
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,999 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects when a process's command line contains 'ssl' or 'tls' and is observed at least 3 times within an hour on the same computer and by the same account. This could indicate various activities, including legitimate system processes, development activities, or potentially malicious use of SSL/TLS-related tools or scripts. The rule focuses on process creation events (EventID 4688) and analyzes the command line arguments.
This rule detects when five or more driver-related files (.inf, .sys, or .drv) are created or modified within a one-hour window by the same initiating process account. This behavior can be indicative of malicious driver installation, rootkit activity, or other forms of persistence or privilege escalation.
Detects the creation of files containing keywords such as 'vulnerability', 'assessment', or 'scan'. This rule aims to identify activities related to vulnerability scanning or security assessments being performed on a system, potentially indicating reconnaissance or unauthorized activity. The events are summarized by the initiating process account name and time to help identify the source of these activities.
This rule detects an unusual number of file creations or modifications where the filename contains keywords like 'patch', 'update', or 'fix' by a single account within a one-hour window. This could indicate an automated patching process, software deployment, or potentially malicious activity attempting to modify system files under the guise of an update.
This rule detects a high volume (5 or more within an hour) of process creation events where the command line contains keywords associated with remote access protocols like DCOM, WMI, or RPC. This could indicate an adversary utilizing these protocols for lateral movement or remote execution.
This rule detects a high frequency (3 or more within an hour) of command-line executions containing keywords like 'antivirus', 'defense', or 'endpoint' on a Windows system. This activity could indicate an adversary attempting to interact with, disable, or tamper with security software to evade detection.
This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin, WMIC, or PowerShell. Attackers commonly perform this action to inhibit system recovery and prevent the restoration of data, often as a precursor or during the impact phase of ransomware attacks.
Detects the use of wmic.exe to execute remote commands using the /node flag and the 'process call create' command string. This pattern is commonly used by adversaries for lateral movement and remote code execution.
Detects the execution of Microsoft Application Virtualization Injector (mavinject.exe) with the '/injectrunning' command-line argument. This utility is frequently abused by adversaries to inject malicious DLLs into target processes, facilitating arbitrary code execution while potentially bypassing security detections due to the binary's legitimate provenance.
Detects instances where Microsoft Teams (teams.exe) initiates child processes that are commonly used as interpreters, such as cmd.exe, powershell.exe, mshta.exe, wscript.exe, or rundll32.exe. This activity is frequently associated with the execution of malicious payloads delivered via phishing or collaboration platforms.
