
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,031 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects workstations establishing multiple connections to non-standard, internal management ports (SSH, Telnet, SNMP). This behavior is often associated with lateral movement or unauthorized network scanning using tools that leverage management protocols.
This rule detects a multi-stage loader chain behavior. Stage 1 identifies PowerShell spawning mshta.exe or wscript.exe, which is commonly used to execute malicious scripts or loaders. Stage 2 detects mshta.exe or wscript.exe subsequently executing schtasks.exe or wmic.exe with command-line arguments indicative of establishing persistence via scheduled tasks or WMI event subscriptions.
Detects potential internal network scanning activity by identifying devices attempting connections to 5 or more distinct sensitive ports within a one-hour window. This behavior is indicative of reconnaissance activities aimed at identifying vulnerable services such as SSH, SMB, RDP, or various database management systems.
Detects network connections to Microsoft OneDrive or SharePoint domains from processes that are not standard, known-good applications (e.g., browsers or standard sync clients). This behavior may indicate an adversary leveraging cloud storage for command-and-control (C2) operations or data exfiltration.
This rule detects a sequence of suspicious activities: the creation or modification of an executable file (.exe or .dll) within a directory path containing update-related keywords, followed by the execution of a file in that same location, and culminating in an outbound network connection from that process. This pattern is characteristic of a software supply chain compromise or an adversary deploying a malicious payload via a fake or compromised update mechanism.
This rule detects command line execution containing keywords associated with offensive security tools (e.g., 'metasploit', 'exploit', 'shellcode', 'payload') in conjunction with external resource indicators such as HTTP/HTTPS or FTP URLs, suggesting the download and potential execution of malicious payloads.
Detects the use of PowerShell, PWSH, or CMD to modify file system timestamps, a technique commonly referred to as timestomping. This is often used by adversaries to hide malicious file activity or blend in with legitimate system files by manipulating file creation, modification, or access time metadata.
Detects the creation of Kubernetes pods where the 'hostPID' or 'hostNetwork' settings are enabled. These configurations allow a pod to share the host's process namespace or network stack, respectively, which are common vectors for container escapes and host-level privilege escalation.
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.
This rule detects potential clipboard data theft by monitoring Windows Sysmon Event ID 10 for process access events involving clipboard-related APIs (OpenClipboard, GetClipboardData) by untrusted processes, and PowerShell Script Block Logging (Event ID 4104) for the use of Get-Clipboard cmdlets. This identifies attempts by non-standard or unauthorized processes to access sensitive information copied by a user.
