avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,953 views

8,664 detections

This rule detects URLs that contain common redirection or link parameters (u=, url=, redirect=, r=, link=, target=, dest=) where the value of the parameter is a long, alphanumeric string that appears to be an encoded domain. This pattern can indicate attempts to obfuscate the true destination of a link, often seen in phishing campaigns or malicious redirection attempts. The rule specifically looks for encoded parameters containing common top-level domains like .com, .net, or .org.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects the use of the rclone tool with data transfer commands (copy, move, sync, copyto, moveto) originating from a GoAnywhere server process or common interactive shell processes (cmd.exe, powershell.exe). This activity is highly suspicious and could indicate data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects when a web browser (Chrome, Edge, Firefox, Brave, Opera) initiates a process that is not another instance of itself. This could indicate a drive-by download, execution of malicious code, or other suspicious activity originating from a browser.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects the use of npm to install known malicious npm packages, which is indicative of a supply chain compromise attempt via typosquatting or malicious dependency injection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects the addition of users to specific high-value or sensitive groups in Microsoft Entra ID (Azure AD), which could indicate potential unauthorized privilege escalation or persistence attempts by an attacker.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects instances where a process running under the NT AUTHORITY\SYSTEM user context spawns a common execution utility (like cmd, powershell, or wscript) on a host that has recently engaged in network communication over port 445 (SMB). This behavior is highly indicative of lateral movement using SMB, such as service-based execution or remote command execution via tools like PsExec or WMI.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects network connection attempts directed toward RFC 1918 private IP address spaces (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost (127.0.0.0/8) that do not involve common Windows file sharing ports (TCP/445 and TCP/139). This behavior may indicate lateral movement, internal reconnaissance, or the use of non-standard protocols for internal communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects unexpected network connections initiated by the Local Security Authority Subsystem Service (lsass.exe) to the localhost (127.0.0.1) on ports other than standard SMB ports (445 or 139). LSASS should typically only communicate locally via RPC or LPC for authentication services, and anomalous network activity from this process may indicate credential theft attempts, process injection, or unauthorized memory access activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of net.exe or net1.exe with the 'tcpport' argument, which is typically used for querying network port connectivity or information on a host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances where a process running under the NT AUTHORITY\SYSTEM user context spawns a common execution utility (like cmd, powershell, or wscript) on a host that has recently engaged in network communication over port 445 (SMB). This behavior is highly indicative of lateral movement using SMB, such as service-based execution or remote command execution via tools like PsExec or WMI.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003