
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,255 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule identifies instances of PowerShell executing with an encoded command followed immediately (within 300 seconds) by an outbound network connection to a non-standard port or non-internal IP address. This behavior is indicative of a remote access tool or reverse shell establishing command and control (C2) communication.
This rule detects when Microsoft Office applications (Word, Excel, PowerPoint) create INI files within the `C:\ProgramData\` directory. This behavior can be indicative of malicious activity, such as macro-enabled documents dropping configuration files or payloads, or other forms of malware attempting to establish persistence or store data in a less scrutinized location.
Detects when fodhelper.exe, a legitimate Windows utility, is used to spawn processes other than cmd.exe or conhost.exe. This behavior is commonly associated with UAC bypass techniques where fodhelper.exe is abused to execute arbitrary commands with elevated privileges without a UAC prompt.
This rule detects multiple failed logon attempts (more than 5 within a 5-minute window) for user accounts from a single IP address. This behavior is indicative of a brute-force attack or password guessing attempt against user accounts.
This rule detects the presence of the string "xhxhxhxhxhxpp" within the AdditionalFields of DeviceEvents. This string =represents a Mutex Indicator of Compromise (IOC).
Detects modifications to the 'User Shell Folders' registry key, which can be abused by adversaries to alter the location of special folders (e.g., Desktop, Documents) to point to attacker-controlled locations, potentially for persistence or data staging.
Detect connections to the known C2 domain.
This rule detects the creation or interaction with mutexes that contain both 'asus_' and '_v' in their names. This pattern has been observed in malware associated with ASUS systems, potentially indicating the presence of malicious software attempting to establish a unique identifier on the compromised system.
This rule detects the presence of known ShadowAgent malware files on devices by matching their SHA256 hashes. It queries 'DeviceFileEvents' to identify any files with SHA256 hashes that are part of a predefined list associated with ShadowAgent.
This rule detects the execution of 'REAGENTC.EXE' with the '/disable' argument and 'WBADMIN.EXE' with 'delete catalog -quiet' within a 10-minute window on the same device. This combination of commands is indicative of an adversary attempting to inhibit system recovery by disabling Windows Recovery Environment and deleting the Windows Backup Catalog, often seen in ransomware attacks.
Page 602 of 867
