avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,997 views

8,664 detections

Detects instances where the Windows script hosts wscript.exe or cscript.exe establish outbound network connections to common web ports (HTTP/HTTPS) on external IP addresses. This behavior is frequently associated with script-based malware, droppers, or C2 beacons.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances of rundll32.exe being used to load DLL, OCX, or CPL files from suspicious locations such as user-writable directories (Temp, AppData, Downloads, etc.) or UNC paths. This behavior is indicative of an adversary attempting to execute malicious code using a trusted Windows system binary (LOLBin).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Monitors GitHub audit logs for suspicious or high-risk activities within CI/CD pipelines, including actions triggered by forks, workflow approvals, branch policy overrides, self-hosted runner registration, and sensitive secret access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
007
Detects abnormally long DNS queries characterized by repetitive alphanumeric patterns, which may indicate potential DNS tunneling activity used for C2 communication or data exfiltration. The rule flags DNS requests exceeding 60 characters with repeating label structures.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the creation of a scheduled task via schtasks.exe that executes a command interpreter or script engine (e.g., PowerShell, cmd, wscript) where the parent process is not signed by Microsoft. This behavior is often associated with the execution of malicious payloads, persistence mechanisms, or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
005
Monitors IIS web servers for signs of potential exploitation by tracking suspicious child processes spawned by worker processes (w3wp.exe/iisexpress.exe), tracking unexpected WER (Windows Error Reporting) crashes associated with IIS workers, aggregating IIS-related application crashes, and detecting anomalous W3C IIS log request patterns (e.g., malformed content-length, negative bytes, or suspicious URI characteristics).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
107
Detects the execution of mshta.exe with command-line arguments that include remote protocols (http/https) or scripts (javascript/vbscript). This behavior is commonly associated with fileless malware execution and proxying malicious code via a trusted Windows binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects path traversal attempts in web server access logs by searching for dot-dot-slash (../), dot-dot-backslash (..\), or their URL-encoded equivalents (..). These patterns are indicative of efforts to access files or directories outside the intended web root.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule identifies network connections (DNS queries, HTTPS/WebSocket traffic) directed toward known suspicious domains associated with potentially malicious C2 infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects potential persistence attempts via WMI event subscriptions. The rule monitors for the creation of WMI event consumers using 'wmic.exe' with suspicious command line arguments, or the use of 'mofcomp.exe' to compile MOF files by non-standard, non-Microsoft signed processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003