avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,105 views

8,664 detections

This rule detects changes to a user account's User Account Control (UAC) settings, specifically when the 'NewUacValue' is set to '0x2080'. This value corresponds to the 'ACCOUNTDISABLE' flag, indicating that a user account has been disabled. Monitoring such changes can help identify potential malicious activity where an attacker might disable legitimate user accounts to disrupt operations or hinder incident response.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detect traffic to the C2 server used by the backdoor linked to MuddyWater.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects multiple stages of activity associated with BaqiyatLock ransomware and Remcos RAT. It identifies the execution of known BaqiyatLock/Remcos files, attempts to bypass User Account Control (UAC) via ms-settings registry hijack, creation of files with the '.bqtlock' extension indicative of BaqiyatLock encryption, and network communication with 'icanhazip.com' for external IP discovery, which is a common reconnaissance step.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects when the 'oskmenu.xml' file, located in 'C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions', is accessed or modified by any process not running under the SYSTEM account. This file is associated with the On-Screen Keyboard and its modification by non-system accounts could indicate an attempt to alter its behavior, potentially for persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of a scheduled task using 'schtasks.exe' with specific command-line arguments that indicate an attempt to establish persistence. The rule looks for 'schtasks.exe' creating a task named 'Runtime Broker' that executes a program from a suspicious path within 'C:\ProgramData\Microsoft\Windows\Runtime\'. This pattern is often used by adversaries to maintain access to a system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the presence of MicroStealer malware by matching known MD5, SHA1, or SHA256 hashes of its binaries against file events on monitored devices. MicroStealer is a credential stealer that targets various applications to exfiltrate sensitive information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the presence of files on endpoints that match a list of known malicious SHA256 hashes associated with the Nuso malware. It queries DeviceFileEvents to identify any file with a matching hash.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects GhostBackdoor malware execution via known file hash.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects suspicious process injection attempts where common scripting/proxy execution tools (wscript.exe, cscript.exe, mshta.exe, powershell.exe, msiexec.exe) are used to inject into other processes (RegAsm.exe, InstallUtil.exe, vbc.exe, svchost.exe, explorer.exe) using CreateRemoteThread. The detection is further refined by looking for command-line indicators often associated with malicious activity, such as downloading content or executing scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
KQL Query from file: INC Ransomware Command Execution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001