
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,106 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects instances where a process attempts to open a handle to itself with high-privilege access rights (e.g., PROCESS_ALL_ACCESS, PROCESS_VM_WRITE, PROCESS_VM_OPERATION). This behavior is often indicative of self-injection, a technique used by malicious code to modify its own memory space or inject shellcode, evading detection and bypassing certain security controls.
Detects the spawning of Windows Script Host (wscript.exe or cscript.exe) as a child process of common web browsers (chrome.exe, msedge.exe, firefox.exe). This pattern is often indicative of a drive-by download attack or a user executing a malicious script file downloaded from the internet.
Detects Microsoft Outlook spawning a command-line interpreter (cmd.exe or powershell.exe) followed by a network connection originating from that interpreter within a 5-minute window. This behavior is highly suspicious and often indicative of malicious macro execution or exploit delivery via email attachments leading to command-and-control activity.
This rule identifies instances where python.exe or python3.exe executes from non-standard system paths and establishes an outbound network connection to external (non-private/non-loopback) IP addresses. This behavior is indicative of potential malicious activity, as legitimate applications typically execute from protected program file directories, while adversaries often execute unauthorized binaries from temporary or user-writable locations to initiate command and control (C2) communication.
Detects the execution of five specific Windows reconnaissance utilities (net.exe, nltest.exe, whoami.exe, ipconfig.exe, and systeminfo.exe) by the same parent process within a 60-second window. This behavior pattern is highly characteristic of an automated discovery phase during a post-exploitation engagement, where an actor attempts to quickly gather system and network environment information.
This rule detects potential credential dumping activity against the Local Security Authority Subsystem Service (LSASS) on a host shortly after a successful VPN logon. It correlates Sysmon Event ID 1 (Process Creation) representing known dumping techniques (Mimikatz, Procdump, or comsvcs.dll) with Windows Security Event ID 4624 (Logon) from a VPN source within a 5-minute window.
Detects an abnormally high volume of Kerberos TGS (Ticket Granting Service) requests encrypted with RC4 (0x17) from a single source IP. This behavior is indicative of Kerberoasting, an attack where an adversary attempts to extract service account passwords from requested TGS tickets.
This rule monitors for file access events (Sysmon Event ID 11) targeting sensitive web browser files, including logins (passwords), cookies, and web data, by processes other than the legitimate browser executables. Such access is a strong indicator of credential theft or session hijacking attempts.
This rule detects potential command and control (C2) beaconing activity by identifying non-browser processes that initiate regular, sustained outbound network connections over port 443. It aggregates connection data by hour and calculates metrics such as average frequency and standard deviation to identify consistent, periodic communication patterns characteristic of C2 agents while excluding common legitimate web browsers.
Detects a sequence of events within a 30-minute window for a single user, specifically capturing MFA configuration changes (reset/enrollment), authentication, and device registration, occurring outside of typical business hours (20:00 - 06:00). This behavioral pattern is often indicative of an adversary establishing persistence or account takeover after gaining access to a valid account.
