
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,031 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation of user accounts or modifications to sensitive groups (Event IDs 4720, 4728, 4732, 4756) where the account name matches naming conventions typically associated with backup service accounts or elevated administrative roles (e.g., prefix 'backup_', 'bkp_' or suffix '_da', '_ea'). This activity can indicate an attacker attempting to establish persistence or escalate privileges via compromised or newly created accounts.
Detects the creation or modification of Windows Registry keys or values within the 'CurrentControlSet\Services' path that refer to 'rustdesk'. This typically indicates the installation or configuration of the RustDesk remote access tool as a system service, which may be unauthorized or used for persistence by an adversary.
Detects instances where the legitimate Windows binary 'consent.exe' loads the library 'msimg32.dll' from a non-standard location (outside of System32 or SysWOW64). This behavior is characteristic of DLL sideloading techniques used by the BumbleBee malware loader to execute malicious code within the context of a trusted system process.
Detects web server processes (e.g., httpd, nginx) spawning common shell interpreters (sh, bash, cmd.exe) that execute suspicious commands often used in reconnaissance or download stages of an attack, such as 'whoami', 'wget', or 'curl'. This behavior is characteristic of an exploited web application being used as a staging or command-and-control pivot point.
This rule monitors Microsoft IIS access logs for unauthenticated POST requests targeting the '/accessv2' endpoint from non-private, external IP addresses. This activity may indicate an attempt to exploit a public-facing application, potential web shell interaction, or unauthorized access attempts.
Detects attempts to clone or snapshot sensitive virtual machines (such as Domain Controllers, PKI, Vault, ADFS, or SSO servers) in a VMware environment. The rule alerts on these activities when performed by non-administrator accounts outside of established maintenance windows, suggesting potential unauthorized data staging or credential extraction.
This rule detects suspicious process creations where common system processes (svchost.exe, explorer.exe, lsass.exe, winlogon.exe) act as parent processes for scripting or command-line interpreters (powershell.exe, cmd.exe, cscript.exe, wscript.exe) and the child process runs with a low or untrusted integrity level. This pattern can indicate process injection or other forms of malicious execution where an attacker attempts to hide their activity by masquerading as legitimate system processes.
This rule detects suspicious execution of rundll32.exe by looking for multiple instances of rundll32.exe executing with command lines containing both '.dll' and '/' characters from the same computer and account. This pattern can indicate an adversary attempting to proxy execution of malicious code via rundll32.exe.
This rule detects the creation or modification of executable files (.exe, .dll, .sys) within critical Windows system directories (C:\Windows\System32\ or C:\Windows\SysWOW64\). Such activity can indicate an attempt to establish persistence, elevate privileges, or inject malicious code into legitimate system processes.
This rule detects suspicious activity related to browser extension installations by monitoring registry modifications. Specifically, it looks for multiple registry value sets within Chrome or Firefox extension paths within a short timeframe (1 hour), which could indicate an automated or malicious installation of browser extensions.
