avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,978 views

8,664 detections

Detects instances where package managers like npm, pip, or python execute shells or scripting interpreters with command-line arguments indicative of software installation or build processes. This pattern is common in supply chain attacks where malicious packages run code during their installation phase.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential internal network reconnaissance activities by monitoring for either mass execution of network discovery commands (such as 'net view' or 'net share') targeting multiple unique hosts within a 5-minute window, or by monitoring for mass outbound network connections to port 445 (SMB) across multiple unique destination hosts within the same timeframe. This behavior is indicative of an attacker attempting to map available network shares or identify reachable systems for lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation or manipulation of WMI event subscriptions using wmic.exe, powershell.exe, or mofcomp.exe. These tools are commonly abused by adversaries to establish persistence by triggering malicious code execution via WMI event filters, consumers, and bindings.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects high-frequency non-standard process executions involving WMI queries that specifically target virtual environment artifacts (e.g., VMware, VirtualBox, VBoxService, QEMU). This behavior is characteristic of sandbox or virtualization evasion, where malware attempts to identify if it is running in a virtualized or analysis environment to potentially alter its behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high frequency administrative modifications, such as user creation/deletion, password resets, or group membership changes, performed by service accounts associated with Azure AD Connect or Microsoft Entra Connect. This behavior may indicate account compromise where a service principal is being abused to perform bulk identity management operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects rapid succession of power-off, suspend, or destroy operations on virtual machines via esxcli or vim-cmd following an SSH login, a behavior pattern often associated with ESXi ransomware activity (e.g., Qilin).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects execution of the Microsoft InstallUtil.exe utility with suspicious command-line arguments (logging suppressed to file and console) where the binary is unsigned. This is a common technique used by adversaries to proxy execution of arbitrary .NET code while attempting to avoid detection and maintain stealth.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of known Active Directory discovery tools, specifically 'adfind.exe' or 'dsquery.exe' with arguments targeting user or group enumeration. These tools are commonly used by adversaries during the reconnaissance phase to map domain structure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
macOS malware used by JINX-0164 against cryptocurrency developers
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002