
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects potential financial data exfiltration by monitoring for bulk downloads of files with financial keywords from SaaS/Office365 platforms, and identifies unauthorized processes attempting to access sensitive financial application data files (.qbw, .qbb, etc.) on local systems.
This rule detects potential exploitation activity related to CVE-2026-45657 involving the Windows Kernel tcpip.sys driver. It monitors for a combination of system crashes (Kernel-Power 41 or EventLog 6008) correlated with Windows Error Reporting (WER) events referencing 'tcpip.sys', or significant spikes in external authentication attempts occurring shortly before a system crash. The rule aims to identify potential remote code execution attempts manifesting as kernel instability.
Monitors IIS web servers for signs of potential exploitation by tracking suspicious child processes spawned by worker processes (w3wp.exe/iisexpress.exe), tracking unexpected WER (Windows Error Reporting) crashes associated with IIS workers, aggregating IIS-related application crashes, and detecting anomalous W3C IIS log request patterns (e.g., malformed content-length, negative bytes, or suspicious URI characteristics).
This rule detects potential privilege escalation activity associated with the abuse of CTFMON related objects (named pipes, symlinks, junctions) which may be used in conjunction with high-privilege operations (like SeDebugPrivilege or SeImpersonatePrivilege) to elevate access to SYSTEM. It correlates access events for CTF objects by processes (other than the legitimate ctfmon.exe) with subsequent sensitive privilege assignments within a short time window.
Detects anomalous activity associated with information stealing malware, including unauthorized access to browser credential files (Login Data, Cookies), remote thread injection into browser processes, outbound connections to the Telegram API by non-browser processes, and rapid bulk access to multiple sensitive credential or crypto wallet files.
Detects the execution of the 'diagnose sniffer packet' command on FortiOS devices. This command can be abused by malware, such as FortigateSniffer, to intercept authentication traffic, as observed in campaigns like FortiBleed.
Detects network activity associated with Cobalt Strike Beacon behavior by identifying specific file extensions (.bin, .stager, .update, .task, .post) commonly used in Beacon staging and communication profiles within network inspection events.
Detects attempts to clone or snapshot sensitive virtual machines (such as Domain Controllers, PKI, Vault, ADFS, or SSO servers) in a VMware environment. The rule alerts on these activities when performed by non-administrator accounts outside of established maintenance windows, suggesting potential unauthorized data staging or credential extraction.
Detects the execution of major web browsers (Chrome, Firefox, Internet Explorer) with command line arguments containing keywords related to browser extensions, addons, or plugins. This pattern is often used to load unauthorized or malicious extensions for persistence or browser hijacking.
Detects the creation of WMI Event Subscriptions using wmic.exe or scrcons.exe. Adversaries can use WMI event subscriptions to achieve persistence by executing malicious code when a specific event occurs, such as system boot or user logon.
