
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects potential abuse of Active Directory Certificate Services (AD CS) by monitoring for suspicious command-line activity from 'certreq.exe' and 'certutil.exe' associated with certificate enrollment, submission, or management. It also identifies the staging of certificate-related files (.pem, .pfx, .p12, .crt, .cer, .key) in common user directories.
This rule detects the use of Regsvr32.exe to execute remote scriptlets (.sct files) from external HTTP/HTTPS URLs by loading the scrobj.dll module. This technique, commonly known as 'Squiblydoo', is used to bypass application allowlisting (such as AppLocker) and proxy execution of malicious code.
This rule detects instances where PowerShell or PowerShell Core (pwsh.exe) are spawned as child processes of common COM object host processes (e.g., wscript.exe, mshta.exe, rundll32.exe). The detection specifically looks for command-line arguments containing encoded commands or indicators of download cradles (e.g., IEX, Net.WebClient, DownloadString), which are common patterns for fileless execution and malicious script staging.
This rule detects when a user clicks on a URL that contains a domain identified as malicious. The rule specifically looks for `UrlClickEvents` where the extracted domain from the URL matches any of the domains listed in the `malicious_domains` array. This can indicate a successful phishing attempt or an accidental click on a known malicious link.
Detects when 'Cursor.exe' (a legitimate application) spawns common command-line utilities (cmd.exe, powershell.exe, pwsh.exe, curl.exe, wget.exe, certutil.exe, bitsadmin.exe) with command-line arguments indicative of downloading files from the internet (e.g., containing 'http://', 'https://', 'ftp://', '-o', '-OutFile', 'iwr', 'DownloadString', 'DownloadFile'). This could indicate malicious activity where 'Cursor.exe' is being abused to facilitate ingress tool transfer or execute malicious payloads.
Detects inbound emails originating from 'azure-noreply@microsoft.com' with subjects that typically indicate financial transactions (e.g., 'Invoice Paid', 'Payment Reference') or system alerts (e.g., 'MemorySpike', 'DiskFull'). This pattern could be indicative of phishing attempts leveraging a seemingly legitimate sender to trick recipients.
This rule detects when the 'oskmenu.xml' file, located in 'C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions', is accessed or modified by any process not running under the SYSTEM account. This file is associated with the On-Screen Keyboard and its modification by non-system accounts could indicate an attempt to alter its behavior, potentially for persistence or privilege escalation.
This rule detects successful SSH authentications using the GSSAPI-with-MIC mechanism. This can indicate legitimate user logins or, in some cases, an adversary using valid credentials to access a system via SSH.
Detects multiple failed SSH login attempts from a single source IP address, indicating a potential brute force attack. The rule identifies 'Invalid user' or 'Failed password' messages in syslog from the 'sshd' process and groups them by source IP and time to count unique attempted users and total attempts. A threshold of more than 5 attempted users from a single source IP within a 10-minute window triggers an alert.
This rule detects attempts to manipulate user or service principal names (SPN/UPN) in Active Directory by adding non-ASCII or zero-width characters. Such modifications can be used by adversaries for obfuscation, to bypass detection mechanisms, or to create stealthy persistence. The rule specifically looks for Event IDs 4738 (User Account Changed) and 5136 (Directory Service Object Modified) where the 'servicePrincipalName' or 'userPrincipalName' attributes contain characters outside the standard ASCII range or zero-width characters like U+200B, U+200C, U+200D.
