avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views

8,664 detections

This rule detects potential command and control (C2) beaconing activity associated with Mythic implants. It monitors for high-frequency outbound connections (20 or more) from a single device to the same external IP address within a 30-minute window across common C2 listener ports (80, 443, 8080, 8443, 7443).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects outbound network connections to a known KuinaExtractor (k0to) infostealer C2 server. The rule monitors DeviceNetworkEvents for connections to the malicious IP address 103.229.53.18 on port 3000 and correlates them with process information to identify the originating application.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects shell commands (bash, sh, zsh) initiated by AI-agent or development-related processes (e.g., Python, Claude Desktop, openclaw) that target sensitive macOS paths associated with credentials, SSH keys, crypto wallets, and browser cookies, a technique characteristic of the Atomic Stealer (AMOS) malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects potential cross-process memory injection activity by monitoring for a non-debugger process that performs both NtAllocateVirtualMemory and WriteProcessMemory operations against a sensitive GUI target process within a short 5-minute correlation window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects instances where a process obtains a handle with PROCESS_VM_WRITE access to another process, followed shortly thereafter by a WriteProcessMemory operation into that same target process. This behavior is indicative of potential process injection, such as hooking remote GUI processes or other memory-based manipulation techniques.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution or file creation of identified Turla STOCKSTAY malware components, specifically targeting a list of known malicious filenames and installers used by this actor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where the Excel process (excel.exe) initiates outbound network connections to non-private IP addresses on specific ports often associated with command and control or data exfiltration. This rule specifically excludes known Microsoft-owned CDN and update infrastructure, aiming to identify potential exploitation activity, such as that potentially associated with CVE-2025-60727.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects modifications to the 'Software\Classes\ms-settings\shell\open\command' registry key, a technique commonly used to bypass User Account Control (UAC). By setting the default handler for the ms-settings protocol to a malicious command, an attacker can achieve elevated execution when the protocol is triggered by a legitimate Windows component.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects outbound network connections initiated by the Windows Installer utility (msiexec.exe) to non-private (external) IP addresses over standard web ports (80/443). Msiexec.exe can be abused to download and execute malicious payloads or packages from remote locations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects the use of 'wmic.exe', 'powershell.exe', or 'pwsh.exe' to interact with WMI event consumers (ActiveScriptEventConsumer or CommandLineEventConsumer) and filter bindings. Adversaries use these WMI components to establish persistence by executing malicious code when specific system events occur, such as a process start or a scheduled time trigger.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002