avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views

8,664 detections

Detects the spawning of administrative command-line utilities (cmd.exe, powershell.exe, wscript.exe, certutil.exe, mshta.exe) from processes related to Wyse Management Suite (WMS), Tomcat, or Java. This pattern is often indicative of exploitation of web applications or management services to gain command-line access on the underlying system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of a process named 'gemini.exe' with the '--yolo' command-line argument when spawned by common CI/CD runner processes such as 'actions-runner', 'runner.worker', 'node', or 'npm'. This pattern may indicate unauthorized use of execution environments or potential exploitation of a CI/CD pipeline to run suspicious tools.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects network activity involving known suspicious domains and the download of specific, potentially malicious files (archives and installers). The monitoring focuses on HTTP/proxy/DNS traffic where hostnames, URLs, or query parameters match indicators of malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects processes that load .NET-related modules (clr.dll or dotnet.exe) and maintain a network connection (port 80 or 443) for more than one hour during standard business hours. This behavior is indicative of potentially persistent, long-running .NET-based applications or potentially malicious tools maintaining persistence and C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP traffic patterns associated with the Turla STOCKSTAY malware establishing a WebSocket connection to the known C2 domain 'wool-basalt-clock.glitch.me'. The rule monitors for a GET request containing specific HTTP headers (Upgrade: websocket) required for protocol switching to WebSocket, which is a common technique for establishing persistent C2 channels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects outbound HTTP traffic generated by the WinHTTP library, specifically when the User-Agent identifies as WinHttp.WinHttpRequest. This pattern is indicative of potential post-exploitation activity, such as command-and-control communication or data exfiltration, originating from a process associated with an exploited Excel document (CVE-2025-60727).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects attempts to exploit a path traversal vulnerability (CVE-2026-49506) in the Dell Wyse Management Suite API. The rule inspects HTTP requests for directory traversal sequences such as '..' or URL-encoded equivalents, which could allow an unauthorized attacker to access files or directories outside the intended scope on the web server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects HTTP GET requests for specific malicious archives (calculator.rar, EditorToolsPdf.zip) originating from suspected compromised Ukrainian domains (basecon.com.ua, online.zp.ua). This behavior is associated with the STOCKSTAY malware used by the threat actor Turla.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects web traffic where the referrer header contains keywords associated with gaming or educational themes (such as 'bioshock', 'game', 'puzzle', 'math', 'quiz') combined with access attempts to sensitive URI paths (like '/code', '/token', '/secret', '/private', '/api-key') resulting in a redirect status (301-308). This behavior pattern is often indicative of automated reconnaissance or exploitation attempts using non-standard or obfuscated referrers to bypass simple security filters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the use of 'net.exe' or 'net1.exe' to configure a non-standard SMB port, which is a technique often used for NTLM reflection and relay attacks. By specifying an arbitrary port for SMB traffic, an attacker may attempt to bypass standard network filtering or establish a listener to intercept authentication requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001