
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,006 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects execution of the Microsoft .NET installer utility (InstallUtil.exe) from non-standard locations. Adversaries often abuse InstallUtil.exe as a proxy to execute malicious code or bypass application control policies, as it is a trusted, digitally signed Microsoft binary. The rule filters out legitimate execution paths typically associated with .NET framework installations, SDKs, or system directories.
This rule detects AppDomainManager injection attempts by monitoring for the loading of suspicious DLLs (related to AppDomainManager functionality) by specific processes or from unexpected file paths. The rule specifically targets attempts to hijack the .NET AppDomainManager class by checking against known suspicious filenames and excluding legitimate .NET framework directories, which is a common technique used for arbitrary code execution in the context of a target process.
Detects anomalous network communication patterns and file system changes indicative of SoftEther VPN usage, particularly when linked to processes masquerading as VMware or communicating with known malicious C2 infrastructure. The rule monitors for network connections on common SoftEther ports, connections to specific command-and-control IP addresses, and the creation of SoftEther configuration files like 'hamcore.se2' or 'vpn_bridge.config'.
Detects the creation of Kubernetes pods where the 'hostPID' or 'hostNetwork' settings are enabled. These configurations allow a pod to share the host's process namespace or network stack, respectively, which are common vectors for container escapes and host-level privilege escalation.
This rule detects potential unauthorized access to Azure Storage Blobs following the retrieval of storage account access keys. It correlates 'ListKeys' API events with subsequent blob access activities from either unrecognized IP addresses or via Shared Access Signature (SAS) tokens, indicating potential credential misuse.
This rule detects the creation or registration of scheduled tasks that involve the 'PerfWatson2.exe' utility or execution paths originating from within the local AppData directory. These patterns are often associated with persistence mechanisms used by malware or malicious scripts to maintain execution after reboots.
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
Detects instances where common web server processes initiate command interpreters or system utilities. This behavior is a common indicator of web shell execution, where an adversary uses a web application vulnerability to gain remote code execution on the underlying server.
Detects various techniques used by an attacker to escape a container environment or gain unauthorized access to host-level resources. This includes the execution of namespace manipulation tools (nsenter, unshare, chroot), unauthorized access to the docker.sock Unix socket, mounting of host filesystems from within a container, and direct attempts to access the host's /proc/1 namespace files.
Detects common lateral movement patterns associated with Pass-the-Hash (PtH) attacks, specifically identifying remote execution via WMI/services, the use of explicit credentials in management utilities (wmic/net), and suspicious network connections from known administration tools over lateral movement ports.
