avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views

8,664 detections

Detects high-volume file writes or the use of common command-line copy utilities (xcopy, robocopy, copy) targeting removable drive paths (E-G:). This behavior is often indicative of data staging or exfiltration activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
403
Detects the execution and network activity of known reverse tunneling and proxy tools such as Chisel, Ngrok, and FRP. These tools are commonly abused by adversaries to establish persistence, bypass firewalls, and facilitate command and control (C2) communication. The rule monitors for specific process names, command-line arguments, and DNS requests related to these services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects processes attempting to connect to the Cloud Instance Metadata Service (IMDS) IP address (169.254.169.254) or referencing it in the command line. This behavior is often associated with credential theft or reconnaissance on cloud instances.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects behaviors associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, including the dropping of .sys driver files into non-canonical directories, the registration and execution of kernel services via sc.exe, the use of fltMC to load filter drivers, and the loading of driver modules from non-standard locations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects common productivity applications (e.g., Word, Excel, Acrobat Reader) spawning typical command-line interpreters or scripting hosts. This behavior is a frequent indicator of malicious macro execution or exploit-based payload delivery often seen in phishing campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects attempts to access or exfiltrate the Windows Security Account Manager (SAM) or SYSTEM registry hives, which are primary targets for extracting credential hashes. This rule identifies common attack vectors including native Windows registry utilities (reg.exe), PowerShell-based volume shadow copy techniques (Invoke-NinjaCopy), and known credential dumping tools like secretsdump (from the Impacket suite) executed via command line or interpreted through Python.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the abuse of the legitimate Windows binary regsvr32.exe for malicious purposes. This rule monitors for two common attack patterns: 1) The use of regsvr32.exe with specific command-line arguments (/i, /s, /u, /n) to load remote scripts (SCT files) or libraries from the internet, a technique known as 'Squiblydoo'. 2) Suspicious child processes spawned by regsvr32.exe, which often indicates follow-on malicious activity such as command shell execution or lateral movement tools.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects potential DCOM-based lateral movement by monitoring for suspicious process spawns from COM surrogates (dllhost.exe), WMI provider hosts (wmiprvse.exe), or remote invocation of office/management applications (mmc.exe, excel.exe, outlook.exe) that subsequently execute command shells or scripting interpreters.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects potential misuse of the legitimate Windows utility 'InstallUtil.exe' for proxy execution. It flags instances where InstallUtil is executed with suspicious command-line parameters often used for bypass techniques (e.g., logging flags or loading code from user-writable directories like Temp, AppData, or Downloads), or when InstallUtil acts as a parent process to suspicious child processes typically associated with post-exploitation activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects unauthorized modifications to SSH 'authorized_keys' files or the '/etc/ssh/sshd_config' configuration file on Linux systems. These actions can be used for persistent access (key injection) or to weaken SSH security controls (e.g., enabling root login) and are typical indicators of account manipulation or compromise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003