
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,113 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects anomalous HTTP GET requests targeting the ClawHub API for 'skills' that match known patterns of malicious file downloads, specifically identifying poc.py scripts or skill.md files which are indicative of the ClawHavoc campaign activity.
Detects HTTP response bodies containing common PE/Shellcode magic headers (MZ, PE, or NOP sleds) which are associated with the delivery of payloads designed to exploit or utilize the Windows KernelCallbackTable for process injection. The detection focuses on suspicious content delivered over HTTP connections.
Detects usage of the Windows certutil.exe utility with flags commonly associated with malicious activity, including downloading files from remote URLs or decoding/encoding files within temporary or application data directories.
Detects the execution of vssadmin.exe or wmic.exe with command-line arguments intended to delete Volume Shadow Copies. This activity is a common indicator of ransomware or other destructive attacks aiming to inhibit system recovery.
This rule detects a high frequency of file rename or modification events targeting files with extensions commonly associated with ransomware. It filters out activity from processes signed by trusted vendors like Microsoft, Symantec, Sophos, and Trend Micro to reduce noise, flagging mass rename operations that could indicate an active ransomware encryption process.
Detects usage of the Windows certutil.exe utility with flags commonly associated with malicious activity, including downloading files from remote URLs or decoding/encoding files within temporary or application data directories.
Detects attempts to access or copy the Active Directory domain database (NTDS.dit) by monitoring for direct file access to the file or the execution of ntdsutil.exe with arguments intended to create an Install From Media (IFM) set, which is a known technique for exfiltrating the NTDS.dit file for offline password cracking.
Detects the execution of sc.exe with subcommands 'create' or 'start' where the command line includes a UNC path. This pattern is indicative of an adversary attempting to install or execute a service on a remote host to facilitate lateral movement.
Detects attempts to extract the Security Account Manager (SAM) database, either by using the 'reg save' utility to export registry hives containing the SAM or by directly creating/modifying the SAM file on disk outside of known legitimate system processes.
Detects the execution of the PsExec service (PSEXESVC) or command-line usage indicating remote service execution, including the standard PsExec '-accepteula' flag combined with network path indicators. Additionally detects the creation of the PSEXESVC service registry key, which is indicative of PsExec-based lateral movement or remote administration.
