avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,106 views

8,664 detections

This rule detects instances where a process attempts to open a handle to itself with high-privilege access rights (e.g., PROCESS_ALL_ACCESS, PROCESS_VM_WRITE, PROCESS_VM_OPERATION). This behavior is often indicative of self-injection, a technique used by malicious code to modify its own memory space or inject shellcode, evading detection and bypassing certain security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the spawning of Windows Script Host (wscript.exe or cscript.exe) as a child process of common web browsers (chrome.exe, msedge.exe, firefox.exe). This pattern is often indicative of a drive-by download attack or a user executing a malicious script file downloaded from the internet.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Microsoft Outlook spawning a command-line interpreter (cmd.exe or powershell.exe) followed by a network connection originating from that interpreter within a 5-minute window. This behavior is highly suspicious and often indicative of malicious macro execution or exploit delivery via email attachments leading to command-and-control activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule identifies instances where python.exe or python3.exe executes from non-standard system paths and establishes an outbound network connection to external (non-private/non-loopback) IP addresses. This behavior is indicative of potential malicious activity, as legitimate applications typically execute from protected program file directories, while adversaries often execute unauthorized binaries from temporary or user-writable locations to initiate command and control (C2) communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of five specific Windows reconnaissance utilities (net.exe, nltest.exe, whoami.exe, ipconfig.exe, and systeminfo.exe) by the same parent process within a 60-second window. This behavior pattern is highly characteristic of an automated discovery phase during a post-exploitation engagement, where an actor attempts to quickly gather system and network environment information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential credential dumping activity against the Local Security Authority Subsystem Service (LSASS) on a host shortly after a successful VPN logon. It correlates Sysmon Event ID 1 (Process Creation) representing known dumping techniques (Mimikatz, Procdump, or comsvcs.dll) with Windows Security Event ID 4624 (Logon) from a VPN source within a 5-minute window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
301
Detects an abnormally high volume of Kerberos TGS (Ticket Granting Service) requests encrypted with RC4 (0x17) from a single source IP. This behavior is indicative of Kerberoasting, an attack where an adversary attempts to extract service account passwords from requested TGS tickets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors for file access events (Sysmon Event ID 11) targeting sensitive web browser files, including logins (passwords), cookies, and web data, by processes other than the legitimate browser executables. Such access is a strong indicator of credential theft or session hijacking attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
701
This rule detects potential command and control (C2) beaconing activity by identifying non-browser processes that initiate regular, sustained outbound network connections over port 443. It aggregates connection data by hour and calculates metrics such as average frequency and standard deviation to identify consistent, periodic communication patterns characteristic of C2 agents while excluding common legitimate web browsers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects a sequence of events within a 30-minute window for a single user, specifically capturing MFA configuration changes (reset/enrollment), authentication, and device registration, occurring outside of typical business hours (20:00 - 06:00). This behavioral pattern is often indicative of an adversary establishing persistence or account takeover after gaining access to a valid account.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001