
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,013 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects potential PrintNightmare or Print Spooler exploitation by monitoring for the spoolsv.exe service spawning suspicious child processes (e.g., cmd, powershell, rundll32) and unauthorized files being dropped into the printer driver directory.
This rule detects the creation of scheduled tasks using the 'schtasks.exe' utility with command-line arguments indicating persistence triggers ('onlogon', 'onstart') or elevation to the 'SYSTEM' account. Adversaries commonly use these methods to ensure malicious code executes automatically upon system startup or with high privileges to facilitate further exploitation.
This rule monitors for potentially malicious use of the Windows Certutil utility, specifically targeting the -urlcache (often used to download remote files) and -decode (used to decode hidden or obfuscated payloads) command-line arguments. It filters out common trusted processes like Microsoft's msiexec.exe to reduce noise.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate background data transfer jobs pointing to non-Microsoft or non-Windows Update domains. This technique is commonly used by adversaries for C2 communication or to download malicious payloads.
Detects common reconnaissance activities using built-in Windows utilities to enumerate domain users, domain groups, and local administrators, as well as LDAP enumeration using dsquery and dsget.
Detects the execution of PowerShell with encoded commands that include signs of web-based downloads or unusually long payloads, which are often used to hide malicious scripts or execute stagers. The rule filters out trusted signers and common administrative management tools to reduce noise.
Detects evidence of file timestomping, a technique used by attackers to modify file system timestamps (Create, Access, Modify, Change) to evade forensic detection or masquerade malicious files. The rule monitors for explicit usage of timestomping tools (e.g., Invoke-TimeStomp), abuse of system utilities like fsutil.exe for timestamp modification by suspicious parent processes, and unauthorized or unsigned processes performing timestamp modification on sensitive file types.
Detects attempts to clear Windows event logs using the wevtutil command-line utility or PowerShell cmdlets (Clear-EventLog, Remove-EventLog). Adversaries often clear event logs to hinder forensic investigations and remove evidence of their malicious activity.
Detects signs of access token manipulation and impersonation, including the use of 'runas' with saved credentials, suspicious PowerShell API calls for identity management, usage of known token-manipulation tools (e.g., incognito), and reconnaissance using 'whoami /priv'. These activities are indicative of privilege escalation attempts or lateral movement.
Detects the use of native Windows utilities such as shutdown.exe, wmic, powershell, and rundll32 to trigger an immediate system shutdown or restart, which may be indicative of unauthorized system disruption or malicious activity.
