access or firewall configuration changes within Azure Activity Logs. A high count (3 or more) of such operations by the same caller within an hour could indicate malicious activity, such as an attacker attempting to open up network access to compromised resources or exfiltrate data.
