
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,004 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects browser processes connecting to internal IP addresses followed by a connection to an external (non-whitelisted) destination within a 2-minute window. This behavior is indicative of potential data staging or exfiltration, where a web browser is used to access internal resources before transferring data to an external site.
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
Detects clipboard access operations (Read/Write) initiated by common web browsers (Chrome, Edge, Brave, Electron-based apps) when running with specific command-line arguments typically associated with renderer or extension processes. This can indicate malicious code or browser extensions attempting to monitor or steal sensitive clipboard content.
Detects unexpected crashes of critical macOS system processes such as sharingd, nsurlsessiond, airplayd, AirPlayXPCHelper, and NetAuthSysAgent. Frequent crashing of these components can indicate instability or potentially malicious attempts to interfere with system services.
Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.
Detects browser processes connecting to internal IP addresses followed by a connection to an external (non-whitelisted) destination within a 2-minute window. This behavior is indicative of potential data staging or exfiltration, where a web browser is used to access internal resources before transferring data to an external site.
Detects NTLM-authenticated network logons (Logon Type 3) originating from loopback IP addresses (127.0.0.1, ::1, or 0.0.0.0). This behavior is often associated with NTLM relay attacks or credential reflection bypass techniques where an adversary forces a local service to authenticate to itself to gain unauthorized access.
Detects a multi-stage attack pattern associated with the Qilin ransomware, beginning with suspicious VPN authentication (potential credential stuffing or bypass), moving through lateral movement attempts (SMB/RDP/WMI), and culminating in ransomware behaviors such as shadow copy deletion, mass file encryption, and ransom note creation.
Detects instances where privileged system processes such as lsass.exe or svchost.exe attempt a network connection to the local loopback address on ports other than standard SMB ports (445, 139). This pattern is indicative of potential coercion or relay attacks, specifically targeting the authentication mechanisms of these services to an attacker-controlled SMB server.
Detects the execution of Python-based SMB server implementations commonly associated with the Impacket toolset. Impacket is frequently used by attackers to facilitate lateral movement, credential relay, and remote file manipulation.
