
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the transmission of potential sensitive information, such as passwords, tokens, API keys, or private keys, within Microsoft Teams chat messages by matching message content against a regular expression pattern for common credential formats.
Detects the execution of VS Code Tunnel processes (code-tunnel.exe or code.exe with tunnel arguments) initiated by processes other than standard development-related parent processes (e.g., explorer, terminal, IDEs). This behavior may indicate an adversary attempting to establish persistent unauthorized remote access to a compromised host using the VS Code Tunnel functionality.
Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
Detects the installation of Visual Studio Code extensions from sources other than the official Marketplace. This activity is monitored by checking process command line arguments for the --install-extension flag combined with external URLs or local file paths, which may indicate an attempt to install malicious extensions.
This rule detects suspicious command-line execution originating from common web browsers. It identifies instances where a browser process launches a command-line interpreter (cmd, powershell, or wscript) and immediately invokes known download or utility commands (curl, iwr, bitsadmin, certutil), which is a common pattern for file-less or stage-two payload delivery from malicious websites.
This rule detects the execution of common Python-based network relay and exploitation tools such as Impacket's ntlmrelayx, smbserver.py, and PetitPotam. These tools are frequently utilized by adversaries to conduct NTLM relay attacks, perform remote service execution, or facilitate credential dumping.
Detects the execution of known NTLM relay and coercion tools (such as PetitPotam, EfsPotato, PrinterBug, DFSCoerce, or Coercer) when attempting to coerce a local authentication or credential relay using the local loopback address. These tools leverage various RPC-based techniques to force the local machine to authenticate to an attacker-controlled source, facilitating NTLM relay attacks.
This rule detects when the Python interpreter (python.exe or py.exe) initiates a network connection to an internal or loopback IP address. This behavior can be indicative of a local process scanning the internal network, pivoting, or interacting with locally running services as part of a post-exploitation or reconnaissance activity.
Detects potential token manipulation attacks using SMB loopback connections. The rule identifies processes executing with privileges commonly associated with token impersonation (SeImpersonatePrivilege, SeAssignPrimaryTokenPrivilege) or running as SYSTEM that are not expected system processes, correlated with an SMB network connection to the local loopback address on port 445.
Detects unauthorized file operations (Creation, Modification, Rename, Deletion) on sensitive browser-related credential files (e.g., Login Data, Cookies, key4.db) by potentially unauthorized or suspicious processes identified by name.
