
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects attempts to delete Volume Shadow Copies (VSS) using standard Windows utilities like vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is a common tactic employed by ransomware to inhibit system recovery and prevent the restoration of encrypted files.
Detects the creation of scheduled tasks (schtasks.exe) spawned by common scripting or social engineering-related parent processes (PowerShell, Cmd, WScript, MSHTA). The rule specifically looks for payloads associated with common attack patterns, such as downloading remote content or executing encoded commands, which indicates potential persistence or payload delivery activities.
This rule detects a multi-stage loader chain behavior. Stage 1 identifies PowerShell spawning mshta.exe or wscript.exe, which is commonly used to execute malicious scripts or loaders. Stage 2 detects mshta.exe or wscript.exe subsequently executing schtasks.exe or wmic.exe with command-line arguments indicative of establishing persistence via scheduled tasks or WMI event subscriptions.
Detects instances where known endpoint security product binaries (EDR/AV) load DLL files from directories outside of their trusted, standard installation paths. This behavior is a common indicator of DLL sideloading, where an attacker attempts to masquerade malicious code as a component of a trusted security process to evade detection.
Detects attempts by unsigned or non-Microsoft processes to perform cross-process memory injection (such as CreateRemoteThread or NtCreateThreadEx) into critical processes including browser processes (chrome.exe, msedge.exe) or the local security authority subsystem service (lsass.exe).
Detects FTP protocol traffic (on port 21) initiated by a process named 'squid.exe' or containing 'squid' in its filename. This rule is designed to identify potential exploitation attempts related to the Squidbleed vulnerability, where a compromised Squid proxy might be used for unauthorized FTP communications.
Detects instances where the WMI Provider Host process (WmiPrvSE.exe) spawns common interactive shells, scripting interpreters, or other binaries typically associated with remote command execution. This pattern is a strong indicator of WMI being abused for lateral movement or remote code execution within a Windows environment.
Detects unauthorized attempts to enumerate stored Windows credentials using native command-line utilities such as vaultcmd.exe and cmdkey.exe, or by invoking CredEnumerate/Get-StoredCredential functions via PowerShell scripts. These methods are commonly used by attackers to gain access to cached passwords, tokens, or network credentials stored in the Windows Credential Manager.
Detects the use of bitsadmin.exe to initiate file transfers from remote HTTP/HTTPS locations. This behavior is frequently used by adversaries to download malicious payloads onto a host using legitimate system utilities.
Detects execution of regsvr32.exe with flags indicative of the Squiblydoo application control bypass technique. The rule monitors for the use of the /i flag to load COM scriptlets from remote URLs (http/https) or UNC paths, or the inline loading of scrobj.dll, specifically in conjunction with the silent (/s) flag. Legitimate processes signed by Microsoft are excluded from detection unless remote URL execution is involved.
Page 561 of 867
