
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects instances where common productivity applications (like Office suite) or web browsers spawn child processes that create system mutexes. This is a common indicator of malicious activity where a benign-looking document or web-based threat launches secondary payloads or persistence mechanisms.
This rule detects potential cloud resource hijacking (e.g., cryptojacking) by monitoring for a sudden spike in the deployment of Azure virtual machines by a single user. It triggers if a user creates five or more virtual machines in a 10-minute window, specifically looking for deployments in regions where the user has not recently created VMs, or deployments utilizing high-compute SKUs commonly targeted for cryptocurrency mining.
This rule detects potential Business Email Compromise (BEC) attempts by identifying emails containing financial keywords sent to sensitive finance/accounting roles from domains that have not been observed in the last 180 days. It then correlates this email event with subsequent device-level network activity involving banking or financial URLs initiated by the recipient user, which may indicate follow-up reconnaissance or unauthorized access.
Detects the use of PowerShell to perform DNS lookups for TXT records followed by immediate command execution, such as using 'Invoke-Expression' or 'Start-Process'. This pattern is frequently indicative of fileless command-and-control (C2) communication where stage-payload commands or scripts are retrieved via DNS TXT records to evade detection.
This rule detects network connections on TCP ports 7000, 7001, 8770, and 5353 (commonly associated with Apple services like AirPlay, AirPrint, and Bonjour) initiated by processes other than standard Apple binaries such as iTunes, AppleMobileDeviceService, Bonjour, or mDNSResponder. This behavior may indicate an attempt to blend into expected network traffic by masquerading as legitimate Apple service communication.
Detects high volumes of network connections initiated by common file sharing processes such as AirDrop, sharingd, NearShare, or QuickShare. This behavioral pattern, characterized by a large number of successful connections or numerous unique remote IP addresses, may indicate unauthorized mass data collection, reconnaissance, or potential lateral movement attempts.
Detects the creation of user accounts or modifications to sensitive groups (Event IDs 4720, 4728, 4732, 4756) where the account name matches naming conventions typically associated with backup service accounts or elevated administrative roles (e.g., prefix 'backup_', 'bkp_' or suffix '_da', '_ea'). This activity can indicate an attacker attempting to establish persistence or escalate privileges via compromised or newly created accounts.
Detects the creation or modification of Windows Registry keys or values within the 'CurrentControlSet\Services' path that refer to 'rustdesk'. This typically indicates the installation or configuration of the RustDesk remote access tool as a system service, which may be unauthorized or used for persistence by an adversary.
Detects the creation of scheduled tasks using schtasks.exe that point to the ProgramData directory, which is a common persistence location for malware like SystemBC. The rule excludes common, benign software installers and updaters that frequently use this directory to avoid false positives.
This rule monitors web request URLs and associated messages for common SQL injection characters and sequences, such as quotes and semicolons. It specifically targets requests involving the 'apiuser' account to identify potential attempts to manipulate or exploit backend database queries.
