
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the creation of scheduled tasks using schtasks.exe where the task action executes a scripting engine or living-off-the-land binary (LOLBin). This behavior is often indicative of adversaries attempting to establish persistence or execute code using native system tools to evade detection.
Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
Detects the use of certutil.exe to download files from a remote URL using the -urlcache or -split flags. This behavior is a common Living-off-the-Land (LotL) technique used by adversaries to bypass security controls and download secondary payloads.
Detects the use of native Windows utilities (vssadmin, wmic, powershell, wbadmin) to delete volume shadow copies or backup catalogs. This activity is commonly associated with ransomware or destructive attacks attempting to prevent system recovery.
Detects the execution of known adversary-in-the-middle (AiTM) phishing frameworks, such as Evilginx or Modlishka, by identifying process names, paths, or specific command-line arguments (e.g., --phishlets, --proxy, --lure) used to initiate these proxy-based phishing sessions.
Detects the execution of Remote Monitoring and Management (RMM) software initiated by common Windows script interpreters. This pattern is indicative of unauthorized deployment of remote access tools, often used by adversaries to establish persistence and command-and-control channels following initial compromise.
Detects file creation or modification events targeting sensitive cloud credential storage locations, such as AWS credentials files, Azure configurations, and Google Cloud credentials databases. The rule filters out known legitimate CLI tools, flagging potential unauthorized access or exfiltration of cloud credentials by other processes.
Detects execution of regsvr32.exe with flags indicative of the Squiblydoo application control bypass technique. The rule monitors for the use of the /i flag to load COM scriptlets from remote URLs (http/https) or UNC paths, or the inline loading of scrobj.dll, specifically in conjunction with the silent (/s) flag. Legitimate processes signed by Microsoft are excluded from detection unless remote URL execution is involved.
Detects the creation of scheduled tasks using schtasks.exe where the task action executes a scripting engine or living-off-the-land binary (LOLBin). This behavior is often indicative of adversaries attempting to establish persistence or execute code using native system tools to evade detection.
Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
Page 562 of 867
