
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,106 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for scenarios where a DLL is created and subsequently loaded by a process within a short time frame (60 seconds or less). The rule specifically excludes files located in 'C:\Windows\' and 'C:\Program Files\' to minimize noise, focusing on suspicious modules originating from user-writable or unexpected locations, which is a common behavior of malware or side-loading attacks.
KQL Query from file: Detects when a user uploads, shares, or sends executable files (e.g., .exe, .dll, .scr) through Office 365 services (OneDrive / SharePoint / Exchange). This Query is used to find the SHA values of file.
Detects modifications to the 'SSLKEYLOGFILE' environment variable in the Windows Registry. This variable is often used by applications like web browsers to log SSL/TLS session keys to a file, which can then be used to decrypt encrypted network traffic. Malicious actors might enable this to capture sensitive data.
This rule detects suspicious network connections made by processes (excluding legitimate EDR processes like mssense.exe and senseir.exe) to URLs commonly associated with EDR command and control (C2) infrastructure. This could indicate an attempt by an adversary to communicate with or manipulate the EDR agent.
This rule detects suspicious execution of 'RUNDLL32.EXE' with specific command-line arguments. It looks for instances where 'RUNDLL32.EXE' is executed with both a backslash and a comma in the command line, combined with specific DLL names or keywords like 'iamnotarobot.dll', 'checkme.dll', 'machinerie.dll', 'humanCheck', or 'verifyme'. This pattern is often indicative of malicious DLL loading or persistence mechanisms.
Detects instances where msbuild.exe is used to execute project files (.proj) from suspicious or uncommon directories. Adversaries may abuse MSBuild to proxy execution of malicious code, often placing these project files in temporary or public user directories to evade detection.
Detects PowerShell processes executing with command-line arguments that suggest the use of 'Get-Alias' (gal) or 'Get-Command' (gcm) followed by suspicious patterns. This could indicate an adversary attempting to discover system capabilities or installed modules.
Detects the execution of SyncAppvPublishingServer.vbs via wscript.exe or cscript.exe. This legitimate Windows script can be abused by adversaries to proxy execution of malicious PowerShell commands, bypassing execution restrictions and evading defensive measures.
Detects suspicious PowerShell execution initiated by explorer.exe, specifically when the command line includes a .lnk file, execution policy bypass, and contains keywords or paths commonly associated with malicious activity (e.g., tor, ssh, github.io, dropbox.com, or suspicious temporary/public directories). This pattern is often observed in initial access or execution phases of attacks.
Detects suspicious network connections to 'outlook-one.vercel.app' or 'api.telegram.org' when initiated by common web browsers (msedge.exe, chrome.exe, firefox.exe) or Outlook (outlook.exe). This pattern can indicate phishing attempts, credential harvesting, or data exfiltration via Telegram bots.
