
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects suspicious network activity originating from the InstallUtil.exe process. InstallUtil is a legitimate Windows .NET utility that can be abused as a LOLBin (Living-off-the-Land Binary) to proxy the execution of malicious payloads, potentially bypassing application control mechanisms.
This rule detects potential lateral movement attempts using Windows Remote Management (WinRM) by monitoring for specific WSMan SOAP protocol headers in HTTP traffic. It specifically looks for POST requests to the WSMan endpoint that contain suspicious keywords like 'winrs', 'MSRPC', or 's:Envelope', which are commonly associated with remote command execution via winrs or PSSession.
Detects HTTP traffic where the User-Agent header references Regasm or Regsvcs, which are trusted Windows utilities often abused by attackers to proxy execution of malicious code (Living-off-the-Land Binary technique).
Detects HTTP GET requests for .msc (Microsoft Management Console) files, which can be leveraged as part of an attack chain to abuse the mmc.exe binary for proxy execution of malicious configurations.
Detects SMB traffic patterns containing commands indicative of file obfuscation or permission tampering, specifically the use of 'attrib' to set hidden or system attributes, 'icacls' to deny access to files, or PowerShell execution with the '-WindowStyle Hidden' argument.
Detects remote system shutdown attempts initiated via the MSRPC winreg named pipe over SMB. This behavior is indicative of an attacker attempting to shut down or reboot a target system remotely to interrupt availability, often as a prelude to or consequence of destructive actions.
Detects the creation or modification of inbox rules in Office 365/Exchange that configure email forwarding or redirection to external domains. Attackers often use these rules to exfiltrate email data or maintain persistence within an environment by redirecting communications to attacker-controlled accounts.
Detects outbound network connections to well-known public DNS-over-HTTPS (DoH) providers (e.g., Google, Cloudflare, Quad9) from processes other than standard web browsers. This behavior is often associated with adversary attempts to bypass local DNS monitoring or security controls by tunnelled traffic over HTTPS.
Detects the use of known named pipes associated with Cobalt Strike post-exploitation frameworks, often used for inter-process communication during beaconing or lateral movement.
Detects attempts to stop or disable critical security, backup, and logging services on Windows systems using command-line utilities (net.exe, sc.exe) or PowerShell. Adversaries frequently perform these actions to impair defensive monitoring, bypass security controls, or prepare the system for destructive activities like ransomware deployment.
