
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects authentication events for service accounts (matching patterns like 'svc', 'sa', 'service') originating from at least two different countries within a short time window (30 minutes or less), indicating potential credential compromise and anomalous geographic movement.
This rule detects potentially malicious OAuth activity in Azure AD where a user performs a device code authentication flow, followed by a refresh token request from a different, anomalous IP address or geographical location. This behavior is indicative of an attacker who has successfully phished a device code from a user and is now attempting to maintain persistent access to the account via a stolen refresh token.
This rule detects potential tunnel creation using PowerShell. It identifies network connections from PowerShell processes to common SSH (22) or Tor (9001, 9050) ports, as well as PowerShell script block activity involving socket connections directed at .onion domains, SSH keys, or authorized keys files, which may indicate remote access tunneling or command-and-control communication.
This rule identifies potential mass phishing campaigns by monitoring O365 email activity for high-volume outbound mail from newly registered or observed domains. It specifically flags senders that have no prior historical activity in the last 90 days, have a domain age of less than 30 days, and exhibit a low variation in email subjects across a large volume of recipients, which is characteristic of automated bulk phishing.
Detects potential supply chain attacks where a suspicious Python package is installed via 'pip' followed by execution of suspicious commands or network activity from 'python.exe' within a short timeframe. This rule correlates process creation events involving pip installations with subsequent suspicious command-line activity or external network connections from Python processes.
This rule detects potential data staging and exfiltration behavior characterized by large volumes of outbound network data combined with high frequency file write operations across multiple file types. It monitors Sysmon Event IDs 3 (Network connection) and 11 (FileCreate) to identify indicators often associated with pre-encryption staging by ransomware or data theft campaigns.
This rule detects potential large-scale exfiltration or staging of sensitive documents to common cloud storage locations (Dropbox, Google Drive, OneDrive) or removable media. The rule specifically triggers when a high count (more than 20) of files labeled as sensitive are accessed or transferred by a single user within a session, specifically outside of standard business hours (before 7 AM or after 8 PM).
Detects the installation of a new Windows service where the ImagePath contains strings commonly associated with remote access or remote control software, such as 'remotepc' or 'rpclient'. This may indicate the unauthorized deployment of remote administration tools.
This rule detects instances where a process attempts to open a handle to itself with high-privilege access rights (e.g., PROCESS_ALL_ACCESS, PROCESS_VM_WRITE, PROCESS_VM_OPERATION). This behavior is often indicative of self-injection, a technique used by malicious code to modify its own memory space or inject shellcode, evading detection and bypassing certain security controls.
This rule detects DLL loading events where specific legitimate applications (Adobe Creative Cloud, Microsoft Edge, or Opera GX) load a DLL from their own directory where the DLL file is unsigned or has an invalid digital signature. This pattern is often indicative of DLL sideloading, where an attacker places a malicious DLL in the application's folder to be loaded by the legitimate process.
