
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of sensitive ESXi administrative commands (e.g., esxcli, vim-cmd) that suggest potential hypervisor management or tampering, especially when initiated by non-administrative processes or specific shells.
This rule correlates multiple low-to-medium confidence signals across file, process, network, and registry events to detect potential ransomware activity. The rule identifies suspicious behaviors including mass file renames, creation of known ransom note file types in multiple directories, shadow copy deletion via system utilities, disabling of antivirus and security monitoring, large archive staging, unauthorized outbound network connections, and suspicious process injection. Alerts are generated based on the aggregation and frequency of these signals, indicating a high probability of ransomware-related malicious activity.
Detects a multi-stage attack pattern associated with the Qilin ransomware, beginning with suspicious VPN authentication (potential credential stuffing or bypass), moving through lateral movement attempts (SMB/RDP/WMI), and culminating in ransomware behaviors such as shadow copy deletion, mass file encryption, and ransom note creation.
Detects outbound network connections to common Azure-related domains originating from suspicious file paths such as Temp, Downloads, or AppData subdirectories. This behavior is indicative of potential malware or unauthorized scripts executing from temporary user locations to reach out to cloud infrastructure.
Detects instances where the Outlook process (OUTLOOK.EXE) initiates a network connection via port 445 (SMB) to an IP address that is not part of the internal private network ranges. This activity is highly anomalous for an email client and may indicate exploitation, data exfiltration, or attempts to relay NTLM credentials to a remote malicious SMB server.
Detects the use of rundll32.exe to process files with common image extensions (.jpg, .jpeg, .png, .bmp, .gif). This behavior is often associated with steganography or attempts to disguise malicious payloads by masquerading them as image files.
Detects network connections to Google Cloud services (calendar.google.com, googleapis.com) over port 443 originating from processes other than known web browsers or standard Google background applications. This behavior may indicate unauthorized tools, custom scripts, or malware using Google services for command and control or data exfiltration.
Detects the modification of the 'LoadMacroProviderOnBoot' registry value in Microsoft Outlook. Enabling this setting can cause Outlook to load macros upon startup, which is a technique often leveraged for persistence or malicious code execution.
Detects modifications to the Outlook Security registry key, specifically setting the 'Level' value to '1'. This configuration (often associated with 'OutlookSecurityMode' or related programmatic access policies) can be used by adversaries to bypass security prompts when accessing the Outlook Object Model, allowing malicious scripts or applications to interact with Outlook to send emails, harvest contacts, or access attachments without user intervention.
This rule detects the creation or modification of a COM object registry key under HKEY_CURRENT_USER\Software\Classes\CLSID\ with an 'InProcServer32' subkey. This is a common technique used by adversaries for persistence and privilege escalation by hijacking COM object references to execute arbitrary malicious code when the legitimate application attempts to use the hijacked COM object.
