
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,582 copies160 likes52,381 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the creation of shortcut (.lnk) files within the Windows Startup folder initiated by potentially suspicious processes such as WinRAR, unrar, or PowerShell. This behavior is indicative of an attempt to achieve persistence by ensuring the execution of a malicious file upon user login.
This rule detects suspicious PowerShell execution patterns involving scripts or payloads stored within specific directory paths (ProgramData\WC3\ or ProgramData\wt1). It flags instances where PowerShell commands include reflective loading techniques ('IEX' or 'Invoke-Expression') while referencing files in these paths, which is often associated with fileless malware execution or malicious loaders.
Detects the use of 'hdiutil' to mount disk images with the '-nobrowse' flag, initiated by common command-line or scripting interpreters. The '-nobrowse' flag prevents the mounted volume from appearing on the desktop or in Finder, which is a common technique used by attackers to mount malicious disk images stealthily to facilitate execution of payloads while avoiding user detection.
This rule monitors process command lines and file activity for keywords associated with potential reconnaissance, error logs, or debugging artifacts often used during post-exploitation or system profiling. It flags commands or files containing terms like 'memory dump', 'stack trace', 'SQL injection', or 'Redis failure', which may indicate an attacker analyzing system information or attempting to interact with backend services.
Detects unusually large FTP responses containing 'LIST' or 'NLST' commands, potentially indicating an attempt to exploit the Squidbleed vulnerability or similar data exfiltration over FTP. The rule specifically looks for network events on port 21 (FTP) where the action type is 'NetworkSignatureInspected' and the RemoteUrl contains either 'LIST' or 'NLST' with a string length greater than 4000 characters.
This rule detects the execution of known remote access tools (such as AnyDesk, TeamViewer, or RustDesk) that are spawned as child processes from common web browsers. It correlates process creation events with subsequent network connections by these tools to public IP addresses over specific ports commonly used by remote access software, within a 30-minute timeframe of the process start.
Detects the execution of known remote access and remote management tools (e.g., TeamViewer, AnyDesk) where the process was initiated by a web browser, suggesting potential drive-by downloads or social engineering attacks involving remote access software.
Detects when a user or machine account is added to a highly privileged Active Directory group. This event is often a sign of privilege escalation or persistence establishment by an adversary.
This rule detects unauthorized modifications to sensitive Group Policy Object (GPO) attributes, such as file system paths, version numbers, or extension settings. It monitors Security Event 5136 for changes targeting GPO containers by non-standard administrative accounts, flagging potential attempts to persist access or escalate privileges via GPO tampering.
This rule detects network connections to remote URLs containing indicators associated with the XWorm Remote Access Trojan (RAT). It specifically looks for 'xworm', 'x-worm', 'wormx', or '/xworm' within the RemoteUrl field of DeviceNetworkEvents.
Page 552 of 867
