
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potentially malicious activity related to the 'node-gyp' build tool used by npm. It monitors for two patterns: 1) npm spawning node-gyp, which can be an automated trigger for malicious binding.gyp files, and 2) node-gyp spawning node.exe with command-line arguments indicative of obfuscated JavaScript (e.g., base64 encoding, eval, AES-GCM patterns), a technique often seen in malicious Node.js packages.
Detects a sequence of events where PowerShell is used to download files from 'nvidiadriver.net' or with filenames containing 'winPatch', followed by a suspicious file drop (specifically 'winPatch.zip' or 'update.vbs') in a temporary directory within a 30-minute window. This behavior is indicative of potential initial staging for a RAT or malicious script deployment.
This rule detects network connections from internal hosts to identified C2 or phishing infrastructure associated with the threat actor group UNC1151 (also known as Ghostwriter). It monitors both host-based network events (via DeviceNetworkEvents) and centralized network security logs (via CommonSecurityLog) for traffic targeting a curated list of known malicious IP addresses.
This rule detects potential Remote Access Trojan (RAT) activity by identifying specific indicators associated with Nuitka-compiled binaries, specifically the 'chost.exe' filename or paths containing 'win-driver-xd7d'. Additionally, it monitors for suspicious Python-based loader executions ('loader.py') initiated from temporary directories, which is a common persistence or execution technique for such malware.
Detects Microsoft Office applications (Word, Excel, PowerPoint, Outlook, OneNote, Access, Publisher) spawning common command interpreters or scripting engines. This behavior is a common indicator of macro-based malware or malicious document exploitation where Office applications are used as an initial access vector to execute arbitrary code.
This rule detects potential SSH brute force attacks by identifying high-frequency authentication failures from sshd logs (more than 10 failures in 5 minutes) and rapid, potentially automated connection attempts on port 22 (more than 20 connections in 1 minute) originating from the same source IP on Linux systems.
Detects potential defense evasion using common Windows LOLBins (Living off the Land Binaries) to execute code from untrusted locations or remote sources. Specifically targets mshta.exe loading remote HTA files, regsvr32.exe performing Squiblydoo-style COM scriptlet execution via URL, and rundll32.exe executing DLLs from user-writable directories like Temp or AppData.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell processes. The rule looks for known bypass strings, memory patching via Marshal, reflection-based disabling of AmsiUtils, or base64-encoded AMSI patch targets.
Detects execution of PowerShell processes (powershell.exe, pwsh.exe) containing command-line arguments indicative of Antimalware Scan Interface (AMSI) bypass attempts. This includes known bypass strings, reflection-based patching of memory internals (AmsiUtils, GetDelegateForFunctionPointer), and base64-encoded fragments of common bypass techniques.
Detects modification or creation of Windows Registry Run keys by non-Microsoft signed instances of reg.exe, powershell.exe, or pwsh.exe. This activity is a common method for achieving persistence by ensuring malicious code executes automatically upon user login.
