
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,082 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of known remote access and remote management tools (e.g., TeamViewer, AnyDesk) where the process was initiated by a web browser, suggesting potential drive-by downloads or social engineering attacks involving remote access software.
This rule detects a sequence of suspicious activities on macOS: downloading a file from a potentially malicious source using curl, mounting a disk image using hdiutil, and subsequently opening files from the mounted volume. This pattern is commonly associated with the delivery and execution of malicious payloads, such as trojanized software or malware installers.
This rule detects suspicious activity associated with the Bun runtime after an npm package install. It flags instances where Bun, or download utilities (curl/wget) fetching 'bun.sh', are spawned from Node.js-related processes (npm, node, node-gyp) particularly when located in common temporary or cache directories, indicating potential supply chain compromise or unauthorized runtime deployment during build processes.
Detects the execution of Dropbear SSH binaries (dropbear, dropbearkey, dropbearmulti) on identified OT, ICS, or SCADA assets. The rule flags suspicious configurations such as the use of non-standard ports (2222, 44818), remote port forwarding, or running in the foreground, which may indicate unauthorized remote access or tunneling on sensitive operational technology infrastructure.
Detects a sequence of events where a non-root user attempts to manipulate kernel components (specifically involving xfrm/esp modules via ip or modprobe) followed immediately by a sudo or su command, suggesting an attempt to load malicious kernel modules or exploit kernel vulnerabilities to escalate privileges.
Detects rapid deletion and recreation of cloud storage buckets (S3 or Azure Storage) within a short timeframe (60 seconds). This behavior is often indicative of an attempt to hijack a bucket name or gain unauthorized access to data by exploiting race conditions or misconfigurations in infrastructure management.
Detects modifications to domain trust relationships, such as the creation of a new trust, removal of an existing trust, or changes to trusted domain information. Such events are monitored as they can indicate an adversary attempting to elevate privileges or establish persistence across a forest or multi-domain environment.
This rule detects the configuration of 'Trusted for Delegation' on a computer or user account, followed by a modification to the Active Directory nTDSDSA object on the same host. This combination is a classic indicator of setting up an account for Kerberos delegation attacks, often related to the creation of rogue domain controllers or setting up pivot points for lateral movement.
Detects Kerberos AS-REQ events (Event ID 4768) where pre-authentication is not used (PreAuthType 0). This is a common indicator of attempts to perform Kerberoasting or AS-REP roasting, as attackers may attempt to request tickets for accounts without requiring the initial pre-authentication step.
This rule detects common methods used by adversaries to perform credential dumping by accessing the memory of the Local Security Authority Subsystem Service (LSASS). It specifically flags the use of Procdump to create a memory dump of LSASS, the use of the native Windows utility comsvcs.dll via rundll32 to dump process memory, and the creation of LSASS dump files via the Windows Task Manager.
