
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects processes attempting to access or manipulate Windows clipboard data, often used by adversaries to steal sensitive information copied by users. It monitors common living-off-the-land tools like PowerShell, WScript, CScript, and MSHTA executing clipboard-related functions or interacting with clip.exe.
Detects when a signed process loads a DLL from a non-standard, user-writable directory (e.g., Temp, Downloads, Public folders). This is a common indicator of DLL hijacking or side-loading, where a legitimate signed application is leveraged to load a malicious library from a compromised location.
This rule detects activities associated with credential dumping, specifically targeting techniques that abuse the Directory Replication Service (DRS) protocol, such as DCSync or the use of tools like secretsdump. It monitors both process execution command lines and network traffic for keywords indicative of these credential extraction behaviors, which are commonly used by attackers to obtain domain credentials.
Detects instances where common Windows system processes (dllhost.exe, mmc.exe, svchost.exe) spawn known living-off-the-land binaries (LotLBin) or command-line interpreters. This behavior is often indicative of process injection or malicious activity where an adversary leverages trusted system processes to execute commands or malicious scripts.
This rule detects processes attempting to access or manipulate Windows clipboard data, often used by adversaries to steal sensitive information copied by users. It monitors common living-off-the-land tools like PowerShell, WScript, CScript, and MSHTA executing clipboard-related functions or interacting with clip.exe.
Detects the execution of known command-line sync tools (Rclone, MEGAsync) or commands attempting to sync or move data to various cloud storage services (s3, gdrive, onedrive, mega, dropbox). The rule focuses on executions from suspicious or temporary directory paths and excludes processes signed by trusted publishers to minimize noise.
This rule monitors for successful external logins occurring on an endpoint that previously demonstrated patterns of suspected MFA fatigue (multiple failed push notifications) and subsequent internal reconnaissance activity (execution of commands used for domain or system discovery). The rule correlates these events to identify potential compromised credentials being actively used for lateral movement or persistence.
Detects the execution of common Windows utilities (diskpart, format, cipher, sdelete, eraser) when used with flags indicative of data destruction or disk wiping behavior. This rule monitors for process creations involving commands designed to irrecoverably erase data or wipe drive contents.
Detects the execution of command-line archiving utilities (7z, rar, tar) invoked by common scripting engines (PowerShell, CMD, Python, etc.) targeting typical staging directories (Temp, Public, AppData, ProgramData). This pattern is frequently observed during the data staging phase of an attack, where adversaries encrypt or compress gathered files for eventual exfiltration.
Detects unauthorized access, modification, or deletion attempts against common web browser credential storage files (key4.db, logins.json, and Microsoft Edge 'Login Data'). These files store sensitive authentication information, and non-browser processes interacting with them are indicative of credential harvesting attempts.
