
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects unauthorized access or modification to common CI/CD credential files (.npmrc, .pypirc, .git-credentials, jenkins credentials.xml) and CI/CD configuration files (.github/workflows, .gitlab-ci.yml). The rule monitors both file system activities by non-standard processes and the execution of command-line tools that reference these sensitive files.
Detects the abuse of Windows Background Intelligent Transfer Service (BITS) via 'bitsadmin.exe' or PowerShell's 'Start-BitsTransfer' cmdlet to download files from remote URLs. This rule identifies potentially malicious activity by monitoring for specific transfer-related command-line arguments coupled with external network connections, excluding Microsoft-signed processes. It further refines detection by flagging output to suspicious directories (like Temp, AppData, or Public) or files with common executable extensions.
Detects the use of tar.exe to extract archives into common staging directories (Temp, AppData, Public, ProgramData), particularly when the process is initiated by suspicious parent processes such as Office applications, command shells, or download utilities, which is often indicative of malicious payload staging.
Detects DNS lookups and network connections to known AI API endpoints (OpenAI, Anthropic, Google Generative Language) initiated by non-standard processes. This rule excludes common web browsers, productivity applications, and development tools to identify potentially unauthorized or suspicious interaction with AI services from internal processes.
Detects unauthorized attempts to terminate, stop, or access Endpoint Detection and Response (EDR) or Antivirus agent processes. This is identified by monitoring command-line utilities like taskkill, net, and sc targeting known security service names, as well as detecting suspicious cross-process access (e.g., OpenProcess) by unauthorized processes targeting security agent PIDs.
Detects unauthorized access to Windows Credential Manager files, TokenBroker OAuth cache files, or the loading of crypt32.dll from suspicious, user-writable directories (e.g., Temp, Downloads, Desktop) by non-Microsoft or non-system processes. This activity is indicative of credential theft, session hijacking, or attempts to abuse the Windows Data Protection API (DPAPI) to decrypt sensitive local secrets.
Detects potential execution chains related to QR code phishing (Quishing) by monitoring for suspicious process creation or outbound network connections originating from document readers, office applications, and QR scanner utilities. It covers three primary vectors: suspicious process spawning (e.g., Office apps launching cmd or powershell), non-standard network connections from document readers, and malicious URL-based LNK files spawned via explorer.exe.
Detects cross-process access to the Local Security Authority Subsystem Service (LSASS) memory by processes that are not standard Microsoft-signed system components. This behavior is often indicative of credential dumping activity using tools like Mimikatz or other custom malicious utilities attempting to read sensitive memory contents.
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns common shell or script interpreter processes (cmd.exe, powershell.exe, cscript.exe, wscript.exe). This behavior is often indicative of fileless remote code execution used for lateral movement across Windows environments, as WMI is frequently abused by attackers to remotely trigger malicious commands.
Detects the execution of known AI/LLM command-line interface tools (such as Ollama, OpenAI, or Claude) when spawned by command shells (cmd.exe, powershell.exe) or executed from suspicious locations like user profiles or temporary directories. This pattern is indicative of potential use of LLMs for generating malicious code, analyzing data, or assisting in post-exploitation activities within a compromised environment.
Page 558 of 867
