
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,052 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or start a service on a remote host, identified by the presence of UNC paths (\\) and service management commands (create, start) in the command line.
Detects the usage of net.exe or net1.exe to enumerate domain users, groups, local administrators, and domain controllers, which is frequently indicative of post-compromise reconnaissance.
Detects Distributed Component Object Model (DCOM) lateral movement activity by monitoring for mmc.exe and dllhost.exe network connections to non-local endpoints or when these processes are spawned by suspicious parent processes typically associated with command execution or malicious behavior.
Detects the use of rundll32.exe to execute code via remote URLs, JavaScript, or specific DLL functions known to be abused for proxy execution. This behavior is commonly associated with fileless malware and living-off-the-land techniques to bypass security controls by utilizing legitimate Windows binaries.
Detects suspicious activity related to the Print Spooler service (spoolsv.exe), specifically focusing on the spawning of known command-line interpreters (cmd.exe, powershell.exe, rundll32.exe) by spoolsv.exe, as well as the creation or modification of DLL files within the system print spool drivers directory by processes other than spoolsv.exe. This activity is often associated with privilege escalation and persistence techniques involving print spooler service abuse.
Detects the creation of named pipes with names commonly utilized by offensive C2 frameworks such as Cobalt Strike, Metasploit, and Covenant. By monitoring for specific pipe naming patterns created by non-system processes, this rule aims to identify potential post-exploitation activity, C2 beacons, or lateral movement tools.
This rule detects successful self-service password reset (SSPR) operations performed by users from IP addresses geolocated to a country that does not match their typical sign-in activity over the past 30 days. This behavior may indicate account takeover where an adversary has compromised credentials and is resetting the password to maintain access or gain further persistence.
This rule detects successful sign-ins using the OAuth 2.0 Device Code Flow. This flow is often abused in phishing attacks (device code phishing) where an attacker tricks a user into authenticating a malicious application. A successful sign-in using this method could indicate a compromised account or a successful phishing attempt.
Detects Microsoft 365 sign-ins using the device code grant flow from an unusual location or a previously unseen/unmanaged device. This behavior is consistent with OAuth phishing abuse, specifically 'device code phishing' where an adversary tricks a user into entering a code/credentials on a malicious authorization page to obtain a device token.
This rule detects potential AS-REP Roasting activity by monitoring for a single source IP address requesting Kerberos TGTs (Event ID 4768) for multiple distinct user accounts within a 10-minute window. This behavior often indicates an attacker attempting to identify and harvest Kerberos pre-authentication hashes from accounts that do not require pre-authentication, which can then be cracked offline.
