
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,970 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects when a user account is deleted on a Windows system. This event (EventID 4726) is critical for monitoring potential malicious activity, such as an attacker attempting to remove traces of their presence or disrupt operations by deleting legitimate user accounts.
This rule detects multiple executions of 'netsh firewall' commands within a one-hour window on a single computer. This activity can indicate an adversary attempting to modify or disable system firewalls to bypass security controls, enable C2 communications, or facilitate lateral movement.
This rule detects the creation of scheduled tasks (Event ID 4697) where the command line contains either 'System' or 'Admin'. This could indicate an attempt to create a scheduled task that runs with elevated privileges or impersonates system/admin accounts for persistence or privilege escalation.
Detects process creations (EventID 4688) where the command line contains keywords indicative of loading or installing kernel modules or drivers. This activity can be associated with privilege escalation or persistence techniques used by adversaries.
This rule detects an unusually high volume of SharePoint sharing invitation creations or sharing setting modifications by a single user within an hour. This could indicate an attacker attempting to exfiltrate data or broadly share sensitive information.
This rule detects an unusually high volume of file sharing events from a single user in OneDrive within a one-hour window. Specifically, it looks for five or more 'SharingSet' or 'AnonymousLinkCreated' operations by the same UserId within an hour, which could indicate data exfiltration or unauthorized sharing.
Detects Terminal commands downloading remote content via curl and immediately piping it into bash or zsh, a common ClickFix execution pattern.
Detects creation or modification of LaunchAgent plist files used for persistence.
Detects use of screencapture -x, which suppresses the camera shutter sound and has been observed in ClickFix-delivered malware.
This rule detects potential persistence mechanisms associated with Microsoft Outlook, specifically targeting registry modifications related to Outlook security settings or suspicious child processes (cmd.exe or powershell.exe) spawned by outlook.exe.
