
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors process command line arguments for a combination of programming language interpreters (java, python, node, .NET, go) and keywords commonly associated with malware, payloads, shellcode, or injection techniques. This is intended to identify suspicious execution patterns that may indicate the staging or execution of malicious code.
Detects the loading of DLLs with suspicious names ('hook.dll', 'inject.dll', 'logger.dll', 'loader.dll') from common user-writable directories such as 'Temp', 'AppData', or 'Downloads'. These patterns are frequently associated with malware loaders, persistence mechanisms, or unauthorized code injection attempts.
Detects the use of PowerShell to modify Microsoft Defender preferences, specifically attempting to disable security features like Realtime Monitoring, IOAV protection, or Behavior Monitoring.
Detects the execution of processes containing command-line arguments associated with the Mimikatz post-exploitation tool, such as credential dumping, privilege escalation, and certificate manipulation keywords.
Detects the creation or modification of registry values within the AppCertDlls registry key. Adversaries use this technique to achieve persistence by forcing malicious DLLs to be loaded into every process that calls common Windows API functions such as CreateProcess.
Detects potential lateral movement activity where PowerShell or the Windows Remote Management (WinRM) host process (wsmprovhost.exe) initiates network connections to multiple distinct destination IP addresses over the WinRM default ports (5985/5986). This behavior is characteristic of an adversary using legitimate remote administration tools to pivot or spread across a network.
Detects the use of the Windows net.exe or net1.exe utilities to add users to privileged groups such as 'Administrators' or 'Domain Admins'. This is a common technique used by attackers to achieve privilege escalation or establish persistence by modifying sensitive account group memberships.
Detects the execution of processes containing command-line arguments associated with the Mimikatz post-exploitation tool, such as credential dumping, privilege escalation, and certificate manipulation keywords.
Detects the creation or modification of registry values within the AppCertDlls registry key. Adversaries use this technique to achieve persistence by forcing malicious DLLs to be loaded into every process that calls common Windows API functions such as CreateProcess.
Detects the execution of command-line tools associated with Kerberoasting and Kerberos ticket manipulation techniques, such as requesting TGS tickets or targeting specific user accounts for ticket extraction.
