avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,004 views

8,664 detections

Detects the execution of 'runas.exe' with the '/savecred' or '/netonly' parameters. The '/savecred' parameter allows the use of credentials previously stored in the credential manager, while '/netonly' allows the use of credentials for remote network resources without authenticating locally. Both flags can be abused by adversaries to persist or move laterally with compromised or cached credentials while evading local authentication monitoring. The rule excludes common system-signed processes originating from the Windows System32 directory.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the creation of a Windows service where the service type is set to 'kernel' via the sc.exe command-line utility. This behavior is indicative of an attempt to load a kernel driver or perform low-level system modifications, which is often used by rootkits or malicious drivers. The rule filters out known trusted publishers to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin, WMIC, or PowerShell. Attackers commonly perform this action to inhibit system recovery and prevent the restoration of data, often as a precursor or during the impact phase of ransomware attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the execution of PowerShell commands and scripts known to be used for Kerberoasting, a technique for obtaining TGS tickets that can be cracked offline to recover service account passwords. The rule matches specific tool names and command line flags associated with common offensive security tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of Microsoft Application Virtualization Injector (mavinject.exe) with the '/injectrunning' command-line argument. This utility is frequently abused by adversaries to inject malicious DLLs into target processes, facilitating arbitrary code execution while potentially bypassing security detections due to the binary's legitimate provenance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects network activity initiated by the TukTuk malware to communicate with Arweave public gateways (arweave.net and g8way.io), which are utilized as dead-drop resolvers for C2 infrastructure resolution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects DNS queries for domains ending in '.trycloudflare.com', which are commonly used to establish unauthorized remote access tunnels (Cloudflare Tunnel) by threat actors for C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects HTTP PUT requests directed at Wasabi Cloud Storage domains that originate from an Rclone user agent. This pattern is commonly indicative of data exfiltration activities where an attacker uses the Rclone utility to synchronize or upload sensitive data to unauthorized cloud storage.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects HTTP POST requests targeting Cisco Firepower Management Center (FMC) that contain Java exploitation patterns (Runtime.getRuntime or ProcessBuilder) associated with the exploitation of CVE-2026-20131. This activity is indicative of an attempt to achieve Remote Code Execution (RCE) on the FMC appliance, likely by an actor utilizing the Interlock Ransomware threat.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network activity initiated by the TukTuk malware to communicate with Arweave public gateways (arweave.net and g8way.io), which are utilized as dead-drop resolvers for C2 infrastructure resolution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102