
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Identifies mshta.exe accessing externally hosted HTA content from a user-initiated Explorer session, potentially indicating malicious remote code execution.
Identifies the creation of PowerShell or batch files in unusual ProgramData subdirectories by command-line interpreters, which may indicate malware staging or persistence preparation.
Detects excessive caret (^) escaping in command lines, a common obfuscation technique used by attackers to evade detection and conceal malicious commands. The rule specifically looks for command-line executions by cmd.exe, powershell.exe, or pwsh.exe that contain more than 5 caret characters and a pattern of at least three alphanumeric characters immediately followed by a caret.
Detects mshta.exe launched from Windows Explorer to retrieve remote HTA content over HTTP, a technique frequently observed in phishing campaigns and initial access attacks.
Detects the use of 'forfiles.exe' with the '/c' execution parameter, a technique that can be abused to launch arbitrary commands while potentially bypassing application controls. This activity is often associated with defense evasion tactics.
Detects scheduled tasks created with embedded PowerShell XOR decoding logic, ReadAllBytes, and Invoke-Expression techniques that may be used to establish persistence and execute obfuscated payloads. The rule specifically looks for 'schtasks.exe' creating a task with '/create', containing 'OneDrive', 'Startup', 'Task' in the command line, and also includes '-bxor', 'ReadAllBytes', 'iex', and '[Text.Encoding]::UTF8.GetBytes' which are indicative of obfuscated PowerShell execution via XOR decoding.
Detects execution of DWAgent from download or temporary directories rather than standard installation locations, potentially indicating unauthorized remote management activity.
Detects the creation of PowerShell or batch scripts within the C:\ProgramData directory, which is a common location abused by malware for payload staging and persistence. The rule specifically looks for file creation events where the initiating process is cmd.exe or powershell.exe and the file extension is either .ps1 or .bat.
Look for traffic to the known Sunburst C&C.
Exploited SolarWinds process starting CMD with suspicious parameters.
Page 607 of 867
