
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects network connections initiated by a non-Microsoft signed rundll32.exe process. The rule identifies processes named rundll32.exe that are not signed by Microsoft and are communicating over common ports associated with malicious activity, specifically focusing on external IP addresses and multiple connection attempts.
Detects cross-process activity where an unsigned executable residing in common user-writable directories (AppData, Temp, ProgramData) attempts to interact with or inject into sensitive system processes (explorer.exe, svchost.exe, notepad.exe). This behavior is characteristic of malicious process injection attempts.
This rule detects the execution of the Rubeus tool or the usage of common command-line arguments associated with Kerberoasting activities (e.g., GetUserSPNs, Request-SPNTicket). Kerberoasting is a technique used to extract service account password hashes from Active Directory by requesting service tickets for accounts with Service Principal Names (SPNs). These hashes can then be cracked offline to obtain cleartext credentials.
Detects the execution of vssadmin.exe or wmic.exe with command-line arguments intended to delete Volume Shadow Copies. This activity is a common indicator of ransomware or other destructive attacks aiming to inhibit system recovery.
Detects the use of PowerShell commands that leverage 'Invoke-Expression' (IEX) in conjunction with 'Net.WebClient' or 'DownloadString' methods to download and execute code directly from the internet into memory.
Detects the use of regsvr32.exe to execute remote scriptlets (SCT files) via HTTP, HTTPS, or FTP protocols. This technique, often referred to as 'Squiblydoo', allows for proxying code execution to bypass application whitelisting and execute arbitrary code directly from a remote web server without writing the script to the local disk.
This rule detects network connections on port 443 made to common public DNS resolvers (1.1.1.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 149.112.112.112) by processes other than known web browsers. This behavior is atypical for standard endpoint processes and may indicate the use of DNS-over-HTTPS (DoH) for command and control or data exfiltration to bypass network filtering.
This rule detects a high frequency of file rename or modification events targeting files with extensions commonly associated with ransomware. It filters out activity from processes signed by trusted vendors like Microsoft, Symantec, Sophos, and Trend Micro to reduce noise, flagging mass rename operations that could indicate an active ransomware encryption process.
Detects cross-process activity where an unsigned executable residing in common user-writable directories (AppData, Temp, ProgramData) attempts to interact with or inject into sensitive system processes (explorer.exe, svchost.exe, notepad.exe). This behavior is characteristic of malicious process injection attempts.
This rule detects DNS queries with suspicious characteristics that may indicate DNS tunneling, data exfiltration, or command and control activity. It identifies queries with unusually long names, long first labels combined with high entropy, or a high number of subdomains combined with a long first label. Exclusions are made for common legitimate DNS suffixes and specific service-related domains.
