
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation or modification of services associated with PsExec, a legitimate tool often abused by adversaries for remote execution. The rule looks for specific service names or file paths indicative of PsExec activity, including the default 'PSEXESVC' service name, or file paths containing 'ADMIN$' or 'IPC$' shares, or a randomly named executable in the SystemRoot directory. It filters out activity from designated administrative workstations and common system accounts.
Detects the successful removal of Azure Resource Management locks. Attackers may attempt to delete these locks to modify, move, or delete protected resources that would otherwise be restricted, often as a precursor to data destruction or infrastructure tampering.
This rule detects potential credential dumping attempts against the Local Security Authority Subsystem Service (LSASS). It monitors two distinct suspicious behaviors: 1) The enablement of 'SeDebugPrivilege' by non-system processes via Windows security event 4703, and 2) Suspicious OpenProcess calls targeting sensitive Windows processes (lsass.exe, csrss.exe, winlogon.exe, services.exe, smss.exe) initiated by non-system accounts with high-level access rights.
This rule monitors for unauthorized deletion or modification of Microsoft Sentinel alert rules and automation rules. Such actions are indicative of an attacker attempting to impair security monitoring, silence alerts, or disable automated responses to maintain persistence and evade detection.
Detects the use of 'net.exe' or 'net1.exe' with arguments 'view', 'share', or 'use' that appear in rapid succession or are initiated by potentially suspicious parent processes. This behavior is often associated with network enumeration and reconnaissance activities.
Detects instances where processes other than legitimate browser components attempt to access, read, or copy the browser 'Login Data' file. This file stores credentials used by Google Chrome and Microsoft Edge, and unauthorized access is a common technique used by credential-stealing malware.
Detects the successful removal of Azure Resource Management locks. Attackers may attempt to delete these locks to modify, move, or delete protected resources that would otherwise be restricted, often as a precursor to data destruction or infrastructure tampering.
Detects the use of wmic.exe to execute commands or retrieve OS information on remote systems by monitoring for the '/node:' flag in command lines. The rule excludes local host references (localhost, 127.0.0.1) to focus on remote management activity that may indicate lateral movement or remote code execution.
Detects the use of rundll32.exe to execute code via remote URLs, JavaScript, or specific DLL functions known to be abused for proxy execution. This behavior is commonly associated with fileless malware and living-off-the-land techniques to bypass security controls by utilizing legitimate Windows binaries.
This rule detects potential credential dumping attempts against the Local Security Authority Subsystem Service (LSASS). It monitors two distinct suspicious behaviors: 1) The enablement of 'SeDebugPrivilege' by non-system processes via Windows security event 4703, and 2) Suspicious OpenProcess calls targeting sensitive Windows processes (lsass.exe, csrss.exe, winlogon.exe, services.exe, smss.exe) initiated by non-system accounts with high-level access rights.
