
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of known archive utilities (e.g., 7-Zip, WinRAR) when interacting with sensitive user or system directories. This behavior is often indicative of data staging prior to potential exfiltration, especially when the originating process is not a recognized installer or backup application.
The rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or the use of its specific command-line arguments (e.g., sekurlsa::logonpasswords, /ntlm:). It also monitors for suspicious, unauthorized processes attempting to open a handle to the LSASS process to access its memory, a common technique for dumping credentials.
Detects instances where Windows event logs are cleared using built-in utilities (wevtutil.exe) or PowerShell (Get-EventLog/Get-WinEvent, Clear-EventLog) shortly after those same logs were queried or enumerated by the same user on the same device. This pattern is highly indicative of an adversary attempting to conceal malicious activity.
Detects potential financial data exfiltration by monitoring for bulk downloads of files with financial keywords from SaaS/Office365 platforms, and identifies unauthorized processes attempting to access sensitive financial application data files (.qbw, .qbb, etc.) on local systems.
This rule monitors for three categories of potentially suspicious network behavior: connections to common CDN providers over non-standard ports, high-volume HTTPS connections directly to IP addresses (IP-direct) bypassing standard domain resolution, and high-volume traffic to CDN infrastructure that may indicate domain fronting or C2 communication. Such patterns are often used by adversaries to mask egress traffic or exfiltrate data.
This rule detects the creation of named pipes or mutexes with GUID-like naming patterns by non-system processes. Threat actors frequently use uniquely generated GUIDs for IPC mechanisms like named pipes and mutexes to coordinate between processes or to check for existing infection, often to avoid detection by using non-obvious names.
Detects suspicious OAuth application or service principal registration, or permission consent, performed by users who are not part of designated IT administrator groups. This rule flags high-privilege permission grants (e.g., Mail.Read, Directory.ReadWrite.All) or application consent events, which are common methods for establishing long-term persistence in cloud environments.
This rule monitors for suspicious activity related to Microsoft Exchange server exploitation and persistence techniques. It detects three distinct behaviors: the creation of web shell files (.aspx, .ashx, .asmx) within Exchange directories (OWA/ECP), the spawning of shell processes (cmd, powershell) by the w3wp.exe web server process, and DLL sideloading occurring through identified signed binaries (dfsvc.exe, rasautou.exe) outside of standard system directories.
Detects modifications to Registry Run or RunOnce keys that include references to 'ManageEngine' or 'SystemOptimizer' and attempt to execute scripting hosts like wscript, cscript, powershell, or cmd. This behavior is indicative of persistence mechanisms often used by adversaries.
Detects the execution of rundll32.exe initiated by explorer.exe where the command line references common user folders (AppData, Temp, Downloads) and includes suspicious file extensions (e.g., images, PDFs, Office docs). This pattern is often indicative of malicious code execution where an adversary uses rundll32.exe to proxy execution of payloads masked as benign files.
