
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects NTLM-authenticated network logons (Logon Type 3) originating from loopback IP addresses (127.0.0.1, ::1, or 0.0.0.0). This behavior is often associated with NTLM relay attacks or credential reflection bypass techniques where an adversary forces a local service to authenticate to itself to gain unauthorized access.
Detects instances where privileged system processes such as lsass.exe or svchost.exe attempt a network connection to the local loopback address on ports other than standard SMB ports (445, 139). This pattern is indicative of potential coercion or relay attacks, specifically targeting the authentication mechanisms of these services to an attacker-controlled SMB server.
Detects the execution of Python-based SMB server implementations commonly associated with the Impacket toolset. Impacket is frequently used by attackers to facilitate lateral movement, credential relay, and remote file manipulation.
Detects outbound network connections from devices to known FortiBleed command and control (C2) servers and sniffer infrastructure IP addresses. This rule helps identify potential compromises involving the FortiBleed vulnerability exploitation.
Detects inbound network connections initiated by common Windows Nearby Sharing processes ('NearShare.exe', 'NearbySharing.exe', 'quickshare.exe', 'NearbyConnectionsService.exe') that occur on non-standard ports, potentially indicating unauthorized or malicious use of these utilities.
This rule detects Windows application crash events (Event IDs 1000 and 1001) specifically for 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. The detection triggers when the crash description contains indicators of memory-related instability, such as access violations, heap corruption, or invalid virtual calls, which may suggest exploitation attempts or service instability.
This rule monitors for recurring application crashes involving 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. Frequent crashes of these components may indicate instability, misconfiguration, or an attempt to exploit vulnerabilities within these specific file sharing services.
Detects high frequency inbound network connection attempts or accepted connections initiated by common file sharing processes (e.g., NearShare.exe, NearbySharing.exe, quickshare.exe, sharingd, airplayd). A high volume of inbound connection attempts may indicate brute force, discovery, or malicious scanning behavior using legitimate file sharing tools as a conduit.
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
