
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,186 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the installation of known vulnerable kernel drivers (Bring Your Own Vulnerable Driver - BYOVD). These drivers are often exploited by adversaries to gain kernel-level code execution, elevate privileges, or disable security tools (EDR).
Detects potential persistence or configuration activity associated with the Remcos Remote Access Trojan (RAT). The rule monitors for the creation or modification of registry keys explicitly named 'Remcos', as well as the addition of executables from suspicious paths (e.g., AppData, Temp) to the Windows 'Run' registry keys, a common technique for achieving persistence.
Detects high-frequency HTTPS network connections to Google Drive or Google APIs originating from processes that are not common web browsers or productivity software. This behavior is indicative of the GearDoor backdoor, commonly used by APT41, which leverages Google services as a command-and-control (C2) channel.
Detects critical Windows system processes (svchost.exe, lsass.exe, csrss.exe, wininit.exe, winlogon.exe, spoolsv.exe) that are either spawned by unexpected parent processes or reside in non-standard directories. This behavior is indicative of potential masquerading, process injection, or malicious persistence attempts.
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
Detects attempts by the Remcos RAT loader to perform WebRTC IP leakage by monitoring process command lines for keywords like 'webrtc', 'stun', 'turn', or 'ice' when initiated by common browsers (chrome.exe, firefox.exe, opera.exe) and having a parent process related to 'Remcos'. This indicates an attempt to gather victim IP addresses.
Detects the execution of known Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Action1) from user-writable directories such as Temp, Downloads, or INetCache. Adversaries frequently utilize these legitimate remote access tools to establish persistence or command-and-control channels, often dropping them into temporary directories to avoid detection.
This rule detects unauthorized processes attempting to create, modify, rename, or delete the 'Login Data' SQLite database files used by Google Chrome and Microsoft Edge to store saved credentials. By excluding legitimate browser processes and updates, the rule identifies potential credential theft attempts by infostealer malware or unauthorized actor tools.
This rule detects potential exploitation attempts related to the Squidbleed vulnerability, specifically looking for command-line arguments indicative of heap buffer overread conditions within the 'squid.exe' process. It monitors for keywords such as 'strchr', 'buffer', 'overread', 'parse', 'directory', and 'listing' in the command line.
This rule detects the creation of large files (1MB or greater) with names suggestive of exfiltration or staging (e.g., containing 'exfil', 'stage', 'batch', 'zip', 'archive') in common temporary or public user directories. This behavior can indicate an adversary preparing data for exfiltration.
Page 560 of 867
