avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

Detects instances where msbuild.exe is used to execute project files (.proj) from suspicious or uncommon directories. Adversaries may abuse MSBuild to proxy execution of malicious code, often placing these project files in temporary or public user directories to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of SyncAppvPublishingServer.vbs via wscript.exe or cscript.exe. This legitimate Windows script can be abused by adversaries to proxy execution of malicious PowerShell commands, bypassing execution restrictions and evading defensive measures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the presence of known malicious drivers (hlpdrv.sys, rwdrv.sys) by their SHA256 hash or file path. It also identifies attempts to install these drivers via service creation commands and monitors for modifications to Windows Defender registry keys that could disable its functionality, indicating defense evasion.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potential persistence mechanisms related to browser extensions. It looks for processes launching Chrome or Edge with the '--load-extension' command-line argument, which can be used to load unpacked extensions. Additionally, it monitors registry modifications to 'ExtensionInstallForcelist' that contain 'http' or 'crx', indicating a forced installation of an extension, potentially from a remote source or a local file.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects potential discovery activities indicative of a virtual machine or virtualization environment enumeration. It monitors for the execution of wmic.exe or powershell.exe triggered by suspicious parent processes (python.exe, chost.exe) that query hardware-specific identifiers like Manufacturer, Model, or MAC Address using Win32_ComputerSystem or Win32_NetworkAdapterConfiguration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the creation or modification of specific suspicious .pyd files (Python extension modules) within temporary directory paths, excluding legitimate processes or publishers associated with Python Software Foundation or Microsoft Corporation. This behavior is indicative of potential side-loading or persistence mechanisms involving malicious Python extensions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects instances where a guest user or an external account (identified by the #EXT# suffix) performs an operation to add a new member to a Microsoft 365 Group. This behavior can be indicative of a guest account being compromised or misused to escalate privileges or gain unauthorized access by modifying group memberships.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
303
Detects the creation of .ics calendar invitation files in common user download and temporary directories when originated by web browsers or Microsoft Outlook. This pattern is often indicative of spearphishing campaigns where attackers use weaponized calendar files to deliver malicious payloads or links, attempting to exploit users through social engineering.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances where a user successfully authenticates from geographically distant locations within a short timeframe (impossible travel) followed by sensitive privileged operations within a 4-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
108
Detects the transmission of potential sensitive information, such as passwords, tokens, API keys, or private keys, within Microsoft Teams chat messages by matching message content against a regular expression pattern for common credential formats.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
707