avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,956 views

8,664 detections

Description- Detects PDF invoice files associated with Crimson Kingsnake using consistent metadata author “hpins”.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Correlates phishing email delivery with subsequent communication to attacker-controlled domains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects DNS queries for reverse lookups, specifically those ending with '.in-addr.arpa' or '.ip6.arpa'. While legitimate, frequent or unusual reverse DNS queries from a specific device or process could indicate reconnaissance activities or attempts to map internal network infrastructure by an attacker.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
This rule detects network connections to or from known suspicious IP addresses and requests to known suspicious domains. These indicators are often associated with command and control (C2) activity, malware distribution, or other malicious infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects successful SSH login attempts from external IP addresses (not within common private IP ranges). It specifically looks for 'Accepted' messages in syslog from the 'sshd' process and filters out internal source IPs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
This rule detects potential Kerberoasting activity by identifying an unusual number of Kerberos service ticket requests (Event ID 4769) for service principal names (SPNs) ending with '$' from a single client address within an hour. A high count (over 10) is flagged as 'High' suspicion, while a count between 5 and 10 is flagged as 'Medium'. This behavior is indicative of an attacker attempting to obtain service ticket hashes for offline cracking.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects suspicious network connections made by processes (excluding legitimate EDR processes like mssense.exe and senseir.exe) to URLs commonly associated with EDR command and control (C2) infrastructure. This could indicate an attempt by an adversary to communicate with or manipulate the EDR agent.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects suspicious execution of 'RUNDLL32.EXE' with specific command-line arguments. It looks for instances where 'RUNDLL32.EXE' is executed with both a backslash and a comma in the command line, combined with specific DLL names or keywords like 'iamnotarobot.dll', 'checkme.dll', 'machinerie.dll', 'humanCheck', or 'verifyme'. This pattern is often indicative of malicious DLL loading or persistence mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects when Microsoft Office applications (Word, Excel, PowerPoint) create INI files within the `C:\ProgramData\` directory. This behavior can be indicative of malicious activity, such as macro-enabled documents dropping configuration files or payloads, or other forms of malware attempting to establish persistence or store data in a less scrutinized location.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects successful or failed logon attempts originating from IP addresses identified by threat intelligence as associated with botnets, command and control (C2) infrastructure, or proxies. The rule specifically looks for 'LogOn' or 'FailedLogOn' activity types where the source IP's threat intelligence indicator type is 'Botnet', 'C2', or 'Proxy', and where activity insights are available.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104