
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects core Windows system processes (svchost.exe, lsass.exe, csrss.exe, winlogon.exe) executing from non-standard locations other than System32 or SysWOW64. This is a common indicator of process masquerading, where malicious actors rename or move their executable to blend in with legitimate system activity.
Detects DNS queries with exceptionally long request strings (30 characters or more), which is a common indicator of DNS tunneling or command and control (C2) communication. Adversaries often encode data within the subdomain portion of a DNS query to bypass network security controls.
Detects the execution of sensitive ESXi administrative commands (e.g., esxcli, vim-cmd) that suggest potential hypervisor management or tampering, especially when initiated by non-administrative processes or specific shells.
This rule detects various commands and processes used by adversaries to enumerate virtual machine software, hypervisor configurations, and virtualization-based security features on a host. This is often part of reconnaissance to understand the environment, detect sandboxing, or identify virtualization platforms for further post-exploitation activities.
This rule detects the creation of named pipes or mutexes with GUID-like naming patterns by non-system processes. Threat actors frequently use uniquely generated GUIDs for IPC mechanisms like named pipes and mutexes to coordinate between processes or to check for existing infection, often to avoid detection by using non-obvious names.
Detects the execution of remote commands on cloud virtual machines (Azure RunCommand or AWS SSM SendCommand) during defined off-hours (18:00 to 06:00). This rule identifies potentially unauthorized administrative or management activity occurring outside of standard business hours across cloud environments.
Detects attempts to clear Windows event logs using the native 'wevtutil.exe' utility or the PowerShell 'Clear-EventLog' command. This behavior is often associated with adversaries attempting to remove evidence of their actions from a compromised system.
Detects native Windows command and scripting interpreters (e.g., cmd.exe, powershell.exe, mshta.exe) initiating external network connections to multiple distinct IP addresses, which is often an indicator of automated C2 beaconing or lateral movement activity.
Detects the use of the 'net.exe' or 'net1.exe' utilities with the 'group' and '/domain' arguments, indicating an attempt to query domain-level groups. This technique is commonly used by attackers during the discovery phase to map out domain security groups.
Detects attempts to clear Windows event logs using the native 'wevtutil.exe' utility or the PowerShell 'Clear-EventLog' command. This behavior is often associated with adversaries attempting to remove evidence of their actions from a compromised system.
