
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,026 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects unauthorized modifications to SSH 'authorized_keys' files or the '/etc/ssh/sshd_config' configuration file on Linux systems. These actions can be used for persistent access (key injection) or to weaken SSH security controls (e.g., enabling root login) and are typical indicators of account manipulation or compromise.
Detects the use of legitimate command-line utilities such as rclone, AWS CLI, AzCopy, curl, and wget to upload data to cloud storage endpoints, which is a common technique used for data exfiltration.
Detects when an administrator explicitly disables Unified Audit Log (UAL) ingestion for Exchange Online using the Set-AdminAuditLogConfig cmdlet. This action effectively stops the generation of audit records for Exchange administration and user activity, a critical defense evasion tactic used to conceal malicious operations.
Detects when an administrator explicitly disables Unified Audit Log (UAL) ingestion for Exchange Online using the Set-AdminAuditLogConfig cmdlet. This action effectively stops the generation of audit records for Exchange administration and user activity, a critical defense evasion tactic used to conceal malicious operations.
Detects when an application or service principal is assigned an app role containing sensitive permissions in Azure AD/Microsoft Entra ID. Such assignments can grant an application elevated access to mail, directory, or user management, which is a common tactic for persistence and privilege escalation in cloud environments.
Detects the execution of PsExec (psexec.exe or psexesvc.exe) where the binary is not digitally signed by Microsoft Corporation. This is often an indicator of renamed or tampered versions of the tool used for lateral movement or remote command execution.
Detects the abuse of the legitimate Windows binary regsvr32.exe for malicious purposes. This rule monitors for two common attack patterns: 1) The use of regsvr32.exe with specific command-line arguments (/i, /s, /u, /n) to load remote scripts (SCT files) or libraries from the internet, a technique known as 'Squiblydoo'. 2) Suspicious child processes spawned by regsvr32.exe, which often indicates follow-on malicious activity such as command shell execution or lateral movement tools.
Detects the addition of secrets or certificates to Azure service principals during non-business hours (before 7 AM or after 7 PM, or on weekends). This behavior may indicate an adversary attempting to establish persistence in a cloud environment by adding their own credentials to an existing service principal.
Detects modifications to COM object registration keys under HKEY_CURRENT_USER (HKCU) which can be used to hijack COM objects for persistence. The rule monitors for the creation or modification of InProcServer32 or LocalServer32 values, while excluding common system paths to reduce noise.
This rule detects potential ransomware activity by monitoring for two key signals: interaction with known canary/trap files designed to detect unauthorized access, and rapid, mass file modification of common user data extensions within a short timeframe. Either behavior is indicative of encryption or automated file destruction processes typical of ransomware attacks.
