
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,049 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of the Windows runas command using the /savecred flag. This flag instructs Windows to save the supplied credentials locally, which can be abused by unauthorized users to elevate privileges or execute processes in the context of a saved account without providing a password again.
Detects DNS queries with exceptionally long request strings (30 characters or more), which is a common indicator of DNS tunneling or command and control (C2) communication. Adversaries often encode data within the subdomain portion of a DNS query to bypass network security controls.
Detects the execution of net.exe or net1.exe with command line arguments used to enumerate domain users, domain groups, or local administrators. This pattern is commonly used by adversaries for discovery of accounts and permission groups within a Windows environment.
This rule monitors for three categories of potentially suspicious network behavior: connections to common CDN providers over non-standard ports, high-volume HTTPS connections directly to IP addresses (IP-direct) bypassing standard domain resolution, and high-volume traffic to CDN infrastructure that may indicate domain fronting or C2 communication. Such patterns are often used by adversaries to mask egress traffic or exfiltrate data.
This rule detects potentially malicious activities related to Active Directory Certificate Services (AD CS). It identifies suspicious certificate export commands (certutil, PowerShell), non-privileged processes writing to system certificate stores, and dangerous AD CS enrollment patterns such as Subject Alternative Name (SAN) modifications, often associated with ESC1 privilege escalation techniques.
Detects the creation or modification of scheduled tasks using the schtasks.exe utility initiated by a process not signed by Microsoft. This behavior is often associated with adversary attempts to establish persistence or automate malicious code execution.
Detects the use of built-in Windows utilities (vssadmin, wmic, wbadmin) to delete shadow copies or backup catalogs. This activity is commonly associated with ransomware and data destruction attacks aiming to inhibit system recovery.
Detects modifications to Windows Defender registry keys intended to disable core security features, including real-time monitoring and threat reporting, when performed by non-Microsoft signed processes.
Detects the creation or modification of scheduled tasks using the schtasks.exe utility initiated by a process not signed by Microsoft. This behavior is often associated with adversary attempts to establish persistence or automate malicious code execution.
Detects the use of the Windows attrib.exe utility to set the hidden file attribute (+h) on files. Adversaries often use this technique to hide malicious files, scripts, or directories from standard file browsing tools to evade detection. The rule includes an exclusion for processes signed by Microsoft to reduce noise from legitimate system operations.
