
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of reg.exe to query the Windows registry for information related to software versions or service configurations. This activity is often associated with discovery efforts to identify installed software, system configuration, or potential security controls.
Detects the creation of a scheduled task using the schtasks.exe utility with persistence-related triggers such as system startup or user logon. The rule excludes common trusted processes that frequently interact with the Task Scheduler to minimize false positives.
Detects the use of the Windows command-line utility 'wevtutil.exe' to clear Windows event logs. Attackers often clear logs to hide evidence of post-compromise activity.
Detects the use of 7-Zip (7z.exe or 7zip.exe) to archive files within common user directories (Desktop, Documents, Users, AppData). This activity is often associated with staging sensitive data prior to exfiltration.
Detects unauthorized cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). Such attempts are commonly associated with credential dumping techniques to extract credentials from memory.
Detects execution of common network reconnaissance tools such as nmap, masscan, and zmap, or PowerShell commands that utilize Test-NetConnection for automated port sweeping across a defined range.
Detects the execution of PowerShell commands intended to disable or bypass the Antimalware Scan Interface (AMSI). This is achieved by referencing internal AMSI methods such as 'AmsiUtils', 'amsiInitFailed', or 'amsi.dll' within command line arguments, typically used to neutralize endpoint security scanning during malicious script execution.
Detects the execution of processes associated with remote command execution, specifically identifying the PsExec service (psexesvc.exe) or the invocation of command shell (cmd.exe) by the Service Control Manager (services.exe) with remote path arguments.
Detects execution of the Microsoft InstallUtil.exe utility with suspicious command-line arguments (logging suppressed to file and console) where the binary is unsigned. This is a common technique used by adversaries to proxy execution of arbitrary .NET code while attempting to avoid detection and maintain stealth.
Detects SYSTEM privilege escalation attempts via ctfmon.exe or cloudfiles.exe processes.
