avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views

8,664 detections

This rule detects the creation of new processes where the command line contains keywords such as 'exploit' or 'vulnerability'. This could indicate an attempt to execute an exploit or leverage a known vulnerability, potentially as part of an attack.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the execution of processes where the command line contains keywords commonly associated with malware, specifically 'backdoor', 'rootkit', or 'trojan'. It monitors Windows Security Event ID 4688 (a process creation event) and flags any command lines containing these terms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the creation or modification of user accounts on Windows systems by monitoring Security Event IDs 4741 (A security-enabled local group was created) and 4742 (A computer account was changed). It summarizes the count of such changes per hour by the subject user name, which can help identify unusual or excessive account management activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of BITSAdmin to create or modify background intelligent transfer jobs. Attackers often abuse BITSAdmin to download malicious payloads (ingress tool transfer) or to execute commands when a transfer job completes or errors, which can be leveraged for persistence or arbitrary code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of regsvr32.exe with the /s (silent) and /u (unregister) flags to execute a remote scriptlet file (e.g., .sct, scrobj.dll) via HTTP, a common technique for proxy execution and bypassing application control mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects execution of Certutil.exe with arguments commonly used by adversaries for downloading files (urlcache) or decoding malicious payloads (decode/decodehex). These techniques are frequently used to bypass security controls and facilitate the delivery of secondary payloads or tools.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
301
Detects the use of administrative tools like wmic.exe, powershell.exe, or pwsh.exe to invoke WMI event subscription components such as ActiveScriptEventConsumer, CommandLineEventConsumer, or FilterToConsumerBinding. This behavior is a common technique for establishing persistence or elevating privileges by executing malicious code when specific system events occur.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
301
Detects the use of BITSAdmin to create or modify background intelligent transfer jobs. Attackers often abuse BITSAdmin to download malicious payloads (ingress tool transfer) or to execute commands when a transfer job completes or errors, which can be leveraged for persistence or arbitrary code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects execution of mshta.exe with command line arguments containing web-related indicators (http) or scripting engines (vbscript, javascript). This behavior is characteristic of adversaries using mshta.exe as a proxy to execute remote malicious payloads or inline scripts, effectively bypassing application controls and browser security contexts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the spawning of common command-line or script execution shells (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe) by the Windows Remote Management (WinRM) provider host (wsmprovhost.exe). This behavior is often indicative of remote code execution or lateral movement via WinRM.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001