
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of common system discovery utilities (whoami, ipconfig, net, etc.) by a process named 'setup.exe' originating from suspicious directories such as 'AppData\Local\Temp\' or 'Downloads'. This behavior is often indicative of automated reconnaissance following the initial execution of a potentially malicious installer or dropper.
Detects the creation or modification of '.config' or '.exe.config' files within commonly user-writable directories such as AppData, Temp, Downloads, or Desktop. These files are often used by .NET applications to define behavior, and attackers may manipulate them to perform activities such as assembly redirection, loading malicious DLLs, or altering security settings for elevated processes.
This rule monitors for processes named 'setup.exe' executing from user-writable directories (e.g., AppData, Downloads, Temp) that load unsigned or non-Microsoft DLLs from the same suspicious directories. This pattern is commonly associated with DLL side-loading or malicious installation attempts where a process attempts to load illegitimate code from local user space.
This rule correlates multiple suspicious activities indicative of ransomware or destructive attacks. It detects a combination of volume shadow copy deletion, bulk file modifications, creation of suspicious scheduled tasks, and network connections occurring during periods of high file write activity. The rule triggers when multiple signals are observed or when specific high-fidelity destructive indicators are present.
Detects the execution of PowerShell with encoded commands initiated by common Windows script hosting utilities (mshta.exe, wscript.exe, or cscript.exe). This pattern is frequently used by adversaries to bypass execution policy restrictions or evade detection by proxying the execution of malicious payloads through legitimate, signed system binaries.
This rule detects potentially malicious behavior associated with web browser processes, including the execution of Python scripts, the loading of browser extensions from non-standard directories like AppData or Temp, the creation of Python scripts by browsers in temp folders, and outbound network connections by Python processes following browser activity. These patterns are often associated with browser-based exploitation, extension-based malware, or initial access stages where a browser is used as a conduit for malicious code execution.
Detects the creation or modification of '.config' or '.exe.config' files within commonly user-writable directories such as AppData, Temp, Downloads, or Desktop. These files are often used by .NET applications to define behavior, and attackers may manipulate them to perform activities such as assembly redirection, loading malicious DLLs, or altering security settings for elevated processes.
Detects a suspicious execution chain potentially associated with Deed RAT (used by Mustang Panda/Twill Typhoon), consisting of DLL sideloading by a legitimate signed executable followed by persistence mechanism creation (Registry Run keys or Scheduled Tasks) on the same host. Additionally, it identifies devices exhibiting repeated outbound connections to the same remote public IP over multiple days, serving as an indicator of potential re-compromise or persistent C2.
This rule monitors for indicators associated with MiniUpdate/MiniJunk V2 RAT and general .NET AppDomainManager hijacking. It detects suspicious registry keys (AppDomainManagerAssembly/Type) or environment variable manipulation used to hijack .NET application execution flow. Additionally, it identifies .NET host processes loading DLLs from user-writable directories (e.g., AppData, Temp) and tracks suspicious beaconing patterns to known Azure CDN domains often used by these threats for Command and Control.
Detects the use of the command-line utility 'taskkill' to terminate 'explorer.exe' followed by a command to restart it, often used by malware or unauthorized scripts to force a refresh of the desktop environment or hide malicious activities.
