
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,986 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the creation of web shell files (ASPX, PHP, JSP) in common web server directories such as 'wwwroot', 'inetpub', or 'var\\www'. This activity is indicative of an adversary establishing persistent access to a web server.
This rule detects the creation of a new Windows service (EventID 7045) where the service executable path contains both 'System32' and 'svchost', and the service description is either empty or contains 'Network'. This combination of characteristics can indicate the installation of a malicious service, potentially a backdoor or trojan, attempting to masquerade as a legitimate system service.
This rule detects potential ransomware activity by monitoring for a high volume of file creation or renaming events where the new file names end with common ransomware extensions such as '.encrypted', '.locked', or '.crypted'. It aggregates these events over 5-minute intervals and triggers if 50 or more such files are observed on a single device.
This rule detects suspicious file activity indicative of ransomware by monitoring for a high volume of file creations or renames where the filenames contain common ransomware-related extensions such as '.encrypted', '.locked', or '.ransom'. It aggregates these events over a one-hour period per device and triggers if 20 or more such events occur.
Detects attempts to delete volume shadow copies using 'vssadmin' or 'wmic shadowcopy' commands. Adversaries often delete shadow copies to prevent system recovery and hinder forensic analysis, especially during ransomware attacks or data destruction efforts.
Detects suspicious process execution patterns involving PowerShell with encoded commands or CMD with command execution flags. The rule looks for multiple occurrences of these patterns from the same computer and account within a one-hour window, which could indicate malicious activity such as script execution or obfuscated command execution.
This rule detects suspicious command-line obfuscation techniques by monitoring process creation events (EventID 4688) for specific patterns in the command line. It looks for the use of environment variables like %TEMP% or %SystemRoot%, the `${env:` syntax, and nested `cmd /c "cmd /c"` calls. These patterns are often used by adversaries to hide the true nature of executed commands, evade detection, or bypass security controls. The rule triggers if three or more such events are observed from the same computer and account within a one-hour window.
This rule detects multiple unauthorized access attempts (5 or more within an hour) to sensitive Active Directory objects such as 'Admin', 'krbtgt', or 'Domain Admins'. It leverages Windows Security Event ID 4662, which indicates an operation was performed on an object, and filters for specific sensitive object names. The rule then groups these attempts by object, IP address, and user, alerting when a threshold of attempts is met.
This rule detects potential Pass-the-Hash (PtH) attacks by looking for multiple successful network logons (LogonType 3) using NTLM authentication for the same user from the same IP address. A count of 5 or more such events is considered suspicious.
This rule detects unusual logon activity for service accounts. It identifies service accounts by looking for a dollar sign ($) at the end of the username. The rule then counts logons, unique IP addresses, and unique computers for these service accounts within one-hour bins. An alert is triggered if a service account has 10 or more logons or logs in from 5 or more unique IP addresses within that hour, indicating potential abuse or compromise.
