
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects two suspicious behaviors associated with the TinyRCT malware family: the execution of common installer or archiver utilities in the Downloads folder that terminate within two seconds, and the use of 'choice.exe' for self-deletion of an executing process within a short timeframe.
This rule monitors DeviceNetworkEvents for connections to domains that match naming patterns and TLDs frequently associated with the Ghostwriter/UNC1151 threat group. The rule specifically looks for URLs containing common credential-harvesting keywords (e.g., login, verify, account) combined with specific TLDs (e.g., .digital, .icu, .cc.cd). Connections to known common public DNS providers are excluded.
Detects DNS queries and network connection attempts to a set of known malicious domains associated with the threat actor UNC1151 (Ghostwriter). This rule monitors both DNS resolutions and direct network connection attempts to these indicators of compromise (IOCs), which are commonly used in spearphishing campaigns.
Detects indicators of the KuinaExtractor infostealer, including specific named pipes/objects, the creation of a 'zenith_debug.txt' file in user profile directories, and the presence of build-related aliases ('kuina1999', 'k0to') in process command lines or file paths.
Detects browser-based network connections to URLs containing Google or Gmail branding where the resolved IP address does not match the expected Google IP address prefixes. This behavior is indicative of an Adversary-in-the-Middle (AiTM) phishing attack, where a user is being redirected to a malicious proxy server that mimics the legitimate Google login service to intercept credentials and MFA tokens.
This rule monitors DeviceNetworkEvents for connections to domains that match naming patterns and TLDs frequently associated with the Ghostwriter/UNC1151 threat group. The rule specifically looks for URLs containing common credential-harvesting keywords (e.g., login, verify, account) combined with specific TLDs (e.g., .digital, .icu, .cc.cd). Connections to known common public DNS providers are excluded.
Detects outbound network connections to common Mythic C2 ports initiated by processes identified as compiler-related binaries (Go, Zig, Rust) or binaries running from suspicious, user-writable directories (Temp, AppData, etc.). This behavior is consistent with the execution of staging or initial implants associated with the Mythic post-exploitation framework.
Detects the KuinaExtractor UAC bypass technique, which exploits the auto-elevated 'SilentCleanup' scheduled task. The rule identifies suspicious activity via two patterns: the execution of 'cleanmgr.exe' from an unexpected parent process (bypassing normal task scheduler invocation) or the explicit execution of 'schtasks.exe' to trigger the 'SilentCleanup' task.
Detects attempts to disable or impair Microsoft Defender Antivirus using legitimate system administration tools such as PowerShell (Set-MpPreference, Add-MpPreference), WMIC, sc.exe, or net.exe. Adversaries may use these tools to bypass security controls by disabling real-time monitoring or adding unauthorized exclusion paths.
Detects the execution of RDP files (mstsc.exe) initiated by common application vectors (email clients, browsers, archive utilities) from suspicious user-writable paths like Temp, Downloads, or AppData directories. This behavior is consistent with Turla group's phishing delivery chain where malicious RDP files are used for persistence or lateral movement.
