avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,978 views

8,664 detections

Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
307
This rule monitors network logs (from proxies and firewalls) for web traffic (HTTP GET requests) containing suspicious JavaScript code injection patterns in the request context or message fields. It specifically looks for common XSS indicators such as <script tags, eval(), document.write(), fromCharCode(), and atob().
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
107
This rule detects process execution where the command line arguments contain keywords commonly associated with memory corruption and exploitation (e.g., shellcode, buffer overflow, heap/stack manipulation). The rule further filters for small executable files (less than 100KB) to increase the likelihood of identifying malicious tools or stagers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects network traffic associated with known Cobalt Strike Beacon request URI patterns. This rule utilizes network signature inspection to flag outbound connections containing URI fragments commonly used by Cobalt Strike default profiles.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects the execution of Mimikatz or its common command-line arguments used for credential dumping. This rule identifies attempts to extract sensitive authentication material such as passwords, hashes, and tickets from memory (LSASS), SAM database, LSA secrets, and cached domain credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the creation or execution of files named 'RuntimeBroker.exe', 'Telemetry.exe', or 'WindowsRunetimeBroker.exe' within the AppData folders. These filenames are commonly abused by adversaries to masquerade as legitimate system processes to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects anomalous network connections or DNS queries to known Ethereum RPC infrastructure providers (Infura, Alchemy, Cloudflare-eth) or ports/domains associated with Ethereum mainnet activity. It specifically targets processes other than common browsers or known blockchain clients, as well as Java-based processes performing DNS lookups for these domains. This behavior is indicative of potential 'EtherHiding' techniques where malicious code or data is hidden within blockchain transactions or distributed via blockchain infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the creation or execution of files named 'RuntimeBroker.exe', 'Telemetry.exe', or 'WindowsRunetimeBroker.exe' within the AppData folders. These filenames are commonly abused by adversaries to masquerade as legitimate system processes to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects suspicious usage of the Bun runtime, specifically when it is spawned by common Node.js development processes (like npm or node-gyp) or downloaded from non-official sources using command-line tools or browsers. This behavior is associated with the Miasma malware campaign, which abuses the Bun runtime for malicious operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003