
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potential Business Email Compromise (BEC) attempts by identifying emails containing financial keywords sent to sensitive finance/accounting roles from domains that have not been observed in the last 180 days. It then correlates this email event with subsequent device-level network activity involving banking or financial URLs initiated by the recipient user, which may indicate follow-up reconnaissance or unauthorized access.
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
Detects the execution of native Windows utilities (vssadmin, wbadmin, bcdedit, diskshadow) configured to delete volume shadow copies, remove backup catalogs, or disable automatic recovery features. This activity is a common indicator of ransomware preparation to prevent data recovery.
Detects anomalous behavior associated with msiexec.exe that aligns with activity patterns of infostealer malwares like Lumma Stealer and Amadey Bot. This includes cross-process injection from unsigned processes, spawning of msiexec.exe by LOLBins or script interpreters, suspicious outbound network connectivity, and unauthorized access to browser credential storage files.
This rule detects DNS queries with suspicious characteristics that may indicate DNS tunneling, data exfiltration, or command and control activity. It identifies queries with unusually long names, long first labels combined with high entropy, or a high number of subdomains combined with a long first label. Exclusions are made for common legitimate DNS suffixes and specific service-related domains.
Detects unauthorized attempts to terminate, stop, or access Endpoint Detection and Response (EDR) or Antivirus agent processes. This is identified by monitoring command-line utilities like taskkill, net, and sc targeting known security service names, as well as detecting suspicious cross-process access (e.g., OpenProcess) by unauthorized processes targeting security agent PIDs.
Detects the use of native Windows binaries 'netsh.exe' to establish port proxies or 'pktmon.exe' for network packet monitoring/filtering by processes that are not signed by Microsoft. This behavior is indicative of network tunneling or C2 communication techniques used by actors such as Volt Typhoon to maintain persistence and establish network pivots.
This rule detects indicators of WMI event subscription persistence, including the creation of WMI event filters, consumers, and bindings. It monitors for the use of command-line tools like wmic, powershell, or mofcomp to manipulate WMI objects, and identifies suspicious process activity originating from WMI provider host or consumer processes.
Detects unauthorized processes attempting to access or perform operations on sensitive files such as browser credentials, SSH keys, crypto wallets, and password manager databases. The rule specifically looks for non-standard or unsigned processes interacting with a high volume of these files in a short time frame, which is indicative of credential harvesting by infostealer malware like Lumma, Redline, or Vidar.
Detects unauthorized access to Windows Credential Manager files, TokenBroker OAuth cache files, or the loading of crypt32.dll from suspicious, user-writable directories (e.g., Temp, Downloads, Desktop) by non-Microsoft or non-system processes. This activity is indicative of credential theft, session hijacking, or attempts to abuse the Windows Data Protection API (DPAPI) to decrypt sensitive local secrets.
