
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to COM object InProcServer32 registry keys within the user's registry hive (HKEY_USERS). Attackers often hijack COM objects to achieve persistence by pointing them to malicious DLLs or OCX files. This rule specifically filters out common legitimate paths (Windows directories, Program Files) and known installers to reduce noise.
Detects execution of mshta.exe with a command-line containing a URL, which is a common technique used by attackers to proxy the execution of remote malicious payloads such as HTA, VBScript, or JScript files. The rule excludes common Microsoft domains to reduce false positives.
Detects the execution of Mimikatz or its common command-line arguments used for credential dumping. This rule identifies attempts to extract sensitive authentication material such as passwords, hashes, and tickets from memory (LSASS), SAM database, LSA secrets, and cached domain credentials.
Detects successful OAuth application consent events where the requested permissions include sensitive scopes such as Mail, Files, or User profile access. This is a common indicator of OAuth application-based phishing or persistence attempts, often referred to as 'Illicit Consent Grant' attacks.
This rule detects various methods used to extract credentials protected by the Windows Data Protection API (DPAPI). It covers multiple vectors, including Mimikatz DPAPI module usage, unauthorized loading of the dpapi.dll library, suspicious access to browser or WiFi credential stores, and cross-process memory access to the LSASS process to extract DPAPI master keys.
This rule detects indicators of Adversary-in-the-Middle (AiTM) phishing infrastructure, specifically targeting Evilginx2 and similar proxy frameworks. It identifies unauthorized execution of Evilginx2 binaries, the presence of specific session and configuration files (.evilginx/, phishlets, session databases), unauthorized modifications to Nginx configurations, and the dropping of suspicious HTML lure files into web document roots by scripting interpreters.
Detects the execution of native Windows utilities (vssadmin, wbadmin, bcdedit, diskshadow) configured to delete volume shadow copies, remove backup catalogs, or disable automatic recovery features. This activity is a common indicator of ransomware preparation to prevent data recovery.
Detects modifications to the Windows Defender exclusion list via registry keys. Adding exclusions can be used by attackers to hide malicious files, processes, or directories from antivirus scanning.
This rule detects when sensitive administrative roles are assigned directly to users in Microsoft Entra ID (formerly Azure AD) without utilizing the Privileged Identity Management (PIM) service. Direct assignment of these roles bypasses the security controls and JIT (Just-In-Time) access workflows enforced by PIM, potentially indicating unauthorized privilege escalation or a misconfiguration.
This rule detects unauthorized or suspicious modifications to Microsoft Sentinel alert rules. It specifically monitors for the deletion of alert rules or the disabling of existing rules via the Azure activity logs. Such actions may indicate an attempt by an adversary to impair security monitoring and defensive capabilities.
