
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects suspicious staging activity by monitoring for the creation of 'editor.dat' files in sensitive directories like C:\Users\Public or C:\Windows\Tasks, or the rapid accumulation of multiple executable files (.exe, .dll, .cpl) within the C:\Users\Public directory, which is a common technique used by attackers to stage tools before execution or lateral movement.
This rule detects file creation or modification events associated with the Miasma campaign. It identifies specific payload files (e.g., .claude/setup.mjs, .vscode/tasks.json), the use of specific marker strings in file metadata or origin URLs, and obfuscated task configurations in VS Code directories that leverage bun or node to execute base64-encoded or character-encoded commands.
Detects instances where the legitimate Windows utility 'Fondue.exe' (Features on Demand) loads the control panel library 'APPWIZ.cpl' from non-standard locations such as C:\Users\Public or AppData directories. It also identifies the staging phase where 'APPWIZ.cpl' is written to 'C:\Users\Public', which is indicative of a DLL side-loading attack sequence, often associated with the Elephant malware dropper.
Detects potential Command and Control (C2) communication associated with Emotet malware by monitoring for successful network connections to suspicious remote ports frequently used by the malware. The rule flags endpoints that establish connections to at least three of these high-risk ports within a one-hour window, which is indicative of automated C2 beaconing behavior.
This rule detects potentially unauthorized installation of extensions in Visual Studio Code (VSIX) or plugins in JetBrains IDEs (IntelliJ, PyCharm, WebStorm). It flags installations that do not originate from verified official marketplaces, which may indicate the manual installation of malicious or supply-chain compromised development environment extensions.
Detects outbound network connections from workstations or servers to common message broker ports (MQTT 1883/8883, AMQP 5672). These protocols are sometimes abused for command-and-control (C2) communication, as they allow for pub/sub messaging patterns that can blend into legitimate network traffic.
This rule detects outbound network connections to common webhook and temporary storage services (e.g., discord.com webhooks, webhook.site, pipedream.net) initiated by processes other than standard web browsers. Such behavior is often indicative of automated data exfiltration, command-and-control (C2) communication, or malicious script activity using these services to bypass traditional network defenses.
This rule detects potentially unauthorized installation of extensions in Visual Studio Code (VSIX) or plugins in JetBrains IDEs (IntelliJ, PyCharm, WebStorm). It flags installations that do not originate from verified official marketplaces, which may indicate the manual installation of malicious or supply-chain compromised development environment extensions.
Detects the use of PowerShell to perform DNS lookups for TXT records followed by immediate command execution, such as using 'Invoke-Expression' or 'Start-Process'. This pattern is frequently indicative of fileless command-and-control (C2) communication where stage-payload commands or scripts are retrieved via DNS TXT records to evade detection.
Detects the execution of Python interpreters spawned by code editors or runtime environments (e.g., VS Code, Cursor, Node.js) with specific command-line arguments involving 'init'. This behavior may indicate an adversary attempting to leverage development tools to execute custom scripts, potentially for automated deployment, persistence, or malicious payload initialization.
