avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,042 views

8,664 detections

Detects instances where WinRAR.exe is observed writing potentially malicious script or link files (.hta, .vbs, .js, .ps1, .lnk) into the Windows Startup folder. This pattern is indicative of exploitation of CVE-2025-8088, a path traversal vulnerability in WinRAR often leveraged by the Gamaredon group to establish persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
006
This rule detects anomalous or risky sign-in events for user accounts that have recently configured an active out-of-office (OOF) auto-reply. An attacker may leverage a user's known absence to gain access to their email or other corporate resources using compromised credentials, as the user is less likely to notice suspicious account activity while away.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
206
This rule monitors for inbound email messages containing SVG file attachments. SVG files can contain embedded scripts that may be leveraged for malicious purposes, such as SVG smuggling to deliver secondary payloads or perform credential harvesting.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
006
Detects network traffic associated with known Cobalt Strike Beacon request URI patterns. This rule utilizes network signature inspection to flag outbound connections containing URI fragments commonly used by Cobalt Strike default profiles.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
208
Detects the execution of specific Python scripts associated with the FortiBleed campaign. These scripts include 'spray_da.py' for domain admin password spraying, 'smb_test.py' for SMB validation and lateral movement, 'spider.py' for Active Directory crawling, and 'ad_full_audit.py' for Active Directory auditing. Detection is based on the Python interpreter executing these specific script filenames.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
10015
This rule detects potential data exfiltration attempts by monitoring for network connections to URLs containing suspicious substrings (bit, onion, .cc, .su) over common web and DNS ports (53, 80, 443, 8080). It flags high-frequency unique connection attempts from a single device, which may indicate command-and-control (C2) traffic or data exfiltration over covert channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
308
This rule detects network connections from internal devices to identified APT Command and Control (C2) IP address ranges over common ports (8080, 443, 21, 22, 23, 25, 445). This traffic pattern is indicative of unauthorized external communication commonly associated with malware or adversary activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
008
This rule detects the creation or modification of at least 10 files within an hour that have the '.prinzeugen' extension, which is indicative of the Prinz Eugen ransomware encrypting files using ChaCha20.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
7014
This rule detects potential cloud resource hijacking (e.g., cryptojacking) by monitoring for a sudden spike in the deployment of Azure virtual machines by a single user. It triggers if a user creates five or more virtual machines in a 10-minute window, specifically looking for deployments in regions where the user has not recently created VMs, or deployments utilizing high-compute SKUs commonly targeted for cryptocurrency mining.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
106
Detects high-impact configuration changes to Azure management groups or subscriptions (e.g., write/delete operations) that are performed by non-privileged accounts or outside of defined business change windows. This activity can indicate unauthorized privilege escalation, resource manipulation, or reconnaissance by an adversary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
006