
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,065 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the abuse of MSBuild.exe to execute arbitrary code. The rule monitors for three primary suspicious behaviors: MSBuild spawning suspicious child processes indicative of inline task execution, MSBuild being launched with project file arguments from non-standard or untrusted parents, and MSBuild being launched without a project file (implying piped or inline payload delivery).
Detects instances where the Windows script hosts wscript.exe or cscript.exe establish outbound network connections to common web ports (HTTP/HTTPS) on external IP addresses. This behavior is frequently associated with script-based malware, droppers, or C2 beacons.
Detects the creation of a new scheduled task using the Windows native schtasks.exe command-line utility. This behavior is commonly associated with persistence mechanisms or lateral movement activities where attackers schedule tasks to execute malicious payloads.
Detects the use of regsvr32.exe to load a remote COM scriptlet via a URL. This technique, commonly known as Squiblydoo, allows adversaries to bypass application whitelisting and proxy the execution of malicious code, as regsvr32.exe is a trusted Windows binary.
Detects modifications or creations of registry values within common Windows auto-start locations, specifically the 'Run' and 'Winlogon' keys. These locations are frequently abused by adversaries to maintain persistence on a host. The rule excludes common, legitimate installer and administration processes to reduce noise.
Detects the use of the Windows net.exe or net1.exe utility to query network shares or session information, which is a common technique used by attackers for internal reconnaissance and network discovery.
Detects the execution of script files (.vbs, .js, .wsf) using Windows script hosts (wscript.exe, cscript.exe) from common user-writable directories such as Temp, Downloads, and AppData. This behavior is often indicative of malicious files being dropped by phishing attachments or drive-by downloads and subsequently executed by an adversary.
Detects abnormally long DNS queries characterized by repetitive alphanumeric patterns, which may indicate potential DNS tunneling activity used for C2 communication or data exfiltration. The rule flags DNS requests exceeding 60 characters with repeating label structures.
Detects the use of the Windows net.exe or net1.exe utility to query network shares or session information, which is a common technique used by attackers for internal reconnaissance and network discovery.
Detects the use of the BITSAdmin command-line utility to initiate file transfers from external sources to user-writable directories or temporary folders. This behavior is indicative of living-off-the-land (LotL) techniques where adversaries use legitimate system binaries to download and potentially execute malicious files.
