
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the creation of new processes where the command line contains keywords such as 'exploit' or 'vulnerability'. This could indicate an attempt to execute an exploit or leverage a known vulnerability, potentially as part of an attack.
This rule detects the execution of processes with command lines containing keywords associated with common vulnerability scanners such as 'scanner', 'nessus', or 'qualys'. It aggregates these events by computer and account over one-hour intervals to identify potential vulnerability scanning activity within the environment.
This rule detects potential vulnerability scanning activity by identifying devices making multiple successful network connections to specific ports commonly used by vulnerability scanners (8834, 8889, 1241). A device is flagged if it makes 3 or more such connections within a one-hour window.
This rule detects a high volume of process creation events (EventID 4688) where the command line contains keywords indicative of patching or updating activity (e.g., 'patch', 'update', 'KB', 'hotfix'). Specifically, it triggers if 3 or more such events occur on a single computer within an hour. This could indicate legitimate system updates, but also potentially malicious activity masquerading as updates to evade detection or perform unauthorized actions.
This rule detects when the Windows Security Event Log (Event ID 1102) has been cleared on a system. Clearing event logs is a common technique used by adversaries to remove traces of their activity and evade detection.
This rule detects an unusually high volume (10 or more within an hour) of permission changes to files or registry keys by a single user. This activity can be indicative of an adversary attempting to modify access controls to facilitate persistence, privilege escalation, or defense evasion.
This rule detects changes to the domain password policy by monitoring Windows Security Event ID 4739. It summarizes these events by the user who made the change and the time, providing an hourly count of policy modifications. This can help identify unauthorized or suspicious alterations to critical security policies.
This rule detects and summarizes changes to domain groups (creation, deletion, or modification) by a specific user. It counts the number of such changes per user per hour, which can be indicative of administrative activity or potential malicious account manipulation.
This rule detects a high volume (50 or more) of HTTP errors (status codes 400 and above) originating from a single client IP address within a 5-minute time window. This behavior can be indicative of various malicious activities such as brute-force attacks, web application vulnerability scanning, or denial-of-service attempts against a web server.
This rule detects a high volume of POST requests to login, authentication, or password-related URI stems within a 5-minute window from unique IP addresses. This behavior is indicative of brute-force attacks or credential stuffing attempts against web applications.
