
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,006 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of net.exe or net1.exe to perform enumeration of local administrators or domain-level users and groups. This behavior is commonly associated with attackers attempting to map out the environment for privilege escalation or lateral movement.
Detects abnormal termination, crash, or error messages related to the 'sharingd' process on macOS. 'sharingd' is a daemon responsible for various sharing features including AirDrop, Handoff, and Instant Hotspot. Unexpected errors or crashes within this process may indicate service instability, potential exploitation attempts, or abnormal interactions with sharing services.
Detects web traffic where the referrer header contains keywords associated with gaming or educational themes (such as 'bioshock', 'game', 'puzzle', 'math', 'quiz') combined with access attempts to sensitive URI paths (like '/code', '/token', '/secret', '/private', '/api-key') resulting in a redirect status (301-308). This behavior pattern is often indicative of automated reconnaissance or exploitation attempts using non-standard or obfuscated referrers to bypass simple security filters.
Detects network connections originating from a process and directed towards the local loopback interface (127.0.0.1 or ::1) on non-privileged, non-SMB ports (>= 1024 and != 445). This pattern can identify inter-process communication (IPC) over local network sockets which may be used by malware or malicious scripts to bypass security controls or communicate with local services.
Detects instances where the Local Security Authority Subsystem Service (lsass.exe) initiates a network connection to the loopback address (127.0.0.1 or ::1), excluding standard SMB traffic (Port 445). Such behavior by LSASS is highly anomalous and may indicate exploitation attempts, such as memory dumping or credential harvesting techniques involving inter-process communication.
Detects network logon events (Logon Type 3) using NTLM authentication where the source IP address is local (127.0.0.1 or ::1). This behavior can be indicative of attempts to interact with local services or perform lateral movement within the same host using credential-based techniques such as 'Pass-the-Hash' or unauthorized access to local resources.
Detects command-line activity indicative of the PetitPotam exploit or general EFSRPC (Encrypting File System Remote Protocol) coercion attempts. Adversaries use these techniques to force a machine to authenticate against another system (e.g., a domain controller), typically as a precursor to NTLM relay attacks.
This rule detects WebSocket upgrade attempts to 'google-ai-labs-it.onrender.com', which is associated with the Turla group's STOCKSTAY malware C2 infrastructure.
Detects HTTP response bodies containing common PE/Shellcode magic headers (MZ, PE, or NOP sleds) which are associated with the delivery of payloads designed to exploit or utilize the Windows KernelCallbackTable for process injection. The detection focuses on suspicious content delivered over HTTP connections.
Detects the abuse of MSBuild.exe to execute arbitrary code. The rule monitors for three primary suspicious behaviors: MSBuild spawning suspicious child processes indicative of inline task execution, MSBuild being launched with project file arguments from non-standard or untrusted parents, and MSBuild being launched without a project file (implying piped or inline payload delivery).
