avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,118 views

8,664 detections

Detects file operations (creation, modification, deletion, renaming) involving common SSH key files (id_rsa, id_ed25519) or files located within .ssh directories, initiated by processes typically associated with AI/LLM tools (chatgpt, perplexity, etc.) or generic process names. This may indicate an attempt to exfiltrate or manipulate authentication credentials by unauthorized applications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects unusual network connections or process creation events originating from the 'sharingd' daemon on macOS. 'sharingd' handles various Apple sharing features (AirDrop, Handoff, Shared Clipboard). Unusual child processes or network activity involving this daemon may indicate abuse for unauthorized data transfer, lateral movement, or remote service interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the loading of an unsigned DLL by 'quick_share.exe', 'NearbyShare.exe', or 'nearby_sharing.exe' from suspicious directory paths such as User Temp, AppData, or Downloads folders. This behavior is highly indicative of DLL side-loading attempts where an adversary leverages a legitimate, known process to execute malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects when the Python interpreter (python.exe or py.exe) initiates a network connection to an internal or loopback IP address. This behavior can be indicative of a local process scanning the internal network, pivoting, or interacting with locally running services as part of a post-exploitation or reconnaissance activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects instances where browser processes (chrome.exe, msedge.exe, brave.exe, firefox.exe) access clipboard-related APIs via Sysmon Event ID 10. This behavior is indicative of potential malicious or unauthorized clipboard interaction, such as sensitive data harvesting or clipboard manipulation by automated agents or scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects macOS 'sharingd' or 'Foundation' service crashes (stack overflow, recursion limit exceeded, or EXC_BAD_ACCESS) that occur during the processing of plist files. This behavior is indicative of potential memory corruption exploits targeting vulnerabilities in Apple's plist parsing logic, potentially exploited via AirDrop.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects outbound proxy traffic originating from identified AI and automation agent user-agents (e.g., ChatGPT, Perplexity, Claude, etc.) attempting to access sensitive URI paths, such as credential files, SSH keys, configuration files, or cloud-hosted secrets. This may indicate an attempt to exfiltrate sensitive data to or through AI platforms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects application crash events recorded in the Windows Application Event Log involving executables named 'quickshare.exe' or 'nearby.exe'.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule monitors network traffic for HTTP POST requests directed toward specific destination ports (443 or 8770) that return HTTP status codes in the 4xx range (client errors), excluding known legitimate URI paths. This pattern may indicate scanning activity, exploitation attempts, or unauthorized access attempts against internal services or misconfigured applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the transmission of plaintext 'OfflineFrame' protocol messages (such as CONNECTIONRESPONSE, BANDWIDTHUPGRADE, or KEEPALIVE) within the 'Nearby Connections' protocol that lack required encryption ('SecureMessage') after the UKEY2 key exchange phase. This behavior indicates a potential misconfiguration or an attempt to intercept/manipulate Nearby Connections traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001