
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects when a user grants an OAuth application consent to access high-privilege scopes in an Azure environment. It specifically flags instances where the consent is not for all principals and the user performing the action is not a Global Administrator, which may indicate an attacker-controlled application being granted access to sensitive data or resources.
This rule detects potentially unauthorized installation of extensions in Visual Studio Code (VSIX) or plugins in JetBrains IDEs (IntelliJ, PyCharm, WebStorm). It flags installations that do not originate from verified official marketplaces, which may indicate the manual installation of malicious or supply-chain compromised development environment extensions.
This rule monitors the creation of new Azure Function Apps and identifies those that receive external, non-private network requests within 48 hours of their creation. This pattern may indicate the deployment of malicious or unauthorized serverless infrastructure for command-and-control, proxying, or automated tasks.
This rule detects two common persistence techniques: the modification of Windows Registry Run keys with paths referencing temporary or application data directories, and the creation of autorun.inf files on removable or non-system drives to facilitate potential code execution upon media insertion.
This rule detects potentially malicious activity where a web browser (e.g., Chrome, Edge, Firefox) spawns suspicious child processes (e.g., mshta.exe, wscript.exe) with command-line arguments that include indicators of script execution, remote code download, or command invocation, which is a common pattern in drive-by download attacks and malicious link execution.
This rule detects network connections from devices to a specific IP address (62.102.148.212) and a set of associated ports (37393, 45839, 38471, 12345, 4444, 5555). This IP address and these ports are known indicators of compromise for the Remcos Remote Access Trojan (RAT) Command and Control (C2) infrastructure. Detection of such connections indicates potential Remcos RAT activity within the environment.
Detects the execution of remote commands on cloud virtual machines (Azure RunCommand or AWS SSM SendCommand) during defined off-hours (18:00 to 06:00). This rule identifies potentially unauthorized administrative or management activity occurring outside of standard business hours across cloud environments.
Detects potential execution chains related to QR code phishing (Quishing) by monitoring for suspicious process creation or outbound network connections originating from document readers, office applications, and QR scanner utilities. It covers three primary vectors: suspicious process spawning (e.g., Office apps launching cmd or powershell), non-standard network connections from document readers, and malicious URL-based LNK files spawned via explorer.exe.
This rule detects potentially malicious behavior associated with web browser processes, including the execution of Python scripts, the loading of browser extensions from non-standard directories like AppData or Temp, the creation of Python scripts by browsers in temp folders, and outbound network connections by Python processes following browser activity. These patterns are often associated with browser-based exploitation, extension-based malware, or initial access stages where a browser is used as a conduit for malicious code execution.
Detects instances where common web browsers (Chrome, Edge, Firefox, Brave) spawn command-line tools or script interpreters (cmd, PowerShell, wscript, mshta) as child processes. This behavior is highly indicative of drive-by download attacks, including the 'ClickFix' technique, where users are socially engineered into executing malicious commands under the guise of fake browser updates or error resolution.
