avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views

8,664 detections

Detects the creation of scheduled tasks using schtasks.exe or at.exe by processes not signed by Microsoft. This behavior is often associated with adversary attempts to establish persistence by running code on a recurring basis or at specific times using native Windows utilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of BITSAdmin to download files from remote URLs. Attackers frequently abuse BITSAdmin, a legitimate Windows administrative tool, to download malicious payloads or secondary tools from external servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects modifications to the 'Software\Classes\ms-settings\shell\open\command' registry key, a technique commonly used to bypass User Account Control (UAC). By setting the default handler for the ms-settings protocol to a malicious command, an attacker can achieve elevated execution when the protocol is triggered by a legitimate Windows component.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the use of 'wmic.exe', 'powershell.exe', or 'pwsh.exe' to interact with WMI event consumers (ActiveScriptEventConsumer or CommandLineEventConsumer) and filter bindings. Adversaries use these WMI components to establish persistence by executing malicious code when specific system events occur, such as a process start or a scheduled time trigger.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of scheduled tasks using schtasks.exe or at.exe by processes not signed by Microsoft. This behavior is often associated with adversary attempts to establish persistence by running code on a recurring basis or at specific times using native Windows utilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects emails successfully delivered to the inbox that exhibit authentication failures for SPF, DKIM, or DMARC, or where a mismatch between the 'SenderFromDomain' and 'SenderMailFromDomain' is observed, indicating potential email spoofing or unauthorized sender impersonation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
205
Detects common web server processes (IIS, Apache, Nginx, PHP, Tomcat) spawning command-line interpreters or utilities (cmd.exe, powershell.exe, wscript.exe, cscript.exe, certutil.exe). This pattern is often indicative of exploitation of a web application to gain command execution on the host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the creation or modification of Windows Registry Run keys (Run/RunOnce) by processes other than those signed by Microsoft Corporation. This is a common technique used to maintain persistence by executing programs automatically upon user logon.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the execution of common command-line utilities (cmd, powershell, wscript, cscript, mshta, certutil) directly spawned by Microsoft Office applications (Word, Excel, PowerPoint, Outlook). This is a common indicator of macro-based attacks or other exploit delivery chains where Office documents are used to execute malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potentially malicious use of the ClickOnce process (dfsvc.exe) by monitoring for suspicious parent processes (such as rundll32.exe or mshta.exe) spawning dfsvc.exe, or dfsvc.exe spawning unexpected child processes. ClickOnce is often abused by attackers to proxy the execution of malicious code, and these patterns are indicative of such activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105