
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the use of PsExec or the Service Control Manager (sc.exe) to execute code remotely, which is a common technique used by attackers for lateral movement and remote code execution.
Detects the execution of 'runas.exe' with the '/savecred' or '/netonly' parameters. The '/savecred' parameter allows the use of credentials previously stored in the credential manager, while '/netonly' allows the use of credentials for remote network resources without authenticating locally. Both flags can be abused by adversaries to persist or move laterally with compromised or cached credentials while evading local authentication monitoring. The rule excludes common system-signed processes originating from the Windows System32 directory.
Detects outbound TCP traffic originating from the internal network to external hosts on TCP port 45588, which is associated with Interlock ransomware beaconing behavior. This rule monitors for initial TCP SYN packets, characteristic of an outbound connection attempt potentially related to command-and-control activity following the exploitation of CVE-2026-20131.
Detects HTTP traffic initiating a WebSocket protocol upgrade with a specific 'binary' subprotocol header, characteristic of the Brickstorm backdoor used by the UNC5221 threat actor for command and control (C2) communication.
Detects HTTP traffic destined for the 1rpc.io Ethereum node gateway containing 'eth_call' in the request body, which is indicative of EtherRAT malware using blockchain infrastructure for command and control (C2) resolution.
Detects network traffic over SMB targeting the SYSVOL or NETLOGON network shares that includes the transfer or reference of common executable file extensions. This behavior is indicative of an adversary attempting to stage malicious payloads for deployment via Group Policy Objects (GPOs), a common method for lateral movement and persistence.
This rule detects network traffic directed at 'goldsky.arweave.net', a domain known to be used by the TukTuk malware as a dead-drop resolver. Adversaries often use legitimate web services like Arweave to host command-and-control (C2) configuration data, such as secondary C2 IP addresses or domains, allowing them to redirect infected hosts to backend infrastructure while masking the traffic as legitimate web communication.
Detects outbound HTTP PUT requests to 'filen.io', which has been associated with command-and-control (C2) communication for the PRISMEX malware used by the threat actor APT28 (also known as Pawn Storm/Fancy Bear).
Detects DNS queries for domains ending in '.trycloudflare.com', which are commonly used to establish unauthorized remote access tunnels (Cloudflare Tunnel) by threat actors for C2 communication.
Detects HTTP PUT requests directed at Wasabi Cloud Storage domains that originate from an Rclone user agent. This pattern is commonly indicative of data exfiltration activities where an attacker uses the Rclone utility to synchronize or upload sensitive data to unauthorized cloud storage.
