avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views

8,664 detections

Detects outbound internet communications generated by rundll32.exe, which is uncommon and frequently associated with malware execution, including ACR Stealer.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects connections to domains associated with observed ACR Stealer command-and-control infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Flags Intune assignments to “All Devices” or “All Users,” which attackers may abuse for mass deployment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects PowerShell commands that reverse byte arrays before dynamically loading assemblies into memory, a behavior commonly associated with advanced malware loaders and fileless execution techniques. The rule specifically looks for PowerShell process command lines containing 'IO.File', 'System.Reflection.Assembly', 'Length-1', and '..0', which are indicative of byte array manipulation and in-memory assembly loading.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects PowerShell reading image files and loading their contents directly into memory as .NET assemblies, a stealth technique used to hide malicious payloads inside benign-looking files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Hero proxyware artifacts being written or modified within the Windows SysWOW64 directory. Presence of these files may indicate installation of unauthorized proxy services or abuse of enterprise endpoints for traffic relaying.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects execution of OneDriveUpdater.exe from C:\ProgramData, which may represent a masqueraded binary attempting to impersonate legitimate Microsoft software. This could indicate an attempt at defense evasion or persistence by an attacker.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Flags executables whose embedded metadata identifies them as Cloudflared while the filename differs from expected distribution names, suggesting potential evasion through binary renaming.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects MSBuild project files created beneath C:\ProgramData, an uncommon location that has been abused by threat actors to stage malicious project files for code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects PowerShell commands using XOR operations together with execution primitives that may indicate obfuscated in-memory payload decoding. Specifically looks for 'powershell.exe' executing with '-bxor', '81', and either 'IEX' or 'Invoke-Expression' in the command line.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101