
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects high volumes of network connections initiated by common file sharing processes such as AirDrop, sharingd, NearShare, or QuickShare. This behavioral pattern, characterized by a large number of successful connections or numerous unique remote IP addresses, may indicate unauthorized mass data collection, reconnaissance, or potential lateral movement attempts.
This rule detects successful outbound network connections from an endpoint to a known Tor directory authority IP address. Establishing a connection to these authorities is a strong indicator that the system is attempting to join the Tor network or is interacting with Tor infrastructure, which may be unauthorized in enterprise environments.
Detects instances of rundll32.exe being executed with command-line arguments that suggest malicious activity, specifically loading modules from remote UNC paths, using the javascript: protocol, or explicitly invoking ShellExec_RunDLL via shell32.dll. This rule filters out legitimate signed Microsoft binaries to focus on potentially unauthorized or malicious proxies.
Detects the execution of MAVInject.exe (Microsoft Application Virtualization Injector) with the /INJECTRUNNING parameter, a technique used to inject malicious code into a running process to evade detection.
Detects the use of native Windows binaries 'netsh.exe' to establish port proxies or 'pktmon.exe' for network packet monitoring/filtering by processes that are not signed by Microsoft. This behavior is indicative of network tunneling or C2 communication techniques used by actors such as Volt Typhoon to maintain persistence and establish network pivots.
Detects the creation, reading, or execution of payloads stored within NTFS Alternate Data Streams (ADS). This technique is commonly used by adversaries to hide malicious content within file metadata to evade security tools. The rule monitors process command-line arguments for ADS syntax, identifies usage of utilities like type, Get-Content, wmic, or various LOLBins (e.g., regsvr32, rundll32) interacting with ADS paths, and flags anomalous file creation/modification events that involve ADS, excluding known system-generated streams.
Detects unauthorized processes attempting to access or perform operations on sensitive files such as browser credentials, SSH keys, crypto wallets, and password manager databases. The rule specifically looks for non-standard or unsigned processes interacting with a high volume of these files in a short time frame, which is indicative of credential harvesting by infostealer malware like Lumma, Redline, or Vidar.
Detects the creation of scheduled tasks using schtasks.exe that exhibit suspicious characteristics. This includes tasks referencing external URLs, those containing base64-encoded or obfuscated command strings, and tasks pointing to binaries or scripts in user-writable paths (e.g., AppData, Temp). The rule specifically targets tasks intended to run with SYSTEM privileges or those using common persistence triggers, while excluding known legitimate administrative software.
This rule detects outbound network connections to common webhook and temporary storage services (e.g., discord.com webhooks, webhook.site, pipedream.net) initiated by processes other than standard web browsers. Such behavior is often indicative of automated data exfiltration, command-and-control (C2) communication, or malicious script activity using these services to bypass traditional network defenses.
Detects attempts to terminate security-related processes or stop security services using common Windows command-line utilities such as taskkill, tskill, or the net stop command. This behavior is indicative of an adversary attempting to impair defensive measures on a compromised system.
