avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,972 views

8,664 detections

Detects HTTP traffic patterns consistent with data exfiltration to major cloud storage providers (AWS S3, Azure Blob Storage, Google Cloud Storage) using common command-line interface tools like rclone, aws-cli, and AzCopy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects potential misuse of the legitimate Windows utility InstallUtil.exe (a .NET component installer) to proxy the execution of malicious code. It identifies two specific suspicious patterns: first, the execution of InstallUtil with command-line arguments indicative of bypass attempts (e.g., /logfile, /LogToConsole, or /U) or loading files from user-writable directories (Temp, AppData, Downloads, ProgramData); second, instances where InstallUtil spawns potentially malicious child processes such as PowerShell, cmd, or various system binaries often used for persistence or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects potentially malicious activity involving the Windows binaries Regasm.exe and Regsvcs.exe, which can be abused to proxy the execution of arbitrary code. It specifically identifies three suspicious behaviors: spawning of common command shells or script engines by these binaries, execution of these binaries when located in or loading assemblies from user-writable directories (e.g., Temp, AppData, Downloads), and module loading of DLLs from those same writable locations, especially when the binary is not Microsoft-signed.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects potential lateral movement activity involving Windows Remote Management (WinRM). The rule monitors for common WinRM-related tools (winrs.exe), PowerShell WinRM cmdlets (e.g., Invoke-Command) targeting non-local systems, and the spawning of suspicious processes by the WinRM host process (wsmprovhost.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects outbound WebSocket connections from endpoints to known infrastructure associated with the Turla group's STOCKSTAY malware. The rule monitors DeviceNetworkEvents for successful connections or attempts to specific domains (glitch.me, onrender.com, theworkpc.com) or connections containing WebSocket-related headers in the metadata, which indicate C2 activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
Detects mshta.exe spawning from archive utilities (winrar.exe, 7z.exe) or Windows Explorer, or executing HTA files directly from common user-writable temporary or download directories. This pattern is commonly associated with the execution of malicious payloads delivered via compressed archives, a technique observed in campaigns attributed to the Turla threat group.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule monitors for potentially malicious use of the Windows Certutil utility, specifically targeting the -urlcache (often used to download remote files) and -decode (used to decode hidden or obfuscated payloads) command-line arguments. It filters out common trusted processes like Microsoft's msiexec.exe to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects potential DCOM-based lateral movement by monitoring for suspicious process spawns from COM surrogates (dllhost.exe), WMI provider hosts (wmiprvse.exe), or remote invocation of office/management applications (mmc.exe, excel.exe, outlook.exe) that subsequently execute command shells or scripting interpreters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects evidence of file timestomping, a technique used by attackers to modify file system timestamps (Create, Access, Modify, Change) to evade forensic detection or masquerade malicious files. The rule monitors for explicit usage of timestomping tools (e.g., Invoke-TimeStomp), abuse of system utilities like fsutil.exe for timestamp modification by suspicious parent processes, and unauthorized or unsigned processes performing timestamp modification on sensitive file types.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the use of common archive utilities (7-Zip, WinRAR) to perform file archiving operations within sensitive user-profile directories (Desktop, Documents, Downloads, etc.). This pattern is often used by adversaries to stage or bundle sensitive data prior to exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004