avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,118 views

8,664 detections

Detects a specific network handshake pattern (05 01 00) associated with the SystemBC malware acting as a SOCKS5 proxy. This pattern is characteristic of the initial communication phase used by SystemBC to establish C2 connectivity, often utilized by ransomware affiliates.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects outbound TCP traffic from internal network hosts to known Tor relay ports (9001, 9030), which is a common communication pattern for the NBLock ransomware strain to establish a command and control channel through the Tor network.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP traffic destined for the 1rpc.io Ethereum node gateway containing 'eth_call' in the request body, which is indicative of EtherRAT malware using blockchain infrastructure for command and control (C2) resolution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network traffic over SMB targeting the SYSVOL or NETLOGON network shares that includes the transfer or reference of common executable file extensions. This behavior is indicative of an adversary attempting to stage malicious payloads for deployment via Group Policy Objects (GPOs), a common method for lateral movement and persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects suspicious remote thread creation events (Sysmon Event ID 8) where a process initiates a thread in high-value system processes like lsass.exe, svchost.exe, explorer.exe, or winlogon.exe. It specifically filters out activity originating from common Windows system directories, highlighting potential process injection attempts by unauthorized binaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects instances where a process loads a DLL from suspicious, commonly user-writable directories (such as Temp, AppData, ProgramData, or Public). It filters for DLLs that lack standard file metadata (FileVersion/Description) or contain an OriginalFileName mismatch, which is often indicative of side-loading or malicious library injection. The rule further correlates this event with a network connection initiated by the same process to highlight potential C2 activity associated with the suspicious DLL load.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential mass emailing or spam activity by identifying instances where a single email account sends more than 100 emails within a one-minute window. This behavior is often characteristic of compromised accounts performing phishing campaigns or bulk unauthorized communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of the 'netsh interface portproxy' command to set up a port forwarding rule where the connection address is outside of common private IP ranges. This behavior is frequently associated with attackers establishing persistent network pivots or internal proxies to redirect C2 traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects processes accessing registry keys associated with common cryptocurrency wallets (e.g., Electrum, Exodus, MetaMask, Ledger) that are not the legitimate wallet applications themselves. This behavior is indicative of unauthorized attempts to extract sensitive wallet information, such as configuration, seeds, or keys, stored in the Windows Registry.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects instances where a process loads a DLL from suspicious, commonly user-writable directories (such as Temp, AppData, ProgramData, or Public). It filters for DLLs that lack standard file metadata (FileVersion/Description) or contain an OriginalFileName mismatch, which is often indicative of side-loading or malicious library injection. The rule further correlates this event with a network connection initiated by the same process to highlight potential C2 activity associated with the suspicious DLL load.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001