
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,997 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where the Windows script hosts wscript.exe or cscript.exe establish outbound network connections to common web ports (HTTP/HTTPS) on external IP addresses. This behavior is frequently associated with script-based malware, droppers, or C2 beacons.
Detects instances of rundll32.exe being used to load DLL, OCX, or CPL files from suspicious locations such as user-writable directories (Temp, AppData, Downloads, etc.) or UNC paths. This behavior is indicative of an adversary attempting to execute malicious code using a trusted Windows system binary (LOLBin).
Monitors GitHub audit logs for suspicious or high-risk activities within CI/CD pipelines, including actions triggered by forks, workflow approvals, branch policy overrides, self-hosted runner registration, and sensitive secret access.
Detects abnormally long DNS queries characterized by repetitive alphanumeric patterns, which may indicate potential DNS tunneling activity used for C2 communication or data exfiltration. The rule flags DNS requests exceeding 60 characters with repeating label structures.
Detects the creation of a scheduled task via schtasks.exe that executes a command interpreter or script engine (e.g., PowerShell, cmd, wscript) where the parent process is not signed by Microsoft. This behavior is often associated with the execution of malicious payloads, persistence mechanisms, or lateral movement.
Monitors IIS web servers for signs of potential exploitation by tracking suspicious child processes spawned by worker processes (w3wp.exe/iisexpress.exe), tracking unexpected WER (Windows Error Reporting) crashes associated with IIS workers, aggregating IIS-related application crashes, and detecting anomalous W3C IIS log request patterns (e.g., malformed content-length, negative bytes, or suspicious URI characteristics).
Detects the execution of mshta.exe with command-line arguments that include remote protocols (http/https) or scripts (javascript/vbscript). This behavior is commonly associated with fileless malware execution and proxying malicious code via a trusted Windows binary.
Detects path traversal attempts in web server access logs by searching for dot-dot-slash (../), dot-dot-backslash (..\), or their URL-encoded equivalents (..). These patterns are indicative of efforts to access files or directories outside the intended web root.
This rule identifies network connections (DNS queries, HTTPS/WebSocket traffic) directed toward known suspicious domains associated with potentially malicious C2 infrastructure.
Detects potential persistence attempts via WMI event subscriptions. The rule monitors for the creation of WMI event consumers using 'wmic.exe' with suspicious command line arguments, or the use of 'mofcomp.exe' to compile MOF files by non-standard, non-Microsoft signed processes.
