avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views

8,664 detections

Detects instances where the Windows binary fodhelper.exe spawns various shell or utility processes. This behavior is a common indicator of a User Account Control (UAC) bypass attack, where the attacker leverages the auto-elevation property of fodhelper.exe to execute arbitrary commands with higher privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of the netsh.exe utility to modify Windows Advanced Firewall settings, specifically disabling profiles or adding/deleting firewall rules. This activity is often used by adversaries to impair security controls on a compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects common web server processes (IIS, Apache, Nginx, PHP, Tomcat) spawning command-line interpreters or utilities (cmd.exe, powershell.exe, wscript.exe, cscript.exe, certutil.exe). This pattern is often indicative of exploitation of a web application to gain command execution on the host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the use of BITSAdmin or PowerShell 'Start-BitsTransfer' to initiate file transfer jobs. These tools can be abused by adversaries to download malicious payloads or exfiltrate data, often bypassing standard firewall restrictions. The rule specifically filters out legitimate Microsoft-signed processes to reduce noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation or modification of Windows Registry Run keys (Run/RunOnce) by processes other than those signed by Microsoft Corporation. This is a common technique used to maintain persistence by executing programs automatically upon user logon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects common Kerberoasting activities by monitoring for the execution of 'Rubeus' or 'GetUserSPNs' (often associated with Impacket) in process command lines. These tools are commonly used by attackers to request service tickets for service accounts, which can then be cracked offline to recover passwords.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the use of 'wmic.exe' with the '/format' switch to execute XSL files, or the direct execution of 'msxsl.exe'. These methods are common techniques used by adversaries to bypass security controls by executing arbitrary scripts embedded within XSL files, often fetched from remote locations or local paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of Windows utilities 'nltest.exe' and 'dsquery.exe' with specific command-line arguments to enumerate Active Directory domain trust relationships. This behavior is indicative of an attacker attempting to map the network environment to identify targets for lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where common Windows processes (explorer.exe, svchost.exe, dllhost.exe) load an unsigned module (DLL) from user-writable directories, such as AppData, Downloads, or Temp folders. This behavior is a common indicator of potential DLL sideloading or malicious code execution originating from user-controlled space.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of known Active Directory discovery tools, specifically 'adfind.exe' or 'dsquery.exe' with arguments targeting user or group enumeration. These tools are commonly used by adversaries during the reconnaissance phase to map domain structure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202