
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for the creation of specific file artifacts associated with the APT28 SimpleLoader malware, including malicious DLLs, steganographic image payloads, and configuration files dropped into non-standard or diagnostic directories.
Detects network and DNS activity involving domains known to be used by the threat actor APT28 for command and control, specifically for hosting WebDAV payloads, malicious LNK files, and weaponized documents.
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
This rule detects the suspicious initialization of the Common Language Runtime (CLR) components (mscoree.dll, clr.dll, or oleaut32.dll) within the explorer.exe process, followed closely by an outbound HTTPS connection to filen.io domains. This pattern is indicative of fileless .NET-based C2 implants, such as those generated by the Covenant framework, executing within the context of a legitimate Windows shell process.
Detects instances where PowerShell.exe is launched by the OneDrive synchronization process, potentially indicating an attempt to mask malicious command execution as a legitimate cloud storage process.
Detects the creation of a scheduled task named 'OneDriveHealth', which is associated with APT28 activity. This task is used for persistence via COM hijacking; it executes 60 seconds after registration, kills and restarts explorer.exe to facilitate the loading of a hijacked COM object, and subsequently removes itself.
Detects network and DNS activity involving domains known to be used by the threat actor APT28 for command and control, specifically for hosting WebDAV payloads, malicious LNK files, and weaponized documents.
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
This rule detects the suspicious initialization of the Common Language Runtime (CLR) components (mscoree.dll, clr.dll, or oleaut32.dll) within the explorer.exe process, followed closely by an outbound HTTPS connection to filen.io domains. This pattern is indicative of fileless .NET-based C2 implants, such as those generated by the Covenant framework, executing within the context of a legitimate Windows shell process.
Detects the opening of suspected APT28 (Fancy Bear) spearphishing lure documents by Microsoft Office or Outlook. The rule monitors for file access, creation, or renaming events where the filename matches known lure patterns associated with APT28 activities, such as naming conventions containing 'BULLETEN', 'OperInformativ', 'Courses', 'Consultation', 'Weapons', or 'Smuggling' in Word or Outlook processes.
