
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where the Windows binary fodhelper.exe spawns various shell or utility processes. This behavior is a common indicator of a User Account Control (UAC) bypass attack, where the attacker leverages the auto-elevation property of fodhelper.exe to execute arbitrary commands with higher privileges.
Detects the use of the netsh.exe utility to modify Windows Advanced Firewall settings, specifically disabling profiles or adding/deleting firewall rules. This activity is often used by adversaries to impair security controls on a compromised host.
Detects common web server processes (IIS, Apache, Nginx, PHP, Tomcat) spawning command-line interpreters or utilities (cmd.exe, powershell.exe, wscript.exe, cscript.exe, certutil.exe). This pattern is often indicative of exploitation of a web application to gain command execution on the host.
This rule detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate file transfer jobs. These tools can be abused by adversaries to download malicious payloads or exfiltrate data, often bypassing standard firewall restrictions. The rule specifically filters out legitimate Microsoft-signed processes to reduce noise.
Detects the creation or modification of Windows Registry Run keys (Run/RunOnce) by processes other than those signed by Microsoft Corporation. This is a common technique used to maintain persistence by executing programs automatically upon user logon.
This rule detects common Kerberoasting activities by monitoring for the execution of 'Rubeus' or 'GetUserSPNs' (often associated with Impacket) in process command lines. These tools are commonly used by attackers to request service tickets for service accounts, which can then be cracked offline to recover passwords.
This rule detects the use of 'wmic.exe' with the '/format' switch to execute XSL files, or the direct execution of 'msxsl.exe'. These methods are common techniques used by adversaries to bypass security controls by executing arbitrary scripts embedded within XSL files, often fetched from remote locations or local paths.
Detects the use of Windows utilities 'nltest.exe' and 'dsquery.exe' with specific command-line arguments to enumerate Active Directory domain trust relationships. This behavior is indicative of an attacker attempting to map the network environment to identify targets for lateral movement.
Detects instances where common Windows processes (explorer.exe, svchost.exe, dllhost.exe) load an unsigned module (DLL) from user-writable directories, such as AppData, Downloads, or Temp folders. This behavior is a common indicator of potential DLL sideloading or malicious code execution originating from user-controlled space.
Detects the execution of known Active Directory discovery tools, specifically 'adfind.exe' or 'dsquery.exe' with arguments targeting user or group enumeration. These tools are commonly used by adversaries during the reconnaissance phase to map domain structure.
