
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,013 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects incoming network connections to Windows 'Nearby Share' process components from external (non-RFC1918) IP addresses. This activity is potentially malicious as legitimate 'Nearby Share' traffic should typically occur within local networks.
This rule detects potentially suspicious process activity where unknown or infrequently seen processes spawn common script interpreters such as cmd.exe, powershell.exe, wscript.exe, or others. This behavior often indicates an attempt to execute malicious commands or scripts as part of a post-exploitation or persistence mechanism.
Detects instances where Windows Nearby Sharing related processes (quick_share.exe, NearbyShare.exe, nearby_sharing.exe) spawn command-line interpreters (cmd.exe, powershell.exe). This pattern is anomalous as these utilities are intended for file transfer, not command execution, and could indicate exploitation of these applications to achieve code execution.
Detects DNS queries to GitHub API domains originating from non-standard or potentially spoofed process names associated with various AI tools, which may indicate data exfiltration or unauthorized interaction with repositories.
Detects unexpected registry modifications (creation, deletion, or modification) performed by processes associated with 'Nearby Share' (quick_share.exe, nearby_sharing.exe). Legitimate registry activity related to Google Nearby Share or Windows native Nearby Sharing is excluded from this alert.
Detects incoming network connections to Windows 'Nearby Share' process components from external (non-RFC1918) IP addresses. This activity is potentially malicious as legitimate 'Nearby Share' traffic should typically occur within local networks.
Detects network connection attempts directed toward RFC 1918 private IP address spaces (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost (127.0.0.0/8) that do not involve common Windows file sharing ports (TCP/445 and TCP/139). This behavior may indicate lateral movement, internal reconnaissance, or the use of non-standard protocols for internal communication.
Detects high-volume outbound network connections (exceeding 10MB) originating from processes associated with AI-driven chatbot or productivity applications (e.g., ChatGPT, Perplexity). This rule identifies potential data exfiltration occurring over legitimate, expected software channels.
Detects instances of PowerShell or PowerShell Core (pwsh) launched with encoded command line arguments (-encodedcommand, -enc, -ec). This is a common technique used by attackers to obfuscate malicious scripts and payloads by passing them as Base64 encoded strings to avoid simple static analysis.
Detects instances where the Windows Management Instrumentation service (WmiPrvSE.exe) or command-line tool (wmic.exe) initiates potentially suspicious child processes, often indicative of lateral movement or remote command execution via WMI.
