
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the creation of new processes where the command line contains keywords such as 'exploit' or 'vulnerability'. This could indicate an attempt to execute an exploit or leverage a known vulnerability, potentially as part of an attack.
This rule detects the execution of processes where the command line contains keywords commonly associated with malware, specifically 'backdoor', 'rootkit', or 'trojan'. It monitors Windows Security Event ID 4688 (a process creation event) and flags any command lines containing these terms.
This rule detects the creation or modification of user accounts on Windows systems by monitoring Security Event IDs 4741 (A security-enabled local group was created) and 4742 (A computer account was changed). It summarizes the count of such changes per hour by the subject user name, which can help identify unusual or excessive account management activities.
Detects the use of BITSAdmin to create or modify background intelligent transfer jobs. Attackers often abuse BITSAdmin to download malicious payloads (ingress tool transfer) or to execute commands when a transfer job completes or errors, which can be leveraged for persistence or arbitrary code execution.
Detects the use of regsvr32.exe with the /s (silent) and /u (unregister) flags to execute a remote scriptlet file (e.g., .sct, scrobj.dll) via HTTP, a common technique for proxy execution and bypassing application control mechanisms.
Detects execution of Certutil.exe with arguments commonly used by adversaries for downloading files (urlcache) or decoding malicious payloads (decode/decodehex). These techniques are frequently used to bypass security controls and facilitate the delivery of secondary payloads or tools.
Detects the use of administrative tools like wmic.exe, powershell.exe, or pwsh.exe to invoke WMI event subscription components such as ActiveScriptEventConsumer, CommandLineEventConsumer, or FilterToConsumerBinding. This behavior is a common technique for establishing persistence or elevating privileges by executing malicious code when specific system events occur.
Detects the use of BITSAdmin to create or modify background intelligent transfer jobs. Attackers often abuse BITSAdmin to download malicious payloads (ingress tool transfer) or to execute commands when a transfer job completes or errors, which can be leveraged for persistence or arbitrary code execution.
Detects execution of mshta.exe with command line arguments containing web-related indicators (http) or scripting engines (vbscript, javascript). This behavior is characteristic of adversaries using mshta.exe as a proxy to execute remote malicious payloads or inline scripts, effectively bypassing application controls and browser security contexts.
Detects the spawning of common command-line or script execution shells (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe) by the Windows Remote Management (WinRM) provider host (wsmprovhost.exe). This behavior is often indicative of remote code execution or lateral movement via WinRM.
