
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,986 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the presence of known malicious drivers (hlpdrv.sys, rwdrv.sys) by their SHA256 hash or file path. It also identifies attempts to install these drivers via service creation commands and monitors for modifications to Windows Defender registry keys that could disable its functionality, indicating defense evasion.
This rule detects an unusually high number of outbound network connections originating from the Local Security Authority Subsystem Service (LSASS) process on a Windows machine. LSASS is a critical system process responsible for enforcing security policy on the system, including user authentication, and typically does not initiate a large number of outbound connections. A high count of outbound connections from LSASS could indicate credential dumping activity, where an attacker is exfiltrating harvested credentials, or other malicious activity compromising the LSASS process.
Detects attempts to read the memory of browser processes (Chrome, Edge, Firefox, Brave, Opera). This activity can be indicative of credential dumping or other forms of data exfiltration from web browsers.
This rule detects potential persistence mechanisms related to browser extensions. It looks for processes launching Chrome or Edge with the '--load-extension' command-line argument, which can be used to load unpacked extensions. Additionally, it monitors registry modifications to 'ExtensionInstallForcelist' that contain 'http' or 'crx', indicating a forced installation of an extension, potentially from a remote source or a local file.
Detects the creation of an MSI (Microsoft Installer) file on a device where the file's origin referrer URL indicates it was downloaded from a ZIP archive that was originally an email attachment. This could indicate a user opening a malicious ZIP file from an email, leading to the execution of an installer.
A detection triggered on endpoint events where common system binaries (e.g., mshta.exe, powershell.exe, cmd.exe) were launched by user-facing parent processes (explorer.exe, chrome.exe, msedge.exe, firefox.exe, iexplore.exe) and executed suspicious command-lines. The pattern matches the evolving technique used in ClickFix-style campaigns whereby malicious pages dynamically place payloads into the clipboard and prompt users to paste or execute them.
This rule detects network connections or URL click events to a list of domains known to be associated with phishing or malware distribution. The rule specifically looks for connections to these domains that also contain certain path segments like '/wlc/', '/load/', or '/success/', which are often indicative of malicious activity or payload delivery. It also broadly checks for any URL click events containing these suspicious domains.
This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
This rule detects network connections to specific deep link patterns associated with messaging applications like Telegram, WhatsApp, and Signal. Such deep links can be used in phishing attempts or to initiate actions on a user's device through these applications.
This rule detects network connections to a predefined list of known Microstealer malicious domains. These domains are often associated with malware command and control (C2) infrastructure, phishing, or other malicious activities. Monitoring connections to such domains can help identify compromised systems or active malware infections.
