
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects processes running from suspicious, writable directories (Temp, AppData, Downloads) that simultaneously load the .NET Common Language Runtime (clr.dll) and initiate network connections. This behavior is indicative of a downloaded binary or payload executing managed code to perform C2 communication.
Detects HTTP requests where the URI or request body contains indicators of internal network references (e.g., localhost, 127.0.0.1, or RFC 1918 private IP address ranges). This pattern is consistent with Server-Side Request Forgery (SSRF) attempts, where an attacker tries to force a vulnerable web application to perform unauthorized requests to internal resources.
Detects anomalous, high-volume DNS query activity where a process attempts to resolve 20 or more unique domains within a 2-minute window. The query patterns match strings that are 8-20 characters long with common top-level domains, excluding known web browsers and standard network diagnostic utilities. This behavior is indicative of malware using Domain Generation Algorithms (DGA) for command and control or secondary communication channels.
Detects Python processes binding to or establishing network connections on the local loopback interface (127.0.0.1 or ::1) on non-standard ports. This behavior may indicate a local backdoor, proxy, or C2 listener implemented in Python that is not associated with common development tools or environments.
Detects the creation of executable files (.exe or .dll) on a removable drive followed by the execution of a process from that same drive within a 30-second window. This behavior is indicative of an adversary using removable media to stage and execute malicious payloads.
Detects the execution of known forensic imaging tools (FTK Imager or AD Imager) or commands interacting with the Active Directory database (ntds.dit). This behavior is characteristic of unauthorized attempts to extract credential hashes from the NTDS.dit file for offline cracking.
This rule detects processes other than standard web browsers (Chrome, Edge, Brave) attempting to access sensitive directories within Chrome extension user data paths, such as IndexedDB, Local Storage, or Sync Data. Such activity is often indicative of credential or session cookie theft by malicious scripts or malware.
Detects the execution of wscript.exe, msiexec.exe, or cmd.exe initiated with command lines pointing to script files (.js, .vbs) or shortcut files (.lnk) located on removable drives (d-z drive letters). This behavior is characteristic of the Raspberry Robin worm spreading via infected USB media.
This rule detects cross-process memory access events (Sysmon Event ID 10) where a process attempts to hook into keyboard-related Windows API functions such as SetWindowsHookEx, GetKeyState, or GetAsyncKeyState. It further filters for processes executing from suspicious locations (Temp, AppData, ProgramData) or those that are unsigned/unverified, which are common indicators of malicious keylogging or spyware activity.
This rule detects potentially malicious activity within Linux environments or containers where a single user context concurrently performs credential hunting (via environment variable dumping or accessing .env files) and terminates processes associated with known cryptocurrency miners or competing malicious actors. This behavior is highly indicative of a cryptojacking infection or a malicious actor clearing out existing resource-hijacking threats.
