
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects emails originating from sender addresses identified by Microsoft as part of the April 2026 "Code of Conduct" adversary-in-the-middle (AiTM) phishing campaign that targeted Microsoft 365 users and attempted to steal authentication tokens.
Detects delivery of known PDF attachments used in the Code of Conduct credential theft campaign.
Detects files staged in C:\Users\Public\Music via RDP (mstsc.exe), a known Grixba ransomware scanner behavior.
Flags mutex creation (CPFATE) in .NET runtime, linked to Grixba ransomware scanner variants.
Identifies .lnk files dropped into Startup folders, a persistence technique tied to WinRAR exploitation.
Detects suspicious PowerShell execution chains (-nop, -w hidden, iex (gc) used in ClickFix RAT delivery.
Detects execution of CRYPTBASE.dll from non‑system directories, a technique used in the STX RAT campaign to hijack legitimate installers (e.g., CPUID HWMonitor, X‑VPN).
Detects PowerShell queries for motherboard serial numbers or UUIDs, behaviors commonly associated with malware reconnaissance and sandbox evasion. This rule specifically looks for 'powershell.exe' executing commands that query 'Win32_BaseBoard' or 'Win32_ComputerSystemProduct' and contain 'SerialNumber' or 'UUID'.
Identifies PowerShell executing scripts or expressions from the ProgramData directory, which may indicate malicious staging or backdoor execution. This rule specifically looks for PowerShell processes where the command line includes 'C:\ProgramData\' and also contains keywords like 'IEX', 'Invoke-Expression', or '.ps1', suggesting the execution of a script or expression.
Detects calls to NtAllocateVirtualMemory originating from scripting engines or binaries executing from temporary user-controlled locations. This behavior is commonly associated with reflective loading, shellcode execution, and in-memory malware.
Page 606 of 867
