
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects the execution of known Command and Control (C2) frameworks such as Sliver, Havoc, SparkRAT, or VShell from common suspicious temporary or staging directories (temp, tmp, appdata, programdata). This rule monitors process creation events to identify the presence of these unauthorized remote access tools.
Detects Microsoft Outlook spawning a command-line interpreter (cmd.exe or powershell.exe) followed by a network connection originating from that interpreter within a 5-minute window. This behavior is highly suspicious and often indicative of malicious macro execution or exploit delivery via email attachments leading to command-and-control activity.
Detects instances where Node.js (node.exe) or the Node Package Manager (npm.exe) process initiates common command-line shells (cmd.exe, powershell.exe) or network utility tools (curl.exe). This behavior is often associated with software supply chain attacks, exploitation of web applications, or malicious post-exploitation activity where Node-based environments are leveraged to execute system commands or download external payloads.
This rule identifies instances where python.exe or python3.exe executes from non-standard system paths and establishes an outbound network connection to external (non-private/non-loopback) IP addresses. This behavior is indicative of potential malicious activity, as legitimate applications typically execute from protected program file directories, while adversaries often execute unauthorized binaries from temporary or user-writable locations to initiate command and control (C2) communication.
This rule detects potential DNS hijacking or redirection by comparing the returned IP address from a DNS query against a known list of authoritative IP addresses for specific domains. If an internal DNS resolver returns an IP address that does not match the authoritative record, it flags the event as a potential DNS response mismatch. It includes risk scoring based on the number of distinct affected hosts.
This rule detects the creation and subsequent deletion of a local user account within a 240-minute window. This behavior is often indicative of an adversary creating a temporary, ephemeral account for malicious activity (e.g., persistence or lateral movement) and then removing it to evade detection or cover their tracks.
Detects failed Windows logon attempts (Event ID 4625) where the supplied username conforms to typical password complexity requirements (minimum 10 characters, including uppercase, lowercase, digit, and special character). This behavior often indicates that a user has mistakenly entered their password into the username field, which may expose credentials in cleartext logs and suggests a potential security awareness issue or an attempt to bypass authentication.
Detects repeated authentication failures (Event ID 4625) with a specific sub-status code 0xC0000072, which indicates that the user account is disabled. This behavior is indicative of a brute-force or credential-stuffing attack against disabled accounts, or potentially misconfigured automated services attempting to authenticate with stale credentials.
Detects potential Pass-the-Hash (PtH) activity by identifying NTLM Type 3 logons where the account domain originates from outside the local or known corporate domain. The rule specifically excludes system-related accounts such as ANONYMOUS LOGON, WORKGROUP, and NT AUTHORITY, focusing on attempts to authenticate against internal resources using potentially forged or captured credentials.
Detects instances where an interactive user initiates a password change attempt as captured by Windows Security Event ID 4723. The rule filters out non-interactive accounts (ending with '$') and common service account naming patterns to focus on human-driven account modifications.
Page 600 of 867
