avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,970 views

8,664 detections

Detects when a user account is deleted on a Windows system. This event (EventID 4726) is critical for monitoring potential malicious activity, such as an attacker attempting to remove traces of their presence or disrupt operations by deleting legitimate user accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects multiple executions of 'netsh firewall' commands within a one-hour window on a single computer. This activity can indicate an adversary attempting to modify or disable system firewalls to bypass security controls, enable C2 communications, or facilitate lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the creation of scheduled tasks (Event ID 4697) where the command line contains either 'System' or 'Admin'. This could indicate an attempt to create a scheduled task that runs with elevated privileges or impersonates system/admin accounts for persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects process creations (EventID 4688) where the command line contains keywords indicative of loading or installing kernel modules or drivers. This activity can be associated with privilege escalation or persistence techniques used by adversaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects an unusually high volume of SharePoint sharing invitation creations or sharing setting modifications by a single user within an hour. This could indicate an attacker attempting to exfiltrate data or broadly share sensitive information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects an unusually high volume of file sharing events from a single user in OneDrive within a one-hour window. Specifically, it looks for five or more 'SharingSet' or 'AnonymousLinkCreated' operations by the same UserId within an hour, which could indicate data exfiltration or unauthorized sharing.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects Terminal commands downloading remote content via curl and immediately piping it into bash or zsh, a common ClickFix execution pattern.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects creation or modification of LaunchAgent plist files used for persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects use of screencapture -x, which suppresses the camera shutter sound and has been observed in ClickFix-delivered malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects potential persistence mechanisms associated with Microsoft Outlook, specifically targeting registry modifications related to Outlook security settings or suspicious child processes (cmd.exe or powershell.exe) spawned by outlook.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003