avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,963 views

8,664 detections

Detects potential credential harvesting attempts by monitoring for the usage of Windows credential management tools (cmdkey.exe and vaultcmd.exe) and the loading of sensitive DLLs (vaultcli.dll, dpapi.dll) by non-Microsoft signed processes, which is commonly used to access stored credentials in the Windows Vault or by DPAPI-protected stores.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects instances of PowerShell or PowerShell Core (pwsh) launched with encoded command line arguments (-encodedcommand, -enc, -ec). This is a common technique used by attackers to obfuscate malicious scripts and payloads by passing them as Base64 encoded strings to avoid simple static analysis.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects the execution of mavinject.exe with the /INJECTRUNNING command-line argument. This utility is a signed Microsoft binary that can be abused by adversaries to inject arbitrary DLLs into the address space of running processes, a technique often used to evade detection or achieve code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the use of nslookup.exe to query DNS TXT records from non-Microsoft signed processes. This behavior is often associated with DNS-based Command and Control (C2) channels or data exfiltration techniques where small amounts of data are encoded within DNS TXT records.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects Microsoft Office applications (Word, Excel, PowerPoint, OneNote) launching command-line interpreters (cmd.exe, powershell.exe, wscript.exe, cscript.exe). This pattern is often associated with macro-based malicious code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1804
This rule monitors for two types of anomalous network behavior: first, it identifies connections to known domains from IP addresses not previously associated with those domains over a seven-day lookback period. Second, it identifies HTTP proxy responses (from Zscaler or Squid) where the content-length significantly deviates from the historical baseline for specific URLs. These patterns are potential indicators of C2 channel shifts or data exfiltration via web protocols.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
109
Detects the creation or modification of Power Automate Flows that utilize non-Microsoft domains for HTTP or webhook connectors. Adversaries may abuse Power Automate to automate exfiltration or command-and-control tasks by connecting workflows to external malicious endpoints.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
604
Detects the successful deletion of diagnostic settings in Azure, which may be an attempt by an adversary to impair logging and hide malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects the creation or update of Azure Network Security Group (NSG) rules that allow inbound traffic from the entire internet (0.0.0.0/0 or *) to management ports (RDP 3389 or SSH 22). This behavior often indicates an attempt to expose administrative services to the public internet.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
404
Detects when a user or service principal is assigned the 'Owner' or 'Contributor' role at the Subscription scope in Azure. This activity is often associated with privilege escalation and persistent access techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
1204