
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,226 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects malicious activity associated with Kimsuky JSE loaders, which leverage XML DOM manipulation (e.g., bin.base64) and ADODB.Stream components to decode and drop base64-encoded payloads into the ProgramData directory. It further monitors for subsequent decoding attempts using certutil and the presence of specific, suspicious file extensions (e.g., .a9oc, .lpXD, .lpxQ) often used by this threat actor.
Detects the execution of JSE files by wscript.exe or cscript.exe followed by the immediate self-deletion of the file from the Downloads folder, a behavior commonly observed in Kimsuky dropper activity.
This rule detects when non-FileZilla processes attempt to read or access sensitive FileZilla configuration files, specifically 'recentservers.xml' or 'sitemanager.xml', which are known to store plain-text credentials for site connections. This behavior is indicative of credential harvesting.
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
Detects potentially unauthorized or suspicious usage of the Jam build tool (jam.exe or jamplus.exe). The rule flags when Jam is executed by non-standard parent processes, when suspicious command-line arguments are used, when Jam spawns unexpected child processes, or when Jam initiates network connections.
Detects the creation or modification of Azure Storage Account management policies that include rules configured to delete blobs, snapshots, or versions in less than 30 days. This behavior may indicate an attempt at data destruction or unauthorized cleanup of cloud storage objects.
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
Detects instances where a specific identity or caller triggers Azure Function or Logic App workflows at a high volume (more than 50 successful invocations within a 5-minute window). This threshold may indicate automated exploitation, potential brute-force attempts on API endpoints, or a misconfigured/malfunctioning service causing excessive resource usage.
Detects the creation of multiple executable files (.exe or .dll) within a 6-hour window in non-standard directories (outside of Windows or Program Files). The rule identifies scenarios where a single filename has three or more distinct SHA256 hashes associated with it on a specific device, which may indicate iterative malware delivery, obfuscation techniques, or persistence mechanism testing.
Page 571 of 867
