
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,141 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects attempts to bypass User Account Control (UAC) using specific Windows executables (eventviewer.exe, fodhelper.exe, computerdefaults.exe, slui.exe) initiated by cmd.exe or powershell.exe. The rule specifically looks for these executables being run from non-standard system directories, indicating a potential UAC bypass technique often observed after an initial compromise, such as via RDP.
Detects the execution of known ransomware-related executables ('servertool.exe', 'encrypt.exe') when their command line arguments indicate interaction with cloud storage services such as OneDrive, SharePoint, GoogleDrive, Dropbox, or iCloud. This behavior is indicative of ransomware attempting to encrypt or exfiltrate data from cloud environments.
This rule detects network connections on port 21 (FTP) where the remote URL contains keywords indicative of NetWare directory listings or related services (netware, NDS, bindery, ncf). This could indicate an attempt to discover or interact with NetWare services, potentially exploiting vulnerabilities like Squidbleed.
This rule detects the creation or manipulation of mutexes by processes that contain keywords associated with the Remcos RAT (Remote Access Trojan). Specifically, it looks for command-line arguments containing "Remcos_Mutex_Inj", "Remcos_Mutex", "mutex", or "CreateMutex". This activity can indicate the presence or execution of Remcos RAT on a system, as mutexes are often used by malware for single-instance enforcement or inter-process communication.
Detects potential Command and Control (C2) communication associated with Emotet malware by monitoring for successful network connections to suspicious remote ports frequently used by the malware. The rule flags endpoints that establish connections to at least three of these high-risk ports within a one-hour window, which is indicative of automated C2 beaconing behavior.
This rule detects network connections on port 21 (FTP) where the remote URL contains keywords indicative of NetWare directory listings or related services (netware, NDS, bindery, ncf). This could indicate an attempt to discover or interact with NetWare services, potentially exploiting vulnerabilities like Squidbleed.
This rule detects potential command and control (C2) beaconing activity by identifying devices communicating with known suspicious remote IP addresses at regular, repeating intervals. It calculates the time difference between consecutive connections to specific suspicious IPs and identifies devices that establish at least three connections within one-hour bins, adhering to a 1 to 15-minute heartbeat interval.
This rule monitors Cisco Unified Communications Manager (UCM) environments for multiple stages of an attack chain, including potential Server-Side Request Forgery (SSRF) attempts against administrative interfaces, suspicious file modifications by service accounts, indicators of privilege escalation, and anomalous outbound network connections from core Cisco processes.
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
Detects anomalous device network activity involving 5G-specific protocol ports (e.g., GTP-U, SIP). The rule aggregates unique port usage per device over 1-hour intervals to identify potential network reconnaissance, scanning, or unauthorized control plane communication.
