avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,997 views

8,664 detections

Detects network connections from internal endpoints to Filen.io cloud storage domains and subdomains. The rule specifically flags interactions involving common API endpoints for file operations (upload, download, directory listing) as 'Critical' risk, while generic traffic to the domain is classified as 'High' risk.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects Microsoft Office applications spawning suspicious child processes (e.g., cmd.exe, rundll32.exe) or initiating network connections to WebDAV paths, which may indicate exploitation of ActiveX OLE auto-execution vulnerabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors for recurring application crashes involving 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. Frequent crashes of these components may indicate instability, misconfiguration, or an attempt to exploit vulnerabilities within these specific file sharing services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects browser processes connecting to internal IP addresses followed by a connection to an external (non-whitelisted) destination within a 2-minute window. This behavior is indicative of potential data staging or exfiltration, where a web browser is used to access internal resources before transferring data to an external site.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of the 'net.exe' or 'net1.exe' command-line utilities to mount a local SMB share using loopback addresses (127.0.0.1 or localhost) with the '/tcpport' argument. This pattern is indicative of attempts to exploit CVE-2026-24294 to bypass NTLM authentication protections through local reflection or relay attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of Python-based SMB server implementations commonly associated with the Impacket toolset. Impacket is frequently used by attackers to facilitate lateral movement, credential relay, and remote file manipulation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors DNS queries for potential exfiltration or C2 communication channels. It flags DNS queries that exceed 100 characters in length or contain labels with at least 30 alphanumeric characters, excluding activity from common web browsers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects when common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) load a DLL file from suspicious or user-writable locations such as AppData, Downloads, Documents, or Temp folders. The rule specifically alerts on DLLs that are unsigned or where the loading process itself is unsigned, which is a common indicator of side-loading or malicious library injection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002