avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,118 views

8,664 detections

Detects network connections originating from a process and directed towards the local loopback interface (127.0.0.1 or ::1) on non-privileged, non-SMB ports (>= 1024 and != 445). This pattern can identify inter-process communication (IPC) over local network sockets which may be used by malware or malicious scripts to bypass security controls or communicate with local services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors Android system logs for suspicious activity related to the NearbyConnections API. It specifically flags incomplete UKEY2 handshakes, unauthenticated frame processing, and pre-authentication frame requests, which may indicate attempts to intercept or interfere with local device discovery and connection protocols.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects network logon events (Logon Type 3) using NTLM authentication where the source IP address is local (127.0.0.1 or ::1). This behavior can be indicative of attempts to interact with local services or perform lateral movement within the same host using credential-based techniques such as 'Pass-the-Hash' or unauthorized access to local resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the spawning of administrative command-line utilities (cmd.exe, powershell.exe, wscript.exe, certutil.exe, mshta.exe) from processes related to Wyse Management Suite (WMS), Tomcat, or Java. This pattern is often indicative of exploitation of web applications or management services to gain command-line access on the underlying system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects instances where Microsoft Excel (excel.exe) acts as a parent process for suspicious child processes, including command-line interpreters (cmd.exe, powershell.exe), scripting hosts (wscript.exe, cscript.exe, mshta.exe), or binary proxies (rundll32.exe, regsvr32.exe). This pattern is commonly associated with weaponized office documents executing malicious payloads via macros or other embedded scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the execution of processes in CI/CD environments (such as runners, Jenkins, or GitLab) where the environment variable 'GEMINI_TRUST_WORKSPACE' is explicitly set to 'true'. This configuration is often used to grant elevated trust or access to workspace files during CI/CD workflows, which could be abused by an attacker to execute arbitrary code or access sensitive data if they can control the pipeline execution or workspace state.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects suspicious execution of Python or shell scripts (bash, zsh, sh) from paths associated with 'openclaw' or 'clawhub' that are interacting with sensitive data files, including browser credential stores (Chrome, Firefox, Edge, Brave), system keychains, and cryptocurrency wallet files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects HTTP POST requests containing the specific string 'GEMINI_TRUST_WORKSPACE', which is associated with environment variable injection attacks targeting CI/CD pipeline configurations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential Remote Code Execution (RCE) exploitation attempts targeting Dell Wyse Management Suite (WMS) by identifying abnormally large POST requests containing JSON payloads directed at specific management paths (/WMS/ or /wyse/). This behavior is indicative of an exploit attempt against CVE-2026-41120.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP traffic attempting to upgrade a connection to a WebSocket protocol directed towards the known Turla-associated command-and-control infrastructure 'driverx86-adobe.onrender.com'. This pattern is characteristic of the STOCKBROKER component within the STOCKSTAY malware framework, observed in recent phishing campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001