
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects when processes other than standard web browsers (Chrome, Edge, Firefox, Brave, Opera) attempt to read sensitive browser data files such as 'Login Data', 'Cookies', or 'Web Data'. These files contain stored credentials and session information, and unauthorized access is a common technique used by credential-stealing malware to exfiltrate sensitive user information.
Detects the creation of large archive files (.zip, .7z, .rar, .tar) exceeding 100MB within sensitive or high-risk directory paths such as Desktop, Temp, or AppData, or on non-system drives. This behavior is often associated with the staging of sensitive data for exfiltration.
This rule identifies instances of PowerShell executing with an encoded command followed immediately (within 300 seconds) by an outbound network connection to a non-standard port or non-internal IP address. This behavior is indicative of a remote access tool or reverse shell establishing command and control (C2) communication.
This rule monitors for scenarios where a DLL is created and subsequently loaded by a process within a short time frame (60 seconds or less). The rule specifically excludes files located in 'C:\Windows\' and 'C:\Program Files\' to minimize noise, focusing on suspicious modules originating from user-writable or unexpected locations, which is a common behavior of malware or side-loading attacks.
Detects the loading of system drivers (.sys files) that are either unsigned or have an invalid digital signature. The rule excludes drivers loaded from common Windows system directories to minimize noise. This behavior is a common indicator of rootkit installation or the use of vulnerable drivers for kernel-mode exploitation.
Detects the use of built-in Windows utilities (vssadmin, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or modify boot configuration settings to disable recovery features, which is a common precursor to ransomware encryption.
This rule detects potential brute force attacks against Microsoft Exchange Outlook Web App (OWA) by monitoring for a high volume of 401 Unauthorized status codes from non-internal IP addresses. It also correlates these authentication events with subsequent post-authentication actions, specifically identifying mailbox logins followed by mailbox searching or export requests, which may indicate account compromise and unauthorized data collection or exfiltration.
This rule detects anomalous RDP (Logon Type 10) sessions occurring outside of typical business hours or from previously unseen geographic locations, followed closely by the execution of system discovery commands (net.exe, ipconfig.exe, whoami.exe, systeminfo.exe) within a 10-minute window. This behavior is indicative of post-exploitation reconnaissance following an unauthorized or suspicious remote access session.
This rule detects multiple failed SSL login attempts from a single source IP to a destination IP within a 24-hour period. A threshold of 10 failed attempts is used to identify potential brute-force attacks or credential stuffing against SSL-enabled services.
This rule identifies if a given IP address falls within the known IP ranges used by Apple's iCloud Private Relay service. It retrieves a list of IPv4 and IPv6 ranges from a public GitHub repository and then checks if a specified IP address is contained within any of these ranges. This can be used to identify traffic potentially obfuscated by iCloud Private Relay.
