avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views

8,664 detections

This rule detects the use of PsExec or the Service Control Manager (sc.exe) to execute code remotely, which is a common technique used by attackers for lateral movement and remote code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of 'runas.exe' with the '/savecred' or '/netonly' parameters. The '/savecred' parameter allows the use of credentials previously stored in the credential manager, while '/netonly' allows the use of credentials for remote network resources without authenticating locally. Both flags can be abused by adversaries to persist or move laterally with compromised or cached credentials while evading local authentication monitoring. The rule excludes common system-signed processes originating from the Windows System32 directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects outbound TCP traffic originating from the internal network to external hosts on TCP port 45588, which is associated with Interlock ransomware beaconing behavior. This rule monitors for initial TCP SYN packets, characteristic of an outbound connection attempt potentially related to command-and-control activity following the exploitation of CVE-2026-20131.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP traffic initiating a WebSocket protocol upgrade with a specific 'binary' subprotocol header, characteristic of the Brickstorm backdoor used by the UNC5221 threat actor for command and control (C2) communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects HTTP traffic destined for the 1rpc.io Ethereum node gateway containing 'eth_call' in the request body, which is indicative of EtherRAT malware using blockchain infrastructure for command and control (C2) resolution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network traffic over SMB targeting the SYSVOL or NETLOGON network shares that includes the transfer or reference of common executable file extensions. This behavior is indicative of an adversary attempting to stage malicious payloads for deployment via Group Policy Objects (GPOs), a common method for lateral movement and persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects network traffic directed at 'goldsky.arweave.net', a domain known to be used by the TukTuk malware as a dead-drop resolver. Adversaries often use legitimate web services like Arweave to host command-and-control (C2) configuration data, such as secondary C2 IP addresses or domains, allowing them to redirect infected hosts to backend infrastructure while masking the traffic as legitimate web communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects outbound HTTP PUT requests to 'filen.io', which has been associated with command-and-control (C2) communication for the PRISMEX malware used by the threat actor APT28 (also known as Pawn Storm/Fancy Bear).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects DNS queries for domains ending in '.trycloudflare.com', which are commonly used to establish unauthorized remote access tunnels (Cloudflare Tunnel) by threat actors for C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP PUT requests directed at Wasabi Cloud Storage domains that originate from an Rclone user agent. This pattern is commonly indicative of data exfiltration activities where an attacker uses the Rclone utility to synchronize or upload sensitive data to unauthorized cloud storage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001