
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,105 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects Azure Bastion RDP or SSH tunnel sessions initiated by users who have no history of using Bastion in the last 60 days, or by users connecting from a geographic location not observed in their recent sign-in history. This behavior may indicate account compromise and unauthorized lateral movement attempts.
This rule detects the execution of RMM (Remote Monitoring and Management) installers (Atera or SimpleHelp) via msiexec.exe or setup.exe when launched from directories commonly used for downloads (Temp/Downloads) and originating from web browsers or Microsoft Office applications. This behavior is indicative of a potential drive-by download or phishing attack aimed at installing unauthorized remote access software.
Detects the presence of specific keywords within PowerShell Script Block logs (EventCode 4104) that are characteristic of Anti-Malware Scan Interface (AMSI) bypass techniques. These include attempts to manipulate the AMSI context, reflectively load assemblies to modify memory, or force scan failures.
This rule monitors for file access events (Sysmon Event ID 11) targeting sensitive web browser files, including logins (passwords), cookies, and web data, by processes other than the legitimate browser executables. Such access is a strong indicator of credential theft or session hijacking attempts.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from common public file sharing and code repository sites, which is a known technique for adversaries to stage or download malicious payloads.
This rule detects indicators of the DCShadow attack technique by monitoring for the creation of nTDSDSA objects (which define domain controllers) or the addition of suspicious Service Principal Names (SPNs) often used in DCShadow simulations (GC/ or E3514235-4B06) to computer accounts. These indicators suggest an attacker is attempting to register a rogue Domain Controller to manipulate Active Directory data.
This rule detects processes other than standard web browsers performing network connections that coincide with OAuth token acquisition activities (POST requests containing 'access_token' in the response body). This behavior is indicative of potential token theft or unauthorized programmatic access to OAuth-protected resources.
Detects the use of legitimate Windows binaries (Certutil and BITSAdmin) to communicate with external, non-Microsoft IP addresses, which is indicative of potential tool downloading or data exfiltration. The rule explicitly filters out known Microsoft update domains to reduce noise.
This rule detects potential data staging and exfiltration behavior characterized by large volumes of outbound network data combined with high frequency file write operations across multiple file types. It monitors Sysmon Event IDs 3 (Network connection) and 11 (FileCreate) to identify indicators often associated with pre-encryption staging by ransomware or data theft campaigns.
This rule detects when an executable or process loads a DLL from commonly writable locations like AppData, Temp, or ProgramData, while also correlating this activity with the loading of .NET CLR runtime components (mscoree.dll, clr.dll, etc.) and potential configuration file modifications. This behavior is indicative of .NET-based injection techniques such as AppDomainManager injection or DLL hijacking targeting .NET applications.
