
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,226 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects WebSocket communication attempts from a device to known command and control (C2) IP addresses associated with the Remcos Remote Access Trojan (RAT). It specifically looks for network events where the remote URL contains 'ws://', 'wss://', or 'websocket' and the remote IP address matches one of the listed indicators of compromise (IOCs).
Detects potential exploitation attempts related to the Squidbleed vulnerability by monitoring 'squid.exe' or processes with 'squid' in their command line for AddressSanitizer related keywords indicating memory safety issues like overflow, underflow, or use-after-free.
This rule detects potential DarkCloud RAT activity by looking for specific strings in process command lines. The strings 'darkcloud', 'dark.cloud', 'cloud.dll', or 'shadow.exe' are indicative of the RAT's components or communication patterns.
Detects attempts to bypass User Account Control (UAC) by abusing 'eventviewer.exe'. This rule specifically looks for 'eventviewer.exe' being initiated by suspicious processes like 'powershell.exe', 'cmd.exe', 'rundll32.exe', or 'Optimax.dll', while excluding legitimate command-line usage of 'eventvwr.exe'.
This rule detects potential memory-resident malware or staging activity by identifying instances where a high volume of DLL, OCX, or SYS files are loaded from user-writable directories (Temp, AppData, Users) on a specific device within a one-hour window. A threshold of 5 or more unique image loads from these locations is flagged as potentially suspicious, as it may indicate an attacker loading multiple malicious components or modules.
This rule detects the execution of PowerShell or pwsh.exe with an encoded command. Adversaries often use encoded commands to obfuscate their malicious scripts and evade detection. The rule specifically looks for the '-EncodedCommand' or '-enc' parameter followed by a base64-encoded string of at least 20 characters.
This rule detects various methods of establishing a reverse shell on Linux systems. It looks for process creation events involving common shell interpreters (bash, sh) attempting to connect to network devices via /dev/tcp or /dev/udp. It also identifies the use of network utilities like netcat (nc, ncat, netcat, nc.traditional) and socat when used with command execution flags (-e, -c, EXEC) and shell interpreters. Additionally, it flags direct outbound network connections initiated by these shell interpreters or network utilities, which could indicate a reverse shell communication channel.
Detects EvilTokens phishing HTML page with AES-GCM encrypted payload by file hash and characteristic code patterns
Detects attempts to invoke 'sudo' for privilege escalation or enumeration from non-interactive contexts such as scripts, scripting language interpreters, or web/application service processes. It also identifies 'sudo -l' or '--list' commands used for privilege enumeration.
This rule detects potential persistence mechanism installation by monitoring the creation of registry values in 'Run' or 'RunOnce' keys, followed by the execution of 'powershell.exe' or 'wscript.exe' on the same host within a 5-minute window.
Page 565 of 867
