
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,129 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for potential abuse of the Microsoft Management Console (mmc.exe) to proxy malicious activity. It detects three primary behaviors: 1) mmc.exe being launched with a .msc file originating from user-writable or suspicious directories; 2) mmc.exe spawning known suspicious child processes (e.g., powershell.exe, cmd.exe, rundll32.exe); and 3) the creation or modification of .msc files in suspicious locations by processes other than mmc.exe or msiexec.exe.
This rule detects unauthorized or suspicious queries against Windows Registry paths known to contain sensitive information, including security hives (SAM, SECURITY), application-specific secrets (PuTTY, OpenSSH, RealVNC), and system autologon credentials. It monitors both command-line executions of 'reg.exe' and PowerShell commands targeting these registry keys.
This rule detects ransomware activity by identifying two primary indicators: a high volume of file renames to common ransomware extensions within a 5-minute window, and the creation of known ransom notes across multiple directories. It excludes processes signed by trusted vendors to minimize noise.
Detects potential dynamic linker hijacking on Linux systems by monitoring for the use of non-standard LD_PRELOAD paths in process command lines or unauthorized modifications to the /etc/ld.so.preload configuration file, which can be used to inject malicious code into processes.
Detects unauthorized cross-process memory operations targeting high-value Windows processes (e.g., lsass.exe, svchost.exe) by unsigned or untrusted processes. It also detects indicators of reflective DLL injection within process command lines.
Detects the use of living-off-the-land tools like plink.exe, netsh.exe, and ssh.exe to create tunnels that forward RDP traffic (port 3389). This behavior is often indicative of an adversary attempting to bypass network controls or hide RDP sessions by tunneling them through other protocols or non-standard port configurations.
This rule detects potential Active Directory Certificate Services (AD CS) abuse (specifically ESC1 and ESC8 patterns) by monitoring command-line executions of 'certreq.exe' and 'certutil.exe' that utilize suspicious flags or originate from non-standard administrative processes. This activity is indicative of an attacker attempting to enroll certificates for unauthorized entities or escalate privileges within a Windows domain.
Detects techniques associated with Golden SAML attacks, including the use of Mimikatz for ADFS token-signing certificate extraction, the execution of AADInternals PowerShell cmdlets for SAML token forgery, and unauthorized access to the ADFS configuration database (AdfsConfiguration.mdf).
Detects successful authentication events from accounts identified as service, managed, or robot accounts (e.g., svc_, sa_, msol, robot) originating from external IP addresses or exhibiting an unusually high number of distinct source IP addresses. This behavior is indicative of potential credential theft, token replay attacks, or unauthorized usage of service account identities.
Detects WMI persistence mechanisms by monitoring for suspicious child process spawning from WMI host processes (scrcons.exe, wbemcons.exe), unauthorized loading of MOF files via mofcomp.exe, and execution of common living-off-the-land binaries directly by the WMI provider host (wmiprvse.exe).
