
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,963 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects potential credential harvesting attempts by monitoring for the usage of Windows credential management tools (cmdkey.exe and vaultcmd.exe) and the loading of sensitive DLLs (vaultcli.dll, dpapi.dll) by non-Microsoft signed processes, which is commonly used to access stored credentials in the Windows Vault or by DPAPI-protected stores.
Detects instances of PowerShell or PowerShell Core (pwsh) launched with encoded command line arguments (-encodedcommand, -enc, -ec). This is a common technique used by attackers to obfuscate malicious scripts and payloads by passing them as Base64 encoded strings to avoid simple static analysis.
Detects the execution of mavinject.exe with the /INJECTRUNNING command-line argument. This utility is a signed Microsoft binary that can be abused by adversaries to inject arbitrary DLLs into the address space of running processes, a technique often used to evade detection or achieve code execution.
Detects the use of nslookup.exe to query DNS TXT records from non-Microsoft signed processes. This behavior is often associated with DNS-based Command and Control (C2) channels or data exfiltration techniques where small amounts of data are encoded within DNS TXT records.
Detects Microsoft Office applications (Word, Excel, PowerPoint, OneNote) launching command-line interpreters (cmd.exe, powershell.exe, wscript.exe, cscript.exe). This pattern is often associated with macro-based malicious code execution.
This rule monitors for two types of anomalous network behavior: first, it identifies connections to known domains from IP addresses not previously associated with those domains over a seven-day lookback period. Second, it identifies HTTP proxy responses (from Zscaler or Squid) where the content-length significantly deviates from the historical baseline for specific URLs. These patterns are potential indicators of C2 channel shifts or data exfiltration via web protocols.
Detects the creation or modification of Power Automate Flows that utilize non-Microsoft domains for HTTP or webhook connectors. Adversaries may abuse Power Automate to automate exfiltration or command-and-control tasks by connecting workflows to external malicious endpoints.
Detects the successful deletion of diagnostic settings in Azure, which may be an attempt by an adversary to impair logging and hide malicious activity.
Detects the creation or update of Azure Network Security Group (NSG) rules that allow inbound traffic from the entire internet (0.0.0.0/0 or *) to management ports (RDP 3389 or SSH 22). This behavior often indicates an attempt to expose administrative services to the public internet.
Detects when a user or service principal is assigned the 'Owner' or 'Contributor' role at the Subscription scope in Azure. This activity is often associated with privilege escalation and persistent access techniques.
