
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,004 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from common public file sharing and code repository sites, which is a known technique for adversaries to stage or download malicious payloads.
This rule detects successful authentication attempts directed at network devices from sources not explicitly marked as authorized management systems. It identifies users or systems that are not recognized service accounts authenticating against network infrastructure and flags activity that involves multiple unique destination targets as high risk.
This rule detects the creation or modification of inbox rules in Office 365 that involve email forwarding or redirection to external domains. It calculates a risk score based on whether the action occurred outside of typical business hours (08:00-18:00 local time/weekends) and whether the user is performing this action from a previously unseen IP address, which may indicate a compromised account attempting to exfiltrate or redirect emails.
This rule detects potential lateral movement by identifying users who, within a short timeframe (90 seconds) of their first recorded network logon (EventID 4624, Logon Type 3), perform suspicious follow-up activities such as explicit credentials usage (4648), network share access (5140), or remote service installation (7045).
Detects potential execution of a Tox ransomware negotiation channel by monitoring for processes that exhibit a high rate of file writes (potential encryption activity) in conjunction with command-line arguments containing specific patterns such as a 76-character string or the 'tox://' URI scheme, which are associated with Tox ransomware client activity.
Detects the use of legitimate Windows binaries (Certutil and BITSAdmin) to communicate with external, non-Microsoft IP addresses, which is indicative of potential tool downloading or data exfiltration. The rule explicitly filters out known Microsoft update domains to reduce noise.
Detects the execution of known archive utilities (e.g., 7-Zip, WinRAR) when interacting with sensitive user or system directories. This behavior is often indicative of data staging prior to potential exfiltration, especially when the originating process is not a recognized installer or backup application.
This rule detects potentially unauthorized or suspicious Remote Desktop Protocol (RDP) activity by monitoring for instances of 'mstsc.exe' initiated with specific command-line arguments, or identifying child processes spawned by RDP-related binaries ('mstsc.exe', 'rdpclip.exe') that are not typically associated with standard RDP functionality.
Detects network connections to Filen.io cloud storage initiated by processes other than common web browsers. This behavior is often associated with the use of command-line tools or scripts for unauthorized file exfiltration or data staging.
Detects high volumes of file operations (creation, rename, or modification) where files are given extensions typically associated with ransomware (e.g., .locked, .encrypted). The rule aggregates activity by process and endpoint and triggers an alert when the number of such operations exceeds a defined threshold, while excluding known legitimate backup and security software.
