
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Rust-based ransomware family targeting enterprise environments
Loader malware delivering follow-on ransomware payloads
Credential and browser data stealer distributed via OXLOADER campaigns
Ransomware group exploiting edge devices and managed file transfer software
Credential and browser data stealer distributed via OXLOADER campaigns
Credential and browser data stealer distributed via OXLOADER campaigns
Detects instances where the Node.js executable (node.exe) spawns common command shells or scripting interpreters such as cmd.exe, powershell.exe, pwsh.exe, or wscript.exe. This behavior is often indicative of Node.js-based applications being used as a staging point for command execution, a common pattern in post-exploitation or the usage of malicious npm packages.
This rule detects the coordinated execution of multiple Windows command-line utilities (vssadmin, wbadmin, and bcdedit) within a short time frame (60 seconds). These tools are frequently used by ransomware and other malware to delete volume shadow copies, clear backup catalogs, and disable system recovery features, effectively preventing the restoration of the system after a damaging event.
This rule detects modifications to Group Policy Objects (GPOs) that involve sensitive attributes such as logon scripts, startup/shutdown scripts, or file system paths, particularly when performed by service accounts or non-administrator users. This activity is a common indicator of persistence mechanisms or lateral movement via GPO abuse.
This rule detects scenarios where a new local user account is created on a Windows system during off-hours (between 7 PM and 7 AM), followed by the execution of known remote access tools within a 30-minute window of that account creation. This combination is often indicative of unauthorized persistent access establishment.
