
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the use of 'wmic.exe' with the '/format' switch to execute XSL files, or the direct execution of 'msxsl.exe'. These methods are common techniques used by adversaries to bypass security controls by executing arbitrary scripts embedded within XSL files, often fetched from remote locations or local paths.
Detects the use of Windows utilities 'nltest.exe' and 'dsquery.exe' with specific command-line arguments to enumerate Active Directory domain trust relationships. This behavior is indicative of an attacker attempting to map the network environment to identify targets for lateral movement.
Detects network communication to well-known public DNS resolvers (1.1.1.1, 8.8.8.8, 9.9.9.9) or DNS queries for their domains, initiated by processes other than standard web browsers. This behavior is often associated with non-browser applications, potential C2 channels, or hidden network activity bypassing system DNS configurations.
This rule detects potentially malicious invocations of rundll32.exe that utilize scripting protocols (javascript:, vbscript:) or suspicious execution parameters (ShellExec_RunDLL, LaunchApplication), as well as rundll32.exe executing from non-standard or user-writable directories (e.g., AppData, Temp). The rule further filters out trusted Microsoft-signed binaries to reduce noise while highlighting potential proxy execution attempts.
Detects the use of cmstp.exe with suspicious command-line arguments (e.g., .inf file references or silent/unattended flags) often associated with bypass of application control or User Account Control (UAC).
This rule detects the use of system utilities (wevtutil.exe, auditpol.exe, PowerShell) to interact with, query, or check status of security event logs and auditing configurations. While these tools are standard for administration, their usage by non-system accounts can indicate an adversary attempting to understand, monitor, or manipulate system audit policies and event log configurations as part of a reconnaissance or defense evasion strategy.
This rule detects the use of the 'powercfg.exe' utility by non-system accounts to modify power settings, such as disabling hibernation, modifying standby/sleep timeouts, or changing monitor/disk timeout configurations. Such actions can be indicative of attempts to maintain system availability, prevent the system from entering a low-power state that might terminate malicious processes, or ensure persistent execution of unauthorized activities.
Detects the use of VMware ESXi command-line management tools (esxcli, esxcfg) or VMware PowerCLI cmdlets (e.g., Connect-VIServer, Invoke-VMScript) from endpoints that are not identified as servers. This behavior often indicates an attacker attempting to manage or interact with a virtualized environment from a compromised workstation.
Detects instances where common browser processes or Windows Explorer initiate suspicious child processes like cmd.exe, powershell.exe, or mshta.exe. The rule uses a scoring mechanism based on the presence of encoded command indicators, web-related payloads, or specific HTA script arguments to identify potentially malicious activity such as drive-by downloads or living-off-the-land execution.
Detects the modification of Azure Storage account management policies where the 'daysAfterModificationGreaterThan' condition is set to 7 days or less, specifically including a 'delete' action. This could indicate an attempt by an adversary to shorten the lifecycle of data for rapid, automated, and potentially malicious data destruction within Azure Blob Storage.
