avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,106 views

8,664 detections

Detects the execution of PowerShell or pwsh that originates from an interactive parent process like explorer.exe or cmd.exe. The rule identifies suspicious command-line patterns containing 'IEX', 'Invoke-Expression', 'Invoke-WebRequest', 'iwr', or 'IRm', while excluding encoded commands, which is indicative of potential malicious clipboard-paste activity or manual attacker intervention.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects Python processes binding to or establishing network connections on the local loopback interface (127.0.0.1 or ::1) on non-standard ports. This behavior may indicate a local backdoor, proxy, or C2 listener implemented in Python that is not associated with common development tools or environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects scenarios where Microsoft Teams initiates a potential screen-sharing session (via outbound network connections on specific ports) followed shortly by the access of VPN configuration files on the same host. This sequence may indicate an attacker using screen-sharing to view credentials or configuration details and subsequently attempting to utilize a VPN client.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of the TruffleHog tool, which is used for scanning Git repositories and codebases to discover exposed sensitive information, such as API keys and passwords. The rule monitors process execution command lines and filters out common CI/CD and automation service accounts to identify potentially malicious or unauthorized use of the tool on endpoints.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects a suspicious pattern involving two events occurring on the same host: the creation of a DLL file with a 'meow_' prefix (potentially associated with known malware patterns) and the execution of a command-line interpreter (cmd.exe, powershell.exe, or pwsh.exe) as a child process of suspicious parent processes like svchost.exe, services.exe, dllhost.exe, or msiexec.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects when processes other than standard web browsers (Chrome, Edge, Firefox, Brave, Opera) attempt to read sensitive browser data files such as 'Login Data', 'Cookies', or 'Web Data'. These files contain stored credentials and session information, and unauthorized access is a common technique used by credential-stealing malware to exfiltrate sensitive user information.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects high-frequency authentication failure events targeting the Microsoft Remote Desktop Web (RDWeb) access login page, indicating a potential brute force or password spraying attack against remote access services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of the TruffleHog tool, which is used for scanning Git repositories and codebases to discover exposed sensitive information, such as API keys and passwords. The rule monitors process execution command lines and filters out common CI/CD and automation service accounts to identify potentially malicious or unauthorized use of the tool on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects a suspicious pattern involving two events occurring on the same host: the creation of a DLL file with a 'meow_' prefix (potentially associated with known malware patterns) and the execution of a command-line interpreter (cmd.exe, powershell.exe, or pwsh.exe) as a child process of suspicious parent processes like svchost.exe, services.exe, dllhost.exe, or msiexec.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects Microsoft Entra ID (formerly Azure AD) sign-in logs where a single user account authenticates from two different countries within a 10-minute window, which is indicative of potential account compromise or credential sharing.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101