
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,230 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects process executions containing sensitive keywords related to trust, certificates, and multi-factor authentication (e.g., 'mfa', '2fa', 'otp') that are not initiated by standard trusted system processes (services.exe, wininit.exe, smss.exe). This pattern is often indicative of credential manipulation, certificate harvesting, or tampering with authentication mechanisms.
Detects anomalous device network activity involving 5G-specific protocol ports (e.g., GTP-U, SIP). The rule aggregates unique port usage per device over 1-hour intervals to identify potential network reconnaissance, scanning, or unauthorized control plane communication.
Detects Microsoft Office applications (Word, Excel, PowerPoint) spawning command-line interpreters (PowerShell, CMD, WScript). This behavior is characteristic of malicious macros or exploitation attempts where Office applications execute shell commands to facilitate second-stage payload delivery or system compromise.
This rule detects network traffic containing keywords commonly associated with Indian payment gateways and financial transactions (NEFT, RTGS, IMPS, GST, PAN, IFSC). This could indicate data exfiltration or suspicious activity involving financial information, potentially related to malware like Remcos RAT.
This rule detects when the Remcos RAT loader attempts to access browser cache folders (Chrome, Firefox, Opera). This activity is indicative of credential dumping, where the malware tries to extract sensitive information like stored passwords or session tokens from web browsers.
This rule detects potentially malicious PowerShell execution by identifying the use of obfuscated encoded commands or common execution policy bypass flags. It monitors for patterns such as '-EncodedCommand' with long strings, '-ExecutionPolicy Bypass', and other flags typically used to hide PowerShell execution or bypass security restrictions, while excluding trusted Microsoft-signed processes and commands executed from standard system paths.
Detects unauthorized or suspicious use of virtualization management tools (e.g., esxcli, vim-cmd, PowerShell cmdlets for vSphere/Hyper-V) to perform disruptive actions such as powering off VMs, removing snapshots, or modifying firewall configurations. The rule excludes activity originating from standard management processes and trusted VMware/Microsoft signed processes.
Detects DNS resolutions for major AI/LLM provider domains (e.g., OpenAI, Anthropic, Google AI) originating from processes that are not common, known browsers or development tools. This behavior is indicative of potentially malicious applications or malware using AI APIs for automated tasks, such as content exfiltration or sophisticated C2 communication.
This rule detects potentially malicious PowerShell execution by identifying the use of obfuscated encoded commands or common execution policy bypass flags. It monitors for patterns such as '-EncodedCommand' with long strings, '-ExecutionPolicy Bypass', and other flags typically used to hide PowerShell execution or bypass security restrictions, while excluding trusted Microsoft-signed processes and commands executed from standard system paths.
This rule detects when common document-handling applications (such as Microsoft Office suite or PDF readers) spawn known remote access and support tools. This behavior is highly indicative of vishing-based social engineering attacks, where a user is tricked into downloading and executing a remote management tool via a malicious document.
Page 567 of 867
