
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,139 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
This rule detects potential ransomware lateral movement patterns by correlating specific network connection attempts (SMB/RDP/RPC) with the observed creation of files having the '.prinzeugen' extension on the same host within a 2-hour window. This behavior is indicative of a ransomware strain propagating across the network and performing encryption.
This rule detects the creation or manipulation of mutexes by processes that contain keywords associated with the Remcos RAT (Remote Access Trojan). Specifically, it looks for command-line arguments containing "Remcos_Mutex_Inj", "Remcos_Mutex", "mutex", or "CreateMutex". This activity can indicate the presence or execution of Remcos RAT on a system, as mutexes are often used by malware for single-instance enforcement or inter-process communication.
This rule detects potentially malicious activity related to the 'node-gyp' build tool used by npm. It monitors for two patterns: 1) npm spawning node-gyp, which can be an automated trigger for malicious binding.gyp files, and 2) node-gyp spawning node.exe with command-line arguments indicative of obfuscated JavaScript (e.g., base64 encoding, eval, AES-GCM patterns), a technique often seen in malicious Node.js packages.
Detects rapid access (three or more distinct files within a 60-second window) to sensitive files typically containing credentials or configuration data (e.g., SSH keys, AWS credentials, environment files, container configurations). This pattern is often associated with credential dumping or reconnaissance activity by an adversary attempting to harvest secrets.
This rule detects the creation or configuration of a scheduled task named 'GoogleErrorReport' which references 'Fondue.exe' located in the 'C:\Users\Public' directory. This specific pattern is associated with 'Dropping Elephant' malware persistence, where the task ensures the binary executes persistently on the host.
Detects instances where the legitimate Windows utility 'Fondue.exe' (Features on Demand) loads the control panel library 'APPWIZ.cpl' from non-standard locations such as C:\Users\Public or AppData directories. It also identifies the staging phase where 'APPWIZ.cpl' is written to 'C:\Users\Public', which is indicative of a DLL side-loading attack sequence, often associated with the Elephant malware dropper.
Detects the execution of PowerShell with suspicious download-related commands (Invoke-WebRequest, DownloadFile, WebClient, IEX, DownloadString) when initiated through conhost.exe, specifically when the originating parent process is a common shell or utility associated with shortcut (.lnk) file execution or specific command patterns.
This rule detects suspicious activity related to GitHub Actions workflows, including the creation or modification of workflow configuration files, the placement of suspicious JavaScript files in the repository's .github directory, the execution of the 'Bun' runtime within an Actions runner environment, and cloud-based events indicating workflow modification containing 'Run Copilot' strings. These patterns are often associated with CI/CD pipeline compromise, malicious automation, or unauthorized code execution within build environments.
Detects command-line activity containing keywords associated with process injection or hollowing techniques (e.g., shellcode, inject, hollow, replace) when executed by common script interpreters targeting critical system processes.
