
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell. Attackers often perform this action during the impact phase to prevent file recovery after ransomware deployment or other data destruction activities.
Detects modifications to the WDigest UseLogonCredential registry value, which is a known technique to force Windows to store plaintext credentials in memory. This is often performed by adversaries using tools like Mimikatz to facilitate credential dumping from the LSASS process.
Detects the abuse of the Windows utility mshta.exe to execute potentially malicious scripts or remote HTML applications (HTA). The rule looks for command-line arguments involving remote URL fetches (HTTP/HTTPS/UNC) or inline script execution (vbscript/javascript), which are common techniques for bypassing security controls and executing payloads.
Detects the creation or configuration of Windows services using sc.exe or PowerShell where the binary path points to suspicious, writable directories (Temp, AppData, or ProgramData). This behavior is often associated with persistence mechanisms where adversaries place malicious binaries in user-writable locations to execute with higher privileges.
Detects attempts to clear Windows event logs using the native command-line utility 'wevtutil' or PowerShell cmdlets 'Clear-EventLog' and 'Remove-EventLog'. Adversaries often perform this action to remove evidence of their activities from security, system, and application logs. The rule includes exclusions for common administrative, backup, and security-related processes to minimize false positives.
Detects attempts to disable or modify Windows Firewall settings using netsh, PowerShell, or direct registry modifications. Adversaries often perform these actions to evade detection and maintain uninhibited network communication for C2 or data exfiltration.
Detects modifications or creation of 'StubPath' registry values within the 'Active Setup\Installed Components' registry key, where the value points to suspicious, user-writable directories. This technique is commonly used to establish persistence by executing a malicious file upon user logon.
This rule detects unauthorized or suspicious queries against Windows Registry paths known to contain sensitive information, including security hives (SAM, SECURITY), application-specific secrets (PuTTY, OpenSSH, RealVNC), and system autologon credentials. It monitors both command-line executions of 'reg.exe' and PowerShell commands targeting these registry keys.
Detects the use of legitimate command-line utilities such as rclone, AWS CLI, AzCopy, curl, and wget to upload data to cloud storage endpoints, which is a common technique used for data exfiltration.
Detects attempts to disable the Windows Firewall using the netsh command-line utility or PowerShell cmdlets, as well as registry modifications related to firewall profiles. Adversaries often perform this action to impair host-based security controls and facilitate unauthorized inbound or outbound network traffic.
