avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes52,013 views

8,664 detections

Detects potential PrintNightmare or Print Spooler exploitation by monitoring for the spoolsv.exe service spawning suspicious child processes (e.g., cmd, powershell, rundll32) and unauthorized files being dropped into the printer driver directory.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
This rule detects the creation of scheduled tasks using the 'schtasks.exe' utility with command-line arguments indicating persistence triggers ('onlogon', 'onstart') or elevation to the 'SYSTEM' account. Adversaries commonly use these methods to ensure malicious code executes automatically upon system startup or with high privileges to facilitate further exploitation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors for potentially malicious use of the Windows Certutil utility, specifically targeting the -urlcache (often used to download remote files) and -decode (used to decode hidden or obfuscated payloads) command-line arguments. It filters out common trusted processes like Microsoft's msiexec.exe to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate background data transfer jobs pointing to non-Microsoft or non-Windows Update domains. This technique is commonly used by adversaries for C2 communication or to download malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
Detects common reconnaissance activities using built-in Windows utilities to enumerate domain users, domain groups, and local administrators, as well as LDAP enumeration using dsquery and dsget.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the execution of PowerShell with encoded commands that include signs of web-based downloads or unusually long payloads, which are often used to hide malicious scripts or execute stagers. The rule filters out trusted signers and common administrative management tools to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects evidence of file timestomping, a technique used by attackers to modify file system timestamps (Create, Access, Modify, Change) to evade forensic detection or masquerade malicious files. The rule monitors for explicit usage of timestomping tools (e.g., Invoke-TimeStomp), abuse of system utilities like fsutil.exe for timestamp modification by suspicious parent processes, and unauthorized or unsigned processes performing timestamp modification on sensitive file types.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects attempts to clear Windows event logs using the wevtutil command-line utility or PowerShell cmdlets (Clear-EventLog, Remove-EventLog). Adversaries often clear event logs to hinder forensic investigations and remove evidence of their malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects signs of access token manipulation and impersonation, including the use of 'runas' with saved credentials, suspicious PowerShell API calls for identity management, usage of known token-manipulation tools (e.g., incognito), and reconnaissance using 'whoami /priv'. These activities are indicative of privilege escalation attempts or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of native Windows utilities such as shutdown.exe, wmic, powershell, and rundll32 to trigger an immediate system shutdown or restart, which may be indicative of unauthorized system disruption or malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002