
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) when initialized with an INF file from potentially suspicious directories (e.g., Temp, AppData), or when cmstp.exe is observed spawning common command-line shells (cmd.exe, powershell.exe) or rundll32.exe, which is indicative of potential proxy execution or UAC bypass techniques.
Detects suspected malicious activity associated with the Dropping Elephant threat group. The rule monitors for two behaviors: 1) IP address geolocation fingerprinting by identifying non-browser processes communicating with ipify.org and ip2c.org within a 60-second window, and 2) Direct network connections to known Dropping Elephant C2 domains, specifically gcl-power.org and chinagreenenergy.org.
This rule detects anomalous network connections or DNS queries to known Ethereum RPC infrastructure providers (Infura, Alchemy, Cloudflare-eth) or ports/domains associated with Ethereum mainnet activity. It specifically targets processes other than common browsers or known blockchain clients, as well as Java-based processes performing DNS lookups for these domains. This behavior is indicative of potential 'EtherHiding' techniques where malicious code or data is hidden within blockchain transactions or distributed via blockchain infrastructure.
Detects the creation of specific scheduled tasks associated with LoaderClient or WeedHack malware. These tasks, named 'JMonitoringTask' or 'JavaSecurityUpdater', are used for persistence and recurring execution of malicious code.
This rule detects file creation or modification events associated with the Miasma campaign. It identifies specific payload files (e.g., .claude/setup.mjs, .vscode/tasks.json), the use of specific marker strings in file metadata or origin URLs, and obfuscated task configurations in VS Code directories that leverage bun or node to execute base64-encoded or character-encoded commands.
Detects anomalous network communication patterns and file system changes indicative of SoftEther VPN usage, particularly when linked to processes masquerading as VMware or communicating with known malicious C2 infrastructure. The rule monitors for network connections on common SoftEther ports, connections to specific command-and-control IP addresses, and the creation of SoftEther configuration files like 'hamcore.se2' or 'vpn_bridge.config'.
This rule detects potential Mythic C2 implant or payload build activity occurring via Docker. It monitors for executions of docker.exe, docker-compose.exe, or docker commands initiated by shells (cmd.exe, powershell.exe) containing keywords associated with the Mythic C2 framework, while explicitly excluding common CI/CD runner parent processes to reduce noise.
Detects anomalous, high-volume data transfers to Telegram API endpoints (api.telegram.org, specific IP ranges), which is indicative of data exfiltration by malware such as KuinaExtractor. The rule monitors for cumulative outbound traffic exceeding 500MB within a 1-hour session window per process.
This rule detects potential Mythic C2 implant or payload build activity occurring via Docker. It monitors for executions of docker.exe, docker-compose.exe, or docker commands initiated by shells (cmd.exe, powershell.exe) containing keywords associated with the Mythic C2 framework, while explicitly excluding common CI/CD runner parent processes to reduce noise.
Detects process activity indicative of keylogging by the Remcos RAT loader. The rule specifically looks for processes with 'Remcos' or 'GST*.com' in their file name that also contain command-line arguments related to capturing window text or foreground window information, which are common keylogger behaviors.
