avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,503 copies160 likes52,041 views

8,664 detections

Detects potential abuse of Active Directory Certificate Services (AD CS) by monitoring for suspicious command-line activity from 'certreq.exe' and 'certutil.exe' associated with certificate enrollment, submission, or management. It also identifies the staging of certificate-related files (.pem, .pfx, .p12, .crt, .cer, .key) in common user directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
404
This rule detects the use of Regsvr32.exe to execute remote scriptlets (.sct files) from external HTTP/HTTPS URLs by loading the scrobj.dll module. This technique, commonly known as 'Squiblydoo', is used to bypass application allowlisting (such as AppLocker) and proxy execution of malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects instances where PowerShell or PowerShell Core (pwsh.exe) are spawned as child processes of common COM object host processes (e.g., wscript.exe, mshta.exe, rundll32.exe). The detection specifically looks for command-line arguments containing encoded commands or indicators of download cradles (e.g., IEX, Net.WebClient, DownloadString), which are common patterns for fileless execution and malicious script staging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects when a user clicks on a URL that contains a domain identified as malicious. The rule specifically looks for `UrlClickEvents` where the extracted domain from the URL matches any of the domains listed in the `malicious_domains` array. This can indicate a successful phishing attempt or an accidental click on a known malicious link.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects when 'Cursor.exe' (a legitimate application) spawns common command-line utilities (cmd.exe, powershell.exe, pwsh.exe, curl.exe, wget.exe, certutil.exe, bitsadmin.exe) with command-line arguments indicative of downloading files from the internet (e.g., containing 'http://', 'https://', 'ftp://', '-o', '-OutFile', 'iwr', 'DownloadString', 'DownloadFile'). This could indicate malicious activity where 'Cursor.exe' is being abused to facilitate ingress tool transfer or execute malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects inbound emails originating from 'azure-noreply@microsoft.com' with subjects that typically indicate financial transactions (e.g., 'Invoice Paid', 'Payment Reference') or system alerts (e.g., 'MemorySpike', 'DiskFull'). This pattern could be indicative of phishing attempts leveraging a seemingly legitimate sender to trick recipients.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
This rule detects when the 'oskmenu.xml' file, located in 'C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions', is accessed or modified by any process not running under the SYSTEM account. This file is associated with the On-Screen Keyboard and its modification by non-system accounts could indicate an attempt to alter its behavior, potentially for persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects successful SSH authentications using the GSSAPI-with-MIC mechanism. This can indicate legitimate user logins or, in some cases, an adversary using valid credentials to access a system via SSH.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects multiple failed SSH login attempts from a single source IP address, indicating a potential brute force attack. The rule identifies 'Invalid user' or 'Failed password' messages in syslog from the 'sshd' process and groups them by source IP and time to count unique attempted users and total attempts. A threshold of more than 5 attempted users from a single source IP within a 10-minute window triggers an alert.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects attempts to manipulate user or service principal names (SPN/UPN) in Active Directory by adding non-ASCII or zero-width characters. Such modifications can be used by adversaries for obfuscation, to bypass detection mechanisms, or to create stealthy persistence. The rule specifically looks for Event IDs 4738 (User Account Changed) and 5136 (Directory Service Object Modified) where the 'servicePrincipalName' or 'userPrincipalName' attributes contain characters outside the standard ASCII range or zero-width characters like U+200B, U+200C, U+200D.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202