avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,506 copies160 likes52,094 views

8,664 detections

Detects modifications to Windows Registry keys associated with Event Tracing for Windows (ETW) Autologger configurations or Event Log service configurations. These modifications can be used by adversaries to disable or tamper with event logging mechanisms, effectively blinding security telemetry and evading detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the execution of potentially malicious processes (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe) initiated by mmc.exe or explorer.exe, excluding known legitimate Microsoft Management Console (MMC) flags and common management snap-ins. This pattern is indicative of potential proxy execution or misuse of system administration utilities to run unauthorized code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the addition of secrets or certificates to Azure service principals during non-business hours (before 7 AM or after 7 PM, or on weekends). This behavior may indicate an adversary attempting to establish persistence in a cloud environment by adding their own credentials to an existing service principal.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where a user successfully authenticates using Multi-Factor Authentication (MFA) from one location, followed by a Single-Factor Authentication (SFA) logon from a different location within a 10-minute window. This behavior is indicative of potential session hijacking or session cookie theft where an attacker reuses an authenticated session or manipulates the authentication flow to bypass MFA requirements.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
302
Detects high-frequency HTTPS network connections to Google Drive or Google APIs originating from processes that are not common web browsers or productivity software. This behavior is indicative of the GearDoor backdoor, commonly used by APT41, which leverages Google services as a command-and-control (C2) channel.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects network connections to Microsoft OneDrive or SharePoint domains from processes that are not standard, known-good applications (e.g., browsers or standard sync clients). This behavior may indicate an adversary leveraging cloud storage for command-and-control (C2) operations or data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects the creation of WMI event subscriptions that utilize CommandLineEventConsumer or ActiveScriptEventConsumer to execute common living-off-the-land binaries like powershell.exe, cmd.exe, wscript.exe, cscript.exe, or mshta.exe. This behavior is a common technique used for establishing persistence or executing malicious payloads via WMI event mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects a sequence of suspicious activities: the creation or modification of an executable file (.exe or .dll) within a directory path containing update-related keywords, followed by the execution of a file in that same location, and culminating in an outbound network connection from that process. This pattern is characteristic of a software supply chain compromise or an adversary deploying a malicious payload via a fake or compromised update mechanism.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects suspicious execution of command-line utilities (cmd, powershell, pwsh) spawned by Windows Explorer (explorer.exe). The rule flags processes with long command lines or those containing evidence of obfuscation (Base64 encoding) or common command-line indicators used for weaponized scripts, such as download requests or expression invocation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102