avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,006 views

8,664 detections

Detects execution of the Microsoft .NET installer utility (InstallUtil.exe) from non-standard locations. Adversaries often abuse InstallUtil.exe as a proxy to execute malicious code or bypass application control policies, as it is a trusted, digitally signed Microsoft binary. The rule filters out legitimate execution paths typically associated with .NET framework installations, SDKs, or system directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects AppDomainManager injection attempts by monitoring for the loading of suspicious DLLs (related to AppDomainManager functionality) by specific processes or from unexpected file paths. The rule specifically targets attempts to hijack the .NET AppDomainManager class by checking against known suspicious filenames and excluding legitimate .NET framework directories, which is a common technique used for arbitrary code execution in the context of a target process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects anomalous network communication patterns and file system changes indicative of SoftEther VPN usage, particularly when linked to processes masquerading as VMware or communicating with known malicious C2 infrastructure. The rule monitors for network connections on common SoftEther ports, connections to specific command-and-control IP addresses, and the creation of SoftEther configuration files like 'hamcore.se2' or 'vpn_bridge.config'.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of Kubernetes pods where the 'hostPID' or 'hostNetwork' settings are enabled. These configurations allow a pod to share the host's process namespace or network stack, respectively, which are common vectors for container escapes and host-level privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential unauthorized access to Azure Storage Blobs following the retrieval of storage account access keys. It correlates 'ListKeys' API events with subsequent blob access activities from either unrecognized IP addresses or via Shared Access Signature (SAS) tokens, indicating potential credential misuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects the creation or registration of scheduled tasks that involve the 'PerfWatson2.exe' utility or execution paths originating from within the local AppData directory. These patterns are often associated with persistence mechanisms used by malware or malicious scripts to maintain execution after reboots.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where common web server processes initiate command interpreters or system utilities. This behavior is a common indicator of web shell execution, where an adversary uses a web application vulnerability to gain remote code execution on the underlying server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1502
Detects various techniques used by an attacker to escape a container environment or gain unauthorized access to host-level resources. This includes the execution of namespace manipulation tools (nsenter, unshare, chroot), unauthorized access to the docker.sock Unix socket, mounting of host filesystems from within a container, and direct attempts to access the host's /proc/1 namespace files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects common lateral movement patterns associated with Pass-the-Hash (PtH) attacks, specifically identifying remote execution via WMI/services, the use of explicit credentials in management utilities (wmic/net), and suspicious network connections from known administration tools over lateral movement ports.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202