
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,987 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects suspicious remote thread creation events (Sysmon Event ID 8) where a process initiates a thread in high-value system processes like lsass.exe, svchost.exe, explorer.exe, or winlogon.exe. It specifically filters out activity originating from common Windows system directories, highlighting potential process injection attempts by unauthorized binaries.
Detects a suspicious spike in Microsoft Teams external meeting or chat invitations directed at a single user within a 30-minute window. This behavior is consistent with UNC6692 tactics, where attackers impersonate internal IT helpdesk staff via Teams to perform vishing and social engineering attacks.
This rule detects network connections to known cloud storage, file hosting, and webhook services (Discord, Pastebin, Dropbox, Telegram, AnonFiles) initiated by processes other than standard web browsers. Such behavior is often indicative of data exfiltration or C2 activity using legitimate web services to blend in with normal traffic.
This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.
Detects rapid succession of MFA authentication requests originating from multiple distinct countries within a 10-minute window, a common pattern indicating an MFA fatigue (push bombing) attack targeting a specific user.
Detects modifications to Azure AD/Entra ID application configurations, specifically updating the 'RedirectUri' or 'ReplyUrls' to point to potentially external or unauthorized domains. This technique is often used in OAuth-based application-consent phishing campaigns to redirect authorization codes to adversary-controlled servers.
This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.
Detects the creation or modification of the VbaProject.OTM file, which stores VBA macros for Microsoft Outlook, by a process other than the Outlook application (OUTLOOK.EXE). This is a common technique used to deploy malicious macros for persistence or code execution within the Outlook environment.
This rule detects activities associated with the NotDoor malware used by APT28 for email-based exfiltration. It specifically monitors for the creation of staging files in temporary directories, the use of Outlook.exe to establish external SMTP connections on common mail ports, and the transmission of emails to known adversary-controlled addresses.
Detects the creation of a scheduled task named 'OneDriveHealth', which is associated with APT28 activity. This task is used for persistence via COM hijacking; it executes 60 seconds after registration, kills and restarts explorer.exe to facilitate the loading of a hijacked COM object, and subsequently removes itself.
