avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,013 views

8,664 detections

Detects incoming network connections to Windows 'Nearby Share' process components from external (non-RFC1918) IP addresses. This activity is potentially malicious as legitimate 'Nearby Share' traffic should typically occur within local networks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potentially suspicious process activity where unknown or infrequently seen processes spawn common script interpreters such as cmd.exe, powershell.exe, wscript.exe, or others. This behavior often indicates an attempt to execute malicious commands or scripts as part of a post-exploitation or persistence mechanism.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where Windows Nearby Sharing related processes (quick_share.exe, NearbyShare.exe, nearby_sharing.exe) spawn command-line interpreters (cmd.exe, powershell.exe). This pattern is anomalous as these utilities are intended for file transfer, not command execution, and could indicate exploitation of these applications to achieve code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects DNS queries to GitHub API domains originating from non-standard or potentially spoofed process names associated with various AI tools, which may indicate data exfiltration or unauthorized interaction with repositories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unexpected registry modifications (creation, deletion, or modification) performed by processes associated with 'Nearby Share' (quick_share.exe, nearby_sharing.exe). Legitimate registry activity related to Google Nearby Share or Windows native Nearby Sharing is excluded from this alert.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects incoming network connections to Windows 'Nearby Share' process components from external (non-RFC1918) IP addresses. This activity is potentially malicious as legitimate 'Nearby Share' traffic should typically occur within local networks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects network connection attempts directed toward RFC 1918 private IP address spaces (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and localhost (127.0.0.0/8) that do not involve common Windows file sharing ports (TCP/445 and TCP/139). This behavior may indicate lateral movement, internal reconnaissance, or the use of non-standard protocols for internal communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-volume outbound network connections (exceeding 10MB) originating from processes associated with AI-driven chatbot or productivity applications (e.g., ChatGPT, Perplexity). This rule identifies potential data exfiltration occurring over legitimate, expected software channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances of PowerShell or PowerShell Core (pwsh) launched with encoded command line arguments (-encodedcommand, -enc, -ec). This is a common technique used by attackers to obfuscate malicious scripts and payloads by passing them as Base64 encoded strings to avoid simple static analysis.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances where the Windows Management Instrumentation service (WmiPrvSE.exe) or command-line tool (wmic.exe) initiates potentially suspicious child processes, often indicative of lateral movement or remote command execution via WMI.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003