
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects Microsoft Office applications (Word, Excel, PowerPoint, Outlook, OneNote, Access, Publisher) spawning common command interpreters or scripting engines. This behavior is a common indicator of macro-based malware or malicious document exploitation where Office applications are used as an initial access vector to execute arbitrary code.
This rule detects unauthorized attempts to create, modify, rename, or delete sensitive browser data files (such as Login Data, Cookies, key4.db, and logins.json) used for storing credentials. It monitors for access by processes that are not known browser executables or authorized system services, which is a common indicator of credential dumping by malicious software.
Detects behaviors associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, including the dropping of .sys driver files into non-canonical directories, the registration and execution of kernel services via sc.exe, the use of fltMC to load filter drivers, and the loading of driver modules from non-standard locations.
This rule detects potential SSH brute force attacks by identifying high-frequency authentication failures from sshd logs (more than 10 failures in 5 minutes) and rapid, potentially automated connection attempts on port 22 (more than 20 connections in 1 minute) originating from the same source IP on Linux systems.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell processes. The rule looks for known bypass strings, memory patching via Marshal, reflection-based disabling of AmsiUtils, or base64-encoded AMSI patch targets.
Detects instances where a digitally signed process loads a DLL file from a user-writable directory (e.g., AppData, Downloads, or Temp). This behavior is characteristic of DLL side-loading or search-order hijacking, where an adversary attempts to execute malicious code within the context of a trusted, signed application.
Detects execution of PowerShell processes (powershell.exe, pwsh.exe) containing command-line arguments indicative of Antimalware Scan Interface (AMSI) bypass attempts. This includes known bypass strings, reflection-based patching of memory internals (AmsiUtils, GetDelegateForFunctionPointer), and base64-encoded fragments of common bypass techniques.
This rule detects potential command and control (C2) beaconing activity by identifying devices communicating with known suspicious remote IP addresses at regular, repeating intervals. It calculates the time difference between consecutive connections to specific suspicious IPs and identifies devices that establish at least three connections within one-hour bins, adhering to a 1 to 15-minute heartbeat interval.
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
This rule detects anomalous network connections or DNS queries to known Ethereum RPC infrastructure providers (Infura, Alchemy, Cloudflare-eth) or ports/domains associated with Ethereum mainnet activity. It specifically targets processes other than common browsers or known blockchain clients, as well as Java-based processes performing DNS lookups for these domains. This behavior is indicative of potential 'EtherHiding' techniques where malicious code or data is hidden within blockchain transactions or distributed via blockchain infrastructure.
