
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,087 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potential wiper activity by monitoring for high-frequency deletion or modification of specific file types (e.g., .docx, .xlsx, .pdf, .db, .bak) within a short window. It triggers when a process like PowerShell or Cmd is observed executing destructive commands (e.g., 'del', 'erase', 'Remove-Item') on a large number of files across multiple directories, which is a common behavior of malware attempting to destroy data.
Detects the use of NTFS Alternate Data Streams (ADS) by monitoring process command lines, initiating process command lines, and folder paths for patterns indicative of ADS notation. The rule specifically flags potential execution or access patterns involving common script interpreters (wscript, cscript, powershell, pwsh) combined with ADS, as well as general ADS usage in file paths.
This rule detects the creation of .lnk files in common suspicious directories (such as startup folders, Temp, or Downloads) followed by the execution of common scripting or command interpreters (powershell.exe, mshta.exe, wscript.exe, cmd.exe) with long command lines within a 10-minute window. This behavior is often indicative of an adversary attempting to achieve persistence or execute malicious payloads via user interaction.
Loader used in click-hijacking traffic distribution scheme
ClickFix style social engineering cluster delivering Mistic and ModeloRAT
Malvertising loader delivering CastleStealer via malicious Google Ads
USB worm and loader leveraging living-off-the-land binaries
Modular remote access trojan associated with long-term espionage intrusions
Malvertising loader delivering CastleStealer via malicious Google Ads
PlugX C2Beacon
YARA
Modular remote access trojan associated with long-term espionage intrusions
