avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,108 views

8,664 detections

Detects NTLM-authenticated network logons (Logon Type 3) originating from loopback IP addresses (127.0.0.1, ::1, or 0.0.0.0). This behavior is often associated with NTLM relay attacks or credential reflection bypass techniques where an adversary forces a local service to authenticate to itself to gain unauthorized access.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where privileged system processes such as lsass.exe or svchost.exe attempt a network connection to the local loopback address on ports other than standard SMB ports (445, 139). This pattern is indicative of potential coercion or relay attacks, specifically targeting the authentication mechanisms of these services to an attacker-controlled SMB server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of Python-based SMB server implementations commonly associated with the Impacket toolset. Impacket is frequently used by attackers to facilitate lateral movement, credential relay, and remote file manipulation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects outbound network connections from devices to known FortiBleed command and control (C2) servers and sniffer infrastructure IP addresses. This rule helps identify potential compromises involving the FortiBleed vulnerability exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
4010
Detects inbound network connections initiated by common Windows Nearby Sharing processes ('NearShare.exe', 'NearbySharing.exe', 'quickshare.exe', 'NearbyConnectionsService.exe') that occur on non-standard ports, potentially indicating unauthorized or malicious use of these utilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects Windows application crash events (Event IDs 1000 and 1001) specifically for 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. The detection triggers when the crash description contains indicators of memory-related instability, such as access violations, heap corruption, or invalid virtual calls, which may suggest exploitation attempts or service instability.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors for recurring application crashes involving 'NearShare.exe', 'NearbySharing.exe', or 'quickshare.exe' processes. Frequent crashes of these components may indicate instability, misconfiguration, or an attempt to exploit vulnerabilities within these specific file sharing services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects high frequency inbound network connection attempts or accepted connections initiated by common file sharing processes (e.g., NearShare.exe, NearbySharing.exe, quickshare.exe, sharingd, airplayd). A high volume of inbound connection attempts may indicate brute force, discovery, or malicious scanning behavior using legitimate file sharing tools as a conduit.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204