
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects suspicious modifications to Registry Run and RunOnce keys that include common scripting or command execution keywords (powershell, cmd, .bat). This activity is often associated with persistence mechanisms where adversaries attempt to execute malicious code upon user login.
Detects attempts to delete volume shadow copies using 'vssadmin' or 'wmic shadowcopy' commands. Adversaries often delete shadow copies to prevent system recovery and hinder forensic analysis, especially during ransomware attacks or data destruction efforts.
Detects suspicious execution of wmic.exe where the command line contains keywords often associated with enumeration or manipulation of processes and services. This can indicate an adversary using WMI for discovery or execution.
This rule detects the installation of new Windows services (EventID 7045) where the service's executable path (ServiceFileName) contains common scripting interpreters like 'cmd', 'powershell', or 'wscript'. This pattern can indicate an adversary attempting to establish persistence or execute malicious code via a newly created service that leverages scripting capabilities.
This rule detects the creation or modification of scheduled tasks (EventID 4698 or 4699) where the command line for the task contains references to scripting languages like PowerShell, cmd, or VBScript. It then groups these events by computer and user, flagging if two or more such tasks are created by the same user on the same computer, which could indicate malicious activity.
This rule detects potential brute force attacks against Azure AD accounts by identifying users with 10 or more failed sign-in attempts due to invalid credentials within a 5-minute window. It summarizes the failure count and associated IP addresses for each user.
Detects multiple failed Kerberos pre-authentication attempts (EventID 4771 with status codes 0x18 or 0x1f) from a single IP address against a target user within a short timeframe (20 attempts in 5 minutes). This pattern is indicative of a brute-force attack against Kerberos accounts.
This rule detects when five or more driver-related files (.inf, .sys, or .drv) are created or modified within a one-hour window by the same initiating process account. This behavior can be indicative of malicious driver installation, rootkit activity, or other forms of persistence or privilege escalation.
This rule detects potential vulnerability scanning activity by identifying multiple network connection attempts to common vulnerable ports (135, 139, 445) where the remote URL contains keywords like 'vuln' or 'scan'. It aggregates these activities by device and time, flagging devices with 5 or more such connections within an hour.
Detects the creation of files containing keywords such as 'vulnerability', 'assessment', or 'scan'. This rule aims to identify activities related to vulnerability scanning or security assessments being performed on a system, potentially indicating reconnaissance or unauthorized activity. The events are summarized by the initiating process account name and time to help identify the source of these activities.
