
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,530 copies160 likes52,244 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects suspicious activities within a Veeam backup environment, including unauthorized process spawning by Veeam services, LSASS memory access, destruction of backup catalogs or restore points via PowerShell, and unauthorized access to Veeam database files by non-Veeam processes.
This rule detects suspicious activity related to high-volume Server Message Block (SMB) share enumeration and the execution of a specific Python script named 'backup_dfs.py'. It combines three detection logics: identifying processes executing 'backup_dfs.py', detecting an unusual number of SMB network connections to common administrative shares (SYSVOL, NETLOGON, DFS), and flagging high-volume SMB-related identity directory events targeting SYSVOL or NETLOGON. This behavior could indicate an adversary performing discovery of network shares, collecting data, or preparing for data exfiltration.
Detects successful non-interactive token acquisitions using specific Microsoft first-party application IDs known to bypass Entra Conditional Access Policies through Nested App Authentication (NAA/BroCI). The detection specifically targets sign-ins to the Microsoft Graph resource.
Detects successful sign-ins to specific Azure AD applications known to bypass Conditional Access policies, where Conditional Access was not applied. This could indicate an attempt to circumvent security controls.
This rule monitors Cisco Unified Communications Manager (UCM) environments for multiple stages of an attack chain, including potential Server-Side Request Forgery (SSRF) attempts against administrative interfaces, suspicious file modifications by service accounts, indicators of privilege escalation, and anomalous outbound network connections from core Cisco processes.
This rule detects potential exploitation activity related to CVE-2026-45657 involving the Windows Kernel tcpip.sys driver. It monitors for a combination of system crashes (Kernel-Power 41 or EventLog 6008) correlated with Windows Error Reporting (WER) events referencing 'tcpip.sys', or significant spikes in external authentication attempts occurring shortly before a system crash. The rule aims to identify potential remote code execution attempts manifesting as kernel instability.
This rule detects processes that load sensitive Windows multimedia and graphics modules (mmdevapi.dll, avrt.dll, magnification.dll, dxgi.dll) which are commonly utilized for audio recording and screen capturing. The rule filters out known legitimate applications (e.g., Teams, Zoom, Web browsers) and trusted software publishers. It further identifies potential suspicious activity by flagging processes originating from common staging paths like 'Temp', 'Downloads', or 'ProgramData' and instances where the process image is unsigned.
Detects processes attempting to query the Cloud Instance Metadata Service (IMDS) endpoint (169.254.169.254) that are not recognized as legitimate cloud agent software (such as AWS, Azure, or Google cloud agents). This behavior is often indicative of SSRF or unauthorized discovery attempts by an adversary on a compromised cloud instance.
This rule detects unauthorized access, creation, or modification of browser-specific sensitive credential files (such as 'Login Data' or 'cookies.sqlite') by processes that are not recognized web browsers or trusted update services. This behavior is a common indicator of information-stealer malware attempting to harvest session cookies and stored credentials.
This rule detects potential ransomware activity by identifying a combination of three distinct behaviors occurring on a single endpoint within a short window: high-volume file modifications (indicative of file encryption), deletion of system recovery resources (e.g., volume shadow copies, backup catalogs), and high-frequency network activity (indicative of data exfiltration). The rule uses cross-event correlation to reduce false positives by requiring all three signals to be present.
Page 575 of 867
