
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,118 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects a specific network handshake pattern (05 01 00) associated with the SystemBC malware acting as a SOCKS5 proxy. This pattern is characteristic of the initial communication phase used by SystemBC to establish C2 connectivity, often utilized by ransomware affiliates.
This rule detects outbound TCP traffic from internal network hosts to known Tor relay ports (9001, 9030), which is a common communication pattern for the NBLock ransomware strain to establish a command and control channel through the Tor network.
Detects HTTP traffic destined for the 1rpc.io Ethereum node gateway containing 'eth_call' in the request body, which is indicative of EtherRAT malware using blockchain infrastructure for command and control (C2) resolution.
Detects network traffic over SMB targeting the SYSVOL or NETLOGON network shares that includes the transfer or reference of common executable file extensions. This behavior is indicative of an adversary attempting to stage malicious payloads for deployment via Group Policy Objects (GPOs), a common method for lateral movement and persistence.
This rule detects suspicious remote thread creation events (Sysmon Event ID 8) where a process initiates a thread in high-value system processes like lsass.exe, svchost.exe, explorer.exe, or winlogon.exe. It specifically filters out activity originating from common Windows system directories, highlighting potential process injection attempts by unauthorized binaries.
This rule detects instances where a process loads a DLL from suspicious, commonly user-writable directories (such as Temp, AppData, ProgramData, or Public). It filters for DLLs that lack standard file metadata (FileVersion/Description) or contain an OriginalFileName mismatch, which is often indicative of side-loading or malicious library injection. The rule further correlates this event with a network connection initiated by the same process to highlight potential C2 activity associated with the suspicious DLL load.
This rule detects potential mass emailing or spam activity by identifying instances where a single email account sends more than 100 emails within a one-minute window. This behavior is often characteristic of compromised accounts performing phishing campaigns or bulk unauthorized communication.
Detects the use of the 'netsh interface portproxy' command to set up a port forwarding rule where the connection address is outside of common private IP ranges. This behavior is frequently associated with attackers establishing persistent network pivots or internal proxies to redirect C2 traffic.
This rule detects processes accessing registry keys associated with common cryptocurrency wallets (e.g., Electrum, Exodus, MetaMask, Ledger) that are not the legitimate wallet applications themselves. This behavior is indicative of unauthorized attempts to extract sensitive wallet information, such as configuration, seeds, or keys, stored in the Windows Registry.
This rule detects instances where a process loads a DLL from suspicious, commonly user-writable directories (such as Temp, AppData, ProgramData, or Public). It filters for DLLs that lack standard file metadata (FileVersion/Description) or contain an OriginalFileName mismatch, which is often indicative of side-loading or malicious library injection. The rule further correlates this event with a network connection initiated by the same process to highlight potential C2 activity associated with the suspicious DLL load.
