
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to sensitive Group Policy Object (GPO) attributes, specifically those related to file system paths, machine/user extensions, or version numbers, using Windows Security Event ID 5136. These attributes are often targeted during GPO modification to establish persistence, escalate privileges, or deploy malicious configurations across a domain.
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (etype 0x17) by non-service accounts, which is a common indicator of a Kerberoasting attack where adversaries attempt to crack service account passwords offline.
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (etype 0x17) by non-service accounts, which is a common indicator of a Kerberoasting attack where adversaries attempt to crack service account passwords offline.
This rule detects outbound FTP traffic containing the 'STOR' command, which is used in the FTP protocol to upload files to a remote server. This behavior is a common indicator of unauthorized data exfiltration.
Detects DNS queries containing unusually long subdomains (50+ characters) encoded in Base64, which is a common technique used for command-and-control (C2) communication or data exfiltration via DNS tunneling.
Detects the transmission of a Metasploit Meterpreter stage over HTTP, identified by an application/octet-stream response containing the DOS MZ header signature.
This rule detects a high frequency of incoming TCP synchronization (SYN) packets on port 3389 (RDP) from a single external source within a short timeframe. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
This rule monitors network traffic over the Telnet protocol (TCP port 23) for patterns indicative of Mirai botnet propagation. It identifies sequences of characters commonly used in Mirai brute-force attempts to guess default credentials (e.g., 'admin' followed by 'password'). The rule utilizes a threshold-based detection filter to trigger only when multiple such attempts are observed from a single source within a 60-second window, helping to filter out individual noise and focus on active scanning behavior.
This rule monitors process command lines and file activity for keywords associated with potential reconnaissance, error logs, or debugging artifacts often used during post-exploitation or system profiling. It flags commands or files containing terms like 'memory dump', 'stack trace', 'SQL injection', or 'Redis failure', which may indicate an attacker analyzing system information or attempting to interact with backend services.
This rule detects suspicious activity associated with the Bun runtime after an npm package install. It flags instances where Bun, or download utilities (curl/wget) fetching 'bun.sh', are spawned from Node.js-related processes (npm, node, node-gyp) particularly when located in common temporary or cache directories, indicating potential supply chain compromise or unauthorized runtime deployment during build processes.
