avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views

8,664 detections

Detects suspicious modifications to Windows registry keys associated with logon script execution, such as 'UserInitMprLogonScript' or 'Userinit'. These locations are frequently abused by adversaries to achieve persistence by forcing the execution of malicious scripts or binaries upon user logon. The rule excludes modifications made by standard Microsoft Windows processes to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects potential credential dumping activities and unauthorized access to sensitive system files. The rule monitors for three primary indicators: raw disk device access (often associated with volume shadow copy dumping), suspicious DiskShadow utility execution, and NTDS.dit extraction using ntdsutil. Known administrative and backup software processes are excluded to minimize noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects ransomware activity by identifying two primary indicators: a high volume of file renames to common ransomware extensions within a 5-minute window, and the creation of known ransom notes across multiple directories. It excludes processes signed by trusted vendors to minimize noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1202
Detects potential dynamic linker hijacking on Linux systems by monitoring for the use of non-standard LD_PRELOAD paths in process command lines or unauthorized modifications to the /etc/ld.so.preload configuration file, which can be used to inject malicious code into processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects unauthorized cross-process memory operations targeting high-value Windows processes (e.g., lsass.exe, svchost.exe) by unsigned or untrusted processes. It also detects indicators of reflective DLL injection within process command lines.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
Detects the transmission of the 'UserInitMprLogonScript' registry value name over SMB traffic in plaintext. This registry key is commonly used by adversaries to establish persistence by executing a logon script whenever a user logs in.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects clear-text attempts to clear Windows Event Logs using 'wevtutil' or 'Clear-EventLog' command patterns within network traffic, indicating a potential attempt to remove evidence of malicious activity on a host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the transmission of a Portable Executable (PE) file header ('MZ' and 'PE' magic bytes) within an HTTP response stream, which is a common indicator of a staged file download or process injection payload being delivered over the network.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects anomalous SMB NTLM authentication traffic indicative of relay attacks, where an attacker intercepts an authentication request and relays it to another SMB service.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects suspicious SMB traffic targeting raw disk volumes (e.g., PhysicalDrive, C:) or sensitive Windows files such as NTDS.dit and SYSTEM hive files. This behavior is indicative of credential dumping attempts, often performed using tools like secretsdump.py or Invoke-NinjaCopy, which bypass standard file system access controls to exfiltrate critical system credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002