avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,957 views

8,664 detections

Detects attempts by a Chrome web browser process to create, modify, or rename files associated with sensitive user credentials or application data, such as AWS credentials, browser logins, or environment configuration files. This behavior is indicative of credential theft or staging of sensitive information.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects the use of 'net.exe' or 'net1.exe' to configure a non-standard SMB port, which is a technique often used for NTLM reflection and relay attacks. By specifying an arbitrary port for SMB traffic, an attacker may attempt to bypass standard network filtering or establish a listener to intercept authentication requests.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects execution of Python interpreters used as an SMB server, specifically where the implementation is not using the standard SMB port (445). This behavior is often associated with the use of tools like Impacket's smbserver.py for lateral movement, staging, or data exfiltration, attempting to blend in by using non-standard ports.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects Microsoft Excel application crashes (Event ID 1000) characterized by an access violation exception code (c0000005). This pattern can indicate an attempt to exploit vulnerabilities in office applications or memory corruption issues, potentially signaling a malicious document exploitation attempt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects SMTP traffic containing XLSX file attachments, specifically looking for base64 encoded content that matches the criteria for CVE-2025-60727. This rule monitors network traffic for the delivery of potential malicious Office documents.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potential privilege escalation activity associated with the abuse of CTFMON related objects (named pipes, symlinks, junctions) which may be used in conjunction with high-privilege operations (like SeDebugPrivilege or SeImpersonatePrivilege) to elevate access to SYSTEM. It correlates access events for CTF objects by processes (other than the legitimate ctfmon.exe) with subsequent sensitive privilege assignments within a short time window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
4010
Detects anomalous activity where a single user or service principal downloads more than 5 Microsoft Teams meeting recordings within a 1-hour window. This behavior potentially indicates an insider threat or compromised account performing bulk harvesting of sensitive meeting content.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
609
This rule detects outbound HTTP traffic generated by the WinHTTP library, specifically when the User-Agent identifies as WinHttp.WinHttpRequest. This pattern is indicative of potential post-exploitation activity, such as command-and-control communication or data exfiltration, originating from a process associated with an exploited Excel document (CVE-2025-60727).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects SMTP traffic containing XLSX file attachments, specifically looking for base64 encoded content that matches the criteria for CVE-2025-60727. This rule monitors network traffic for the delivery of potential malicious Office documents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
709