avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,986 views

8,664 detections

This rule detects the presence of known malicious drivers (hlpdrv.sys, rwdrv.sys) by their SHA256 hash or file path. It also identifies attempts to install these drivers via service creation commands and monitors for modifications to Windows Defender registry keys that could disable its functionality, indicating defense evasion.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects an unusually high number of outbound network connections originating from the Local Security Authority Subsystem Service (LSASS) process on a Windows machine. LSASS is a critical system process responsible for enforcing security policy on the system, including user authentication, and typically does not initiate a large number of outbound connections. A high count of outbound connections from LSASS could indicate credential dumping activity, where an attacker is exfiltrating harvested credentials, or other malicious activity compromising the LSASS process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
Detects attempts to read the memory of browser processes (Chrome, Edge, Firefox, Brave, Opera). This activity can be indicative of credential dumping or other forms of data exfiltration from web browsers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential persistence mechanisms related to browser extensions. It looks for processes launching Chrome or Edge with the '--load-extension' command-line argument, which can be used to load unpacked extensions. Additionally, it monitors registry modifications to 'ExtensionInstallForcelist' that contain 'http' or 'crx', indicating a forced installation of an extension, potentially from a remote source or a local file.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of an MSI (Microsoft Installer) file on a device where the file's origin referrer URL indicates it was downloaded from a ZIP archive that was originally an email attachment. This could indicate a user opening a malicious ZIP file from an email, leading to the execution of an installer.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
A detection triggered on endpoint events where common system binaries (e.g., mshta.exe, powershell.exe, cmd.exe) were launched by user-facing parent processes (explorer.exe, chrome.exe, msedge.exe, firefox.exe, iexplore.exe) and executed suspicious command-lines. The pattern matches the evolving technique used in ClickFix-style campaigns whereby malicious pages dynamically place payloads into the clipboard and prompt users to paste or execute them.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects network connections or URL click events to a list of domains known to be associated with phishing or malware distribution. The rule specifically looks for connections to these domains that also contain certain path segments like '/wlc/', '/load/', or '/success/', which are often indicative of malicious activity or payload delivery. It also broadly checks for any URL click events containing these suspicious domains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
402
This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects network connections to specific deep link patterns associated with messaging applications like Telegram, WhatsApp, and Signal. Such deep links can be used in phishing attempts or to initiate actions on a user's device through these applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects network connections to a predefined list of known Microstealer malicious domains. These domains are often associated with malware command and control (C2) infrastructure, phishing, or other malicious activities. Monitoring connections to such domains can help identify compromised systems or active malware infections.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002