
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,236 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects access, copying, or creation of files within common cryptocurrency wallet directories, as well as registry lookups related to Bitcoin data directories. This behavior is often indicative of info-stealing malware or an adversary attempting to exfiltrate digital currency assets from a compromised host.
Detects file creation, copy, or rename operations within known VPN application directories (CyberGhost, ExpressVPN, NordVPN) when initiated by Chromium Embedded Framework (CEF) related processes (CefSharp.BrowsersSubprocess). This behavior is highly irregular as standard web browser components should not be modifying the local configuration or installation directories of VPN software.
This rule detects potential exposure of API keys, tokens, or secrets within FTP directory listings. It specifically looks for network events on remote port 21 (FTP) where the 'RemoteUrl' contains keywords like 'api_key', 'apikey', 'token', 'secret', or 'key=' during a network signature inspection.
Detects network events where FTP (port 21) traffic contains specific timestamp-like patterns in the RemoteUrl, which could indicate an attempt to exploit the Squidbleed vulnerability related to timestamp-to-filename parsing anomalies. The rule looks for 'LIST' command combined with '12:34:56', '2026-', or 'timestamp' in the URL.
Detects file creations (images), image loads, and process execution activity originating from or related to the 'SCef.WindowsAdapter' directory. This directory is often associated with specific third-party application behaviors and should be monitored for potential anomalous execution or staging of suspicious files.
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
Detects reads of HKLM\SYSTEM\CurrentControlSet\Control\SystemStartOptions, the value that stores boot parameters (e.g. NOEXECUTE=OPTIN vs SAFEBOOT:MINIMAL). Ransomware including Snatch and Qilin query this key to determine whether the host is already in Safe Mode before forcing a reboot and encrypting with AV/EDR unloaded.
Treat as a high-interest hunting lead when paired within minutes with Safe Mode staging:
bcdedit /set safeboot, reg add under SafeBoot\Minimal or SafeBoot\Network, or
shutdown /r.
Treat as a high-interest hunting lead when paired within minutes with Safe Mode staging:
bcdedit /set safeboot, reg add under SafeBoot\Minimal or SafeBoot\Network, or
shutdown /r.
Detects Hannibal Stealer reconnaissance activity involving the creation of a 'config.json' file within the 'SCef.WindowsAdapter' directory, correlated with suspicious process executions attempting to enumerate system information via 'GetComputerNameEx' or 'GetAdaptersInfo' API calls.
This rule detects potential exploitation of the Squidbleed vulnerability by identifying network connections to FTP port 21 where the remote URL contains 'PASV' or 'EPSV' commands, and the initiating process is 'squid.exe'. This indicates an attempt to abuse FTP passive mode through the Squid proxy.
This rule detects potential credential harvesting activity associated with the Hannibal Stealer. It looks for non-standard processes (processes other than the browsers themselves) that access sensitive browser credential stores (like 'Login Data', 'cookies.sqlite', or 'key4.db') and correlate these file access events with the loading of 'bcrypt.dll' or 'CefSharp.BrowsersSubprocess.dll', which are often used for decryption or browser automation/sub-processes during credential theft.
Page 570 of 867
