
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,999 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the presence of Phoenix malware by identifying known SHA256 hashes of its components or network connections to its command and control (C2) infrastructure. It correlates file events with known malware hashes and network events with known C2 IP addresses.
Correlates phishing email delivery with subsequent communication to attacker-controlled domains.
Detects processes making HTTP/HTTPS requests to localhost on ports 40341 or 40342 for '/metadata'. This pattern can indicate local service discovery, inter-process communication, or potentially malicious activity attempting to interact with local services, possibly for credential access or privilege escalation.
Detects suspicious payload execution or unexpected child processes spawning directly from the IIS worker process (w3wp.exe), which is a common indicator of web shell activity or exploit payload execution on vulnerable IIS instances.
Detects execution of the malicious miner components associated with the Hola Browser supply-chain compromise. Researchers identified me.exe and HolaMonitorService.exe as unauthorized payloads bundled with affected installations.
Detects a Python process spawning curl to make outbound web requests. This behavior aligns with the PoC for CVE-2026-4372 (HuggingFace Transformers RCE), where Python sub-processes curl to exfiltrate credentials.
Detects the creation of the specific PoC proof file (/tmp/hf_rce_poc_proof.txt) generated by the CVE-2026-4372 exploit payload targeting the HuggingFace Transformers library.
Identifies device code sign-ins originating from infrastructure previously associated with phishing operations and adversary-controlled relay servers.
Detects emails matching the Microsoft-reported AiTM phishing campaign that used Code of Conduct review lures and PDF attachments.
Detects RuntimeHost.exe launched from an unusual cache directory frequently associated with malware staging and cryptomining activity.
