
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects DNS queries and network connection attempts to a set of known malicious domains associated with the threat actor UNC1151 (Ghostwriter). This rule monitors both DNS resolutions and direct network connection attempts to these indicators of compromise (IOCs), which are commonly used in spearphishing campaigns.
Detects the activation of Android Accessibility Services by non-legitimate, potentially malicious applications. This behavior is commonly associated with banking trojans like Rokarolla that abuse accessibility permissions to perform UI automation, keystroke logging, and screen scraping.
This rule detects potential Command and Control (C2) communication activity by identifying instances of Domain Generation Algorithms (DGA). It monitors DNS query responses for patterns consisting of 8 to 16 lowercase alphabetic characters followed by common TLDs (com, net, org, ru, cc, su). An alert is triggered if 5 or more unique suspicious domains are queried by the same device within a one-hour window.
Detects adversary activity consistent with credential dumping tools like KuinaExtractor. The rule monitors for the enumeration of Windows Credential Manager stores using vaultcmd /list or cmdkey /list, and the direct instantiation of the Windows PasswordVault via PowerShell, excluding system accounts and known legitimate applications.
Detects Microsoft Excel (excel.exe) spawning child processes commonly used in post-exploitation scenarios, such as command shells, scripting interpreters, and living-off-the-land binaries. This behavior is indicative of potential exploitation of vulnerabilities like CVE-2025-60727 to achieve remote code execution.
Detects the creation or loading of specific DLL files identified as part of the Turla STOCKSTAY malware framework. The rule monitors both file system operations (creation, modification, renaming) and process image loads to identify indicators of this specific campaign.
Detects Python processes that combine potentially dangerous pickle deserialization (pickle.loads) with network-fetching libraries (urllib, requests, socket) and decoding methods (b64decode, fromhex). This pattern is consistent with backdoors or remote access tools (RATs) that fetch encoded payloads over the network and execute them directly in memory via deserialization.
Detects Python processes executing complex, multi-layered decoding chains (Base64, ROT13, and Hex) in their command line arguments. This pattern is often used by malicious AI skill backdoors, such as ClawHub, to obfuscate payload execution and evade signature-based detection.
This rule detects suspicious inter-process communication (IPC) attempts using WM_COPYDATA messaging, where processes (often script interpreters or unsigned binaries) interact with high-value GUI-based applications (like browsers or shell environments). This pattern is a common indicator of process injection techniques, such as hijacking existing Windows callbacks to execute code within the context of a target process.
Detects host-based reconnaissance activity patterns indicative of Trickbot malware. The rule monitors for a high frequency (>= 4 unique commands within a 30-minute window) of diagnostic commands ('tasklist', 'systeminfo', 'ipconfig', 'net') executed by cmd.exe or powershell.exe, which is a common behavior pattern for adversary discovery processes.
