avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,050 views

8,664 detections

This rule monitors for unauthorized access to the Google Chrome 'Login Data' database file by processes other than standard browser executables. It also detects the creation of known file artifacts associated with credential-stealing malware or RATs (e.g., 'chrome_logins_dump.txt' or 'gather.tar.gz'), which are indicative of credential harvesting activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
202
Detects the use of npm to install known malicious npm packages, which is indicative of a supply chain compromise attempt via typosquatting or malicious dependency injection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of PowerShell with an encoded command flag when spawned directly from explorer.exe or cmd.exe. This pattern is frequently used in 'ClickFix' style attacks where users are tricked into copying and pasting malicious, obfuscated PowerShell code into the Windows run dialog or command prompt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects the abuse of the legitimate Windows utility certutil.exe to download files or perform encoding/decoding operations. These techniques are commonly used by attackers to stage malicious payloads, obfuscate files to bypass security controls, or retrieve additional malware components in multi-stage loader chains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects potential BaoLoader drive-by compromise attempts by monitoring two stages: first, the creation of executable files in temporary or application data directories by browser processes; and second, the execution of command-line shells by processes running from those same directories where the browser acted as the grandparent.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects instances where common web browsers (Chrome, Edge, Firefox, Brave) spawn command-line tools or script interpreters (cmd, PowerShell, wscript, mshta) as child processes. This behavior is highly indicative of drive-by download attacks, including the 'ClickFix' technique, where users are socially engineered into executing malicious commands under the guise of fake browser updates or error resolution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the execution of PowerShell with an encoded command flag when spawned directly from explorer.exe or cmd.exe. This pattern is frequently used in 'ClickFix' style attacks where users are tricked into copying and pasting malicious, obfuscated PowerShell code into the Windows run dialog or command prompt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects the abuse of the legitimate Windows utility certutil.exe to download files or perform encoding/decoding operations. These techniques are commonly used by attackers to stage malicious payloads, obfuscate files to bypass security controls, or retrieve additional malware components in multi-stage loader chains.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the use of .NET reflection methods within PowerShell process command lines. These methods, such as System.Reflection.Assembly.Load, are commonly used by attackers for fileless execution of malicious .NET assemblies directly in memory, bypassing disk-based security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the execution of known Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Action1) from user-writable directories such as Temp, Downloads, or INetCache. Adversaries frequently utilize these legitimate remote access tools to establish persistence or command-and-control channels, often dropping them into temporary directories to avoid detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104