
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for unauthorized access to the Google Chrome 'Login Data' database file by processes other than standard browser executables. It also detects the creation of known file artifacts associated with credential-stealing malware or RATs (e.g., 'chrome_logins_dump.txt' or 'gather.tar.gz'), which are indicative of credential harvesting activities.
Detects the use of npm to install known malicious npm packages, which is indicative of a supply chain compromise attempt via typosquatting or malicious dependency injection.
Detects the execution of PowerShell with an encoded command flag when spawned directly from explorer.exe or cmd.exe. This pattern is frequently used in 'ClickFix' style attacks where users are tricked into copying and pasting malicious, obfuscated PowerShell code into the Windows run dialog or command prompt.
Detects the abuse of the legitimate Windows utility certutil.exe to download files or perform encoding/decoding operations. These techniques are commonly used by attackers to stage malicious payloads, obfuscate files to bypass security controls, or retrieve additional malware components in multi-stage loader chains.
Detects potential BaoLoader drive-by compromise attempts by monitoring two stages: first, the creation of executable files in temporary or application data directories by browser processes; and second, the execution of command-line shells by processes running from those same directories where the browser acted as the grandparent.
Detects instances where common web browsers (Chrome, Edge, Firefox, Brave) spawn command-line tools or script interpreters (cmd, PowerShell, wscript, mshta) as child processes. This behavior is highly indicative of drive-by download attacks, including the 'ClickFix' technique, where users are socially engineered into executing malicious commands under the guise of fake browser updates or error resolution.
Detects the execution of PowerShell with an encoded command flag when spawned directly from explorer.exe or cmd.exe. This pattern is frequently used in 'ClickFix' style attacks where users are tricked into copying and pasting malicious, obfuscated PowerShell code into the Windows run dialog or command prompt.
Detects the abuse of the legitimate Windows utility certutil.exe to download files or perform encoding/decoding operations. These techniques are commonly used by attackers to stage malicious payloads, obfuscate files to bypass security controls, or retrieve additional malware components in multi-stage loader chains.
Detects the use of .NET reflection methods within PowerShell process command lines. These methods, such as System.Reflection.Assembly.Load, are commonly used by attackers for fileless execution of malicious .NET assemblies directly in memory, bypassing disk-based security controls.
Detects the execution of known Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Action1) from user-writable directories such as Temp, Downloads, or INetCache. Adversaries frequently utilize these legitimate remote access tools to establish persistence or command-and-control channels, often dropping them into temporary directories to avoid detection.
