
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network connections to a specific suspicious IP address (94.156.181.89) or to domains associated with Cloudflare Tunnel (.trycloudflare.com). This could indicate command and control activity, data exfiltration, or other malicious network communication.
This rule detects the presence of MicroStealer malware by matching known MD5, SHA1, or SHA256 hashes of its binaries against file events on monitored devices. MicroStealer is a credential stealer that targets various applications to exfiltrate sensitive information.
This rule detects a high volume of UDP network connections originating from a single process on a device. A count exceeding 50 UDP connections from the same process to the same remote IP address is considered anomalous and could indicate a UDP flood or other denial-of-service attempt.
This rule detects the presence of the string "xhxhxhxhxhxpp" within the AdditionalFields of DeviceEvents. This string =represents a Mutex Indicator of Compromise (IOC).
This rule detects the execution of 'REAGENTC.EXE' with the '/disable' argument and 'WBADMIN.EXE' with 'delete catalog -quiet' within a 10-minute window on the same device. This combination of commands is indicative of an adversary attempting to inhibit system recovery by disabling Windows Recovery Environment and deleting the Windows Backup Catalog, often seen in ransomware attacks.
Detects the creation of an MSI (Microsoft Installer) file on a device where the file's origin referrer URL indicates it was downloaded from a ZIP archive that was originally an email attachment. This could indicate a user opening a malicious ZIP file from an email, leading to the execution of an installer.
A detection triggered on endpoint events where common system binaries (e.g., mshta.exe, powershell.exe, cmd.exe) were launched by user-facing parent processes (explorer.exe, chrome.exe, msedge.exe, firefox.exe, iexplore.exe) and executed suspicious command-lines. The pattern matches the evolving technique used in ClickFix-style campaigns whereby malicious pages dynamically place payloads into the clipboard and prompt users to paste or execute them.
Detects the execution of 'conhost.exe' with the '--headless' argument, specifically when initiated by 'pcalua.exe'. This combination has been observed in attacks by the GOLD BLADE threat group for indirect command execution.
Detects DLL side-loading attacks where consent.exe loads known malicious DLLs (version.dll, rtworkq.dll, wmsgapi.dll, and the older msimg32.dll) from non-standard locations. This technique is used by Shanya-packed malware including EDR Killer and CastleRAT to load malicious payloads while appearing as a legitimate Windows UAC process.
This rule detects inbound emails that appear to be Microsoft Teams invitations but contain suspicious keywords in the subject line related to financial transactions (invoice, billing, payment, renewal, charge). This could indicate a phishing attempt where adversaries leverage legitimate-looking Microsoft invitation emails to deliver financially themed lures.
