
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,026 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the execution of 'hdiutil' to attach a disk image with the '-nobrowse' flag, initiated by various scripting interpreters (bash, zsh, python, etc.) or terminal applications. This pattern is frequently used by adversaries to silently mount malicious payloads or tools contained within disk images while bypassing user interaction.
Detects anomalous ICMP Echo Request packets (type 8, code 0) that contain payloads exceeding 64 bytes. ICMP Echo requests with large, non-standard payloads are a classic indicator of ICMP tunneling, which can be used to bypass network firewalls and encapsulate non-ICMP traffic for command and control (C2) or data exfiltration. The rule includes a threshold to reduce noise by alerting only when multiple such packets are seen from the same source.
This rule detects HTTP directory traversal attempts by inspecting incoming URI requests for common path traversal sequences such as '../', '..%2F', '..%2f', '..%5C', or '..%5c'. Attackers use these sequences to escape the web root directory and access unauthorized files on the server.
This rule detects the creation of a new domain user account followed by its immediate addition to a privileged Active Directory group within a short timeframe. It specifically ignores common provisioning accounts and service accounts. A high risk score is assigned if the privileged group assignment occurs within 5 minutes of account creation, flagging potentially malicious account takeovers or privilege escalation activity.
Detects reconnaissance activity targeting Active Directory group structures and membership, utilizing common administrative tools such as net.exe, PowerShell, and dsquery. This rule identifies patterns associated with domain group discovery and identification of privileged accounts.
Detects modifications to computer or user accounts in Active Directory where the 'Trusted for Delegation' flag is enabled. Enabling unconstrained delegation allows a compromised account to request and cache Ticket Granting Tickets (TGTs) for any user authenticating to the service, enabling potential privilege escalation and lateral movement.
This rule monitors Active Directory Certificate Services (AD CS) event logs for signs of potential privilege escalation and credential abuse. It specifically targets indicators of ESC1 (AD CS misconfigurations allowing requester-supplied SANs), identifies requests for certificates by non-owners for privileged accounts, and monitors for the use of PKI-based Kerberos authentication against high-privilege targets.
Detects modifications to computer or user accounts in Active Directory where the 'Trusted for Delegation' flag is enabled. Enabling unconstrained delegation allows a compromised account to request and cache Ticket Granting Tickets (TGTs) for any user authenticating to the service, enabling potential privilege escalation and lateral movement.
Detects incoming HTTP POST requests directed at PHP, ASPX, or JSP files that contain suspicious command execution patterns (such as cmd=, exec=, system(, or eval()). This behavior is highly indicative of an attacker interacting with a web shell to execute unauthorized commands on the server.
This rule detects the invocation of local AI/LLM CLI utilities (e.g., ollama, llama-cpp) by potentially malicious or automated parent processes. It specifically flags scenarios where non-interactive or scripting-based processes (such as WScript, PowerShell, or Python) attempt to use these AI tools, particularly when the command line includes keywords related to sensitive data discovery, such as 'password', 'token', or 'private key'. This behavior is characteristic of infostealer activity (e.g., QUIETVAULT) attempting to use AI tools for automated reconnaissance and credential extraction.
