
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,978 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
This rule monitors network logs (from proxies and firewalls) for web traffic (HTTP GET requests) containing suspicious JavaScript code injection patterns in the request context or message fields. It specifically looks for common XSS indicators such as <script tags, eval(), document.write(), fromCharCode(), and atob().
This rule detects process execution where the command line arguments contain keywords commonly associated with memory corruption and exploitation (e.g., shellcode, buffer overflow, heap/stack manipulation). The rule further filters for small executable files (less than 100KB) to increase the likelihood of identifying malicious tools or stagers.
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
Detects network traffic associated with known Cobalt Strike Beacon request URI patterns. This rule utilizes network signature inspection to flag outbound connections containing URI fragments commonly used by Cobalt Strike default profiles.
Detects the execution of Mimikatz or its common command-line arguments used for credential dumping. This rule identifies attempts to extract sensitive authentication material such as passwords, hashes, and tickets from memory (LSASS), SAM database, LSA secrets, and cached domain credentials.
Detects the creation or execution of files named 'RuntimeBroker.exe', 'Telemetry.exe', or 'WindowsRunetimeBroker.exe' within the AppData folders. These filenames are commonly abused by adversaries to masquerade as legitimate system processes to evade detection.
This rule detects anomalous network connections or DNS queries to known Ethereum RPC infrastructure providers (Infura, Alchemy, Cloudflare-eth) or ports/domains associated with Ethereum mainnet activity. It specifically targets processes other than common browsers or known blockchain clients, as well as Java-based processes performing DNS lookups for these domains. This behavior is indicative of potential 'EtherHiding' techniques where malicious code or data is hidden within blockchain transactions or distributed via blockchain infrastructure.
Detects the creation or execution of files named 'RuntimeBroker.exe', 'Telemetry.exe', or 'WindowsRunetimeBroker.exe' within the AppData folders. These filenames are commonly abused by adversaries to masquerade as legitimate system processes to evade detection.
Detects suspicious usage of the Bun runtime, specifically when it is spawned by common Node.js development processes (like npm or node-gyp) or downloaded from non-official sources using command-line tools or browsers. This behavior is associated with the Miasma malware campaign, which abuses the Bun runtime for malicious operations.
