
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects successful sign-ins using OAuth from residential IP addresses. It joins `SigninLogs` with `IdentityLogonEvents` to correlate successful OAuth authentications with user logon events. The intent is to identify potentially suspicious access, possibly indicating credential abuse or unauthorized access attempts from non-corporate or unexpected locations.
Detects outbound network connections to major Large Language Model (LLM) API endpoints (OpenAI, Google, Anthropic) initiated by processes not explicitly identified as standard web browsers or command-line utilities. This pattern may indicate automated data exfiltration ('prompt stealing' or unauthorized access to corporate data) using custom or malicious tools executing from suspicious directories like temp, appdata, or public folders.
This rule monitors for administrative VMware operations (cloning, snapshotting, or process manipulation) performed on sensitive infrastructure servers (such as Domain Controllers, PKI, Vault, or ADFS) that occur outside of a designated maintenance window by non-authorized accounts. It leverages tools like vim-cmd, esxcli, or govc to detect potential unauthorized VM manipulation that could lead to data theft, snapshot-based credential extraction, or unauthorized system changes.
Detects suspicious execution of MSBuild.exe originating from non-standard parent processes or loading project/xml files from unconventional directories such as user-writable or temporary locations. This behavior is indicative of an attempt to bypass application whitelisting and execute arbitrary inline C# code via MSBuild's task functionality.
Detects high-volume failed authentication attempts targeting a specific user account from a source IP address, indicative of 'MFA fatigue' or 'push bombing' attacks. This rule monitors endpoint-visible logon failure events as captured by EDR telemetry to identify potential attempts to circumvent multi-factor authentication by spamming the user with requests.
Detects the creation, reading, or execution of payloads stored within NTFS Alternate Data Streams (ADS). This technique is commonly used by adversaries to hide malicious content within file metadata to evade security tools. The rule monitors process command-line arguments for ADS syntax, identifies usage of utilities like type, Get-Content, wmic, or various LOLBins (e.g., regsvr32, rundll32) interacting with ADS paths, and flags anomalous file creation/modification events that involve ADS, excluding known system-generated streams.
Detects the execution of known AI/LLM command-line interface tools (such as Ollama, OpenAI, or Claude) when spawned by command shells (cmd.exe, powershell.exe) or executed from suspicious locations like user profiles or temporary directories. This pattern is indicative of potential use of LLMs for generating malicious code, analyzing data, or assisting in post-exploitation activities within a compromised environment.
Detects the creation of scheduled tasks using schtasks.exe, where the command line arguments reference known LOLBins (Living Off the Land Binaries) such as certutil, regsvr32, mshta, wscript, cscript, rundll32, or encoded command execution via cmd.exe. This activity often indicates an attempt to establish persistence or execute malicious code using trusted system binaries.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by searching for common memory patching techniques, such as modifying AmsiUtils, AmsiScanBuffer, or related reflection-based obfuscation in process command lines.
This rule detects instances where PowerShell or PowerShell Core (pwsh.exe) are spawned as child processes of common COM object host processes (e.g., wscript.exe, mshta.exe, rundll32.exe). The detection specifically looks for command-line arguments containing encoded commands or indicators of download cradles (e.g., IEX, Net.WebClient, DownloadString), which are common patterns for fileless execution and malicious script staging.
Page 557 of 867
