avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,006 views

8,664 detections

Detects the use of net.exe or net1.exe to perform enumeration of local administrators or domain-level users and groups. This behavior is commonly associated with attackers attempting to map out the environment for privilege escalation or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects abnormal termination, crash, or error messages related to the 'sharingd' process on macOS. 'sharingd' is a daemon responsible for various sharing features including AirDrop, Handoff, and Instant Hotspot. Unexpected errors or crashes within this process may indicate service instability, potential exploitation attempts, or abnormal interactions with sharing services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects web traffic where the referrer header contains keywords associated with gaming or educational themes (such as 'bioshock', 'game', 'puzzle', 'math', 'quiz') combined with access attempts to sensitive URI paths (like '/code', '/token', '/secret', '/private', '/api-key') resulting in a redirect status (301-308). This behavior pattern is often indicative of automated reconnaissance or exploitation attempts using non-standard or obfuscated referrers to bypass simple security filters.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network connections originating from a process and directed towards the local loopback interface (127.0.0.1 or ::1) on non-privileged, non-SMB ports (>= 1024 and != 445). This pattern can identify inter-process communication (IPC) over local network sockets which may be used by malware or malicious scripts to bypass security controls or communicate with local services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where the Local Security Authority Subsystem Service (lsass.exe) initiates a network connection to the loopback address (127.0.0.1 or ::1), excluding standard SMB traffic (Port 445). Such behavior by LSASS is highly anomalous and may indicate exploitation attempts, such as memory dumping or credential harvesting techniques involving inter-process communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network logon events (Logon Type 3) using NTLM authentication where the source IP address is local (127.0.0.1 or ::1). This behavior can be indicative of attempts to interact with local services or perform lateral movement within the same host using credential-based techniques such as 'Pass-the-Hash' or unauthorized access to local resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects command-line activity indicative of the PetitPotam exploit or general EFSRPC (Encrypting File System Remote Protocol) coercion attempts. Adversaries use these techniques to force a machine to authenticate against another system (e.g., a domain controller), typically as a precursor to NTLM relay attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects WebSocket upgrade attempts to 'google-ai-labs-it.onrender.com', which is associated with the Turla group's STOCKSTAY malware C2 infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects HTTP response bodies containing common PE/Shellcode magic headers (MZ, PE, or NOP sleds) which are associated with the delivery of payloads designed to exploit or utilize the Windows KernelCallbackTable for process injection. The detection focuses on suspicious content delivered over HTTP connections.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects the abuse of MSBuild.exe to execute arbitrary code. The rule monitors for three primary suspicious behaviors: MSBuild spawning suspicious child processes indicative of inline task execution, MSBuild being launched with project file arguments from non-standard or untrusted parents, and MSBuild being launched without a project file (implying piped or inline payload delivery).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003