
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects successful authentication events from accounts identified as service, managed, or robot accounts (e.g., svc_, sa_, msol, robot) originating from external IP addresses or exhibiting an unusually high number of distinct source IP addresses. This behavior is indicative of potential credential theft, token replay attacks, or unauthorized usage of service account identities.
Detects the creation of suspicious named pipes by low-privilege processes, which is a technique used by local privilege escalation tools (like PrintSpoofer, RoguePotato, and GodPotato) to intercept and impersonate high-privilege (SYSTEM) tokens.
This rule detects indicators of Adversary-in-the-Middle (AiTM) phishing infrastructure, specifically targeting Evilginx2 and similar proxy frameworks. It identifies unauthorized execution of Evilginx2 binaries, the presence of specific session and configuration files (.evilginx/, phishlets, session databases), unauthorized modifications to Nginx configurations, and the dropping of suspicious HTML lure files into web document roots by scripting interpreters.
This rule detects the creation of scheduled tasks using the 'schtasks.exe' utility with command-line arguments indicating persistence triggers ('onlogon', 'onstart') or elevation to the 'SYSTEM' account. Adversaries commonly use these methods to ensure malicious code executes automatically upon system startup or with high privileges to facilitate further exploitation.
Detects unauthorized attempts to access or list stored credentials via Windows Credential Manager using standard administrative tools (cmdkey.exe, vaultcmd.exe) or PowerShell, as well as direct unauthorized access to credential storage files within the AppData directory.
Detects the abuse of the CertUtil.exe Windows utility to download, decode, encode, or split files. This behavior is considered suspicious when initiated by common command-line shells or Office applications, which are frequently used as entry points for malicious scripts or macro-based attacks.
Detects instances where common web server processes initiate command interpreters or system utilities. This behavior is a common indicator of web shell execution, where an adversary uses a web application vulnerability to gain remote code execution on the underlying server.
Detects various techniques used by an attacker to escape a container environment or gain unauthorized access to host-level resources. This includes the execution of namespace manipulation tools (nsenter, unshare, chroot), unauthorized access to the docker.sock Unix socket, mounting of host filesystems from within a container, and direct attempts to access the host's /proc/1 namespace files.
This rule detects suspicious activity involving the BITSAdmin (bitsadmin.exe) utility, which is a known LOLBin (Living Off the Land Binary). It monitors for the creation of BITS jobs using suspicious flags (e.g., /transfer, /setnotifycmdline) potentially indicating external file downloads, as well as the execution of known command interpreters or utilities spawned as child processes by BITSAdmin, which is a common post-exploitation technique for persistence or secondary payload execution.
Detects potential PrintNightmare or Print Spooler exploitation by monitoring for the spoolsv.exe service spawning suspicious child processes (e.g., cmd, powershell, rundll32) and unauthorized files being dropped into the printer driver directory.
