
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,149 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potential Business Email Compromise (BEC) attempts by identifying emails containing financial keywords sent to sensitive finance/accounting roles from domains that have not been observed in the last 180 days. It then correlates this email event with subsequent device-level network activity involving banking or financial URLs initiated by the recipient user, which may indicate follow-up reconnaissance or unauthorized access.
This rule detects the use of common cloud command-line interfaces (Azure CLI, Azure PowerShell, and AWS CLI) to perform resource discovery, specifically identifying commands used to list virtual machines or describe EC2 instances. Such activity, if performed by an unexpected user or on an endpoint where cloud management tools are not typically installed, may indicate reconnaissance by an adversary.
Detects instances where common browser processes or Windows Explorer initiate suspicious child processes like cmd.exe, powershell.exe, or mshta.exe. The rule uses a scoring mechanism based on the presence of encoded command indicators, web-related payloads, or specific HTA script arguments to identify potentially malicious activity such as drive-by downloads or living-off-the-land execution.
This rule monitors the creation of new Azure Function Apps and identifies those that receive external, non-private network requests within 48 hours of their creation. This pattern may indicate the deployment of malicious or unauthorized serverless infrastructure for command-and-control, proxying, or automated tasks.
Detects outbound network connections from workstations or servers to common message broker ports (MQTT 1883/8883, AMQP 5672). These protocols are sometimes abused for command-and-control (C2) communication, as they allow for pub/sub messaging patterns that can blend into legitimate network traffic.
Detects the execution of regsvr32.exe with command-line arguments that attempt to load and execute a remote scriptlet (SCT file) via a URL. This technique is often used to bypass application control and proxy the execution of arbitrary code using the trusted regsvr32.exe binary.
Detects the creation of files within the Windows Startup directory. Adversaries use this folder to achieve persistence by ensuring that malicious files or shortcuts are executed automatically when a user logs in.
Detects unauthorized cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). Such attempts are commonly associated with credential dumping techniques to extract credentials from memory.
Detects the execution of processes associated with remote command execution, specifically identifying the PsExec service (psexesvc.exe) or the invocation of command shell (cmd.exe) by the Service Control Manager (services.exe) with remote path arguments.
Detects the execution of net.exe or net1.exe with command line arguments used to enumerate domain users, domain groups, or local administrators. This pattern is commonly used by adversaries for discovery of accounts and permission groups within a Windows environment.
