avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views

8,664 detections

This rule detects potentially malicious DNS traffic where queries contain exceptionally long, encoded, or randomized subdomains. Attackers often use these patterns to exfiltrate data from a target network, bypassing traditional security controls by encapsulating information within DNS requests (DNS tunneling). The detection looks for DNS queries exceeding 100 bytes in length with specific character patterns indicative of Base64 or similar encoding.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects suspicious WinRM SOAPAction headers indicating potential lateral movement or remote command execution (e.g., shell command, process creation, or WMI operations) over WinRM HTTP ports 5985 and 5986.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects potential Cobalt Strike Beacon check-in activity over HTTP. It identifies incoming GET requests where the URI is abnormally short and the HTTP Referer header is missing, which are common indicators of default Cobalt Strike malleable C2 profiles.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects potential ransomware lateral movement patterns by correlating specific network connection attempts (SMB/RDP/RPC) with the observed creation of files having the '.prinzeugen' extension on the same host within a 2-hour window. This behavior is indicative of a ransomware strain propagating across the network and performing encryption.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects suspicious usage of the Bun runtime, specifically when it is spawned by common Node.js development processes (like npm or node-gyp) or downloaded from non-official sources using command-line tools or browsers. This behavior is associated with the Miasma malware campaign, which abuses the Bun runtime for malicious operations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects suspicious activity related to GitHub Actions workflows, including the creation or modification of workflow configuration files, the placement of suspicious JavaScript files in the repository's .github directory, the execution of the 'Bun' runtime within an Actions runner environment, and cloud-based events indicating workflow modification containing 'Run Copilot' strings. These patterns are often associated with CI/CD pipeline compromise, malicious automation, or unauthorized code execution within build environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
This rule detects file creation or modification events associated with the Miasma campaign. It identifies specific payload files (e.g., .claude/setup.mjs, .vscode/tasks.json), the use of specific marker strings in file metadata or origin URLs, and obfuscated task configurations in VS Code directories that leverage bun or node to execute base64-encoded or character-encoded commands.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects attempts to modify Windows Defender exclusions using PowerShell cmdlets (Add-MpPreference, Set-MpPreference) or direct Registry manipulation. Adversaries often modify these exclusions to hide malicious files or directories from antivirus scanning, a technique used to impair defensive security tools.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004