
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of the Windows binary 'certutil.exe' using flags commonly abused by adversaries to download files from remote URLs or decode base64-encoded files. It excludes instances where certutil is executed by Microsoft-signed processes from the System32 directory to reduce false positives.
Detects the creation or modification of Windows Registry Run or RunOnce keys, which are commonly used for persistence to execute malicious code automatically upon user logon. The rule excludes common, legitimate software installers and trusted publishers located in Program Files to minimize false positives.
Detects the execution of processes with command-line arguments characteristic of the Mimikatz tool, specifically the 'sekurlsa', 'lsadump', and 'privilege::debug' modules used for credential dumping and process debugging.
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell. This behavior is a common indicator of ransomware activity aimed at preventing system recovery.
This rule detects potential automated credential stuffing attempts followed by successful authentication and subsequent access to sensitive/privileged APIs within Azure/Entra ID environments. It correlates multiple failed login attempts for service-oriented account names (e.g., svc, api, bot) with a successful login from the same user shortly thereafter, followed by privileged API operations (e.g., KeyVault secret access, user management) within a short time window.
Detects the execution of mshta.exe with suspicious command-line arguments, including the use of 'javascript:', 'vbscript:', or HTTP/HTTPS URLs. These patterns are commonly used to proxy the execution of malicious HTML Applications (HTA) or scripts to bypass security controls. The rule includes an exclusion for legitimate Microsoft-signed mshta.exe processes that do not contain these suspicious indicators.
Detects the execution of the 'diagnose sniffer packet' command on FortiOS devices. This command can be abused by malware, such as FortigateSniffer, to intercept authentication traffic, as observed in campaigns like FortiBleed.
This rule detects suspicious activity related to high-volume Server Message Block (SMB) share enumeration and the execution of a specific Python script named 'backup_dfs.py'. It combines three detection logics: identifying processes executing 'backup_dfs.py', detecting an unusual number of SMB network connections to common administrative shares (SYSVOL, NETLOGON, DFS), and flagging high-volume SMB-related identity directory events targeting SYSVOL or NETLOGON. This behavior could indicate an adversary performing discovery of network shares, collecting data, or preparing for data exfiltration.
Detects the use of the sc.exe utility to create a new service on a remote system by specifying a path using a UNC share. This behavior is indicative of lateral movement, where an attacker attempts to execute code on a remote host by installing a service via SMB/Admin Shares.
Detects the creation of an executable file (.exe, .scr, .com, .pif) in user-writable directories (Temp, AppData, ProgramData) followed by the immediate execution of that same file. This is a common pattern for malware droppers where a file is dropped to disk and subsequently executed to initiate the next stage of an attack.
