
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,134 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects two suspicious activities within a user's mailbox: (1) An email flood, where a recipient receives more than 500 emails within a 5-minute window, potentially indicating an attempt to overwhelm or hide secondary emails; and (2) The creation or modification of inbox rules that include actions like deleting or moving messages, which is a common persistence and evasion technique used by attackers to hide C2 or phishing communications.
Detects instances where the WMI Provider Host process (WmiPrvSE.exe) spawns common interactive shells, scripting interpreters, or other binaries typically associated with remote command execution. This pattern is a strong indicator of WMI being abused for lateral movement or remote code execution within a Windows environment.
This rule detects potential email spoofing attempts by identifying mismatches between P1 (envelope) and P2 (header) sender addresses, identifying discrepancies between sender and reply-to domains, and flagging emails where the display name impersonates common executive or IT support roles.
Detects unauthorized attempts to enumerate stored Windows credentials using native command-line utilities such as vaultcmd.exe and cmdkey.exe, or by invoking CredEnumerate/Get-StoredCredential functions via PowerShell scripts. These methods are commonly used by attackers to gain access to cached passwords, tokens, or network credentials stored in the Windows Credential Manager.
Monitors GitHub audit logs for suspicious or high-risk activities within CI/CD pipelines, including actions triggered by forks, workflow approvals, branch policy overrides, self-hosted runner registration, and sensitive secret access.
Detection rule monitoring for indicators of compromise related to SolarWinds Serv-U, including anomalous Content-Encoding headers, unexpected child process execution, large file staging indicative of data exfiltration (Cl0p-style), outbound exfiltration, SQL injection artifacts, and unauthorized LDAP/Active Directory object enumeration by the Serv-U process.
Detects anomalous activity associated with information stealing malware, including unauthorized access to browser credential files (Login Data, Cookies), remote thread injection into browser processes, outbound connections to the Telegram API by non-browser processes, and rapid bulk access to multiple sensitive credential or crypto wallet files.
This rule detects a multi-stage attack chain on macOS involving a browser or mail client spawning a shell to download a file (DMG) via curl/wget, followed by the mounting of that disk image, execution of an application bundle from the mounted volume, and a subsequent outbound network connection from that application. This behavior is indicative of a user-initiated malware execution chain.
Detects the use of legitimate administrative tools (regsvcs.exe, infinstall.exe, devcon.exe) being executed with command-line arguments indicative of driver or kernel-level installations (e.g., 'kernel', 'ring0', 'driver install'). This behavior is commonly associated with the installation of rootkits or the execution of Bring Your Own Vulnerable Driver (BYOVD) attacks to gain kernel-mode privileges.
Detects FTP protocol traffic (on port 21) initiated by a process named 'squid.exe' or containing 'squid' in its filename. This rule is designed to identify potential exploitation attempts related to the Squidbleed vulnerability, where a compromised Squid proxy might be used for unauthorized FTP communications.
