
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,137 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
This rule monitors for inbound email messages containing SVG file attachments. SVG files can contain embedded scripts that may be leveraged for malicious purposes, such as SVG smuggling to deliver secondary payloads or perform credential harvesting.
Detects the installation of Visual Studio Code extensions from sources other than the official Marketplace. This activity is monitored by checking process command line arguments for the --install-extension flag combined with external URLs or local file paths, which may indicate an attempt to install malicious extensions.
Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
This rule detects the presence of Blackbeard malware by identifying known SHA256 hashes of its components or network connections to its known C2 infrastructure. It correlates file events with specific hashes and network events with specific remote IP addresses.
Detects known malicious invoice PDFs and email samples used in Crimson Kingsnake campaigns.
This rule detects potential SSH brute force attacks by identifying multiple failed password attempts from a single source IP address to a specific computer within a 5-minute window. It specifically looks for 'Failed password' messages in syslog entries from the 'sshd' process.
This rule detects potential SSH brute force attacks by monitoring syslog for multiple failed SSH login attempts, connection closures, or invalid user attempts from a single source IP address within a short time frame. It specifically looks for keywords like 'error', 'Connection closed', 'authentication failure', and 'invalid user' in SSHD logs.
Detects the loading of 'hostfxr.dll' from suspicious user-specific AppData folders by 'CrossDeviceService.exe' or 'Teams.exe'. This behavior can indicate an attempt to load a malicious .NET runtime, potentially for DLL hijacking or code injection, often associated with persistence or execution techniques.
