
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,118 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Detects file operations (creation, modification, deletion, renaming) involving common SSH key files (id_rsa, id_ed25519) or files located within .ssh directories, initiated by processes typically associated with AI/LLM tools (chatgpt, perplexity, etc.) or generic process names. This may indicate an attempt to exfiltrate or manipulate authentication credentials by unauthorized applications.
Detects unusual network connections or process creation events originating from the 'sharingd' daemon on macOS. 'sharingd' handles various Apple sharing features (AirDrop, Handoff, Shared Clipboard). Unusual child processes or network activity involving this daemon may indicate abuse for unauthorized data transfer, lateral movement, or remote service interaction.
Detects the loading of an unsigned DLL by 'quick_share.exe', 'NearbyShare.exe', or 'nearby_sharing.exe' from suspicious directory paths such as User Temp, AppData, or Downloads folders. This behavior is highly indicative of DLL side-loading attempts where an adversary leverages a legitimate, known process to execute malicious code.
This rule detects when the Python interpreter (python.exe or py.exe) initiates a network connection to an internal or loopback IP address. This behavior can be indicative of a local process scanning the internal network, pivoting, or interacting with locally running services as part of a post-exploitation or reconnaissance activity.
Detects instances where browser processes (chrome.exe, msedge.exe, brave.exe, firefox.exe) access clipboard-related APIs via Sysmon Event ID 10. This behavior is indicative of potential malicious or unauthorized clipboard interaction, such as sensitive data harvesting or clipboard manipulation by automated agents or scripts.
This rule detects macOS 'sharingd' or 'Foundation' service crashes (stack overflow, recursion limit exceeded, or EXC_BAD_ACCESS) that occur during the processing of plist files. This behavior is indicative of potential memory corruption exploits targeting vulnerabilities in Apple's plist parsing logic, potentially exploited via AirDrop.
Detects outbound proxy traffic originating from identified AI and automation agent user-agents (e.g., ChatGPT, Perplexity, Claude, etc.) attempting to access sensitive URI paths, such as credential files, SSH keys, configuration files, or cloud-hosted secrets. This may indicate an attempt to exfiltrate sensitive data to or through AI platforms.
Detects application crash events recorded in the Windows Application Event Log involving executables named 'quickshare.exe' or 'nearby.exe'.
This rule monitors network traffic for HTTP POST requests directed toward specific destination ports (443 or 8770) that return HTTP status codes in the 4xx range (client errors), excluding known legitimate URI paths. This pattern may indicate scanning activity, exploitation attempts, or unauthorized access attempts against internal services or misconfigured applications.
Detects the transmission of plaintext 'OfflineFrame' protocol messages (such as CONNECTIONRESPONSE, BANDWIDTHUPGRADE, or KEEPALIVE) within the 'Nearby Connections' protocol that lack required encryption ('SecureMessage') after the UKEY2 key exchange phase. This behavior indicates a potential misconfiguration or an attempt to intercept/manipulate Nearby Connections traffic.
