
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,105 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects changes to a user account's User Account Control (UAC) settings, specifically when the 'NewUacValue' is set to '0x2080'. This value corresponds to the 'ACCOUNTDISABLE' flag, indicating that a user account has been disabled. Monitoring such changes can help identify potential malicious activity where an attacker might disable legitimate user accounts to disrupt operations or hinder incident response.
Detect traffic to the C2 server used by the backdoor linked to MuddyWater.
This rule detects multiple stages of activity associated with BaqiyatLock ransomware and Remcos RAT. It identifies the execution of known BaqiyatLock/Remcos files, attempts to bypass User Account Control (UAC) via ms-settings registry hijack, creation of files with the '.bqtlock' extension indicative of BaqiyatLock encryption, and network communication with 'icanhazip.com' for external IP discovery, which is a common reconnaissance step.
This rule detects when the 'oskmenu.xml' file, located in 'C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions', is accessed or modified by any process not running under the SYSTEM account. This file is associated with the On-Screen Keyboard and its modification by non-system accounts could indicate an attempt to alter its behavior, potentially for persistence or privilege escalation.
Detects the creation of a scheduled task using 'schtasks.exe' with specific command-line arguments that indicate an attempt to establish persistence. The rule looks for 'schtasks.exe' creating a task named 'Runtime Broker' that executes a program from a suspicious path within 'C:\ProgramData\Microsoft\Windows\Runtime\'. This pattern is often used by adversaries to maintain access to a system.
This rule detects the presence of MicroStealer malware by matching known MD5, SHA1, or SHA256 hashes of its binaries against file events on monitored devices. MicroStealer is a credential stealer that targets various applications to exfiltrate sensitive information.
This rule detects the presence of files on endpoints that match a list of known malicious SHA256 hashes associated with the Nuso malware. It queries DeviceFileEvents to identify any file with a matching hash.
Detects GhostBackdoor malware execution via known file hash.
Detects suspicious process injection attempts where common scripting/proxy execution tools (wscript.exe, cscript.exe, mshta.exe, powershell.exe, msiexec.exe) are used to inject into other processes (RegAsm.exe, InstallUtil.exe, vbc.exe, svchost.exe, explorer.exe) using CreateRemoteThread. The detection is further refined by looking for command-line indicators often associated with malicious activity, such as downloading content or executing scripts.
KQL Query from file: INC Ransomware Command Execution
