
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Description- Detects PDF invoice files associated with Crimson Kingsnake using consistent metadata author “hpins”.
Detects known malicious invoice PDFs and email samples used in Crimson Kingsnake campaigns.
Detects suspicious command-line executions involving common Windows system binaries (rundll32.exe, mshta.exe, certutil.exe, wmic.exe) combined with keywords often associated with network communication or data transfer (http, https, base64, /transfer). This pattern can indicate attempts at downloading malicious payloads, exfiltrating data, or executing encoded commands.
Detects URL clicks associated with the Moduba cloaking and redirect campaign using UrlClickEvents. Focuses on specific domain IOCs, redirect chains, and beaconing behaviors.
Detects the creation of Windows QoS policies that specifically target EDR, antivirus, or security monitoring processes using the -AppPathNameMatchCondition parameter. This technique can be used to throttle security tool network traffic, reducing telemetry visibility and impairing detection capabilities.
Detects creation of the malicious persistence service observed during the Hola Browser compromise.
Detects Windows Defender exclusion modifications. The malicious Hola miner was observed adding exclusions before beginning mining operations.
Detects PowerShell download activity associated with Argamal's second-stage payload retrieval.
Detects suspicious GitHub-hosted payload retrieval. Argamal has been observed downloading encrypted components from GitHub repositories.
Detects COM object hijacking through InprocServer32 modifications. Argamal establishes persistence using COM hijacking mechanisms.
Page 604 of 867
