
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects outbound internet communications generated by rundll32.exe, which is uncommon and frequently associated with malware execution, including ACR Stealer.
Detects connections to domains associated with observed ACR Stealer command-and-control infrastructure.
Flags Intune assignments to “All Devices” or “All Users,” which attackers may abuse for mass deployment.
Detects PowerShell commands that reverse byte arrays before dynamically loading assemblies into memory, a behavior commonly associated with advanced malware loaders and fileless execution techniques. The rule specifically looks for PowerShell process command lines containing 'IO.File', 'System.Reflection.Assembly', 'Length-1', and '..0', which are indicative of byte array manipulation and in-memory assembly loading.
Detects PowerShell reading image files and loading their contents directly into memory as .NET assemblies, a stealth technique used to hide malicious payloads inside benign-looking files.
Detects Hero proxyware artifacts being written or modified within the Windows SysWOW64 directory. Presence of these files may indicate installation of unauthorized proxy services or abuse of enterprise endpoints for traffic relaying.
Detects execution of OneDriveUpdater.exe from C:\ProgramData, which may represent a masqueraded binary attempting to impersonate legitimate Microsoft software. This could indicate an attempt at defense evasion or persistence by an attacker.
Flags executables whose embedded metadata identifies them as Cloudflared while the filename differs from expected distribution names, suggesting potential evasion through binary renaming.
Detects MSBuild project files created beneath C:\ProgramData, an uncommon location that has been abused by threat actors to stage malicious project files for code execution.
Detects PowerShell commands using XOR operations together with execution primitives that may indicate obfuscated in-memory payload decoding. Specifically looks for 'powershell.exe' executing with '-bxor', '81', and either 'IEX' or 'Invoke-Expression' in the command line.
