
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects HTTP POST requests containing a Content-Length header value indicating a body size exceeding 10MB. Large POST requests may indicate data exfiltration, large file uploads, or misuse of HTTP channels for data transfer to external destinations.
This rule detects network traffic indicative of the NjRAT (Bladabindi) remote access trojan, specifically identifying its pipe-delimited command-and-control protocol patterns (e.g., '|ll|' or '|kl|').
Detects network traffic containing 'Active Setup', 'Installed Components', and 'StubPath' strings, which are indicative of a potential attempt to reference or trigger a malicious StubPath registry key for persistence.
Detects the transmission of a Portable Executable (PE) file header ('MZ' and 'PE' magic bytes) within an HTTP response stream, which is a common indicator of a staged file download or process injection payload being delivered over the network.
Detects network traffic attempting to modify SSH authorized_keys or the sshd_config file using SCP or SFTP protocols, which is a common technique used by attackers to maintain persistence on compromised systems.
This rule detects suspicious SMB traffic targeting raw disk volumes (e.g., PhysicalDrive, C:) or sensitive Windows files such as NTDS.dit and SYSTEM hive files. This behavior is indicative of credential dumping attempts, often performed using tools like secretsdump.py or Invoke-NinjaCopy, which bypass standard file system access controls to exfiltrate critical system credentials.
Detects network traffic attempting to access sensitive Windows Registry keys (SAM, SECURITY, LSA Secrets, winlogon DefaultPassword) over the SMB protocol, which is indicative of credential harvesting activities.
Detects signs of access token manipulation and impersonation, including the use of 'runas' with saved credentials, suspicious PowerShell API calls for identity management, usage of known token-manipulation tools (e.g., incognito), and reconnaissance using 'whoami /priv'. These activities are indicative of privilege escalation attempts or lateral movement.
Detects the use of native Windows utilities such as shutdown.exe, wmic, powershell, and rundll32 to trigger an immediate system shutdown or restart, which may be indicative of unauthorized system disruption or malicious activity.
Detects potential credential dumping activities and unauthorized access to sensitive system files. The rule monitors for three primary indicators: raw disk device access (often associated with volume shadow copy dumping), suspicious DiskShadow utility execution, and NTDS.dit extraction using ntdsutil. Known administrative and backup software processes are excluded to minimize noise.
