
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects potential DCSync attacks by monitoring for Windows Event ID 4662 (Object Access) where a non-domain controller account exercises directory replication rights (DS-Replication-Get-Changes-All) against Active Directory domain objects. This identifies unauthorized attempts to pull sensitive credential data directly from a Domain Controller.
Detects instances where a user or service principal is assigned to high-privilege roles (e.g., Global Administrator, Owner) without utilizing the Microsoft Entra Privileged Identity Management (PIM) service. This is indicated by the absence of 'PIM' in the LoggedByService field for a successful 'Add member to role' operation, which could signify an attempt to bypass established access controls and gain unauthorized elevated persistence.
This rule detects potential clipboard data theft by monitoring Windows Sysmon Event ID 10 for process access events involving clipboard-related APIs (OpenClipboard, GetClipboardData) by untrusted processes, and PowerShell Script Block Logging (Event ID 4104) for the use of Get-Clipboard cmdlets. This identifies attempts by non-standard or unauthorized processes to access sensitive information copied by a user.
Detects instances where known endpoint security product binaries (EDR/AV) load DLL files from directories outside of their trusted, standard installation paths. This behavior is a common indicator of DLL sideloading, where an attacker attempts to masquerade malicious code as a component of a trusted security process to evade detection.
This rule detects when the WMI provider host process (wmiprvse.exe) spawns common scripting interpreters or command-line shells such as cmd.exe, powershell.exe, or wscript.exe. This behavior is a common indicator of remote command execution via WMI, often used by adversaries for lateral movement, remote code execution, or persistence within a Windows environment.
Detects the execution of known living-off-the-land binaries (LOLBins) such as mshta.exe, certutil.exe, bitsadmin.exe, wscript.exe, or cscript.exe directly by explorer.exe. This pattern is indicative of a user-initiated execution, potentially triggered by social engineering lures like the 'ClickFix' technique, where a user is tricked into pasting and running malicious commands in the Windows Run dialog or a command prompt context.
Detects instances where a legitimately signed executable located in protected system directories (System32, SysWOW64, Program Files) loads a DLL module from common user-writable directories (Temp, AppData, Public, ProgramData). This behavior is characteristic of DLL sideloading, where an adversary leverages a trusted binary to execute malicious code contained in a side-loaded DLL.
Detects potential BaoLoader drive-by compromise attempts by monitoring two stages: first, the creation of executable files in temporary or application data directories by browser processes; and second, the execution of command-line shells by processes running from those same directories where the browser acted as the grandparent.
This rule monitors for two distinct suspicious activities: 1) Inbound emails where the sender display name matches a list of executive titles, commonly indicative of Business Email Compromise (BEC) or executive impersonation attacks; 2) The creation of cloud service accounts with names mimicking administrative or IT support roles, which may indicate an adversary establishing persistent, privileged access.
This rule monitors for two types of anomalous network behavior: first, it identifies connections to known domains from IP addresses not previously associated with those domains over a seven-day lookback period. Second, it identifies HTTP proxy responses (from Zscaler or Squid) where the content-length significantly deviates from the historical baseline for specific URLs. These patterns are potential indicators of C2 channel shifts or data exfiltration via web protocols.
