avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views

8,664 detections

Detects network connections to the Telegram API (api.telegram.org) from processes identified as LOLBins or residing in suspicious, potentially writable locations such as Temp, AppData, or user-defined directories. This activity is often indicative of C2 communication or data exfiltration by malware bypassing standard messaging client restrictions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially unauthorized or suspicious outbound network connections to common Generative AI service APIs (OpenAI, Anthropic, Mistral) originating from command-line interpreters (cmd.exe, powershell.exe) or python.exe instances running from temporary directories, which could indicate data exfiltration or the use of AI tools for malicious automation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of five specific Windows reconnaissance utilities (net.exe, nltest.exe, whoami.exe, ipconfig.exe, and systeminfo.exe) by the same parent process within a 60-second window. This behavior pattern is highly characteristic of an automated discovery phase during a post-exploitation engagement, where an actor attempts to quickly gather system and network environment information.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of BPF syscalls by non-root processes or the execution of BPF-related utilities (bpftool, bpfcc) from an interactive shell. This behavior is often associated with the ShadowGuard rootkit and potential BPF-based backdoor activity, which leverages BPF programs for stealthy system monitoring or command execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors for two distinct behaviors: direct modification of Group Policy Object (GPO) containers within Active Directory and suspicious execution of GPO management tools (gpupdate.exe or gpedit.msc) across multiple hosts in a short timeframe. AD modification events are flagged as critical, while elevated tool execution patterns are flagged as high or medium risk based on host prevalence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential credential dumping activity against the Local Security Authority Subsystem Service (LSASS) on a host shortly after a successful VPN logon. It correlates Sysmon Event ID 1 (Process Creation) representing known dumping techniques (Mimikatz, Procdump, or comsvcs.dll) with Windows Security Event ID 4624 (Logon) from a VPN source within a 5-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects the use of system utilities (wevtutil.exe, auditpol.exe, PowerShell) to interact with, query, or check status of security event logs and auditing configurations. While these tools are standard for administration, their usage by non-system accounts can indicate an adversary attempting to understand, monitor, or manipulate system audit policies and event log configurations as part of a reconnaissance or defense evasion strategy.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
404
Detects the use of VMware ESXi command-line management tools (esxcli, esxcfg) or VMware PowerCLI cmdlets (e.g., Connect-VIServer, Invoke-VMScript) from endpoints that are not identified as servers. This behavior often indicates an attacker attempting to manage or interact with a virtualized environment from a compromised workstation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects outbound network connections to common webhook and temporary storage services (e.g., discord.com webhooks, webhook.site, pipedream.net) initiated by processes other than standard web browsers. Such behavior is often indicative of automated data exfiltration, command-and-control (C2) communication, or malicious script activity using these services to bypass traditional network defenses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule monitors for inbound email messages containing SVG file attachments. SVG files can contain embedded scripts that may be leveraged for malicious purposes, such as SVG smuggling to deliver secondary payloads or perform credential harvesting.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304