
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,202 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects unusually fast response times for FTP LIST commands, which could indicate an automated or programmatic interaction with an FTP server, potentially related to a vulnerability exploitation or data exfiltration attempt. The rule specifically looks for network events on port 21 (FTP) where the URL contains 'LIST' and the response time is less than 100 milliseconds.
Detects network communication patterns indicative of RedLine Stealer activity by looking for specific keywords in the RemoteUrl field during inbound or outbound connections.
This rule detects the execution of processes with command lines containing indicators associated with 'Phantom Stealer' malware, such as 'phantom stealer', 'stealer.dll', 'phantom.exe', or 'phtantom'. This could indicate an attempt to load or execute the stealer.
Detects outbound network connections from workstations or servers to common message broker ports (MQTT 1883/8883, AMQP 5672). These protocols are sometimes abused for command-and-control (C2) communication, as they allow for pub/sub messaging patterns that can blend into legitimate network traffic.
This rule detects the creation of an SVG file in common user-writable/temporary directories, followed closely (within 60 seconds) by the execution of common scripting interpreters (cmd.exe, powershell.exe, wscript.exe) by a web browser. This behavior is often associated with browser-based exploitation or malicious file downloads where an attacker uses an SVG or accompanying file to trigger secondary malicious processes.
Detects outbound network connections from 'squid.exe' to internal IP addresses on port 21 (FTP). This could indicate an attacker controlling an FTP server within the internal network, potentially exploiting a vulnerability like Squidbleed.
Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
Detects the creation or modification of Azure Storage Account management policies that include rules configured to delete blobs, snapshots, or versions in less than 30 days. This behavior may indicate an attempt at data destruction or unauthorized cleanup of cloud storage objects.
Page 569 of 867
