
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where msbuild.exe is used to execute project files (.proj) from suspicious or uncommon directories. Adversaries may abuse MSBuild to proxy execution of malicious code, often placing these project files in temporary or public user directories to evade detection.
Detects the execution of SyncAppvPublishingServer.vbs via wscript.exe or cscript.exe. This legitimate Windows script can be abused by adversaries to proxy execution of malicious PowerShell commands, bypassing execution restrictions and evading defensive measures.
This rule detects the presence of known malicious drivers (hlpdrv.sys, rwdrv.sys) by their SHA256 hash or file path. It also identifies attempts to install these drivers via service creation commands and monitors for modifications to Windows Defender registry keys that could disable its functionality, indicating defense evasion.
This rule detects potential persistence mechanisms related to browser extensions. It looks for processes launching Chrome or Edge with the '--load-extension' command-line argument, which can be used to load unpacked extensions. Additionally, it monitors registry modifications to 'ExtensionInstallForcelist' that contain 'http' or 'crx', indicating a forced installation of an extension, potentially from a remote source or a local file.
This rule detects potential discovery activities indicative of a virtual machine or virtualization environment enumeration. It monitors for the execution of wmic.exe or powershell.exe triggered by suspicious parent processes (python.exe, chost.exe) that query hardware-specific identifiers like Manufacturer, Model, or MAC Address using Win32_ComputerSystem or Win32_NetworkAdapterConfiguration.
Detects the creation or modification of specific suspicious .pyd files (Python extension modules) within temporary directory paths, excluding legitimate processes or publishers associated with Python Software Foundation or Microsoft Corporation. This behavior is indicative of potential side-loading or persistence mechanisms involving malicious Python extensions.
Detects instances where a guest user or an external account (identified by the #EXT# suffix) performs an operation to add a new member to a Microsoft 365 Group. This behavior can be indicative of a guest account being compromised or misused to escalate privileges or gain unauthorized access by modifying group memberships.
Detects the creation of .ics calendar invitation files in common user download and temporary directories when originated by web browsers or Microsoft Outlook. This pattern is often indicative of spearphishing campaigns where attackers use weaponized calendar files to deliver malicious payloads or links, attempting to exploit users through social engineering.
Detects instances where a user successfully authenticates from geographically distant locations within a short timeframe (impossible travel) followed by sensitive privileged operations within a 4-hour window.
Detects the transmission of potential sensitive information, such as passwords, tokens, API keys, or private keys, within Microsoft Teams chat messages by matching message content against a regular expression pattern for common credential formats.
