
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,149 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects when critical Windows services or processes associated with Active Directory (NTDS, Netlogon, LSASS, LDAP) or the Print Spooler (Spooler, spoolsv.exe) crash multiple times (3 or more) on a machine within a 7-day period. This could indicate instability, a denial-of-service attempt, or a system compromise affecting core services.
This rule detects an unusually high number of outbound network connections originating from the Local Security Authority Subsystem Service (LSASS) process on a Windows machine. LSASS is a critical system process responsible for enforcing security policy on the system, including user authentication, and typically does not initiate a large number of outbound connections. A high count of outbound connections from LSASS could indicate credential dumping activity, where an attacker is exfiltrating harvested credentials, or other malicious activity compromising the LSASS process.
Detects potential unauthorized browser extension installations or debugging activities by monitoring process and network events related to popular web browsers.
This rule monitors system logs for attempts to disable or stop the Linux Audit daemon (auditd) or modify its configuration via auditctl or system management commands (systemctl, service). Disabling the audit system is a common technique used by adversaries to hide malicious activity from security monitoring.
Detects the creation or modification of a Registry Run key value named 'csshost'. This technique is commonly used by malware or persistent threats to achieve automatic execution upon system logon or boot by masquerading as or hijacking a host-related entry.
Detects network connections to known command and control (C2) infrastructure associated with malicious NPM packages acting as Remote Access Trojans (RATs). The rule identifies specific outbound connections to a hardcoded malicious IP and port, as well as traffic involving a suspicious domain string.
Detects a sequence of events where PowerShell is used to download files from 'nvidiadriver.net' or with filenames containing 'winPatch', followed by a suspicious file drop (specifically 'winPatch.zip' or 'update.vbs') in a temporary directory within a 30-minute window. This behavior is indicative of potential initial staging for a RAT or malicious script deployment.
This rule detects potential discovery activities indicative of a virtual machine or virtualization environment enumeration. It monitors for the execution of wmic.exe or powershell.exe triggered by suspicious parent processes (python.exe, chost.exe) that query hardware-specific identifiers like Manufacturer, Model, or MAC Address using Win32_ComputerSystem or Win32_NetworkAdapterConfiguration.
Detects the creation or modification of a Registry Run key value named 'csshost'. This technique is commonly used by malware or persistent threats to achieve automatic execution upon system logon or boot by masquerading as or hijacking a host-related entry.
Detects indicators of execution related to a known NPM Remote Access Trojan (RAT), including masquerading via chost.exe, execution from specific temporary directories used by the malware, and Python scripts executing a loader.py file from temporary locations.
