
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,233 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects emails successfully delivered to the inbox that exhibit authentication failures for SPF, DKIM, or DMARC, or where a mismatch between the 'SenderFromDomain' and 'SenderMailFromDomain' is observed, indicating potential email spoofing or unauthorized sender impersonation.
This rule detects the creation of scheduled tasks or 'at' jobs initiated by VBScript engines (wscript.exe or cscript.exe). This behavior can be indicative of malicious activity, such as persistence mechanisms established by malware or phishing attacks that leverage VBScript to schedule future execution.
Detects the execution of AutoHotkey or AutoIt automation scripts, particularly when these tools spawn suspicious child processes (e.g., cmd.exe, powershell.exe, wmic.exe), initiate commands from non-standard directories (Temp, AppData, Downloads), or run from locations outside of the standard Program Files installation directory.
Detects usage of common built-in tools (driverquery.exe, sc.exe) and PowerShell commands (Get-WindowsDriver, WMI queries for Win32_PnPSignedDriver or Win32_SystemDriver) used to enumerate installed system drivers. This is often part of reconnaissance to identify third-party drivers for BYOVD (Bring Your Own Vulnerable Driver) attacks.
This rule detects potentially malicious Wi-Fi network enumeration or profile creation using 'netsh' or 'nmcli', as well as the loading of 'wlanapi.dll' by non-standard, unauthorized processes. Such activities can indicate an attempt by an adversary to discover, connect to, or exfiltrate data via nearby wireless networks.
Detects the execution of AutoHotkey or AutoIt automation scripts, particularly when these tools spawn suspicious child processes (e.g., cmd.exe, powershell.exe, wmic.exe), initiate commands from non-standard directories (Temp, AppData, Downloads), or run from locations outside of the standard Program Files installation directory.
This rule detects various commands and processes used by adversaries to enumerate virtual machine software, hypervisor configurations, and virtualization-based security features on a host. This is often part of reconnaissance to understand the environment, detect sandboxing, or identify virtualization platforms for further post-exploitation activities.
Detects high-volume SSH or network logon failures from a single source IP address within a short time window, indicative of a brute force attack. The rule specifically mentions consistency with 'mpbrute2.bin' tooling used in the 'FortiBleed' campaign.
This rule correlates multiple low-to-medium confidence signals across file, process, network, and registry events to detect potential ransomware activity. The rule identifies suspicious behaviors including mass file renames, creation of known ransom note file types in multiple directories, shadow copy deletion via system utilities, disabling of antivirus and security monitoring, large archive staging, unauthorized outbound network connections, and suspicious process injection. Alerts are generated based on the aggregation and frequency of these signals, indicating a high probability of ransomware-related malicious activity.
Detection rule monitoring for indicators of compromise related to SolarWinds Serv-U, including anomalous Content-Encoding headers, unexpected child process execution, large file staging indicative of data exfiltration (Cl0p-style), outbound exfiltration, SQL injection artifacts, and unauthorized LDAP/Active Directory object enumeration by the Serv-U process.
Page 574 of 867
