
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects when a single account initiates a high volume of Office file (Word, Excel, PowerPoint) copy or move operations within a one-hour window. This could indicate data exfiltration or staging activities.
Detects web application processes accessing .env files shortly after execution activity. Bissa Scanner harvested environment files immediately after successful exploitation to collect secrets and credentials.
Detects abuse of the applescript:// execution mechanism used by newer ClickFix variants to bypass Apple's Terminal paste protections.
Detects the creation or modification of WMI event subscriptions via EventID 5861 from the Microsoft-Windows-WMI-Activity log. This activity, involving EventFilters, EventConsumers, or FilterToConsumerBindings, is a well-known technique used by adversaries to establish persistence and achieve execution triggered by system events, often resulting in elevated SYSTEM privileges.
Detects updates or deletions of Azure Active Directory (Entra ID) Conditional Access policies that occur outside of typical business hours (Monday-Friday 08:00-18:00 UTC). Such modifications can be an indicator of an adversary attempting to circumvent security controls or maintain persistent, unauthorized access.
This rule detects the use of PowerShell commands that leverage Windows Forms or GDI APIs (e.g., System.Windows.Forms.Screen, System.Drawing.Bitmap, CopyFromScreen) to perform screen capture. Adversaries often use these native .NET capabilities to capture desktop screenshots during post-exploitation.
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
Detects attempts to terminate security-related processes or stop security-related services using common administrative tools like taskkill.exe, sc.exe, net.exe, or net1.exe. This activity is often indicative of an adversary attempting to disable security monitoring and protection software to facilitate further malicious actions.
This rule detects the installation of known vulnerable kernel drivers (Bring Your Own Vulnerable Driver - BYOVD). These drivers are often exploited by adversaries to gain kernel-level code execution, elevate privileges, or disable security tools (EDR).
Detects the use of NTFS Alternate Data Streams (ADS) by monitoring process command lines, initiating process command lines, and folder paths for patterns indicative of ADS notation. The rule specifically flags potential execution or access patterns involving common script interpreters (wscript, cscript, powershell, pwsh) combined with ADS, as well as general ADS usage in file paths.
