
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,169 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the creation of named pipes associated with known command-and-control (C2) frameworks, post-exploitation toolkits, and suspicious system activity. By filtering out common legitimate system processes and monitoring for specific pipe patterns (e.g., Cobalt Strike, Metasploit, PsExec, and sensitive RPC endpoints), the rule identifies potential lateral movement, remote execution, and post-exploitation communication channels.
Detects anomalous behavior associated with msiexec.exe that aligns with activity patterns of infostealer malwares like Lumma Stealer and Amadey Bot. This includes cross-process injection from unsigned processes, spawning of msiexec.exe by LOLBins or script interpreters, suspicious outbound network connectivity, and unauthorized access to browser credential storage files.
Detects unauthorized processes attempting to read, modify, or create files within common browser credential locations (Chrome, Firefox, Edge, and Windows Credential Manager). Legitimate browser processes and their known signers are excluded, focusing on suspicious secondary processes or tools frequently utilized by infostealers like Lumma and RedLine to dump credentials.
This rule detects potentially malicious activity within Azure Automation by monitoring for the creation or modification of runbooks and jobs, combined with the presence of suspicious command-line or script patterns in job stream output, such as credential harvesting (e.g., Get-AutomationPSCredential) or execution of web-based payloads (e.g., IEX, Invoke-WebRequest).
Detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying successful user sign-ins from a new, historically unseen IP address occurring within 30 minutes of a legitimate sign-in from a known IP, indicating the potential replay of a stolen session or refresh token.
Detects modifications or publication of Azure Automation runbooks by users or service principals other than known, pre-approved automation service principals. This activity may indicate an unauthorized user or compromised service principal attempting to inject malicious code into automation workflows.
Detects modifications to Windows Registry keys associated with Event Tracing for Windows (ETW) Autologger configurations or Event Log service configurations. These modifications can be used by adversaries to disable or tamper with event logging mechanisms, effectively blinding security telemetry and evading detection.
Detects the use of regsvr32.exe to execute remote scripts or components via a URL (a technique often referred to as Squiblydoo). This rule flags process command lines containing /i flags combined with remote HTTP/HTTPS addresses, while excluding known management tools to reduce false positives.
This rule detects potential ransomware activity by monitoring for two key signals: interaction with known canary/trap files designed to detect unauthorized access, and rapid, mass file modification of common user data extensions within a short timeframe. Either behavior is indicative of encryption or automated file destruction processes typical of ransomware attacks.
Detects anomalous, high-frequency account enumeration activity in cloud audit logs, specifically targeting user, group, device, and service principal listing operations. This behavior is indicative of potential reconnaissance or discovery efforts by an attacker who has compromised a user account.
