avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views

8,664 detections

This rule detects scenarios where a common web browser (Chrome, Firefox, Edge, IE, Opera, or Brave) connects to an external destination not on a known allow-list, followed shortly (within 30 seconds) by the execution of a script-based binary (wscript.exe or mshta.exe) on the same host. This is a common pattern for initial access where a user downloads a malicious script from an unknown source via a browser and subsequently executes it.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potentially malicious use of the ClickOnce process (dfsvc.exe) by monitoring for suspicious parent processes (such as rundll32.exe or mshta.exe) spawning dfsvc.exe, or dfsvc.exe spawning unexpected child processes. ClickOnce is often abused by attackers to proxy the execution of malicious code, and these patterns are indicative of such activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
107
Detects an unusually high frequency of storage blob and container listing operations within a short time window. This behavior often indicates an attempt to enumerate the contents of Azure Blob Storage, which may be a precursor to data discovery or exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
This rule detects when the Windows Security Event Log has been cleared, which is often an indicator that an adversary is attempting to hide their tracks and remove evidence of unauthorized activities on a system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects rapid creation of multiple user accounts within a one-hour window. This behavior can be indicative of malicious activity, such as an attacker creating persistence accounts or staging multiple accounts for lateral movement or automated attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where a user account is created and subsequently deleted within 24 hours. This behavior may indicate an adversary creating a temporary account for lateral movement, privilege escalation, or establishing persistence that is intended to be short-lived.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential brute force attacks or username enumeration by identifying 5-minute windows where multiple distinct user accounts trigger a high volume of failed logon events (Event ID 4625). It summarizes failures by timeframe and flags scenarios where more than 5 unique usernames failed to authenticate, categorizing the severity based on the number of accounts affected.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high volumes of authentication failures (EventID 4625) using sub-status 0xC0000064, which indicates the attempted username does not exist. A high frequency of these events targeting multiple non-existent accounts is a strong indicator of automated username enumeration or credential stuffing.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects cases where a user privilege is granted (EventCode 4717) and subsequently revoked (EventCode 4718) within a 60-minute window. This behavior often indicates transient privilege abuse, where an attacker grants themselves temporary elevated rights to perform an action and then revokes them to evade detection or minimize their footprint.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects processes other than standard web browsers (Chrome, Edge, Brave) attempting to access sensitive directories within Chrome extension user data paths, such as IndexedDB, Local Storage, or Sync Data. Such activity is often indicative of credential or session cookie theft by malicious scripts or malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002