avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,981 views

8,664 detections

Detects the China Chopper web shell spawning CMD from IIS (w3wp.exe) with suspicious command line patterns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the execution of mshta.exe with command-line arguments that indicate the execution of JavaScript or VBScript code, often used for malicious purposes such as bypassing application whitelisting or executing remote code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects the execution of cmstp.exe with the '/s' flag, which indicates a silent installation. This behavior is often abused by adversaries to proxy execution of malicious code, bypass application control, or bypass User Account Control (UAC).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects multiple unauthorized access attempts to files identified as machine learning models, weights, or checkpoints. It specifically looks for Security Event ID 4656 (Auditing of object access) where the object name contains keywords like 'model', 'weights', or 'checkpoint', and the access mask indicates unauthorized access attempts (0x0001 for ReadData or ListDirectory, 0x0002 for WriteData or AddFile). The rule then summarizes these attempts by user, computer, and hour, triggering an alert if 5 or more attempts are made within an hour.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
This rule detects potential data poisoning attacks targeting machine learning models by monitoring Windows Security Event ID 4688 (a process was created) for command-line activity containing keywords indicative of model training or dataset modification, combined with terms suggesting malicious intent like 'corrupted', 'poison', or 'injection'. It aims to identify attempts to manipulate or compromise ML models through their training data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
502
This rule detects emails containing macro-enabled documents (.docm, .xlsm, .pptm). It specifically looks for instances where a sender sends two or more such emails within an hour, which could indicate a targeted phishing attempt using malicious macros.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects suspicious emails with attachments originating from external senders, characterized by urgent or action-oriented subject lines, and sent in bulk (5 or more emails within an hour). This pattern is indicative of phishing attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential 'reply-all' storm attacks or malicious mass emails sent to large distribution lists within the organization. It identifies emails sent to 50 or more recipients where the subject line contains phrases like 'reply all' or 'all members', originating from an internal company domain. The rule then counts such broadcast emails within one-hour bins to identify unusual activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects repeated access attempts (3 or more within an hour) to critical credential storage processes or files, specifically lsass.exe, the Security Account Manager (SAM) database, or the NTDS.dit file. Such activity is indicative of credential theft attempts by an adversary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential lateral movement activities by monitoring for the execution of 'psexec', 'wmiexec', or 'schtasks' commands within a short timeframe on the same computer. A count of 2 or more such command executions within an hour is flagged as suspicious, indicating potential adversary activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202