avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views

8,664 detections

Detects processes running from suspicious, writable directories (Temp, AppData, Downloads) that simultaneously load the .NET Common Language Runtime (clr.dll) and initiate network connections. This behavior is indicative of a downloaded binary or payload executing managed code to perform C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP requests where the URI or request body contains indicators of internal network references (e.g., localhost, 127.0.0.1, or RFC 1918 private IP address ranges). This pattern is consistent with Server-Side Request Forgery (SSRF) attempts, where an attacker tries to force a vulnerable web application to perform unauthorized requests to internal resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects anomalous, high-volume DNS query activity where a process attempts to resolve 20 or more unique domains within a 2-minute window. The query patterns match strings that are 8-20 characters long with common top-level domains, excluding known web browsers and standard network diagnostic utilities. This behavior is indicative of malware using Domain Generation Algorithms (DGA) for command and control or secondary communication channels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
201
Detects Python processes binding to or establishing network connections on the local loopback interface (127.0.0.1 or ::1) on non-standard ports. This behavior may indicate a local backdoor, proxy, or C2 listener implemented in Python that is not associated with common development tools or environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of executable files (.exe or .dll) on a removable drive followed by the execution of a process from that same drive within a 30-second window. This behavior is indicative of an adversary using removable media to stage and execute malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of known forensic imaging tools (FTK Imager or AD Imager) or commands interacting with the Active Directory database (ntds.dit). This behavior is characteristic of unauthorized attempts to extract credential hashes from the NTDS.dit file for offline cracking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects processes other than standard web browsers (Chrome, Edge, Brave) attempting to access sensitive directories within Chrome extension user data paths, such as IndexedDB, Local Storage, or Sync Data. Such activity is often indicative of credential or session cookie theft by malicious scripts or malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of wscript.exe, msiexec.exe, or cmd.exe initiated with command lines pointing to script files (.js, .vbs) or shortcut files (.lnk) located on removable drives (d-z drive letters). This behavior is characteristic of the Raspberry Robin worm spreading via infected USB media.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects cross-process memory access events (Sysmon Event ID 10) where a process attempts to hook into keyboard-related Windows API functions such as SetWindowsHookEx, GetKeyState, or GetAsyncKeyState. It further filters for processes executing from suspicious locations (Temp, AppData, ProgramData) or those that are unsigned/unverified, which are common indicators of malicious keylogging or spyware activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially malicious activity within Linux environments or containers where a single user context concurrently performs credential hunting (via environment variable dumping or accessing .env files) and terminates processes associated with known cryptocurrency miners or competing malicious actors. This behavior is highly indicative of a cryptojacking infection or a malicious actor clearing out existing resource-hijacking threats.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001