avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,505 copies160 likes52,064 views

8,664 detections

Detects instances where explorer.exe loads a DLL file from within C:\ProgramData. This behavior is often associated with adversary activity attempting to hide malicious modules in directories that may have permissive write access or are excluded from routine scans, including techniques used by Covenant frameworks or C2 agents.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects suspicious OpenProcess calls initiated by common user applications (explorer.exe, winword.exe, outlook.exe) targeting svchost.exe, followed by an outbound network connection from the target svchost.exe to the file sharing service filen.io within a 30-minute window. This behavior is indicative of process injection used to facilitate network communication or data exfiltration under the guise of a system process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects the creation or modification of a COM object registry key under HKEY_CURRENT_USER\Software\Classes\CLSID\ with an 'InProcServer32' subkey. This is a common technique used by adversaries for persistence and privilege escalation by hijacking COM object references to execute arbitrary malicious code when the legitimate application attempts to use the hijacked COM object.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized processes modifying the registry value 'PONT_STRING' within the Outlook Options General key. This registry value controls the display of content download warnings in Microsoft Outlook. Modifying this key from a non-Outlook process is a technique used by threat actors, such as APT28, to bypass security warnings and facilitate the execution of malicious payloads or content within Outlook.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects a network-connected Linux process exhibiting beaconing behavior (high-frequency external connections) that is subsequently correlated with unauthorized file access to sensitive Linux configuration files (/etc/passwd, /etc/shadow, or authorized_keys). This rule filters out common system processes and standard management binaries, targeting suspicious command-and-control activity combined with credential theft.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
005
This rule detects potential Command and Control (C2) communication activity by identifying instances of Domain Generation Algorithms (DGA). It monitors DNS query responses for patterns consisting of 8 to 16 lowercase alphabetic characters followed by common TLDs (com, net, org, ru, cc, su). An alert is triggered if 5 or more unique suspicious domains are queried by the same device within a one-hour window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
406
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
206
Detects execution of 'netstat.exe' with specific flags ('-a', '-n', '-o', or '-b') initiated by command-line interpreters like cmd.exe, powershell.exe, wscript.exe, or cscript.exe. These flags are commonly used for network reconnaissance and discovery of active TCP connections, listening ports, and associated process IDs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects when common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) load a DLL file from suspicious or user-writable locations such as AppData, Downloads, Documents, or Temp folders. The rule specifically alerts on DLLs that are unsigned or where the loading process itself is unsigned, which is a common indicator of side-loading or malicious library injection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of net.exe and dsquery.exe to enumerate domain user accounts and domain groups. Adversaries often perform this reconnaissance to identify target accounts or privileged groups within an Active Directory environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002