
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,545 copies160 likes52,253 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Loader malware delivering follow-on ransomware payloads
Rust-based ransomware family targeting enterprise environments
Ransomware group exploiting edge devices and managed file transfer software
Credential and browser data stealer distributed via OXLOADER campaigns
This rule detects successful HTTP requests (status 200, 201, 202) directed towards management interfaces (Redfish, CIMC, OSS APIs) by unauthenticated or anonymous users originating from outside the internal network. The rule calculates a risk level based on the variety and frequency of requested paths, flagging potential unauthorized enumeration or exploitation attempts against server infrastructure.
Detects unauthorized processes attempting to access sensitive browser files such as 'Login Data', 'Cookies', and 'Web Data' files typically located in Chrome or Firefox user profiles. This behavior is indicative of credential theft or data exfiltration, as these files contain saved usernames, passwords, and session cookies.
This rule monitors build agent processes (e.g., Jenkins, Bamboo, Gradle, MSBuild) for suspicious DNS activity. It alerts when these processes resolve a high volume (3 or more) of unique external domains that are not associated with typical development, build, or dependency management platforms (e.g., Microsoft, Azure, GitHub, NPM, PyPI, Maven, Sonatype). This behavior may indicate an attempt by an adversary to reach command-and-control servers or exfiltrate data from a compromised build environment.
This rule detects successful HTTP requests (status 200, 201, 202) directed towards management interfaces (Redfish, CIMC, OSS APIs) by unauthenticated or anonymous users originating from outside the internal network. The rule calculates a risk level based on the variety and frequency of requested paths, flagging potential unauthorized enumeration or exploitation attempts against server infrastructure.
Detects the creation of multiple archive files (ZIP, 7Z, RAR, TAR) by common utilities (7z, WinRAR, tar) in sensitive temporary directories (Temp, tmp). The rule aggregates activity over a 10-minute window to identify suspicious staging behaviors often associated with ransomware data preparation.
This rule detects the coordinated execution of multiple Windows command-line utilities (vssadmin, wbadmin, and bcdedit) within a short time frame (60 seconds). These tools are frequently used by ransomware and other malware to delete volume shadow copies, clear backup catalogs, and disable system recovery features, effectively preventing the restoration of the system after a damaging event.
Page 592 of 867
