
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation of scheduled tasks using schtasks.exe or at.exe by processes not signed by Microsoft. This behavior is often associated with adversary attempts to establish persistence by running code on a recurring basis or at specific times using native Windows utilities.
Detects the use of BITSAdmin to download files from remote URLs. Attackers frequently abuse BITSAdmin, a legitimate Windows administrative tool, to download malicious payloads or secondary tools from external servers.
Detects modifications to the 'Software\Classes\ms-settings\shell\open\command' registry key, a technique commonly used to bypass User Account Control (UAC). By setting the default handler for the ms-settings protocol to a malicious command, an attacker can achieve elevated execution when the protocol is triggered by a legitimate Windows component.
This rule detects the use of 'wmic.exe', 'powershell.exe', or 'pwsh.exe' to interact with WMI event consumers (ActiveScriptEventConsumer or CommandLineEventConsumer) and filter bindings. Adversaries use these WMI components to establish persistence by executing malicious code when specific system events occur, such as a process start or a scheduled time trigger.
Detects the creation of scheduled tasks using schtasks.exe or at.exe by processes not signed by Microsoft. This behavior is often associated with adversary attempts to establish persistence by running code on a recurring basis or at specific times using native Windows utilities.
Detects emails successfully delivered to the inbox that exhibit authentication failures for SPF, DKIM, or DMARC, or where a mismatch between the 'SenderFromDomain' and 'SenderMailFromDomain' is observed, indicating potential email spoofing or unauthorized sender impersonation.
Detects common web server processes (IIS, Apache, Nginx, PHP, Tomcat) spawning command-line interpreters or utilities (cmd.exe, powershell.exe, wscript.exe, cscript.exe, certutil.exe). This pattern is often indicative of exploitation of a web application to gain command execution on the host.
Detects the creation or modification of Windows Registry Run keys (Run/RunOnce) by processes other than those signed by Microsoft Corporation. This is a common technique used to maintain persistence by executing programs automatically upon user logon.
Detects the execution of common command-line utilities (cmd, powershell, wscript, cscript, mshta, certutil) directly spawned by Microsoft Office applications (Word, Excel, PowerPoint, Outlook). This is a common indicator of macro-based attacks or other exploit delivery chains where Office documents are used to execute malicious payloads.
This rule detects potentially malicious use of the ClickOnce process (dfsvc.exe) by monitoring for suspicious parent processes (such as rundll32.exe or mshta.exe) spawning dfsvc.exe, or dfsvc.exe spawning unexpected child processes. ClickOnce is often abused by attackers to proxy the execution of malicious code, and these patterns are indicative of such activity.
