avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,491 copies160 likes52,016 views

8,664 detections

Detects modifications to sensitive Group Policy Object (GPO) attributes, specifically those related to file system paths, machine/user extensions, or version numbers, using Windows Security Event ID 5136. These attributes are often targeted during GPO modification to establish persistence, escalate privileges, or deploy malicious configurations across a domain.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
403
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (etype 0x17) by non-service accounts, which is a common indicator of a Kerberoasting attack where adversaries attempt to crack service account passwords offline.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
303
Detects Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (etype 0x17) by non-service accounts, which is a common indicator of a Kerberoasting attack where adversaries attempt to crack service account passwords offline.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects outbound FTP traffic containing the 'STOR' command, which is used in the FTP protocol to upload files to a remote server. This behavior is a common indicator of unauthorized data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects DNS queries containing unusually long subdomains (50+ characters) encoded in Base64, which is a common technique used for command-and-control (C2) communication or data exfiltration via DNS tunneling.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the transmission of a Metasploit Meterpreter stage over HTTP, identified by an application/octet-stream response containing the DOS MZ header signature.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects a high frequency of incoming TCP synchronization (SYN) packets on port 3389 (RDP) from a single external source within a short timeframe. This behavior is indicative of a brute-force or credential-stuffing attack against Remote Desktop services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule monitors network traffic over the Telnet protocol (TCP port 23) for patterns indicative of Mirai botnet propagation. It identifies sequences of characters commonly used in Mirai brute-force attempts to guess default credentials (e.g., 'admin' followed by 'password'). The rule utilizes a threshold-based detection filter to trigger only when multiple such attempts are observed from a single source within a 60-second window, helping to filter out individual noise and focus on active scanning behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule monitors process command lines and file activity for keywords associated with potential reconnaissance, error logs, or debugging artifacts often used during post-exploitation or system profiling. It flags commands or files containing terms like 'memory dump', 'stack trace', 'SQL injection', or 'Redis failure', which may indicate an attacker analyzing system information or attempting to interact with backend services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects suspicious activity associated with the Bun runtime after an npm package install. It flags instances where Bun, or download utilities (curl/wget) fetching 'bun.sh', are spawned from Node.js-related processes (npm, node, node-gyp) particularly when located in common temporary or cache directories, indicating potential supply chain compromise or unauthorized runtime deployment during build processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003