
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,193 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects command-line execution patterns associated with the BumbleBee malware loader, specifically looking for process names like 'secur.exe', 'secure.exe', 'update.exe', or the string 'bumblebee' within the command line arguments.
Detects modifications to Windows Registry keys related to Component Object Model (COM) objects (CLSID or InprocServer32) where the registry value points to suspicious file paths, specifically those within temporary directories like Temp or AppData. This behavior is indicative of an attacker attempting to establish persistence or perform privilege escalation by hijacking COM object execution flow.
Detects outbound network connections to URLs containing strings associated with Qakbot (Qbot) malware infrastructure and common ports used by the malware for command-and-control communication.
Detects the creation of executable files (.exe, .com, .scr, .vbs, .js) that contain financial-themed keywords (e.g., GST, NEFT, RTGS, IMPS, Banking) in their filename. This pattern is commonly used in social engineering and phishing attacks to trick users into executing malicious payloads disguised as legitimate banking or financial documents.
Detects command line activity indicative of an attempt to access or extract browser-related files such as 'Cookies' or 'Local State', which are commonly associated with session theft or credential harvesting from major web browsers like Chrome, Firefox, Edge, and Safari.
This rule detects potential ransomware lateral movement patterns by correlating specific network connection attempts (SMB/RDP/RPC) with the observed creation of files having the '.prinzeugen' extension on the same host within a 2-hour window. This behavior is indicative of a ransomware strain propagating across the network and performing encryption.
Detects network activity associated with the ROOTBOY actor, specifically identifying internal devices communicating with known malicious command and control (C2) IP addresses and subsequently attempting to access specific suspicious domains or URLs linked to the actor's infrastructure.
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
Detects the creation of image-related files with generic names in common temporary or user download directories that fall within a specific file size range (100KB-1000KB). These characteristics are often indicative of steganography where malicious payloads or data are embedded within seemingly benign image files to bypass security controls.
Detects process executions containing sensitive keywords related to trust, certificates, and multi-factor authentication (e.g., 'mfa', '2fa', 'otp') that are not initiated by standard trusted system processes (services.exe, wininit.exe, smss.exe). This pattern is often indicative of credential manipulation, certificate harvesting, or tampering with authentication mechanisms.
Page 566 of 867
