avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views

8,664 detections

Detects registry changes affecting DisableRestrictedAdmin, specifically when it is set to '00000000' (disabled). This modification could weaken authentication protections or facilitate credential theft techniques by allowing the use of cached credentials for remote connections.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Exploited SolarWinds process starting PowerShell with base64 in the command line.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects DNS requests and responses linked to Sunburst backdoor.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects the execution of `rundll32.exe` with `shell32.dll` that subsequently launches `cmd.exe`. This behavior is often associated with adversaries using `rundll32.exe` as a proxy to execute commands, specifically leveraging `shell32.dll` to invoke `cmd.exe`. The rule includes several exclusions to reduce false positives, such as legitimate `msiexec.exe` parent processes, specific `RunDLL` commands, and `autorun.bat` related activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
301
Detects the execution of rundll32.exe with command-line arguments indicative of running an HTML Application (mshtml,RunHTMLApplication) or directly executing JavaScript. This technique is often used by adversaries for code execution and bypassing security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
201
Detects the use of regsvr32.exe to execute a remote scriptlet (.sct file) via a URL, a technique often referred to as 'Squiblydoo'. This method bypasses application control by leveraging a trusted Microsoft binary to proxy execution of malicious code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious network connections where the initiating process command line contains keywords indicative of evasion techniques such as 'obfuscate', 'encode', or 'encrypt'. It specifically looks for these activities over common web ports (80, 443, 8080, 8443) and triggers an alert if 10 or more such attempts are observed from a device within an hour.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Looks for generic webshell creation on Windows Servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential data poisoning attacks targeting machine learning models by monitoring Windows Security Event ID 4688 (a process was created) for command-line activity containing keywords indicative of model training or dataset modification, combined with terms suggesting malicious intent like 'corrupted', 'poison', or 'injection'. It aims to identify attempts to manipulate or compromise ML models through their training data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential spear phishing campaigns by identifying a high volume of emails (10 or more within an hour) from external senders (not @company.com) that contain keywords like 'password', 'account', or 'security' in the subject line, and also include either an attachment or a URL. This combination of factors suggests a targeted social engineering attempt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101