
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,167 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation of files with suspicious names (e.g., .xlamb, lambsys) in the /var/tmp directory, initiated by common command-line interpreters or network transfer utilities. This behavior is often indicative of malware deployment or staging in a Linux environment.
Detects the modification or creation of registry values under the Windows Local Security Authority (LSA) configuration key, specifically targeting the 'Authentication Packages' or 'Security Packages' values. Adversaries often use these registry locations to inject custom DLLs that are loaded by the LSA process (lsass.exe) at system boot for persistence or credential dumping.
This rule detects when the Internet Information Services (IIS) worker process (w3wp.exe) accesses sensitive files such as 'web.config', 'applicationHost.config', or 'win.ini'. Unauthorized access to these files by the IIS process can be an indicator of a web shell or other malicious post-exploitation activity attempting to steal credentials, application secrets, or system configuration information.
This rule detects the creation and loading of the 'NSecKrnl.sys' driver file on a system. The filename is associated with potentially malicious or unauthorized kernel-level activity, often indicative of rootkit behavior or unauthorized persistence mechanisms.
Detects execution of the Velociraptor binary (velociraptor.exe) running with SYSTEM privileges while not being launched by the expected services.exe process. This often indicates potential unauthorized use or manual deployment of the tool, bypassing standard management procedures.
This rule detects outgoing network connections from the IIS worker process (w3wp.exe) to public-facing URLs that match common Microsoft Office WOPI (Web Application Open Platform Interface) request patterns, but are directed to domains other than trusted Microsoft-affiliated infrastructure. This behavior can be indicative of a Server-Side Request Forgery (SSRF) attempt, where an attacker tries to coerce the server into making unauthorized requests to external resources.
This rule detects when the Microsoft Teams process (Teams.exe) creates an executable or installer file (.exe or .msi) in common user-writable directories such as AppData, Temp, or Users/Public. This behavior is indicative of potential malicious activity, as legitimate Teams application updates and add-ins typically reside in specific, protected subdirectories within the Teams folder structure.
This rule detects network connections over WinRM ports (5985, 5986) originating from potentially suspicious processes that are not standard Windows remote management binaries. It explicitly identifies activity where SharePoint-related processes initiate WinRM, which may indicate lateral movement patterns such as those seen in activity attributed to Storm-2603.
Detects modifications to the Windows Registry keys under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network. These keys control which services or drivers are permitted to load during Safe Mode with Networking. Unauthorized changes to these keys can be used to ensure malicious drivers or services load during Safe Mode, providing a persistence mechanism that bypasses many security controls.
Detects the modification or creation of registry values under the Windows Local Security Authority (LSA) configuration key, specifically targeting the 'Authentication Packages' or 'Security Packages' values. Adversaries often use these registry locations to inject custom DLLs that are loaded by the LSA process (lsass.exe) at system boot for persistence or credential dumping.
