avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,978 views

8,664 detections

Detects the execution of wscript.exe, msiexec.exe, or cmd.exe initiated with command lines pointing to script files (.js, .vbs) or shortcut files (.lnk) located on removable drives (d-z drive letters). This behavior is characteristic of the Raspberry Robin worm spreading via infected USB media.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potentially malicious activity within Linux environments or containers where a single user context concurrently performs credential hunting (via environment variable dumping or accessing .env files) and terminates processes associated with known cryptocurrency miners or competing malicious actors. This behavior is highly indicative of a cryptojacking infection or a malicious actor clearing out existing resource-hijacking threats.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of PowerShell or pwsh that originates from an interactive parent process like explorer.exe or cmd.exe. The rule identifies suspicious command-line patterns containing 'IEX', 'Invoke-Expression', 'Invoke-WebRequest', 'iwr', or 'IRm', while excluding encoded commands, which is indicative of potential malicious clipboard-paste activity or manual attacker intervention.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where AutoHotkey scripts launch Microsoft Edge or Google Chrome in headless mode. This behavior is indicative of automated browser manipulation, often used in credential harvesting, session hijacking, or automated interaction with web-based platforms by malicious entities such as UNC6692.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential exploitation attempts targeting the BeyondTrust Privileged Remote Access API by identifying unauthenticated POST requests directed at specific sensitive API endpoints (e.g., /api/, /remote-support/). It flags high-frequency or multi-path request patterns indicative of automated vulnerability scanning or exploitation attempts related to CVE-2026-1731, where the absence of authorization headers is a key indicator of unauthorized access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-frequency S3 PutObject requests that utilize Customer-Provided Encryption Keys (SSE-C). A high count of such operations within a short window can be indicative of ransomware activity, where an adversary encrypts data within the victim's cloud storage using their own keys to prevent access by the owner.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
202
Detects HTTP requests where the URI or request body contains indicators of internal network references (e.g., localhost, 127.0.0.1, or RFC 1918 private IP address ranges). This pattern is consistent with Server-Side Request Forgery (SSRF) attempts, where an attacker tries to force a vulnerable web application to perform unauthorized requests to internal resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects anomalous, high-volume DNS query activity where a process attempts to resolve 20 or more unique domains within a 2-minute window. The query patterns match strings that are 8-20 characters long with common top-level domains, excluding known web browsers and standard network diagnostic utilities. This behavior is indicative of malware using Domain Generation Algorithms (DGA) for command and control or secondary communication channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of executable files (.exe or .dll) on a removable drive followed by the execution of a process from that same drive within a 30-second window. This behavior is indicative of an adversary using removable media to stage and execute malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule identifies potentially malicious activity where a process, which has been dormant on the system for at least 7 days since its initial start, suddenly performs a high volume (more than 50 events in 60 seconds) of file creation or modification events. This behavior pattern is often indicative of ransomware encryption activities, where malware lies dormant before initiating a rapid, destructive encryption cycle.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002