avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,987 views

8,664 detections

This rule detects suspicious remote thread creation events (Sysmon Event ID 8) where a process initiates a thread in high-value system processes like lsass.exe, svchost.exe, explorer.exe, or winlogon.exe. It specifically filters out activity originating from common Windows system directories, highlighting potential process injection attempts by unauthorized binaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects a suspicious spike in Microsoft Teams external meeting or chat invitations directed at a single user within a 30-minute window. This behavior is consistent with UNC6692 tactics, where attackers impersonate internal IT helpdesk staff via Teams to perform vishing and social engineering attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects network connections to known cloud storage, file hosting, and webhook services (Discord, Pastebin, Dropbox, Telegram, AnonFiles) initiated by processes other than standard web browsers. Such behavior is often indicative of data exfiltration or C2 activity using legitimate web services to blend in with normal traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects rapid succession of MFA authentication requests originating from multiple distinct countries within a 10-minute window, a common pattern indicating an MFA fatigue (push bombing) attack targeting a specific user.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects modifications to Azure AD/Entra ID application configurations, specifically updating the 'RedirectUri' or 'ReplyUrls' to point to potentially external or unauthorized domains. This technique is often used in OAuth-based application-consent phishing campaigns to redirect authorization codes to adversary-controlled servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation or modification of the VbaProject.OTM file, which stores VBA macros for Microsoft Outlook, by a process other than the Outlook application (OUTLOOK.EXE). This is a common technique used to deploy malicious macros for persistence or code execution within the Outlook environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects activities associated with the NotDoor malware used by APT28 for email-based exfiltration. It specifically monitors for the creation of staging files in temporary directories, the use of Outlook.exe to establish external SMTP connections on common mail ports, and the transmission of emails to known adversary-controlled addresses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the creation of a scheduled task named 'OneDriveHealth', which is associated with APT28 activity. This task is used for persistence via COM hijacking; it executes 60 seconds after registration, kills and restarts explorer.exe to facilitate the loading of a hijacked COM object, and subsequently removes itself.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103