
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where explorer.exe loads a DLL file from within C:\ProgramData. This behavior is often associated with adversary activity attempting to hide malicious modules in directories that may have permissive write access or are excluded from routine scans, including techniques used by Covenant frameworks or C2 agents.
Detects suspicious OpenProcess calls initiated by common user applications (explorer.exe, winword.exe, outlook.exe) targeting svchost.exe, followed by an outbound network connection from the target svchost.exe to the file sharing service filen.io within a 30-minute window. This behavior is indicative of process injection used to facilitate network communication or data exfiltration under the guise of a system process.
This rule detects the creation or modification of a COM object registry key under HKEY_CURRENT_USER\Software\Classes\CLSID\ with an 'InProcServer32' subkey. This is a common technique used by adversaries for persistence and privilege escalation by hijacking COM object references to execute arbitrary malicious code when the legitimate application attempts to use the hijacked COM object.
Detects unauthorized processes modifying the registry value 'PONT_STRING' within the Outlook Options General key. This registry value controls the display of content download warnings in Microsoft Outlook. Modifying this key from a non-Outlook process is a technique used by threat actors, such as APT28, to bypass security warnings and facilitate the execution of malicious payloads or content within Outlook.
Detects a network-connected Linux process exhibiting beaconing behavior (high-frequency external connections) that is subsequently correlated with unauthorized file access to sensitive Linux configuration files (/etc/passwd, /etc/shadow, or authorized_keys). This rule filters out common system processes and standard management binaries, targeting suspicious command-and-control activity combined with credential theft.
This rule detects potential Command and Control (C2) communication activity by identifying instances of Domain Generation Algorithms (DGA). It monitors DNS query responses for patterns consisting of 8 to 16 lowercase alphabetic characters followed by common TLDs (com, net, org, ru, cc, su). An alert is triggered if 5 or more unique suspicious domains are queried by the same device within a one-hour window.
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
Detects execution of 'netstat.exe' with specific flags ('-a', '-n', '-o', or '-b') initiated by command-line interpreters like cmd.exe, powershell.exe, wscript.exe, or cscript.exe. These flags are commonly used for network reconnaissance and discovery of active TCP connections, listening ports, and associated process IDs.
Detects when common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) load a DLL file from suspicious or user-writable locations such as AppData, Downloads, Documents, or Temp folders. The rule specifically alerts on DLLs that are unsigned or where the loading process itself is unsigned, which is a common indicator of side-loading or malicious library injection.
Detects the use of net.exe and dsquery.exe to enumerate domain user accounts and domain groups. Adversaries often perform this reconnaissance to identify target accounts or privileged groups within an Active Directory environment.
