
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,144 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects processes containing sensitive credential-related keywords (cookies, creds, password, token) in their command lines followed by a network connection to known suspicious remote IP addresses within a 60-minute window, suggesting potential credential exfiltration.
Detects potential DLL hijacking persistence by identifying modifications to registry values containing executable or library files that point to locations outside standard Windows system directories (System32 or SysWow64), subsequently joined with the execution of legitimate binary proxies known to be abused for side-loading like rundll32.exe or regsvcs.exe.
This rule detects potential command and control (C2) beaconing activity associated with Mythic implants. It monitors for high-frequency outbound connections (20 or more) from a single device to the same external IP address within a 30-minute window across common C2 listener ports (80, 443, 8080, 8443, 7443).
Detects outbound network connections to a known KuinaExtractor (k0to) infostealer C2 server. The rule monitors DeviceNetworkEvents for connections to the malicious IP address 103.229.53.18 on port 3000 and correlates them with process information to identify the originating application.
Detects the KuinaExtractor UAC bypass technique, which exploits the auto-elevated 'SilentCleanup' scheduled task. The rule identifies suspicious activity via two patterns: the execution of 'cleanmgr.exe' from an unexpected parent process (bypassing normal task scheduler invocation) or the explicit execution of 'schtasks.exe' to trigger the 'SilentCleanup' task.
Detects attempts to disable or impair Microsoft Defender Antivirus using legitimate system administration tools such as PowerShell (Set-MpPreference, Add-MpPreference), WMIC, sc.exe, or net.exe. Adversaries may use these tools to bypass security controls by disabling real-time monitoring or adding unauthorized exclusion paths.
Detects the activation of Android Accessibility Services by non-legitimate, potentially malicious applications. This behavior is commonly associated with banking trojans like Rokarolla that abuse accessibility permissions to perform UI automation, keystroke logging, and screen scraping.
Detects when the default SMS application on an Android device is changed to an application that is not recognized as a trusted SMS provider. This behavior is often indicative of malicious applications attempting to intercept incoming SMS messages, such as those containing multi-factor authentication (MFA) codes, by positioning themselves as the system's primary handler for SMS communications.
Detects adversary activity consistent with credential dumping tools like KuinaExtractor. The rule monitors for the enumeration of Windows Credential Manager stores using vaultcmd /list or cmdkey /list, and the direct instantiation of the Windows PasswordVault via PowerShell, excluding system accounts and known legitimate applications.
Detects reconnaissance behavior associated with the KuinaExtractor tool, identified by three or more distinct WMI hardware-related queries (CPU, disk, memory, etc.) executed within a 5-minute window by a non-administrative parent process.
