avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views

8,664 detections

Detects network connections to a specific suspicious IP address (94.156.181.89) or to domains associated with Cloudflare Tunnel (.trycloudflare.com). This could indicate command and control activity, data exfiltration, or other malicious network communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects the presence of MicroStealer malware by matching known MD5, SHA1, or SHA256 hashes of its binaries against file events on monitored devices. MicroStealer is a credential stealer that targets various applications to exfiltrate sensitive information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects a high volume of UDP network connections originating from a single process on a device. A count exceeding 50 UDP connections from the same process to the same remote IP address is considered anomalous and could indicate a UDP flood or other denial-of-service attempt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects the presence of the string "xhxhxhxhxhxpp" within the AdditionalFields of DeviceEvents. This string =represents a Mutex Indicator of Compromise (IOC).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the execution of 'REAGENTC.EXE' with the '/disable' argument and 'WBADMIN.EXE' with 'delete catalog -quiet' within a 10-minute window on the same device. This combination of commands is indicative of an adversary attempting to inhibit system recovery by disabling Windows Recovery Environment and deleting the Windows Backup Catalog, often seen in ransomware attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of an MSI (Microsoft Installer) file on a device where the file's origin referrer URL indicates it was downloaded from a ZIP archive that was originally an email attachment. This could indicate a user opening a malicious ZIP file from an email, leading to the execution of an installer.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
A detection triggered on endpoint events where common system binaries (e.g., mshta.exe, powershell.exe, cmd.exe) were launched by user-facing parent processes (explorer.exe, chrome.exe, msedge.exe, firefox.exe, iexplore.exe) and executed suspicious command-lines. The pattern matches the evolving technique used in ClickFix-style campaigns whereby malicious pages dynamically place payloads into the clipboard and prompt users to paste or execute them.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the execution of 'conhost.exe' with the '--headless' argument, specifically when initiated by 'pcalua.exe'. This combination has been observed in attacks by the GOLD BLADE threat group for indirect command execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects DLL side-loading attacks where consent.exe loads known malicious DLLs (version.dll, rtworkq.dll, wmsgapi.dll, and the older msimg32.dll) from non-standard locations. This technique is used by Shanya-packed malware including EDR Killer and CastleRAT to load malicious payloads while appearing as a legitimate Windows UAC process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects inbound emails that appear to be Microsoft Teams invitations but contain suspicious keywords in the subject line related to financial transactions (invoice, billing, payment, renewal, charge). This could indicate a phishing attempt where adversaries leverage legitimate-looking Microsoft invitation emails to deliver financially themed lures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102