
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation of named pipes with names frequently associated with common post-exploitation tools, such as Cobalt Strike. The rule filters out common browser processes and critical Windows system processes to reduce noise.
Detects execution of the Microsoft .NET installer utility (InstallUtil.exe) from non-standard locations. Adversaries often abuse InstallUtil.exe as a proxy to execute malicious code or bypass application control policies, as it is a trusted, digitally signed Microsoft binary. The rule filters out legitimate execution paths typically associated with .NET framework installations, SDKs, or system directories.
Detects the use of the built-in Windows utility 'certutil.exe' with arguments commonly used to download remote content (-urlcache -split -f) or decode base64 encoded files (-decode, -decodehex), when the output or operation occurs within temporary system directories such as Temp, AppData, or ProgramData, and the process is not signed by Microsoft.
Detects the use of the BITSAdmin command-line utility to initiate file transfers from external sources to user-writable directories or temporary folders. This behavior is indicative of living-off-the-land (LotL) techniques where adversaries use legitimate system binaries to download and potentially execute malicious files.
Detects attempts to access or copy the Active Directory domain database (NTDS.dit) by monitoring for direct file access to the file or the execution of ntdsutil.exe with arguments intended to create an Install From Media (IFM) set, which is a known technique for exfiltrating the NTDS.dit file for offline password cracking.
Detects the execution of sc.exe with subcommands 'create' or 'start' where the command line includes a UNC path. This pattern is indicative of an adversary attempting to install or execute a service on a remote host to facilitate lateral movement.
Detects the creation or modification of Windows Registry Run keys that point to common LOLBins (Living Off the Land Binaries) like PowerShell, WScript, or MSHTA. This activity is often used for persistence, and the rule specifically excludes Microsoft-signed binaries to reduce false positives.
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate file transfers, specifically targeting non-Microsoft signed processes. Adversaries often abuse the Background Intelligent Transfer Service (BITS) to download malicious payloads or exfiltrate data, as it is a legitimate Windows service that operates in the background.
Detects attempts to extract the Security Account Manager (SAM) database, either by using the 'reg save' utility to export registry hives containing the SAM or by directly creating/modifying the SAM file on disk outside of known legitimate system processes.
Detects the creation of WMI Event Subscriptions using wmic.exe or scrcons.exe. Adversaries can use WMI event subscriptions to achieve persistence by executing malicious code when a specific event occurs, such as system boot or user logon.
