
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,254 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects the execution of RMM (Remote Monitoring and Management) installers (Atera or SimpleHelp) via msiexec.exe or setup.exe when launched from directories commonly used for downloads (Temp/Downloads) and originating from web browsers or Microsoft Office applications. This behavior is indicative of a potential drive-by download or phishing attack aimed at installing unauthorized remote access software.
Detects administrative commands (e.g., showing running configuration, copying startup configuration, or accessing enable secret) executed via SSH or Telnet on network devices from non-baseline management IP addresses.
Detects the presence of specific keywords within PowerShell Script Block logs (EventCode 4104) that are characteristic of Anti-Malware Scan Interface (AMSI) bypass techniques. These include attempts to manipulate the AMSI context, reflectively load assemblies to modify memory, or force scan failures.
Detects the execution of known debugger/disassembler tools (Ghidra, dnSpy, x64dbg) that exhibit suspicious network behavior. The rule specifically looks for these tools initiating network connections to destinations outside of their official update or project domains shortly after execution, and filters out known good hash signatures.
This rule detects a process identified as a Go-compiled binary (via command-line arguments like 'goroutine' or 'runtime.main') that exhibits rapid, high-volume file interactions (more than 100 files accessed or created in a 60-second window) alongside outbound network connectivity. This behavior is indicative of malicious automated activity such as file encryption for ransomware or rapid data staging and exfiltration.
This rule detects processes other than standard web browsers performing network connections that coincide with OAuth token acquisition activities (POST requests containing 'access_token' in the response body). This behavior is indicative of potential token theft or unauthorized programmatic access to OAuth-protected resources.
This rule identifies potential Command and Control (C2) beaconing activity by detecting recurring, consistent HTTP(S) requests from internal hosts to unknown or newly seen external destinations, characterized by stable time intervals and low variance in response sizes. The detection logic filters out common User-Agents, indicating non-browser or automated traffic often associated with malware communication.
Detects instances where a user successfully authenticates from a mobile device (Android or iPhone) that exhibits a geographic mismatch (geo_country vs registered_country), and subsequently performs a sensitive credential or MFA-related action (enrollment or reset) from a different device within one hour. This pattern is indicative of a potential session hijacking or credential compromise where an attacker attempts to establish persistence by enrolling their own MFA device.
This rule detects the execution of common archival utilities (7-Zip, WinRAR, RAR, ZIP) with parameters indicative of password-protected archive creation. It specifically flags instances where a user account, with no recorded prior history of running these utilities in the last 30 days, creates a large archive (exceeding 1GB) spanning multiple directories. This pattern is commonly used for data staging and preparation prior to exfiltration.
This rule detects when an executable or process loads a DLL from commonly writable locations like AppData, Temp, or ProgramData, while also correlating this activity with the loading of .NET CLR runtime components (mscoree.dll, clr.dll, etc.) and potential configuration file modifications. This behavior is indicative of .NET-based injection techniques such as AppDomainManager injection or DLL hijacking targeting .NET applications.
Page 599 of 867
