
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects an unusually high number of web search queries (identified by 'search' or 'query' in the URI) originating from a single IP address within a one-hour window. A threshold of 100 or more queries triggers the alert. This behavior could indicate automated activity such as web scraping, reconnaissance, or a denial-of-service attempt against the search functionality.
This rule detects repeated execution of 'maven' or 'gradle' commands on a system within a one-hour window. A high count (5 or more) of these commands from the same account on the same computer within an hour could indicate unusual development activity, automated build processes, or potentially malicious activity related to software supply chain compromise or development environment abuse.
Detects the creation of files ending with '.sig', '.asc', or '.cer'. These extensions are commonly associated with digital signatures, PGP/GPG keys, and certificates, which could indicate activities like code signing, certificate generation/import, or PGP/GPG key manipulation by an adversary.
This rule detects processes making a high volume of network connections (10 or more within an hour) to URLs containing 'release' or 'download'. This behavior can be indicative of malware downloading additional components, updates, or exfiltrating data, but could also be legitimate software updates or large file transfers.
This rule detects repeated execution of commands containing both 'version' and 'control' keywords within the command line. It specifically looks for at least 5 such executions within a one-hour window on the same computer by the same account. This pattern could indicate an adversary attempting to enumerate system or software versions, or interact with version control systems, potentially as part of reconnaissance or privilege escalation.
This rule detects when a single process account initiates the deletion of 10 or more executable (.exe), dynamic link library (.dll), or system (.sys) files within a 5-minute window on a device. This behavior can be indicative of malicious activity such as malware cleanup, anti-forensics, or an attempt to disrupt system functionality.
This rule monitors successful operations related to Azure Traffic Manager within Azure Activity logs. It summarizes the count of such operations by the caller and time, ordered by the most recent activity. This can be used to track administrative actions or changes made to Traffic Manager configurations.
This rule detects an unusual number of successful encryption-related operations performed by a single caller within a one-hour window in Azure Activity logs. This could indicate legitimate bulk administrative tasks or potentially malicious activity such as data encryption for impact (e.g., ransomware) or preparation for exfiltration by an attacker.
This rule detects a spike in modifications or creations of Azure Diagnostic Settings within a one-hour window. A high volume of 'Diagnostic Setting' operations by a single caller could indicate an attempt to alter logging configurations, potentially to impair defenses or hide malicious activity.
This rule detects the execution of processes where the command line contains keywords commonly associated with privilege escalation or gaining administrative privileges, such as 'getadmin' or 'privesc'. It monitors Windows Security Event ID 4688, which logs process creation.
