avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,955 views

8,664 detections

This rule detects the use of PsExec or the Service Control Manager (sc.exe) to execute code remotely, which is a common technique used by attackers for lateral movement and remote code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects instances where the Windows Management Instrumentation service (WmiPrvSE.exe) spawns a command shell (cmd.exe) with command-line arguments involving standard output redirection (2>&1), often used to capture error and output streams in remote command execution scenarios. This pattern is commonly observed during lateral movement or remote administration activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the use of administrative tools like wmic.exe, powershell.exe, or pwsh.exe to invoke WMI event subscription components such as ActiveScriptEventConsumer, CommandLineEventConsumer, or FilterToConsumerBinding. This behavior is a common technique for establishing persistence or elevating privileges by executing malicious code when specific system events occur.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects outbound TCP traffic originating from the internal network to external hosts on TCP port 45588, which is associated with Interlock ransomware beaconing behavior. This rule monitors for initial TCP SYN packets, characteristic of an outbound connection attempt potentially related to command-and-control activity following the exploitation of CVE-2026-20131.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects network connections to known cloud storage, file hosting, and webhook services (Discord, Pastebin, Dropbox, Telegram, AnonFiles) initiated by processes other than standard web browsers. Such behavior is often indicative of data exfiltration or C2 activity using legitimate web services to blend in with normal traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects high-frequency file renaming or creation activities within a short timeframe (60 seconds) that involve uncommon file extensions. This behavior is highly characteristic of the encryption phase of ransomware attacks, where malicious processes quickly rename or encrypt files across the system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of rundll32.exe or regsvr32.exe as a child process of script interpreters like wscript.exe, cscript.exe, or mshta.exe. The command line parameters often involve potentially malicious paths (e.g., Temp, AppData, ProgramData, Users\Public) or the presence of DLL extensions, indicating potential proxy execution of malicious scripts or side-loaded libraries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects artifacts related to the ValleyRAT malware family, specifically identifying markers such as 'Phantom Persistence Module', 'RegisterApplicationRestart', and specific 'RSL_' strings within process command lines, image paths, or module loads using Windows Event Logs and Sysmon data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects high-frequency file renaming or creation activities within a short timeframe (60 seconds) that involve uncommon file extensions. This behavior is highly characteristic of the encryption phase of ransomware attacks, where malicious processes quickly rename or encrypt files across the system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects network connections to known cloud storage, file hosting, and webhook services (Discord, Pastebin, Dropbox, Telegram, AnonFiles) initiated by processes other than standard web browsers. Such behavior is often indicative of data exfiltration or C2 activity using legitimate web services to blend in with normal traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003