avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,504 copies160 likes52,043 views

8,664 detections

This rule identifies potential ransomware activity by detecting a process performing a high volume of file rename or modification operations within a short time window. It specifically targets files with known ransomware extensions or those using randomized 6-8 character alphanumeric extensions, while excluding common administrative, backup, and temporary file operations performed by trusted software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects network and process execution activity involving Google or Microsoft OAuth2 token endpoints from non-browser and non-trusted processes. This behavior is indicative of potential token theft or session hijacking attempts, where malicious tools (e.g., curl, python) are used to access authentication endpoints to bypass standard user interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the execution of known adversary-in-the-middle (AiTM) phishing frameworks, such as Evilginx or Modlishka, by identifying process names, paths, or specific command-line arguments (e.g., --phishlets, --proxy, --lure) used to initiate these proxy-based phishing sessions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
504
This rule detects the creation of a 'logs.dat' file, which is often associated with Remcos RAT for data exfiltration, in common user-related directories (AppData, Temp, Users, Documents) with a file size greater than or equal to 100KB. This pattern suggests an attempt to stage or exfiltrate collected data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
5011
This rule detects the execution of Windows Script Host (wscript.exe or cscript.exe) where the initiating parent process is not a common legitimate process like explorer.exe, cmd.exe, powershell.exe, svchost.exe, or system.exe, and is also not a web browser (Chrome or Firefox). This pattern can indicate an attempt to execute malicious VBScript or JScript files, potentially delivered via phishing, where the script is launched by an unusual or obfuscated parent process to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
1012
Detects potential Command and Control (C2) communication associated with Emotet malware by monitoring for successful network connections to suspicious remote ports frequently used by the malware. The rule flags endpoints that establish connections to at least three of these high-risk ports within a one-hour window, which is indicative of automated C2 beaconing behavior.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors Cisco Unified Communications Manager (UCM) environments for multiple stages of an attack chain, including potential Server-Side Request Forgery (SSRF) attempts against administrative interfaces, suspicious file modifications by service accounts, indicators of privilege escalation, and anomalous outbound network connections from core Cisco processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects AppDomainManager injection attempts by monitoring for the loading of suspicious DLLs (related to AppDomainManager functionality) by specific processes or from unexpected file paths. The rule specifically targets attempts to hijack the .NET AppDomainManager class by checking against known suspicious filenames and excluding legitimate .NET framework directories, which is a common technique used for arbitrary code execution in the context of a target process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects the creation of specific scheduled tasks associated with LoaderClient or WeedHack malware. These tasks, named 'JMonitoringTask' or 'JavaSecurityUpdater', are used for persistence and recurring execution of malicious code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002