
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the deployment, registration, and loading of known vulnerable drivers (e.g., mhyprot2.sys, gdrv.sys, rtcore64.sys) used in Bring Your Own Vulnerable Driver (BYOVD) attacks. This rule monitors file creation, module loading, service registration via sc.exe, and registry modifications associated with service installation.
Detects instances where non-browser processes access sensitive browser-related files (Login Data, Cookies, or Local State) located within AppData directories. This behavior is highly indicative of credential and session token theft, often associated with AiTM or post-compromise information harvesting activities.
Detects unauthorized or non-standard processes attempting to create, modify, or access sensitive cloud configuration and credential files, such as AWS credentials, Azure CLI token caches, or GCP application default credentials. This behavior is indicative of potential credential theft or unauthorized access to cloud environment tokens.
Detects unauthorized access or modification to common CI/CD credential files (.npmrc, .pypirc, .git-credentials, jenkins credentials.xml) and CI/CD configuration files (.github/workflows, .gitlab-ci.yml). The rule monitors both file system activities by non-standard processes and the execution of command-line tools that reference these sensitive files.
This rule detects potential wiper activity by monitoring for high-frequency deletion or modification of specific file types (e.g., .docx, .xlsx, .pdf, .db, .bak) within a short window. It triggers when a process like PowerShell or Cmd is observed executing destructive commands (e.g., 'del', 'erase', 'Remove-Item') on a large number of files across multiple directories, which is a common behavior of malware attempting to destroy data.
Detects potential persistence or configuration activity associated with the Remcos Remote Access Trojan (RAT). The rule monitors for the creation or modification of registry keys explicitly named 'Remcos', as well as the addition of executables from suspicious paths (e.g., AppData, Temp) to the Windows 'Run' registry keys, a common technique for achieving persistence.
This rule detects activities aimed at inhibiting system recovery by identifying attempts to delete volume shadow copies via vssadmin, wmic, or powershell, in combination with disabling windows recovery mode using bcdedit. This behavior is indicative of ransomware preparation, where an adversary attempts to prevent the restoration of data before encryption.
Detects usage of the Windows certutil.exe binary to perform potentially malicious operations such as downloading files via URL cache or decoding base64/hex payloads. The rule specifically alerts when these actions occur within common user-writable or temporary directories often used by threat actors for file staging.
This rule detects potential persistence via Registry Run keys (T1547.001) where a value is added pointing to a file in an AppData or Temp directory, followed by a successful outbound network connection from a process located in those same directories. This behavior is indicative of malware or an adversary establishing persistence and immediately reaching out to a command-and-control (C2) server.
Detects attempts to terminate security-related processes or stop security-related services using common administrative tools like taskkill.exe, sc.exe, net.exe, or net1.exe. This activity is often indicative of an adversary attempting to disable security monitoring and protection software to facilitate further malicious actions.
Page 559 of 867
