
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the spawning of administrative command-line utilities (cmd.exe, powershell.exe, wscript.exe, certutil.exe, mshta.exe) from processes related to Wyse Management Suite (WMS), Tomcat, or Java. This pattern is often indicative of exploitation of web applications or management services to gain command-line access on the underlying system.
Detects the execution of a process named 'gemini.exe' with the '--yolo' command-line argument when spawned by common CI/CD runner processes such as 'actions-runner', 'runner.worker', 'node', or 'npm'. This pattern may indicate unauthorized use of execution environments or potential exploitation of a CI/CD pipeline to run suspicious tools.
This rule detects network activity involving known suspicious domains and the download of specific, potentially malicious files (archives and installers). The monitoring focuses on HTTP/proxy/DNS traffic where hostnames, URLs, or query parameters match indicators of malicious activity.
This rule detects processes that load .NET-related modules (clr.dll or dotnet.exe) and maintain a network connection (port 80 or 443) for more than one hour during standard business hours. This behavior is indicative of potentially persistent, long-running .NET-based applications or potentially malicious tools maintaining persistence and C2 communication.
Detects HTTP traffic patterns associated with the Turla STOCKSTAY malware establishing a WebSocket connection to the known C2 domain 'wool-basalt-clock.glitch.me'. The rule monitors for a GET request containing specific HTTP headers (Upgrade: websocket) required for protocol switching to WebSocket, which is a common technique for establishing persistent C2 channels.
This rule detects outbound HTTP traffic generated by the WinHTTP library, specifically when the User-Agent identifies as WinHttp.WinHttpRequest. This pattern is indicative of potential post-exploitation activity, such as command-and-control communication or data exfiltration, originating from a process associated with an exploited Excel document (CVE-2025-60727).
This rule detects attempts to exploit a path traversal vulnerability (CVE-2026-49506) in the Dell Wyse Management Suite API. The rule inspects HTTP requests for directory traversal sequences such as '..' or URL-encoded equivalents, which could allow an unauthorized attacker to access files or directories outside the intended scope on the web server.
Detects HTTP GET requests for specific malicious archives (calculator.rar, EditorToolsPdf.zip) originating from suspected compromised Ukrainian domains (basecon.com.ua, online.zp.ua). This behavior is associated with the STOCKSTAY malware used by the threat actor Turla.
Detects web traffic where the referrer header contains keywords associated with gaming or educational themes (such as 'bioshock', 'game', 'puzzle', 'math', 'quiz') combined with access attempts to sensitive URI paths (like '/code', '/token', '/secret', '/private', '/api-key') resulting in a redirect status (301-308). This behavior pattern is often indicative of automated reconnaissance or exploitation attempts using non-standard or obfuscated referrers to bypass simple security filters.
This rule detects the use of 'net.exe' or 'net1.exe' to configure a non-standard SMB port, which is a technique often used for NTLM reflection and relay attacks. By specifying an arbitrary port for SMB traffic, an attacker may attempt to bypass standard network filtering or establish a listener to intercept authentication requests.
