
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects an unusually high volume of registry access events (Event ID 4656) targeting either the 'HKLM' (HKEY_LOCAL_MACHINE) hive or 'System Registry' within a one-hour window. A count of 10 or more such events by a single user on a specific computer within an hour is considered suspicious. This activity could indicate an adversary attempting to enumerate system configurations, modify system settings for persistence, or gather information.
This rule detects a high volume of access attempts to the IPC$ administrative share from a single source IP address within a one-hour window. This behavior can be indicative of reconnaissance, lateral movement, or other malicious activities using SMB/Windows Admin Shares.
This rule detects a high volume of failed object access attempts (EventID 4674) by a single user on a specific computer within a one-hour window. This could indicate an adversary attempting to discover or access sensitive resources, potentially as part of privilege escalation or data exfiltration efforts.
This rule detects modifications to the 'AdminCount' attribute in Active Directory, indicated by Event ID 5136. Changes to this attribute can signify privilege escalation attempts or modifications to highly privileged accounts.
This rule detects when a user account repeatedly (3 or more times within an hour) requests either 'SeDebugPrivilege' or 'SeImpersonatePrivilege' (Event ID 4672). This behavior can be indicative of an attacker attempting to escalate privileges or manipulate access tokens, often seen in techniques like token impersonation or debugging processes for malicious purposes.
This rule detects an unusually high volume (10 or more within an hour) of file creations with extensions commonly associated with backup files (.backup, .bak, .old). This activity could indicate an adversary attempting to inhibit system recovery by creating numerous backup files, potentially to overwrite legitimate backups or to stage data for exfiltration or destruction.
Detects command-line installation of VS Code extensions. Malicious Jupyter notebooks can simulate keystrokes to silently install rogue extensions that steal GitHub tokens.
Detects Bun processes launched from temporary locations within containers. This behavior may indicate unauthorized package execution, workload drift, malicious tooling deployment, or post-compromise activity in cloud-native environments.
Detects execution chains where npm launches Node.js and Node.js subsequently launches Bun. This sequence may indicate malicious package execution, dependency confusion attacks, CI/CD compromise, or supply-chain abuse.
Identifies device code sign-ins originating from infrastructure previously associated with phishing operations and adversary-controlled relay servers.
