avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

This rule detects two suspicious behaviors associated with the TinyRCT malware family: the execution of common installer or archiver utilities in the Downloads folder that terminate within two seconds, and the use of 'choice.exe' for self-deletion of an executing process within a short timeframe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule monitors DeviceNetworkEvents for connections to domains that match naming patterns and TLDs frequently associated with the Ghostwriter/UNC1151 threat group. The rule specifically looks for URLs containing common credential-harvesting keywords (e.g., login, verify, account) combined with specific TLDs (e.g., .digital, .icu, .cc.cd). Connections to known common public DNS providers are excluded.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
403
Detects DNS queries and network connection attempts to a set of known malicious domains associated with the threat actor UNC1151 (Ghostwriter). This rule monitors both DNS resolutions and direct network connection attempts to these indicators of compromise (IOCs), which are commonly used in spearphishing campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects indicators of the KuinaExtractor infostealer, including specific named pipes/objects, the creation of a 'zenith_debug.txt' file in user profile directories, and the presence of build-related aliases ('kuina1999', 'k0to') in process command lines or file paths.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects browser-based network connections to URLs containing Google or Gmail branding where the resolved IP address does not match the expected Google IP address prefixes. This behavior is indicative of an Adversary-in-the-Middle (AiTM) phishing attack, where a user is being redirected to a malicious proxy server that mimics the legitimate Google login service to intercept credentials and MFA tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
303
This rule monitors DeviceNetworkEvents for connections to domains that match naming patterns and TLDs frequently associated with the Ghostwriter/UNC1151 threat group. The rule specifically looks for URLs containing common credential-harvesting keywords (e.g., login, verify, account) combined with specific TLDs (e.g., .digital, .icu, .cc.cd). Connections to known common public DNS providers are excluded.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects outbound network connections to common Mythic C2 ports initiated by processes identified as compiler-related binaries (Go, Zig, Rust) or binaries running from suspicious, user-writable directories (Temp, AppData, etc.). This behavior is consistent with the execution of staging or initial implants associated with the Mythic post-exploitation framework.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the KuinaExtractor UAC bypass technique, which exploits the auto-elevated 'SilentCleanup' scheduled task. The rule identifies suspicious activity via two patterns: the execution of 'cleanmgr.exe' from an unexpected parent process (bypassing normal task scheduler invocation) or the explicit execution of 'schtasks.exe' to trigger the 'SilentCleanup' task.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects attempts to disable or impair Microsoft Defender Antivirus using legitimate system administration tools such as PowerShell (Set-MpPreference, Add-MpPreference), WMIC, sc.exe, or net.exe. Adversaries may use these tools to bypass security controls by disabling real-time monitoring or adding unauthorized exclusion paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of RDP files (mstsc.exe) initiated by common application vectors (email clients, browsers, archive utilities) from suspicious user-writable paths like Temp, Downloads, or AppData directories. This behavior is consistent with Turla group's phishing delivery chain where malicious RDP files are used for persistence or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003