
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,139 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects when a non-root user modifies, creates, or renames files within common cron directories or the main crontab file on Linux systems. This activity can indicate an attempt to establish persistence or schedule malicious tasks.
This rule detects network connections to phishing pages hosted on the workers.dev domain that are attempting to interact with EvilTokens device code API endpoints. These pages are known to implement developer hotkey prevention (F12 blocked, context menu disabled) to hinder in-browser analysis, indicating malicious intent.
This rule detects the creation of user namespaces on Linux systems by unprivileged users. The 'unshare' command with '--user' or '-U' flags allows a process to move into a new user namespace, which can be abused for privilege escalation or container escape. The rule specifically excludes common container runtimes and processes running as 'root' to reduce false positives.
This rule detects attempts to tamper with critical Linux log files such as /var/log/auth.log, /var/log/syslog, and /var/log/audit/audit.log. It specifically looks for file deletion or modification events, or process creation events that involve commands like 'rm', 'shred', 'truncate', 'unlink', or 'dd' targeting these log files. Legitimate processes like 'logrotate', 'rsyslog', 'syslog-ng', 'auditd', 'systemd', and 'journald' are excluded to reduce false positives.
This rule detects a sequence of events indicative of ransomware deployment following a successful Remote Desktop Protocol (RDP) connection. Specifically, it looks for an inbound RDP connection (RemotePort 3389) to a device, followed within 60 minutes by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') on the same device. This pattern suggests an attacker gaining initial access or moving laterally via RDP and then deploying ransomware.
Detects instances of FTP transfer mode switching (ASCII/Binary) by monitoring network events for FTP traffic on port 21 and specific commands like 'TYPE A' or 'TYPE I' in the RemoteUrl. This behavior can be indicative of data transfer activities, potentially related to vulnerabilities or malicious data exfiltration.
Detects the execution of Mimikatz or its common command-line arguments used for credential dumping. This rule identifies attempts to extract sensitive authentication material such as passwords, hashes, and tickets from memory (LSASS), SAM database, LSA secrets, and cached domain credentials.
This rule detects instances where the WhatsApp Desktop application (WhatsApp.exe) spawns suspicious child processes commonly used for scripting or command execution, such as wscript.exe, cscript.exe, powershell.exe, cmd.exe, or rundll32.exe. It specifically excludes known legitimate update and service-related command lines to reduce false positives. This behavior could indicate a phishing attempt or malware execution originating from a compromised WhatsApp session.
Detects attempts to exploit the Squidbleed vulnerability by monitoring 'squid.exe' process command lines for keywords related to FTP default configuration exploitation, specifically 'Safe_ports', 'CONNECT', 'PORT', 'PASV', '21', and 'tcp_outgoing_address'. This indicates an adversary trying to bypass security controls or exfiltrate data via FTP.
Detects process command lines containing keywords associated with resource extraction, decryption, or decompression, specifically when initiated by 'GST*.com' or involving 'Optimax.dll'. This behavior is indicative of a Remcos RAT loader attempting to unpack or prepare its payload.
