avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views

8,664 detections

Detects suspicious network activity originating from the InstallUtil.exe process. InstallUtil is a legitimate Windows .NET utility that can be abused as a LOLBin (Living-off-the-Land Binary) to proxy the execution of malicious payloads, potentially bypassing application control mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential lateral movement attempts using Windows Remote Management (WinRM) by monitoring for specific WSMan SOAP protocol headers in HTTP traffic. It specifically looks for POST requests to the WSMan endpoint that contain suspicious keywords like 'winrs', 'MSRPC', or 's:Envelope', which are commonly associated with remote command execution via winrs or PSSession.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects HTTP traffic where the User-Agent header references Regasm or Regsvcs, which are trusted Windows utilities often abused by attackers to proxy execution of malicious code (Living-off-the-Land Binary technique).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects HTTP GET requests for .msc (Microsoft Management Console) files, which can be leveraged as part of an attack chain to abuse the mmc.exe binary for proxy execution of malicious configurations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects SMB traffic patterns containing commands indicative of file obfuscation or permission tampering, specifically the use of 'attrib' to set hidden or system attributes, 'icacls' to deny access to files, or PowerShell execution with the '-WindowStyle Hidden' argument.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects remote system shutdown attempts initiated via the MSRPC winreg named pipe over SMB. This behavior is indicative of an attacker attempting to shut down or reboot a target system remotely to interrupt availability, often as a prelude to or consequence of destructive actions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation or modification of inbox rules in Office 365/Exchange that configure email forwarding or redirection to external domains. Attackers often use these rules to exfiltrate email data or maintain persistence within an environment by redirecting communications to attacker-controlled accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects outbound network connections to well-known public DNS-over-HTTPS (DoH) providers (e.g., Google, Cloudflare, Quad9) from processes other than standard web browsers. This behavior is often associated with adversary attempts to bypass local DNS monitoring or security controls by tunnelled traffic over HTTPS.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects the use of known named pipes associated with Cobalt Strike post-exploitation frameworks, often used for inter-process communication during beaconing or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
303
Detects attempts to stop or disable critical security, backup, and logging services on Windows systems using command-line utilities (net.exe, sc.exe) or PowerShell. Adversaries frequently perform these actions to impair defensive monitoring, bypass security controls, or prepare the system for destructive activities like ransomware deployment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002