
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,236 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects unauthorized processes reading, copying, or renaming Kerberos ticket cache files (ccache) located in common temporary directories. This behavior is often associated with credential theft and potential Pass the Ticket attacks where adversaries attempt to extract session credentials to perform lateral movement or privilege escalation.
This rule monitors network logs (from proxies and firewalls) for web traffic (HTTP GET requests) containing suspicious JavaScript code injection patterns in the request context or message fields. It specifically looks for common XSS indicators such as <script tags, eval(), document.write(), fromCharCode(), and atob().
This rule detects a pattern of network shared folder access followed by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') within a 45-minute window. This behavior is indicative of ransomware preparing to encrypt data on network shares.
This rule detects a sequence of events indicative of ransomware deployment following a successful Remote Desktop Protocol (RDP) connection. Specifically, it looks for an inbound RDP connection (RemotePort 3389) to a device, followed within 60 minutes by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') on the same device. This pattern suggests an attacker gaining initial access or moving laterally via RDP and then deploying ransomware.
Detects network connections originating from a Squid proxy process (squid.exe or processes containing 'squid' in their name) attempting to connect to an FTP server (port 21). This could indicate a reachability test or other activity related to the Squidbleed vulnerability, or general proxy misuse.
This rule detects network events where an FTP LIST response contains malformed directory entries, potentially indicating an attempt to exploit the Squidbleed vulnerability. It specifically looks for network signature inspections on port 21 (FTP) with common FTP commands (LIST, NLST, MLSD, MLST, RETR) in the RemoteUrl, while excluding common log and text file extensions.
This rule detects attempts to inject malicious DLLs into common Windows processes such as svchost.exe, explorer.exe, lsass.exe, and winlogon.exe. The detection is based on the loading of DLLs with suspicious names like 'hook.dll', 'inject.dll', 'payload.dll', or 'stage.dll' by these processes, which is indicative of process injection techniques often used by malware like Remcos RAT.
Detects attempts by processes identified as Remcos RAT or its loader (GST*.com) to access Local Security Authority (LSA) secrets. This activity is indicative of credential dumping, where an attacker tries to extract sensitive authentication material from the system.
Detects unusual FTP command sequences where common file listing commands (LIST, NLST, MLSD) are used without specifying a filename parameter, and the RemoteUrl length is unusually short, potentially indicating reconnaissance or an attempt to exploit a vulnerability like Squidbleed. The rule specifically excludes common file extensions to reduce false positives.
Detects attempts by processes identified as Remcos RAT or its loader (GST*.com) to access Local Security Authority (LSA) secrets. This activity is indicative of credential dumping, where an attacker tries to extract sensitive authentication material from the system.
Page 572 of 867
