avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,963 views

8,664 detections

Detects the execution of manage-bde.exe with command-line arguments designed to enable encryption, disable/delete BitLocker protectors, or modify authentication keys. This pattern is indicative of ransomware abuse, specifically actors attempting to encrypt drives and destroy recovery capabilities, particularly when spawned from scripting or shell environments like PowerShell, CMD, or WMI.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects processes attempting to connect to the Cloud Instance Metadata Service (IMDS) IP address (169.254.169.254) or referencing it in the command line. This behavior is often associated with credential theft or reconnaissance on cloud instances.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects potential lateral movement activity where PowerShell or the Windows Remote Management (WinRM) host process (wsmprovhost.exe) initiates network connections to multiple distinct destination IP addresses over the WinRM default ports (5985/5986). This behavior is characteristic of an adversary using legitimate remote administration tools to pivot or spread across a network.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects attempts to acquire Windows credentials by accessing critical registry hives (SAM, SYSTEM, SECURITY) or their shadow copies. It looks for the use of 'reg save' to export hives, as well as direct file access to these hives or their shadow copy variations by non-standard system processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects suspicious activity related to GitHub Actions workflows, including the creation or modification of workflow configuration files, the placement of suspicious JavaScript files in the repository's .github directory, the execution of the 'Bun' runtime within an Actions runner environment, and cloud-based events indicating workflow modification containing 'Run Copilot' strings. These patterns are often associated with CI/CD pipeline compromise, malicious automation, or unauthorized code execution within build environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects instances where a guest user or an external account (identified by the #EXT# suffix) performs an operation to add a new member to a Microsoft 365 Group. This behavior can be indicative of a guest account being compromised or misused to escalate privileges or gain unauthorized access by modifying group memberships.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
303
Detects users who modify their MFA settings (registration/update/delete) and subsequently perform privileged actions (such as adding role members or service principal credentials) within a short timeframe, while simultaneously observed active in communication applications like Teams, Zoom, or Webex. This behavior is indicative of potential account takeover where an adversary modifies authentication methods to gain persistent access, followed by privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
8010
Detects anomalous network activity originating from 'NearShareReceive.exe' (Windows Near Share) to public IP addresses on non-standard ports, potentially indicating unauthorized use of the Near Share feature for data staging or exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of Python interpreters spawned by code editors or runtime environments (e.g., VS Code, Cursor, Node.js) with specific command-line arguments involving 'init'. This behavior may indicate an adversary attempting to leverage development tools to execute custom scripts, potentially for automated deployment, persistence, or malicious payload initialization.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects the execution of python.exe or python3.exe using the '-m init' command line flag while attempting to establish a network connection over specific, often non-standard, ports (4444, 1337, 9001, 9002, 5555, 6666, 7777, 8888). This pattern is commonly associated with reverse shells or C2 agent check-ins initiated via Python scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003