
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects scenarios where a common web browser (Chrome, Firefox, Edge, IE, Opera, or Brave) connects to an external destination not on a known allow-list, followed shortly (within 30 seconds) by the execution of a script-based binary (wscript.exe or mshta.exe) on the same host. This is a common pattern for initial access where a user downloads a malicious script from an unknown source via a browser and subsequently executes it.
This rule detects potentially malicious use of the ClickOnce process (dfsvc.exe) by monitoring for suspicious parent processes (such as rundll32.exe or mshta.exe) spawning dfsvc.exe, or dfsvc.exe spawning unexpected child processes. ClickOnce is often abused by attackers to proxy the execution of malicious code, and these patterns are indicative of such activity.
Detects an unusually high frequency of storage blob and container listing operations within a short time window. This behavior often indicates an attempt to enumerate the contents of Azure Blob Storage, which may be a precursor to data discovery or exfiltration.
This rule detects when the Windows Security Event Log has been cleared, which is often an indicator that an adversary is attempting to hide their tracks and remove evidence of unauthorized activities on a system.
Detects rapid creation of multiple user accounts within a one-hour window. This behavior can be indicative of malicious activity, such as an attacker creating persistence accounts or staging multiple accounts for lateral movement or automated attacks.
Detects instances where a user account is created and subsequently deleted within 24 hours. This behavior may indicate an adversary creating a temporary account for lateral movement, privilege escalation, or establishing persistence that is intended to be short-lived.
This rule detects potential brute force attacks or username enumeration by identifying 5-minute windows where multiple distinct user accounts trigger a high volume of failed logon events (Event ID 4625). It summarizes failures by timeframe and flags scenarios where more than 5 unique usernames failed to authenticate, categorizing the severity based on the number of accounts affected.
Detects high volumes of authentication failures (EventID 4625) using sub-status 0xC0000064, which indicates the attempted username does not exist. A high frequency of these events targeting multiple non-existent accounts is a strong indicator of automated username enumeration or credential stuffing.
Detects cases where a user privilege is granted (EventCode 4717) and subsequently revoked (EventCode 4718) within a 60-minute window. This behavior often indicates transient privilege abuse, where an attacker grants themselves temporary elevated rights to perform an action and then revokes them to evade detection or minimize their footprint.
This rule detects processes other than standard web browsers (Chrome, Edge, Brave) attempting to access sensitive directories within Chrome extension user data paths, such as IndexedDB, Local Storage, or Sync Data. Such activity is often indicative of credential or session cookie theft by malicious scripts or malware.
