
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Open-source derived remote access trojan with plugin architecture
macOS malware used by JINX-0164 against cryptocurrency developers
Clipboard hijacking malware for cryptocurrency address substitution
Open-source derived remote access trojan with plugin architecture
This rule detects potential lateral movement by identifying users who, within a short timeframe (90 seconds) of their first recorded network logon (EventID 4624, Logon Type 3), perform suspicious follow-up activities such as explicit credentials usage (4648), network share access (5140), or remote service installation (7045).
This rule detects the execution of common archival utilities (7-Zip, WinRAR, RAR, ZIP) with parameters indicative of password-protected archive creation. It specifically flags instances where a user account, with no recorded prior history of running these utilities in the last 30 days, creates a large archive (exceeding 1GB) spanning multiple directories. This pattern is commonly used for data staging and preparation prior to exfiltration.
This rule detects scenarios where common administrative or attack tools (e.g., whoami, net, ipconfig, psexec) are used within the same 5-minute window as network communication to known Large Language Model (LLM) service providers. This pattern may indicate an attacker using LLMs to assist with post-exploitation discovery, script generation, or data analysis based on local system reconnaissance.
This rule monitors Sysmon Event ID 11 (FileCreate) to detect high-volume file creation activity across multiple unique directories. By filtering out common file types, it identifies potential signs of mass file modification, staging for exfiltration, or malicious encryption characteristic of ransomware or data destructive operations.
This rule detects scenarios where a common web browser (Chrome, Firefox, Edge, IE, Opera, or Brave) connects to an external destination not on a known allow-list, followed shortly (within 30 seconds) by the execution of a script-based binary (wscript.exe or mshta.exe) on the same host. This is a common pattern for initial access where a user downloads a malicious script from an unknown source via a browser and subsequently executes it.
Detects instances where the Node.js runtime (node.exe) spawns a command shell or scripting interpreter (cmd.exe, powershell.exe, or wscript.exe). The detection specifically looks for these processes being initiated from directories commonly associated with Node.js package management (npm) or local module installations, which may indicate malicious activity such as software supply chain attacks or execution of obfuscated scripts.
