avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views

8,664 detections

Detects instances where the legitimate Windows binary 'consent.exe' loads the library 'msimg32.dll' from a non-standard location (outside of System32 or SysWOW64). This behavior is characteristic of DLL sideloading techniques used by the BumbleBee malware loader to execute malicious code within the context of a trusted system process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects various methods used to extract credentials protected by the Windows Data Protection API (DPAPI). It covers multiple vectors, including Mimikatz DPAPI module usage, unauthorized loading of the dpapi.dll library, suspicious access to browser or WiFi credential stores, and cross-process memory access to the LSASS process to extract DPAPI master keys.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
Detects techniques associated with Golden SAML attacks, including the use of Mimikatz for ADFS token-signing certificate extraction, the execution of AADInternals PowerShell cmdlets for SAML token forgery, and unauthorized access to the ADFS configuration database (AdfsConfiguration.mdf).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
This rule detects suspicious network connections originating from internal IP addresses to common service ports (DNS, SMB, RDP, WinRM) on remote, non-internal IP addresses. It flags instances where a single process on a device makes 10 or more such connections within an hour, which could indicate reconnaissance, lateral movement, or data exfiltration attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
303
This rule detects suspicious outbound DNS queries originating from a device that are not directed to common public DNS servers (Google DNS, Cloudflare DNS). The rule specifically flags queries where the remote DNS name contains keywords like 'malware', 'c2', or 'c&c', and where at least 5 such queries occur within an hour from the same device. This pattern can indicate potential malware communication or command and control (C2) activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects suspicious DLL injection activity by identifying multiple DLL loads from unusual folders such as 'Temp', 'AppData', or 'Windows\Temp'. Adversaries often drop malicious DLLs into these directories and then inject them into legitimate processes to achieve persistence, privilege escalation, or defense evasion. The rule counts the number of DLL loads from these suspicious locations by the same initiating process on the same device, triggering an alert if five or more such loads occur, indicating a concerted malicious effort.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects an unusual frequency of inventory-related commands being executed on a device within a one-hour window. Specifically, it looks for `tasklist.exe`, `wmic.exe`, or `Get-HotFix` being run 5 or more times in an hour. This behavior can indicate an adversary performing system information discovery.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the creation of processes where the command line contains keywords such as 'cve' or 'vulnerability'. This could indicate attempts to exploit known vulnerabilities, perform vulnerability research, or execute tools related to vulnerability assessment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects devices making a high volume of successful network connections to GitHub's API endpoints (api.github.com or api.releases). A count of 5 or more successful connections within an hour from a single device is considered suspicious and could indicate data exfiltration, automated tooling, or unusual development activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects failed attempts to change the system audit policy. This could indicate an adversary attempting to disable or modify security monitoring to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003