
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network connections to the Telegram API (api.telegram.org) from processes identified as LOLBins or residing in suspicious, potentially writable locations such as Temp, AppData, or user-defined directories. This activity is often indicative of C2 communication or data exfiltration by malware bypassing standard messaging client restrictions.
This rule detects potentially unauthorized or suspicious outbound network connections to common Generative AI service APIs (OpenAI, Anthropic, Mistral) originating from command-line interpreters (cmd.exe, powershell.exe) or python.exe instances running from temporary directories, which could indicate data exfiltration or the use of AI tools for malicious automation.
Detects the execution of five specific Windows reconnaissance utilities (net.exe, nltest.exe, whoami.exe, ipconfig.exe, and systeminfo.exe) by the same parent process within a 60-second window. This behavior pattern is highly characteristic of an automated discovery phase during a post-exploitation engagement, where an actor attempts to quickly gather system and network environment information.
Detects the use of BPF syscalls by non-root processes or the execution of BPF-related utilities (bpftool, bpfcc) from an interactive shell. This behavior is often associated with the ShadowGuard rootkit and potential BPF-based backdoor activity, which leverages BPF programs for stealthy system monitoring or command execution.
This rule monitors for two distinct behaviors: direct modification of Group Policy Object (GPO) containers within Active Directory and suspicious execution of GPO management tools (gpupdate.exe or gpedit.msc) across multiple hosts in a short timeframe. AD modification events are flagged as critical, while elevated tool execution patterns are flagged as high or medium risk based on host prevalence.
This rule detects potential credential dumping activity against the Local Security Authority Subsystem Service (LSASS) on a host shortly after a successful VPN logon. It correlates Sysmon Event ID 1 (Process Creation) representing known dumping techniques (Mimikatz, Procdump, or comsvcs.dll) with Windows Security Event ID 4624 (Logon) from a VPN source within a 5-minute window.
This rule detects the use of system utilities (wevtutil.exe, auditpol.exe, PowerShell) to interact with, query, or check status of security event logs and auditing configurations. While these tools are standard for administration, their usage by non-system accounts can indicate an adversary attempting to understand, monitor, or manipulate system audit policies and event log configurations as part of a reconnaissance or defense evasion strategy.
Detects the use of VMware ESXi command-line management tools (esxcli, esxcfg) or VMware PowerCLI cmdlets (e.g., Connect-VIServer, Invoke-VMScript) from endpoints that are not identified as servers. This behavior often indicates an attacker attempting to manage or interact with a virtualized environment from a compromised workstation.
This rule detects outbound network connections to common webhook and temporary storage services (e.g., discord.com webhooks, webhook.site, pipedream.net) initiated by processes other than standard web browsers. Such behavior is often indicative of automated data exfiltration, command-and-control (C2) communication, or malicious script activity using these services to bypass traditional network defenses.
This rule monitors for inbound email messages containing SVG file attachments. SVG files can contain embedded scripts that may be leveraged for malicious purposes, such as SVG smuggling to deliver secondary payloads or perform credential harvesting.
