
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of the 'netsh interface portproxy' command to set up a port forwarding rule where the connection address is outside of common private IP ranges. This behavior is frequently associated with attackers establishing persistent network pivots or internal proxies to redirect C2 traffic.
This rule detects modifications to sensitive Windows Registry keys under HKLM\SOFTWARE\Microsoft\Cryptography, such as Providers, OID, Trust, and Protectedroots. These keys control cryptographic services and trust stores on Windows systems. Modifications by non-system processes or accounts may indicate attempts to subvert trust controls, install rogue root certificates, or tamper with system-level security providers.
Detects artifacts related to the ValleyRAT malware family, specifically identifying markers such as 'Phantom Persistence Module', 'RegisterApplicationRestart', and specific 'RSL_' strings within process command lines, image paths, or module loads using Windows Event Logs and Sysmon data.
Detects outbound network connections to common Large Language Model (LLM) APIs (OpenAI, Anthropic, Google) or local LLM instances (Ollama) from processes that are not standard web browsers, common IDEs, or typical development/scripting tools. This behavior may indicate an attempt to exfiltrate sensitive data or interact with LLM services using unauthorized or hidden processes.
Detects a suspicious spike in Microsoft Teams external meeting or chat invitations directed at a single user within a 30-minute window. This behavior is consistent with UNC6692 tactics, where attackers impersonate internal IT helpdesk staff via Teams to perform vishing and social engineering attacks.
Detects processes that execute and remain dormant for more than 120 seconds before performing a high volume of file operations (greater than 50) or initiating a high volume of network connections (greater than 20). This pattern is consistent with malware or beaconing implants attempting to evade detection during automated sandbox analysis.
Detects instances where Windows NearShare or QuickShare utilities spawn child processes that are not part of their standard operational or helper suite (e.g., conhost.exe, WerFault.exe, svchost.exe). This pattern is often indicative of process injection, living-off-the-land techniques, or unauthorized activity masquerading as legitimate Windows sharing services.
Detects network connection attempts or successes from critical Windows processes (System, svchost.exe, lsass.exe) targeting the localhost interface (127.0.0.1 or ::1) on non-standard ports (above 1024, excluding SMB ports 445/139). This behavior is often indicative of local process injection, credential dumping activity, or unauthorized inter-process communication used by malware to bypass network security controls.
Detects instances where Windows NearShare or QuickShare utilities spawn child processes that are not part of their standard operational or helper suite (e.g., conhost.exe, WerFault.exe, svchost.exe). This pattern is often indicative of process injection, living-off-the-land techniques, or unauthorized activity masquerading as legitimate Windows sharing services.
This rule detects Windows application crash events (Event IDs 1000 and 1001) specifically for 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. The detection triggers when the crash description contains indicators of memory-related instability, such as access violations, heap corruption, or invalid virtual calls, which may suggest exploitation attempts or service instability.
