avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,109 views

8,664 detections

Detects the transmission of potential sensitive information, such as passwords, tokens, API keys, or private keys, within Microsoft Teams chat messages by matching message content against a regular expression pattern for common credential formats.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects the execution of VS Code Tunnel processes (code-tunnel.exe or code.exe with tunnel arguments) initiated by processes other than standard development-related parent processes (e.g., explorer, terminal, IDEs). This behavior may indicate an adversary attempting to establish persistent unauthorized remote access to a compromised host using the VS Code Tunnel functionality.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
504
Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the installation of Visual Studio Code extensions from sources other than the official Marketplace. This activity is monitored by checking process command line arguments for the --install-extension flag combined with external URLs or local file paths, which may indicate an attempt to install malicious extensions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects suspicious command-line execution originating from common web browsers. It identifies instances where a browser process launches a command-line interpreter (cmd, powershell, or wscript) and immediately invokes known download or utility commands (curl, iwr, bitsadmin, certutil), which is a common pattern for file-less or stage-two payload delivery from malicious websites.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
This rule detects the execution of common Python-based network relay and exploitation tools such as Impacket's ntlmrelayx, smbserver.py, and PetitPotam. These tools are frequently utilized by adversaries to conduct NTLM relay attacks, perform remote service execution, or facilitate credential dumping.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of known NTLM relay and coercion tools (such as PetitPotam, EfsPotato, PrinterBug, DFSCoerce, or Coercer) when attempting to coerce a local authentication or credential relay using the local loopback address. These tools leverage various RPC-based techniques to force the local machine to authenticate to an attacker-controlled source, facilitating NTLM relay attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects when the Python interpreter (python.exe or py.exe) initiates a network connection to an internal or loopback IP address. This behavior can be indicative of a local process scanning the internal network, pivoting, or interacting with locally running services as part of a post-exploitation or reconnaissance activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential token manipulation attacks using SMB loopback connections. The rule identifies processes executing with privileges commonly associated with token impersonation (SeImpersonatePrivilege, SeAssignPrimaryTokenPrivilege) or running as SYSTEM that are not expected system processes, correlated with an SMB network connection to the local loopback address on port 445.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects unauthorized file operations (Creation, Modification, Rename, Deletion) on sensitive browser-related credential files (e.g., Login Data, Cookies, key4.db) by potentially unauthorized or suspicious processes identified by name.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001