
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,506 copies160 likes52,094 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to Windows Registry keys associated with Event Tracing for Windows (ETW) Autologger configurations or Event Log service configurations. These modifications can be used by adversaries to disable or tamper with event logging mechanisms, effectively blinding security telemetry and evading detection.
This rule detects the execution of potentially malicious processes (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe) initiated by mmc.exe or explorer.exe, excluding known legitimate Microsoft Management Console (MMC) flags and common management snap-ins. This pattern is indicative of potential proxy execution or misuse of system administration utilities to run unauthorized code.
Detects the addition of secrets or certificates to Azure service principals during non-business hours (before 7 AM or after 7 PM, or on weekends). This behavior may indicate an adversary attempting to establish persistence in a cloud environment by adding their own credentials to an existing service principal.
Detects instances where a user successfully authenticates using Multi-Factor Authentication (MFA) from one location, followed by a Single-Factor Authentication (SFA) logon from a different location within a 10-minute window. This behavior is indicative of potential session hijacking or session cookie theft where an attacker reuses an authenticated session or manipulates the authentication flow to bypass MFA requirements.
Detects high-frequency HTTPS network connections to Google Drive or Google APIs originating from processes that are not common web browsers or productivity software. This behavior is indicative of the GearDoor backdoor, commonly used by APT41, which leverages Google services as a command-and-control (C2) channel.
Detects network connections to Microsoft OneDrive or SharePoint domains from processes that are not standard, known-good applications (e.g., browsers or standard sync clients). This behavior may indicate an adversary leveraging cloud storage for command-and-control (C2) operations or data exfiltration.
Detects the creation of WMI event subscriptions that utilize CommandLineEventConsumer or ActiveScriptEventConsumer to execute common living-off-the-land binaries like powershell.exe, cmd.exe, wscript.exe, cscript.exe, or mshta.exe. This behavior is a common technique used for establishing persistence or executing malicious payloads via WMI event mechanisms.
This rule detects a sequence of suspicious activities: the creation or modification of an executable file (.exe or .dll) within a directory path containing update-related keywords, followed by the execution of a file in that same location, and culminating in an outbound network connection from that process. This pattern is characteristic of a software supply chain compromise or an adversary deploying a malicious payload via a fake or compromised update mechanism.
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
Detects suspicious execution of command-line utilities (cmd, powershell, pwsh) spawned by Windows Explorer (explorer.exe). The rule flags processes with long command lines or those containing evidence of obfuscation (Base64 encoding) or common command-line indicators used for weaponized scripts, such as download requests or expression invocation.
