
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,092 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects known Living-off-the-Land Binaries (LOLBins) initiating outbound network connections to specific non-standard or commonly suspicious ports (8080, 8443, 4444, 1337, 1234). The rule excludes private/loopback network traffic and common Microsoft-related domains to reduce noise. Such behavior is often indicative of malicious activity, including C2 communication or unauthorized file downloads via trusted system processes.
This rule detects potential token theft or MFA bypass by correlating successful MFA-satisfied interactive sign-ins with subsequent non-interactive sign-ins (token refreshes) occurring within a 60-minute window from different IP addresses for the same user. This pattern is indicative of an attacker stealing a session token (e.g., via session cookie theft or AiTM phishing) and using it to authenticate from a different location.
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
Detects when a single user account performs 3 or more Privileged Identity Management (PIM) role activations within a 30-minute window. This behavior may indicate an attacker who has compromised a privileged account and is rapidly assuming multiple roles to perform lateral movement or privilege escalation.
This rule detects the execution of potentially malicious processes (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe) initiated by mmc.exe or explorer.exe, excluding known legitimate Microsoft Management Console (MMC) flags and common management snap-ins. This pattern is indicative of potential proxy execution or misuse of system administration utilities to run unauthorized code.
Detects instances where common administrative tools (such as PowerShell, cmd, or network utilities) are launched as child processes of the WinRM service process (wsmprovhost.exe) shortly after an inbound WinRM network connection is established on port 5985 or 5986.
This rule detects when a user grants an OAuth application consent to access high-privilege scopes in an Azure environment. It specifically flags instances where the consent is not for all principals and the user performing the action is not a Global Administrator, which may indicate an attacker-controlled application being granted access to sensitive data or resources.
Detects instances where common administrative tools (such as PowerShell, cmd, or network utilities) are launched as child processes of the WinRM service process (wsmprovhost.exe) shortly after an inbound WinRM network connection is established on port 5985 or 5986.
Detects the use of common PowerShell cmdlets often associated with fileless malware execution, such as 'Invoke-Expression', 'IEX', or 'DownloadString', initiated by 'powershell.exe'. These patterns are frequently used to download and execute malicious payloads directly in memory, bypassing traditional disk-based scanning.
This rule detects multiple outbound network connections to a specific set of known malicious C2 IP addresses on specific ports within a one-hour window. This behavior is indicative of a multi-payload delivery pattern associated with malware families such as Remcos, Agent Tesla, and RedLine.
