
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,254 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects cross-process memory access events (Sysmon Event ID 10) where a process attempts to hook into keyboard-related Windows API functions such as SetWindowsHookEx, GetKeyState, or GetAsyncKeyState. It further filters for processes executing from suspicious locations (Temp, AppData, ProgramData) or those that are unsigned/unverified, which are common indicators of malicious keylogging or spyware activity.
Detects high-frequency requests (over 30 unique paths within a 5-minute window) to sensitive VPN-related URL paths that result in 403 (Forbidden) or 404 (Not Found) status codes from non-internal IP addresses. This behavior is indicative of an adversary performing directory enumeration or vulnerability scanning on public-facing infrastructure.
Detects high-frequency requests (over 30 unique paths within a 5-minute window) to sensitive VPN-related URL paths that result in 403 (Forbidden) or 404 (Not Found) status codes from non-internal IP addresses. This behavior is indicative of an adversary performing directory enumeration or vulnerability scanning on public-facing infrastructure.
Detects high volume HTTPS outbound traffic (greater than 50MB within a 5-minute window) from a host that does not show evidence of preceding file encryption or volume shadow copy deletion activity. This rule is designed to identify potential unauthorized data exfiltration that deviates from typical ransomware-associated behavior patterns.
Detects the creation of scheduled tasks using schtasks.exe that point to high-risk directories (Temp, AppData, ProgramData) or utilize obfuscated PowerShell commands (encoded parameters). This behavior is often associated with adversary persistence or initial execution.
Detects the execution of PowerShell or Command Prompt as child processes spawned by wscript.exe or cscript.exe, where the parent process command line indicates a JavaScript file being executed from the AppData or Temp directories. This behavior is highly characteristic of the Gootloader malware dropper, which leverages script engines to initiate subsequent malicious stages.
Detects the use of built-in Windows utilities (vssadmin, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or modify boot configuration settings to disable recovery features, which is a common precursor to ransomware encryption.
Detects the creation of scheduled tasks using schtasks.exe that point to high-risk directories (Temp, AppData, ProgramData) or utilize obfuscated PowerShell commands (encoded parameters). This behavior is often associated with adversary persistence or initial execution.
Detects the execution of PowerShell or Command Prompt as child processes spawned by wscript.exe or cscript.exe, where the parent process command line indicates a JavaScript file being executed from the AppData or Temp directories. This behavior is highly characteristic of the Gootloader malware dropper, which leverages script engines to initiate subsequent malicious stages.
Detects potential password spraying or brute force activity by monitoring Windows Event Code 4625. The rule identifies source IP addresses that have attempted to authenticate against more than 10 unique accounts within a 5-minute window, calculating a spray ratio to differentiate high-intensity credential spraying attempts.
Page 601 of 867
