avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,964 views

8,664 detections

Detects instances where the legitimate Windows utility 'Fondue.exe' (Features on Demand) loads the control panel library 'APPWIZ.cpl' from non-standard locations such as C:\Users\Public or AppData directories. It also identifies the staging phase where 'APPWIZ.cpl' is written to 'C:\Users\Public', which is indicative of a DLL side-loading attack sequence, often associated with the Elephant malware dropper.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects suspected malicious activity associated with the Dropping Elephant threat group. The rule monitors for two behaviors: 1) IP address geolocation fingerprinting by identifying non-browser processes communicating with ipify.org and ip2c.org within a 60-second window, and 2) Direct network connections to known Dropping Elephant C2 domains, specifically gcl-power.org and chinagreenenergy.org.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects the creation or registration of scheduled tasks that involve the 'PerfWatson2.exe' utility or execution paths originating from within the local AppData directory. These patterns are often associated with persistence mechanisms used by malware or malicious scripts to maintain execution after reboots.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects high-frequency ICMP Echo Requests (Type 8) directed from internal networks to external destinations with oversized payloads (greater than 200 bytes). This pattern is indicative of ICMP tunneling, which is often used by adversaries for covert command-and-control (C2) communications or data exfiltration, bypassing standard filtering or monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects network traffic indicative of the EternalBlue (MS17-010) exploit attempt against SMBv1 services. The rule specifically looks for SMB packets with transaction command patterns associated with this exploit, which was commonly used by the WannaCry ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of VS Code Tunnel processes (code-tunnel.exe or code.exe with tunnel arguments) initiated by processes other than standard development-related parent processes (e.g., explorer, terminal, IDEs). This behavior may indicate an adversary attempting to establish persistent unauthorized remote access to a compromised host using the VS Code Tunnel functionality.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
309
This rule detects DNS queries containing an exceptionally long subdomain label (50 or more characters). Such patterns are often indicative of DNS tunneling techniques where data is encoded within the subdomain portion of a DNS query to bypass network security controls or establish command-and-control channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects clear-text attempts to clear Windows Event Logs using 'wevtutil' or 'Clear-EventLog' command patterns within network traffic, indicating a potential attempt to remove evidence of malicious activity on a host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects anomalous, high-volume data transfers to Telegram API endpoints (api.telegram.org, specific IP ranges), which is indicative of data exfiltration by malware such as KuinaExtractor. The rule monitors for cumulative outbound traffic exceeding 500MB within a 1-hour session window per process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects anomalous SMB NTLM authentication traffic indicative of relay attacks, where an attacker intercepts an authentication request and relays it to another SMB service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003