avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,058 views

8,664 detections

Detects the execution of sensitive ESXi administrative commands (e.g., esxcli, vim-cmd) that suggest potential hypervisor management or tampering, especially when initiated by non-administrative processes or specific shells.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
This rule correlates multiple low-to-medium confidence signals across file, process, network, and registry events to detect potential ransomware activity. The rule identifies suspicious behaviors including mass file renames, creation of known ransom note file types in multiple directories, shadow copy deletion via system utilities, disabling of antivirus and security monitoring, large archive staging, unauthorized outbound network connections, and suspicious process injection. Alerts are generated based on the aggregation and frequency of these signals, indicating a high probability of ransomware-related malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105
Detects a multi-stage attack pattern associated with the Qilin ransomware, beginning with suspicious VPN authentication (potential credential stuffing or bypass), moving through lateral movement attempts (SMB/RDP/WMI), and culminating in ransomware behaviors such as shadow copy deletion, mass file encryption, and ransom note creation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects outbound network connections to common Azure-related domains originating from suspicious file paths such as Temp, Downloads, or AppData subdirectories. This behavior is indicative of potential malware or unauthorized scripts executing from temporary user locations to reach out to cloud infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects instances where the Outlook process (OUTLOOK.EXE) initiates a network connection via port 445 (SMB) to an IP address that is not part of the internal private network ranges. This activity is highly anomalous for an email client and may indicate exploitation, data exfiltration, or attempts to relay NTLM credentials to a remote malicious SMB server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of rundll32.exe to process files with common image extensions (.jpg, .jpeg, .png, .bmp, .gif). This behavior is often associated with steganography or attempts to disguise malicious payloads by masquerading them as image files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects network connections to Google Cloud services (calendar.google.com, googleapis.com) over port 443 originating from processes other than known web browsers or standard Google background applications. This behavior may indicate unauthorized tools, custom scripts, or malware using Google services for command and control or data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the modification of the 'LoadMacroProviderOnBoot' registry value in Microsoft Outlook. Enabling this setting can cause Outlook to load macros upon startup, which is a technique often leveraged for persistence or malicious code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
Detects modifications to the Outlook Security registry key, specifically setting the 'Level' value to '1'. This configuration (often associated with 'OutlookSecurityMode' or related programmatic access policies) can be used by adversaries to bypass security prompts when accessing the Outlook Object Model, allowing malicious scripts or applications to interact with Outlook to send emails, harvest contacts, or access attachments without user intervention.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the creation or modification of a COM object registry key under HKEY_CURRENT_USER\Software\Classes\CLSID\ with an 'InProcServer32' subkey. This is a common technique used by adversaries for persistence and privilege escalation by hijacking COM object references to execute arbitrary malicious code when the legitimate application attempts to use the hijacked COM object.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002