
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of vssadmin.exe or wmic.exe to delete Volume Shadow Copies. This is a common technique used by ransomware and other malware to prevent system recovery and impede incident response efforts.
Detects the execution of mshta.exe with arguments containing URLs, script languages (vbscript, javascript), or .hta file extensions, which is a common technique used by attackers to execute malicious code via a legitimate Windows utility.
Detects unauthorized or suspicious processes attempting to access the memory of the Local Security Authority Subsystem Service (lsass.exe). This activity often indicates attempts to dump process memory to harvest sensitive credentials, a common technique used by attackers to facilitate lateral movement.
Detects the use of Mimikatz to perform a DCSync attack, which allows an adversary to simulate the replication process from a domain controller to extract sensitive password hashes from Active Directory.
Detects the execution of rundll32.exe from common user-writable or temporary directories (Temp, AppData, ProgramData), which is a common technique used by malware to execute payloads while avoiding security monitoring of standard system directories.
Detects cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). The rule filters out known Microsoft-signed system processes and common Windows binaries to identify potential unauthorized credential dumping activity.
Detects the execution of PowerShell with an encoded command flag (e.g., -EncodedCommand, -e, -ec) where the command string exceeds 200 characters. This pattern is commonly used to obfuscate malicious PowerShell scripts, payloads, or downloader cradles.
Detects the usage of net.exe or net1.exe to enumerate domain users, groups, local administrators, and domain controllers, which is frequently indicative of post-compromise reconnaissance.
Detects the execution of Windows Script Host (wscript.exe or cscript.exe) to run script files (.vbs, .js, .wsf, .hta) located in commonly abused writable directories such as Temp, AppData, Downloads, or ProgramData. This behavior is indicative of a malicious actor executing scripts that have been dropped onto the system as part of a phishing campaign or other attack vector.
Detects potential persistence attempts via WMI event subscriptions. The rule monitors for the creation of WMI event consumers using 'wmic.exe' with suspicious command line arguments, or the use of 'mofcomp.exe' to compile MOF files by non-standard, non-Microsoft signed processes.
