avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,999 views

8,664 detections

This rule detects HTTP POST requests targeting Cisco Firepower Management Center (FMC) that contain Java exploitation patterns (Runtime.getRuntime or ProcessBuilder) associated with the exploitation of CVE-2026-20131. This activity is indicative of an attempt to achieve Remote Code Execution (RCE) on the FMC appliance, likely by an actor utilizing the Interlock Ransomware threat.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects modifications or creation of 'InprocServer32' registry keys within 'HKEY_CURRENT_USER\Software\Classes\CLSID'. This pattern is frequently used for COM hijacking to achieve persistence or execute arbitrary code when a COM object is invoked by an application or the OS.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule monitors DeviceNetworkEvents to identify processes that are not typically associated with cloud storage and synchronization software initiating network connections on port 443 to popular cloud providers (OneDrive, SharePoint, Dropbox). This behavior is often indicative of data exfiltration to cloud storage services or potential command and control communication disguised as web traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects modifications or creation of 'InprocServer32' registry keys within 'HKEY_CURRENT_USER\Software\Classes\CLSID'. This pattern is frequently used for COM hijacking to achieve persistence or execute arbitrary code when a COM object is invoked by an application or the OS.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule monitors DeviceNetworkEvents to identify processes that are not typically associated with cloud storage and synchronization software initiating network connections on port 443 to popular cloud providers (OneDrive, SharePoint, Dropbox). This behavior is often indicative of data exfiltration to cloud storage services or potential command and control communication disguised as web traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the use of the 'netsh interface portproxy' command to set up a port forwarding rule where the connection address is outside of common private IP ranges. This behavior is frequently associated with attackers establishing persistent network pivots or internal proxies to redirect C2 traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of rundll32.exe or regsvr32.exe as a child process of script interpreters like wscript.exe, cscript.exe, or mshta.exe. The command line parameters often involve potentially malicious paths (e.g., Temp, AppData, ProgramData, Users\Public) or the presence of DLL extensions, indicating potential proxy execution of malicious scripts or side-loaded libraries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1302
This rule detects modifications to sensitive Windows Registry keys under HKLM\SOFTWARE\Microsoft\Cryptography, such as Providers, OID, Trust, and Protectedroots. These keys control cryptographic services and trust stores on Windows systems. Modifications by non-system processes or accounts may indicate attempts to subvert trust controls, install rogue root certificates, or tamper with system-level security providers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the deletion of volume shadow copies using standard Windows utilities like vssadmin.exe or wmic.exe, combined with concurrent file activity in multiple directories, a behavior frequently observed during the impact phase of a ransomware attack (specifically associated with the Qilin ransomware family).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002