avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views

8,664 detections

Detects the use of the 'netsh interface portproxy' command to set up a port forwarding rule where the connection address is outside of common private IP ranges. This behavior is frequently associated with attackers establishing persistent network pivots or internal proxies to redirect C2 traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects modifications to sensitive Windows Registry keys under HKLM\SOFTWARE\Microsoft\Cryptography, such as Providers, OID, Trust, and Protectedroots. These keys control cryptographic services and trust stores on Windows systems. Modifications by non-system processes or accounts may indicate attempts to subvert trust controls, install rogue root certificates, or tamper with system-level security providers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects artifacts related to the ValleyRAT malware family, specifically identifying markers such as 'Phantom Persistence Module', 'RegisterApplicationRestart', and specific 'RSL_' strings within process command lines, image paths, or module loads using Windows Event Logs and Sysmon data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects outbound network connections to common Large Language Model (LLM) APIs (OpenAI, Anthropic, Google) or local LLM instances (Ollama) from processes that are not standard web browsers, common IDEs, or typical development/scripting tools. This behavior may indicate an attempt to exfiltrate sensitive data or interact with LLM services using unauthorized or hidden processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects a suspicious spike in Microsoft Teams external meeting or chat invitations directed at a single user within a 30-minute window. This behavior is consistent with UNC6692 tactics, where attackers impersonate internal IT helpdesk staff via Teams to perform vishing and social engineering attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects processes that execute and remain dormant for more than 120 seconds before performing a high volume of file operations (greater than 50) or initiating a high volume of network connections (greater than 20). This pattern is consistent with malware or beaconing implants attempting to evade detection during automated sandbox analysis.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where Windows NearShare or QuickShare utilities spawn child processes that are not part of their standard operational or helper suite (e.g., conhost.exe, WerFault.exe, svchost.exe). This pattern is often indicative of process injection, living-off-the-land techniques, or unauthorized activity masquerading as legitimate Windows sharing services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network connection attempts or successes from critical Windows processes (System, svchost.exe, lsass.exe) targeting the localhost interface (127.0.0.1 or ::1) on non-standard ports (above 1024, excluding SMB ports 445/139). This behavior is often indicative of local process injection, credential dumping activity, or unauthorized inter-process communication used by malware to bypass network security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where Windows NearShare or QuickShare utilities spawn child processes that are not part of their standard operational or helper suite (e.g., conhost.exe, WerFault.exe, svchost.exe). This pattern is often indicative of process injection, living-off-the-land techniques, or unauthorized activity masquerading as legitimate Windows sharing services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects Windows application crash events (Event IDs 1000 and 1001) specifically for 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. The detection triggers when the crash description contains indicators of memory-related instability, such as access violations, heap corruption, or invalid virtual calls, which may suggest exploitation attempts or service instability.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001