
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,230 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the use of the Windows certutil.exe utility for potentially suspicious file operations, including downloading files from remote URLs via 'urlcache' or 'split', or encoding/decoding files. This is a common Living-off-the-Land (LotL) technique used by attackers to stage malicious payloads or deobfuscate malicious content.
Detects unauthorized or suspicious use of virtualization management tools (e.g., esxcli, vim-cmd, PowerShell cmdlets for vSphere/Hyper-V) to perform disruptive actions such as powering off VMs, removing snapshots, or modifying firewall configurations. The rule excludes activity originating from standard management processes and trusted VMware/Microsoft signed processes.
Detects the use of common Windows system administration tools (cmd, powershell, net, sc, taskkill, wmic) to stop, delete, or terminate known backup software agents. This behavior is highly characteristic of ransomware or destructive attacks attempting to inhibit system recovery by destroying backup infrastructure.
Detects the creation of a new local account using the 'net' utility, followed immediately by that account being added to the local administrators group on the same endpoint. This behavior is a common indicator of persistence or privilege escalation attempts.
Detects instances where common Windows processes (svchost.exe, explorer.exe, or notepad.exe) spawn suspicious child processes (such as cmd.exe, powershell.exe, or wscript.exe). The rule identifies potential process hollowing or living-off-the-land techniques by correlating parent-child relationships with suspicious command-line parameters (encoding, hidden execution, or in-memory execution) or anomalous file paths (running from user-writable directories).
Detects MFA fatigue attacks where a user receives more than 10 MFA push denials within a 10-minute window, followed immediately by a successful authentication from a different IP address. This behavior is indicative of an adversary bombarding a user with push notifications until they are approved, followed by account takeover.
Detects anomalous activity where a single user or service principal downloads more than 5 Microsoft Teams meeting recordings within a 1-hour window. This behavior potentially indicates an insider threat or compromised account performing bulk harvesting of sensitive meeting content.
This rule detects when a non-administrative user grants an application high-privilege OAuth scopes (such as mail reading, file access, or directory management) within an Azure/Microsoft 365 environment. Such consent grants can be used by attackers to maintain persistence and bypass MFA by gaining delegated access to sensitive resources.
Detects potential container breakout attempts on Windows systems by monitoring for the launch of privileged containers with sensitive host paths mounted, the execution of host-level processes directly spawned by container runtime binaries (docker.exe, containerd.exe), and direct access to sensitive host filesystems (e.g., C:\windows, C:\etc, C:\programdata) by container runtimes.
Detects successful sign-ins using legacy authentication protocols (e.g., IMAP, POP3, SMTP AUTH, ROPC) for user accounts that are in scope of a Conditional Access policy requiring multi-factor authentication (MFA). Legacy protocols do not support modern authentication flows, effectively bypassing configured MFA requirements and increasing the risk of credential-based attacks.
Page 568 of 867
