avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views

8,664 detections

This rule detects when processes other than standard web browsers (Chrome, Edge, Firefox, Brave, Opera) attempt to read sensitive browser data files such as 'Login Data', 'Cookies', or 'Web Data'. These files contain stored credentials and session information, and unauthorized access is a common technique used by credential-stealing malware to exfiltrate sensitive user information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the creation of large archive files (.zip, .7z, .rar, .tar) exceeding 100MB within sensitive or high-risk directory paths such as Desktop, Temp, or AppData, or on non-system drives. This behavior is often associated with the staging of sensitive data for exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule identifies instances of PowerShell executing with an encoded command followed immediately (within 300 seconds) by an outbound network connection to a non-standard port or non-internal IP address. This behavior is indicative of a remote access tool or reverse shell establishing command and control (C2) communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
This rule monitors for scenarios where a DLL is created and subsequently loaded by a process within a short time frame (60 seconds or less). The rule specifically excludes files located in 'C:\Windows\' and 'C:\Program Files\' to minimize noise, focusing on suspicious modules originating from user-writable or unexpected locations, which is a common behavior of malware or side-loading attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the loading of system drivers (.sys files) that are either unsigned or have an invalid digital signature. The rule excludes drivers loaded from common Windows system directories to minimize noise. This behavior is a common indicator of rootkit installation or the use of vulnerable drivers for kernel-mode exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of built-in Windows utilities (vssadmin, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or modify boot configuration settings to disable recovery features, which is a common precursor to ransomware encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential brute force attacks against Microsoft Exchange Outlook Web App (OWA) by monitoring for a high volume of 401 Unauthorized status codes from non-internal IP addresses. It also correlates these authentication events with subsequent post-authentication actions, specifically identifying mailbox logins followed by mailbox searching or export requests, which may indicate account compromise and unauthorized data collection or exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
This rule detects anomalous RDP (Logon Type 10) sessions occurring outside of typical business hours or from previously unseen geographic locations, followed closely by the execution of system discovery commands (net.exe, ipconfig.exe, whoami.exe, systeminfo.exe) within a 10-minute window. This behavior is indicative of post-exploitation reconnaissance following an unauthorized or suspicious remote access session.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects multiple failed SSL login attempts from a single source IP to a destination IP within a 24-hour period. A threshold of 10 failed attempts is used to identify potential brute-force attacks or credential stuffing against SSL-enabled services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule identifies if a given IP address falls within the known IP ranges used by Apple's iCloud Private Relay service. It retrieves a list of IPv4 and IPv6 ranges from a public GitHub repository and then checks if a specified IP address is contained within any of these ranges. This can be used to identify traffic potentially obfuscated by iCloud Private Relay.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002