
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,999 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects HTTP POST requests targeting Cisco Firepower Management Center (FMC) that contain Java exploitation patterns (Runtime.getRuntime or ProcessBuilder) associated with the exploitation of CVE-2026-20131. This activity is indicative of an attempt to achieve Remote Code Execution (RCE) on the FMC appliance, likely by an actor utilizing the Interlock Ransomware threat.
Detects modifications or creation of 'InprocServer32' registry keys within 'HKEY_CURRENT_USER\Software\Classes\CLSID'. This pattern is frequently used for COM hijacking to achieve persistence or execute arbitrary code when a COM object is invoked by an application or the OS.
This rule monitors DeviceNetworkEvents to identify processes that are not typically associated with cloud storage and synchronization software initiating network connections on port 443 to popular cloud providers (OneDrive, SharePoint, Dropbox). This behavior is often indicative of data exfiltration to cloud storage services or potential command and control communication disguised as web traffic.
Detects modifications or creation of 'InprocServer32' registry keys within 'HKEY_CURRENT_USER\Software\Classes\CLSID'. This pattern is frequently used for COM hijacking to achieve persistence or execute arbitrary code when a COM object is invoked by an application or the OS.
This rule monitors DeviceNetworkEvents to identify processes that are not typically associated with cloud storage and synchronization software initiating network connections on port 443 to popular cloud providers (OneDrive, SharePoint, Dropbox). This behavior is often indicative of data exfiltration to cloud storage services or potential command and control communication disguised as web traffic.
Detects the use of the 'netsh interface portproxy' command to set up a port forwarding rule where the connection address is outside of common private IP ranges. This behavior is frequently associated with attackers establishing persistent network pivots or internal proxies to redirect C2 traffic.
Detects the execution of rundll32.exe or regsvr32.exe as a child process of script interpreters like wscript.exe, cscript.exe, or mshta.exe. The command line parameters often involve potentially malicious paths (e.g., Temp, AppData, ProgramData, Users\Public) or the presence of DLL extensions, indicating potential proxy execution of malicious scripts or side-loaded libraries.
This rule detects modifications to sensitive Windows Registry keys under HKLM\SOFTWARE\Microsoft\Cryptography, such as Providers, OID, Trust, and Protectedroots. These keys control cryptographic services and trust stores on Windows systems. Modifications by non-system processes or accounts may indicate attempts to subvert trust controls, install rogue root certificates, or tamper with system-level security providers.
Detects the deletion of volume shadow copies using standard Windows utilities like vssadmin.exe or wmic.exe, combined with concurrent file activity in multiple directories, a behavior frequently observed during the impact phase of a ransomware attack (specifically associated with the Qilin ransomware family).
This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.
