
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,193 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
Detects the execution of rundll32.exe with arguments pointing to remote UNC paths, HTTP/FTP URLs, or local DLL files residing outside of standard, trusted Windows system directories (System32/SysWOW64). This behavior is indicative of an attempt to proxy malicious code execution, commonly associated with fileless or remote payload retrieval techniques.
Detects potential Remcos RAT loader activity involving process hollowing or injection into browser processes. This rule specifically looks for common browser executables (iexplore.exe, chrome.exe, firefox.exe) where the initiating parent process is 'Optimax.dll' or contains 'SystemOptimizer', which are indicators associated with the Remcos RAT loader.
This rule detects the creation of common media file types (audio and video) within user-specific application data, temporary, or user profile directories. This activity could be indicative of various malicious behaviors, including data exfiltration, staging of malicious payloads, or the dropping of decoy files by malware.
This rule detects the use of password derivation functions (like argon2id, scrypt, pbkdf2) in command lines, which can be indicative of ransomware activity, specifically associated with Prinz Eugen. It focuses on processes like 'servertool.exe', 'encrypt.exe', and 'powershell.exe' initiating these commands.
This rule detects the creation or modification of executable files (.com, .exe, .scr, .pif, .bat, .cmd) in common user directories (Documents, Downloads, Desktop) where the initiating process is a legitimate application like explorer.exe, winrar.exe, or 7z.exe. This pattern is often used in phishing attacks where malicious executables are disguised as benign documents.
Detects suspicious installations of ManageEngine Endpoint Central components (ManageEngineADSelfService.exe or me_servicelaunchpad.exe) when executed with silent installation parameters or initiated by scripting engines (wscript.exe, cscript.exe, powershell.exe), followed by the execution of 'reg.exe' or 'regsvcs.exe' within a two-hour window. This pattern can indicate an attempt to install or configure the software surreptitiously, potentially for persistence or privilege escalation.
This rule detects inbound Remote Desktop Protocol (RDP) connections (ports 3389, 3390, 3391) that are initiated by common scripting engines such as wscript.exe, cscript.exe, or powershell.exe. This behavior can be indicative of post-exploitation activity where an attacker uses scripts to establish remote access.
This rule detects potential memory-resident malware or staging activity by identifying instances where a high volume of DLL, OCX, or SYS files are loaded from user-writable directories (Temp, AppData, Users) on a specific device within a one-hour window. A threshold of 5 or more unique image loads from these locations is flagged as potentially suspicious, as it may indicate an attacker loading multiple malicious components or modules.
Detects the execution of script-based interpreters (wscript.exe, cscript.exe, powershell.exe) where the command line contains keywords typically associated with downloading or executing remote content (http, ftp, download, invoke, execute). This activity is often used in the initial stages of a malware attack to retrieve and run malicious payloads.
Page 563 of 867
