avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,496 copies160 likes52,031 views

8,664 detections

Detects workstations establishing multiple connections to non-standard, internal management ports (SSH, Telnet, SNMP). This behavior is often associated with lateral movement or unauthorized network scanning using tools that leverage management protocols.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects a multi-stage loader chain behavior. Stage 1 identifies PowerShell spawning mshta.exe or wscript.exe, which is commonly used to execute malicious scripts or loaders. Stage 2 detects mshta.exe or wscript.exe subsequently executing schtasks.exe or wmic.exe with command-line arguments indicative of establishing persistence via scheduled tasks or WMI event subscriptions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
105
Detects potential internal network scanning activity by identifying devices attempting connections to 5 or more distinct sensitive ports within a one-hour window. This behavior is indicative of reconnaissance activities aimed at identifying vulnerable services such as SSH, SMB, RDP, or various database management systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
207
Detects network connections to Microsoft OneDrive or SharePoint domains from processes that are not standard, known-good applications (e.g., browsers or standard sync clients). This behavior may indicate an adversary leveraging cloud storage for command-and-control (C2) operations or data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects a sequence of suspicious activities: the creation or modification of an executable file (.exe or .dll) within a directory path containing update-related keywords, followed by the execution of a file in that same location, and culminating in an outbound network connection from that process. This pattern is characteristic of a software supply chain compromise or an adversary deploying a malicious payload via a fake or compromised update mechanism.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects command line execution containing keywords associated with offensive security tools (e.g., 'metasploit', 'exploit', 'shellcode', 'payload') in conjunction with external resource indicators such as HTTP/HTTPS or FTP URLs, suggesting the download and potential execution of malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
107
Detects the use of PowerShell, PWSH, or CMD to modify file system timestamps, a technique commonly referred to as timestomping. This is often used by adversaries to hide malicious file activity or blend in with legitimate system files by manipulating file creation, modification, or access time metadata.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of Kubernetes pods where the 'hostPID' or 'hostNetwork' settings are enabled. These configurations allow a pod to share the host's process namespace or network stack, respectively, which are common vectors for container escapes and host-level privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is commonly associated with ransomware or other malicious activity aimed at inhibiting system recovery by removing backups.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential clipboard data theft by monitoring Windows Sysmon Event ID 10 for process access events involving clipboard-related APIs (OpenClipboard, GetClipboardData) by untrusted processes, and PowerShell Script Block Logging (Event ID 4104) for the use of Get-Clipboard cmdlets. This identifies attempts by non-standard or unauthorized processes to access sensitive information copied by a user.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102