
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the China Chopper web shell spawning CMD from IIS (w3wp.exe) with suspicious command line patterns.
Detects the execution of mshta.exe with command-line arguments that indicate the execution of JavaScript or VBScript code, often used for malicious purposes such as bypassing application whitelisting or executing remote code.
Detects the execution of cmstp.exe with the '/s' flag, which indicates a silent installation. This behavior is often abused by adversaries to proxy execution of malicious code, bypass application control, or bypass User Account Control (UAC).
This rule detects multiple unauthorized access attempts to files identified as machine learning models, weights, or checkpoints. It specifically looks for Security Event ID 4656 (Auditing of object access) where the object name contains keywords like 'model', 'weights', or 'checkpoint', and the access mask indicates unauthorized access attempts (0x0001 for ReadData or ListDirectory, 0x0002 for WriteData or AddFile). The rule then summarizes these attempts by user, computer, and hour, triggering an alert if 5 or more attempts are made within an hour.
This rule detects potential data poisoning attacks targeting machine learning models by monitoring Windows Security Event ID 4688 (a process was created) for command-line activity containing keywords indicative of model training or dataset modification, combined with terms suggesting malicious intent like 'corrupted', 'poison', or 'injection'. It aims to identify attempts to manipulate or compromise ML models through their training data.
This rule detects emails containing macro-enabled documents (.docm, .xlsm, .pptm). It specifically looks for instances where a sender sends two or more such emails within an hour, which could indicate a targeted phishing attempt using malicious macros.
Detects suspicious emails with attachments originating from external senders, characterized by urgent or action-oriented subject lines, and sent in bulk (5 or more emails within an hour). This pattern is indicative of phishing attempts.
This rule detects potential 'reply-all' storm attacks or malicious mass emails sent to large distribution lists within the organization. It identifies emails sent to 50 or more recipients where the subject line contains phrases like 'reply all' or 'all members', originating from an internal company domain. The rule then counts such broadcast emails within one-hour bins to identify unusual activity.
This rule detects repeated access attempts (3 or more within an hour) to critical credential storage processes or files, specifically lsass.exe, the Security Account Manager (SAM) database, or the NTDS.dit file. Such activity is indicative of credential theft attempts by an adversary.
This rule detects potential lateral movement activities by monitoring for the execution of 'psexec', 'wmiexec', or 'schtasks' commands within a short timeframe on the same computer. A count of 2 or more such command executions within an hour is flagged as suspicious, indicating potential adversary activity.
