
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,518 copies160 likes52,162 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for suspicious activity related to Microsoft Exchange server exploitation and persistence techniques. It detects three distinct behaviors: the creation of web shell files (.aspx, .ashx, .asmx) within Exchange directories (OWA/ECP), the spawning of shell processes (cmd, powershell) by the w3wp.exe web server process, and DLL sideloading occurring through identified signed binaries (dfsvc.exe, rasautou.exe) outside of standard system directories.
Detects the use of net.exe and dsquery.exe to enumerate domain user accounts and domain groups. Adversaries often perform this reconnaissance to identify target accounts or privileged groups within an Active Directory environment.
Detects the creation or modification of Windows services using sc.exe where the binary path (binpath) points to suspicious or user-writable directories such as User profiles, AppData, Temp, or Public folders, which are often used by adversaries for persistence or privilege escalation.
Detects the creation or modification of Windows Registry Run keys by processes that are not part of the standard Microsoft Windows installation, suggesting potential unauthorized persistence mechanisms.
This rule detects cross-process operations (such as memory access or thread injection) initiated by processes that are not signed by known, trusted vendors, or that do not reside in protected system directories. This behavior is a common indicator of process injection techniques used to evade security controls.
Detects the execution of known critical system processes (e.g., svchost.exe, lsass.exe) from directories other than the standard Windows System32 or SysWOW64 paths. This behavior is indicative of masquerading, where an adversary attempts to evade detection by naming malicious files after legitimate system binaries.
Detects the execution of common Windows system information discovery utilities (systeminfo, hostname, ver) when spawned by command interpreters or scripting engines, which is a common behavior in post-exploitation reconnaissance.
Detects network connections over port 3389 (RDP) initiated by processes other than standard Remote Desktop clients (mstsc.exe). This rule specifically looks for suspicious indicators such as execution from non-standard or temporary file paths, or the use of common living-off-the-land binaries (like powershell.exe, cmd.exe, rundll32.exe) that might be acting as a proxy for remote access or lateral movement.
Detects potentially malicious process execution behaviors, including the use of 'runas.exe' with saved credentials, the execution of 'runas.exe' by unauthorized users, and unauthorized cross-process access to sensitive Windows system processes such as lsass.exe, winlogon.exe, or services.exe, which are common indicators of credential access or privilege escalation attempts.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) by monitoring for specific keywords associated with memory patching or tampering within the command lines of PowerShell, .NET-based binaries (dotnet.exe, csc.exe, msbuild.exe), and related processes. The rule specifically looks for strings like 'AmsiUtils', 'amsiInitFailed', and base64-encoded equivalents often used by offensive security tools to neutralize AMSI scanning capabilities.
