avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,004 views

8,664 detections

Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to download files from common public file sharing and code repository sites, which is a known technique for adversaries to stage or download malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects successful authentication attempts directed at network devices from sources not explicitly marked as authorized management systems. It identifies users or systems that are not recognized service accounts authenticating against network infrastructure and flags activity that involves multiple unique destination targets as high risk.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the creation or modification of inbox rules in Office 365 that involve email forwarding or redirection to external domains. It calculates a risk score based on whether the action occurred outside of typical business hours (08:00-18:00 local time/weekends) and whether the user is performing this action from a previously unseen IP address, which may indicate a compromised account attempting to exfiltrate or redirect emails.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
This rule detects potential lateral movement by identifying users who, within a short timeframe (90 seconds) of their first recorded network logon (EventID 4624, Logon Type 3), perform suspicious follow-up activities such as explicit credentials usage (4648), network share access (5140), or remote service installation (7045).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects potential execution of a Tox ransomware negotiation channel by monitoring for processes that exhibit a high rate of file writes (potential encryption activity) in conjunction with command-line arguments containing specific patterns such as a 76-character string or the 'tox://' URI scheme, which are associated with Tox ransomware client activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of legitimate Windows binaries (Certutil and BITSAdmin) to communicate with external, non-Microsoft IP addresses, which is indicative of potential tool downloading or data exfiltration. The rule explicitly filters out known Microsoft update domains to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of known archive utilities (e.g., 7-Zip, WinRAR) when interacting with sensitive user or system directories. This behavior is often indicative of data staging prior to potential exfiltration, especially when the originating process is not a recognized installer or backup application.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects potentially unauthorized or suspicious Remote Desktop Protocol (RDP) activity by monitoring for instances of 'mstsc.exe' initiated with specific command-line arguments, or identifying child processes spawned by RDP-related binaries ('mstsc.exe', 'rdpclip.exe') that are not typically associated with standard RDP functionality.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects network connections to Filen.io cloud storage initiated by processes other than common web browsers. This behavior is often associated with the use of command-line tools or scripts for unauthorized file exfiltration or data staging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high volumes of file operations (creation, rename, or modification) where files are given extensions typically associated with ransomware (e.g., .locked, .encrypted). The rule aggregates activity by process and endpoint and triggers an alert when the number of such operations exceeds a defined threshold, while excluding known legitimate backup and security software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003