
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,978 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where package managers like npm, pip, or python execute shells or scripting interpreters with command-line arguments indicative of software installation or build processes. This pattern is common in supply chain attacks where malicious packages run code during their installation phase.
This rule detects potential internal network reconnaissance activities by monitoring for either mass execution of network discovery commands (such as 'net view' or 'net share') targeting multiple unique hosts within a 5-minute window, or by monitoring for mass outbound network connections to port 445 (SMB) across multiple unique destination hosts within the same timeframe. This behavior is indicative of an attacker attempting to map available network shares or identify reachable systems for lateral movement.
Detects the creation or manipulation of WMI event subscriptions using wmic.exe, powershell.exe, or mofcomp.exe. These tools are commonly abused by adversaries to establish persistence by triggering malicious code execution via WMI event filters, consumers, and bindings.
Detects high-frequency non-standard process executions involving WMI queries that specifically target virtual environment artifacts (e.g., VMware, VirtualBox, VBoxService, QEMU). This behavior is characteristic of sandbox or virtualization evasion, where malware attempts to identify if it is running in a virtualized or analysis environment to potentially alter its behavior.
Detects high frequency administrative modifications, such as user creation/deletion, password resets, or group membership changes, performed by service accounts associated with Azure AD Connect or Microsoft Entra Connect. This behavior may indicate account compromise where a service principal is being abused to perform bulk identity management operations.
Detects rapid succession of power-off, suspend, or destroy operations on virtual machines via esxcli or vim-cmd following an SSH login, a behavior pattern often associated with ESXi ransomware activity (e.g., Qilin).
Detects execution of the Microsoft InstallUtil.exe utility with suspicious command-line arguments (logging suppressed to file and console) where the binary is unsigned. This is a common technique used by adversaries to proxy execution of arbitrary .NET code while attempting to avoid detection and maintain stealth.
Detects the execution of known Active Directory discovery tools, specifically 'adfind.exe' or 'dsquery.exe' with arguments targeting user or group enumeration. These tools are commonly used by adversaries during the reconnaissance phase to map domain structure.
Open-source derived remote access trojan with plugin architecture
macOS malware used by JINX-0164 against cryptocurrency developers
