
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,550 copies160 likes52,264 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects attempts to authenticate to SSH using GSSAPI (Generic Security Service Application Programming Interface). While GSSAPI can be used for legitimate authentication, its presence in logs might indicate an attacker attempting to use alternative authentication methods, potentially for lateral movement or privilege escalation, especially if unexpected in the environment.
This rule detects successful SSH authentications using the GSSAPI-with-MIC mechanism. This can indicate legitimate user logins or, in some cases, an adversary using valid credentials to access a system via SSH.
This rule detects attempts to manipulate user or service principal names (SPN/UPN) in Active Directory by adding non-ASCII or zero-width characters. Such modifications can be used by adversaries for obfuscation, to bypass detection mechanisms, or to create stealthy persistence. The rule specifically looks for Event IDs 4738 (User Account Changed) and 5136 (Directory Service Object Modified) where the 'servicePrincipalName' or 'userPrincipalName' attributes contain characters outside the standard ASCII range or zero-width characters like U+200B, U+200C, U+200D.
Detects network connections to a specific suspicious IP address (94.156.181.89) or to domains associated with Cloudflare Tunnel (.trycloudflare.com). This could indicate command and control activity, data exfiltration, or other malicious network communication.
Detects the loading of 'hostfxr.dll' from suspicious user-specific AppData folders by 'CrossDeviceService.exe' or 'Teams.exe'. This behavior can indicate an attempt to load a malicious .NET runtime, potentially for DLL hijacking or code injection, often associated with persistence or execution techniques.
Detects the creation of a named object with the specific name 'MakeAmericaGreatAgain'. This string has been associated with various malware and potentially unwanted programs, often used as a mutex or other synchronization object to ensure only one instance of the malicious process is running.
Detects when a file is renamed to have the suffix ':payload' and the initiating process's file name is the same as the previous file name. This behavior can be indicative of Payload Ransomware to hide or modify files.
This rule detects the presence of Blackbeard malware by identifying known SHA256 hashes of its components or network connections to its known C2 infrastructure. It correlates file events with specific hashes and network events with specific remote IP addresses.
Detects LampoRAT malware based on known file hash execution.
Detects when 'Cursor.exe' (a legitimate application) spawns common command-line utilities (cmd.exe, powershell.exe, pwsh.exe, curl.exe, wget.exe, certutil.exe, bitsadmin.exe) with command-line arguments indicative of downloading files from the internet (e.g., containing 'http://', 'https://', 'ftp://', '-o', '-OutFile', 'iwr', 'DownloadString', 'DownloadFile'). This could indicate malicious activity where 'Cursor.exe' is being abused to facilitate ingress tool transfer or execute malicious payloads.
Page 603 of 867
