avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,999 views

8,664 detections

This rule detects when a process's command line contains 'ssl' or 'tls' and is observed at least 3 times within an hour on the same computer and by the same account. This could indicate various activities, including legitimate system processes, development activities, or potentially malicious use of SSL/TLS-related tools or scripts. The rule focuses on process creation events (EventID 4688) and analyzes the command line arguments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects when five or more driver-related files (.inf, .sys, or .drv) are created or modified within a one-hour window by the same initiating process account. This behavior can be indicative of malicious driver installation, rootkit activity, or other forms of persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of files containing keywords such as 'vulnerability', 'assessment', or 'scan'. This rule aims to identify activities related to vulnerability scanning or security assessments being performed on a system, potentially indicating reconnaissance or unauthorized activity. The events are summarized by the initiating process account name and time to help identify the source of these activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects an unusual number of file creations or modifications where the filename contains keywords like 'patch', 'update', or 'fix' by a single account within a one-hour window. This could indicate an automated patching process, software deployment, or potentially malicious activity attempting to modify system files under the guise of an update.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects a high volume (5 or more within an hour) of process creation events where the command line contains keywords associated with remote access protocols like DCOM, WMI, or RPC. This could indicate an adversary utilizing these protocols for lateral movement or remote execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects a high frequency (3 or more within an hour) of command-line executions containing keywords like 'antivirus', 'defense', or 'endpoint' on a Windows system. This activity could indicate an adversary attempting to interact with, disable, or tamper with security software to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin, WMIC, or PowerShell. Attackers commonly perform this action to inhibit system recovery and prevent the restoration of data, often as a precursor or during the impact phase of ransomware attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the use of wmic.exe to execute remote commands using the /node flag and the 'process call create' command string. This pattern is commonly used by adversaries for lateral movement and remote code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the execution of Microsoft Application Virtualization Injector (mavinject.exe) with the '/injectrunning' command-line argument. This utility is frequently abused by adversaries to inject malicious DLLs into target processes, facilitating arbitrary code execution while potentially bypassing security detections due to the binary's legitimate provenance.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where Microsoft Teams (teams.exe) initiates child processes that are commonly used as interpreters, such as cmd.exe, powershell.exe, mshta.exe, wscript.exe, or rundll32.exe. This activity is frequently associated with the execution of malicious payloads delivered via phishing or collaboration platforms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002