avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,004 views

8,664 detections

Detects browser processes connecting to internal IP addresses followed by a connection to an external (non-whitelisted) destination within a 2-minute window. This behavior is indicative of potential data staging or exfiltration, where a web browser is used to access internal resources before transferring data to an external site.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects clipboard access operations (Read/Write) initiated by common web browsers (Chrome, Edge, Brave, Electron-based apps) when running with specific command-line arguments typically associated with renderer or extension processes. This can indicate malicious code or browser extensions attempting to monitor or steal sensitive clipboard content.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unexpected crashes of critical macOS system processes such as sharingd, nsurlsessiond, airplayd, AirPlayXPCHelper, and NetAuthSysAgent. Frequent crashing of these components can indicate instability or potentially malicious attempts to interfere with system services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-frequency access to sensitive web paths (e.g., /admin, /vault, /credentials) from common web browsers on a device. This activity may indicate malicious credential harvesting, administrative panel enumeration, or sensitive data exfiltration performed by an adversary or malicious browser extension.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects browser processes connecting to internal IP addresses followed by a connection to an external (non-whitelisted) destination within a 2-minute window. This behavior is indicative of potential data staging or exfiltration, where a web browser is used to access internal resources before transferring data to an external site.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects NTLM-authenticated network logons (Logon Type 3) originating from loopback IP addresses (127.0.0.1, ::1, or 0.0.0.0). This behavior is often associated with NTLM relay attacks or credential reflection bypass techniques where an adversary forces a local service to authenticate to itself to gain unauthorized access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects a multi-stage attack pattern associated with the Qilin ransomware, beginning with suspicious VPN authentication (potential credential stuffing or bypass), moving through lateral movement attempts (SMB/RDP/WMI), and culminating in ransomware behaviors such as shadow copy deletion, mass file encryption, and ransom note creation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
207
Detects instances where privileged system processes such as lsass.exe or svchost.exe attempt a network connection to the local loopback address on ports other than standard SMB ports (445, 139). This pattern is indicative of potential coercion or relay attacks, specifically targeting the authentication mechanisms of these services to an attacker-controlled SMB server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of Python-based SMB server implementations commonly associated with the Impacket toolset. Impacket is frequently used by attackers to facilitate lateral movement, credential relay, and remote file manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002