
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,978 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of wscript.exe, msiexec.exe, or cmd.exe initiated with command lines pointing to script files (.js, .vbs) or shortcut files (.lnk) located on removable drives (d-z drive letters). This behavior is characteristic of the Raspberry Robin worm spreading via infected USB media.
This rule detects potentially malicious activity within Linux environments or containers where a single user context concurrently performs credential hunting (via environment variable dumping or accessing .env files) and terminates processes associated with known cryptocurrency miners or competing malicious actors. This behavior is highly indicative of a cryptojacking infection or a malicious actor clearing out existing resource-hijacking threats.
Detects the execution of PowerShell or pwsh that originates from an interactive parent process like explorer.exe or cmd.exe. The rule identifies suspicious command-line patterns containing 'IEX', 'Invoke-Expression', 'Invoke-WebRequest', 'iwr', or 'IRm', while excluding encoded commands, which is indicative of potential malicious clipboard-paste activity or manual attacker intervention.
Detects instances where AutoHotkey scripts launch Microsoft Edge or Google Chrome in headless mode. This behavior is indicative of automated browser manipulation, often used in credential harvesting, session hijacking, or automated interaction with web-based platforms by malicious entities such as UNC6692.
This rule detects potential exploitation attempts targeting the BeyondTrust Privileged Remote Access API by identifying unauthenticated POST requests directed at specific sensitive API endpoints (e.g., /api/, /remote-support/). It flags high-frequency or multi-path request patterns indicative of automated vulnerability scanning or exploitation attempts related to CVE-2026-1731, where the absence of authorization headers is a key indicator of unauthorized access.
Detects high-frequency S3 PutObject requests that utilize Customer-Provided Encryption Keys (SSE-C). A high count of such operations within a short window can be indicative of ransomware activity, where an adversary encrypts data within the victim's cloud storage using their own keys to prevent access by the owner.
Detects HTTP requests where the URI or request body contains indicators of internal network references (e.g., localhost, 127.0.0.1, or RFC 1918 private IP address ranges). This pattern is consistent with Server-Side Request Forgery (SSRF) attempts, where an attacker tries to force a vulnerable web application to perform unauthorized requests to internal resources.
Detects anomalous, high-volume DNS query activity where a process attempts to resolve 20 or more unique domains within a 2-minute window. The query patterns match strings that are 8-20 characters long with common top-level domains, excluding known web browsers and standard network diagnostic utilities. This behavior is indicative of malware using Domain Generation Algorithms (DGA) for command and control or secondary communication channels.
Detects the creation of executable files (.exe or .dll) on a removable drive followed by the execution of a process from that same drive within a 30-second window. This behavior is indicative of an adversary using removable media to stage and execute malicious payloads.
This rule identifies potentially malicious activity where a process, which has been dormant on the system for at least 7 days since its initial start, suddenly performs a high volume (more than 50 events in 60 seconds) of file creation or modification events. This behavior pattern is often indicative of ransomware encryption activities, where malware lies dormant before initiating a rapid, destructive encryption cycle.
