
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,043 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule identifies potential ransomware activity by detecting a process performing a high volume of file rename or modification operations within a short time window. It specifically targets files with known ransomware extensions or those using randomized 6-8 character alphanumeric extensions, while excluding common administrative, backup, and temporary file operations performed by trusted software.
Detects network and process execution activity involving Google or Microsoft OAuth2 token endpoints from non-browser and non-trusted processes. This behavior is indicative of potential token theft or session hijacking attempts, where malicious tools (e.g., curl, python) are used to access authentication endpoints to bypass standard user interaction.
Detects the execution of known adversary-in-the-middle (AiTM) phishing frameworks, such as Evilginx or Modlishka, by identifying process names, paths, or specific command-line arguments (e.g., --phishlets, --proxy, --lure) used to initiate these proxy-based phishing sessions.
This rule detects the creation of a 'logs.dat' file, which is often associated with Remcos RAT for data exfiltration, in common user-related directories (AppData, Temp, Users, Documents) with a file size greater than or equal to 100KB. This pattern suggests an attempt to stage or exfiltrate collected data.
This rule detects the execution of Windows Script Host (wscript.exe or cscript.exe) where the initiating parent process is not a common legitimate process like explorer.exe, cmd.exe, powershell.exe, svchost.exe, or system.exe, and is also not a web browser (Chrome or Firefox). This pattern can indicate an attempt to execute malicious VBScript or JScript files, potentially delivered via phishing, where the script is launched by an unusual or obfuscated parent process to evade detection.
Detects potential Command and Control (C2) communication associated with Emotet malware by monitoring for successful network connections to suspicious remote ports frequently used by the malware. The rule flags endpoints that establish connections to at least three of these high-risk ports within a one-hour window, which is indicative of automated C2 beaconing behavior.
This rule monitors Cisco Unified Communications Manager (UCM) environments for multiple stages of an attack chain, including potential Server-Side Request Forgery (SSRF) attempts against administrative interfaces, suspicious file modifications by service accounts, indicators of privilege escalation, and anomalous outbound network connections from core Cisco processes.
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
This rule detects AppDomainManager injection attempts by monitoring for the loading of suspicious DLLs (related to AppDomainManager functionality) by specific processes or from unexpected file paths. The rule specifically targets attempts to hijack the .NET AppDomainManager class by checking against known suspicious filenames and excluding legitimate .NET framework directories, which is a common technique used for arbitrary code execution in the context of a target process.
Detects the creation of specific scheduled tasks associated with LoaderClient or WeedHack malware. These tasks, named 'JMonitoringTask' or 'JavaSecurityUpdater', are used for persistence and recurring execution of malicious code.
