
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,168 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule monitors for the creation of .exe or .msi files within common user-writable directories (Downloads, Temp, AppData) initiated by web browser processes (Chrome, Edge, Firefox, Brave). This behavior is often indicative of drive-by downloads or users interacting with malicious web content that delivers installers to the host.
Detects execution of the Velociraptor binary (velociraptor.exe) running with SYSTEM privileges while not being launched by the expected services.exe process. This often indicates potential unauthorized use or manual deployment of the tool, bypassing standard management procedures.
This rule detects when the Microsoft Teams process (Teams.exe) creates an executable or installer file (.exe or .msi) in common user-writable directories such as AppData, Temp, or Users/Public. This behavior is indicative of potential malicious activity, as legitimate Teams application updates and add-ins typically reside in specific, protected subdirectories within the Teams folder structure.
This rule detects network communication (connections, DNS queries, or proxy logs) between endpoints and a list of known malicious domains and IP addresses associated with Mistic and Woodgnat/KongTuke threat families. It identifies these activities across network event logs, DNS queries, and security logs.
This rule monitors DNS queries and network connections for access to a set of known domain names associated with Adversary-in-the-Middle (AiTM) phishing infrastructure. It correlates data from DNS events, device network logs, and virtual machine network connections to identify potential interactions with malicious phishing sites typically used to capture user credentials or session tokens.
This rule detects instances where Microsoft Teams (Teams.exe or ms-teams.exe) initiates a PowerShell process (powershell.exe or pwsh.exe) with command-line arguments typically associated with malicious activity, such as downloading content from the internet, executing encoded commands, or utilizing scripting shortcuts (e.g., IEX, curl). This behavior may indicate an attempt to achieve code execution through compromised collaboration tools.
Detects the execution of the Mimikatz tool or the usage of specific command-line arguments associated with common credential dumping and persistence techniques, such as Skeleton Key or LSASS patching.
Detects successful NTLMv1 logon events (Event ID 4624) where the logon type is 3 (Network). NTLMv1 is a legacy and insecure authentication protocol. Its use in a modern environment, particularly for network logons, is often associated with pass-the-hash attacks or legacy compatibility issues that attackers may exploit.
Detects the creation of a local user account in the Windows Security event logs. The rule filters out service accounts (those ending in '$') and events triggered by well-known system accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise. This helps identify unauthorized account creation, which can be an early indicator of persistence establishment or privilege escalation.
This rule detects potential cleartext leakage of usernames and passwords over FTP (port 21) by identifying HTTP requests containing common credential-related keywords in the URL, while explicitly excluding HTTPS traffic. This could indicate sensitive information being transmitted insecurely.
