avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views

8,664 detections

Detects potential financial data exfiltration by monitoring for bulk downloads of files with financial keywords from SaaS/Office365 platforms, and identifies unauthorized processes attempting to access sensitive financial application data files (.qbw, .qbb, etc.) on local systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
206
This rule detects potential exploitation activity related to CVE-2026-45657 involving the Windows Kernel tcpip.sys driver. It monitors for a combination of system crashes (Kernel-Power 41 or EventLog 6008) correlated with Windows Error Reporting (WER) events referencing 'tcpip.sys', or significant spikes in external authentication attempts occurring shortly before a system crash. The rule aims to identify potential remote code execution attempts manifesting as kernel instability.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
006
Monitors IIS web servers for signs of potential exploitation by tracking suspicious child processes spawned by worker processes (w3wp.exe/iisexpress.exe), tracking unexpected WER (Windows Error Reporting) crashes associated with IIS workers, aggregating IIS-related application crashes, and detecting anomalous W3C IIS log request patterns (e.g., malformed content-length, negative bytes, or suspicious URI characteristics).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
206
This rule detects potential privilege escalation activity associated with the abuse of CTFMON related objects (named pipes, symlinks, junctions) which may be used in conjunction with high-privilege operations (like SeDebugPrivilege or SeImpersonatePrivilege) to elevate access to SYSTEM. It correlates access events for CTF objects by processes (other than the legitimate ctfmon.exe) with subsequent sensitive privilege assignments within a short time window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
106
Detects anomalous activity associated with information stealing malware, including unauthorized access to browser credential files (Login Data, Cookies), remote thread injection into browser processes, outbound connections to the Telegram API by non-browser processes, and rapid bulk access to multiple sensitive credential or crypto wallet files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
306
Detects the execution of the 'diagnose sniffer packet' command on FortiOS devices. This command can be abused by malware, such as FortigateSniffer, to intercept authentication traffic, as observed in campaigns like FortiBleed.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
4014
Detects network activity associated with Cobalt Strike Beacon behavior by identifying specific file extensions (.bin, .stager, .update, .task, .post) commonly used in Beacon staging and communication profiles within network inspection events.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
307
Detects attempts to clone or snapshot sensitive virtual machines (such as Domain Controllers, PKI, Vault, ADFS, or SSO servers) in a VMware environment. The rule alerts on these activities when performed by non-administrator accounts outside of established maintenance windows, suggesting potential unauthorized data staging or credential extraction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
206
Detects the execution of major web browsers (Chrome, Firefox, Internet Explorer) with command line arguments containing keywords related to browser extensions, addons, or plugins. This pattern is often used to load unauthorized or malicious extensions for persistence or browser hijacking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
107
Detects the creation of WMI Event Subscriptions using wmic.exe or scrcons.exe. Adversaries can use WMI event subscriptions to achieve persistence by executing malicious code when a specific event occurs, such as system boot or user logon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004