
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,997 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network connections from internal endpoints to Filen.io cloud storage domains and subdomains. The rule specifically flags interactions involving common API endpoints for file operations (upload, download, directory listing) as 'Critical' risk, while generic traffic to the domain is classified as 'High' risk.
Detects Microsoft Office applications spawning suspicious child processes (e.g., cmd.exe, rundll32.exe) or initiating network connections to WebDAV paths, which may indicate exploitation of ActiveX OLE auto-execution vulnerabilities.
Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.
This rule monitors for recurring application crashes involving 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. Frequent crashes of these components may indicate instability, misconfiguration, or an attempt to exploit vulnerabilities within these specific file sharing services.
Detects browser processes connecting to internal IP addresses followed by a connection to an external (non-whitelisted) destination within a 2-minute window. This behavior is indicative of potential data staging or exfiltration, where a web browser is used to access internal resources before transferring data to an external site.
Detects the use of the 'net.exe' or 'net1.exe' command-line utilities to mount a local SMB share using loopback addresses (127.0.0.1 or localhost) with the '/tcpport' argument. This pattern is indicative of attempts to exploit CVE-2026-24294 to bypass NTLM authentication protections through local reflection or relay attacks.
Detects the execution of Python-based SMB server implementations commonly associated with the Impacket toolset. Impacket is frequently used by attackers to facilitate lateral movement, credential relay, and remote file manipulation.
This rule monitors DNS queries for potential exfiltration or C2 communication channels. It flags DNS queries that exceed 100 characters in length or contain labels with at least 30 alphanumeric characters, excluding activity from common web browsers.
Detects when common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) load a DLL file from suspicious or user-writable locations such as AppData, Downloads, Documents, or Temp folders. The rule specifically alerts on DLLs that are unsigned or where the loading process itself is unsigned, which is a common indicator of side-loading or malicious library injection.
Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.
