avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views

8,664 detections

This rule detects potential phishing attempts by identifying emails where the sender's address contains international (Cyrillic) characters that look similar to Latin characters (homoglyphs) and the subject line contains keywords often associated with phishing, such as 'verify', 'confirm', or 'urgent'. This combination suggests an attempt to spoof legitimate domains using visual deception.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects attempts to establish persistence by modifying registry run keys (Run or RunOnce) to execute scripting interpreters like PowerShell, cmd, or wscript. The rule looks for at least two such events within an hour on the same device and registry key, indicating potential malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects the creation of new processes (Event ID 4688) where the command line contains keywords indicative of driver or kernel module installation or loading. It looks for combinations of terms like 'driver', 'kernel', 'sys' along with 'install' or 'load'. This activity can be a sign of rootkit installation or other malicious kernel-level modifications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects a single process creating a large number of files with diverse file types within a short time frame (5 minutes). This behavior can be indicative of malicious activity such as ransomware encrypting files, data staging for exfiltration, or malware dropping multiple components.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects multiple registry value set events where the registry value data contains keywords like 'ransom' or 'payment', or the registry key contains 'Run'. This behavior can indicate ransomware activity attempting to establish persistence or communicate its demands.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious process creations where common system processes (svchost.exe, explorer.exe, lsass.exe, winlogon.exe) act as parent processes for scripting or command-line interpreters (powershell.exe, cmd.exe, cscript.exe, wscript.exe) and the child process runs with a low or untrusted integrity level. This pattern can indicate process injection or other forms of malicious execution where an attacker attempts to hide their activity by masquerading as legitimate system processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the installation of new Windows services (EventID 7045) where the service's executable path (ServiceFileName) contains common scripting interpreters like 'cmd', 'powershell', or 'wscript'. This pattern can indicate an adversary attempting to establish persistence or execute malicious code via a newly created service that leverages scripting capabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the creation or modification of executable files (.exe, .dll, .sys) within critical Windows system directories (C:\Windows\System32\ or C:\Windows\SysWOW64\). Such activity can indicate an attempt to establish persistence, elevate privileges, or inject malicious code into legitimate system processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the creation or modification of scheduled tasks (EventID 4698 or 4699) where the command line for the task contains references to scripting languages like PowerShell, cmd, or VBScript. It then groups these events by computer and user, flagging if two or more such tasks are created by the same user on the same computer, which could indicate malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects suspicious Azure AD sign-in activity where a user successfully signs in from multiple unusual cities within a 24-hour period. It specifically looks for sign-ins that are not from a trusted network and are not from a compliant device, aggregating successful sign-ins by UserPrincipalName and IpAddress, and flagging if there are 5 or more distinct cities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001