
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,193 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects modifications to Windows Registry keys related to Component Object Model (COM) objects (CLSID or InprocServer32) where the registry value points to suspicious file paths, specifically those within temporary directories like Temp or AppData. This behavior is indicative of an attacker attempting to establish persistence or perform privilege escalation by hijacking COM object execution flow.
Detects host-based reconnaissance activity patterns indicative of Trickbot malware. The rule monitors for a high frequency (>= 4 unique commands within a 30-minute window) of diagnostic commands ('tasklist', 'systeminfo', 'ipconfig', 'net') executed by cmd.exe or powershell.exe, which is a common behavior pattern for adversary discovery processes.
Detects the execution of processes with command-line arguments containing keywords related to known supply chain attacks (e.g., solarwinds, 3cx, kaseya, npm, pypi). This rule is intended for threat hunting to identify potential exploitation attempts or malicious activity involving software supply chain components.
Detects the execution of processes with command-line arguments indicative of destructive activity, such as wiping disks, partitions, or boot records, often associated with wiper malware.
This rule detects potential lateral movement activity by identifying devices that establish connections to three or more distinct remote IP addresses via SMB/CIFS ports (445 or 139) within a one-hour window. The query excludes internal network ranges (10.x.x.x and 192.168.x.x) to focus on connections that may be traversing network boundaries or reaching out to segments that might indicate unauthorized discovery or movement.
This rule detects connection attempts to common administrative and remote access ports (RDP, SSH, SMB, RPC) from non-internal IP address ranges. Such activity may indicate an attempt to bypass Zero-Trust network policies or unauthorized remote access attempts from external or untrusted segments.
Detects a sequence of events where ManageEngine or IDrive remote monitoring software is followed within 120 minutes by the execution of potential staging or encryption-related tools (servertool.exe or encrypt.exe) on the same device. This pattern may indicate the abuse of legitimate administrative tools for unauthorized activities or ransomware-like behavior.
This rule detects the usage of standard Windows system administration utilities (infinstall.exe, devcon.exe, pnputil.exe, sc.exe) when the command line arguments include keywords commonly associated with driver loading or kernel-level operations, which may indicate the installation of a rootkit or malicious driver.
Detects attempts to exploit the Squidbleed vulnerability (C11 strchr() Null Terminator Behavior Exploitation) by monitoring 'squid.exe' process command lines for the presence of null terminator characters or their string representations. This indicates an attempt to manipulate string handling functions.
This rule detects WebSocket communication attempts from a device to known command and control (C2) IP addresses associated with the Remcos Remote Access Trojan (RAT). It specifically looks for network events where the remote URL contains 'ws://', 'wss://', or 'websocket' and the remote IP address matches one of the listed indicators of compromise (IOCs).
Page 564 of 867
