avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,511 copies160 likes52,113 views

8,664 detections

Detects anomalous HTTP GET requests targeting the ClawHub API for 'skills' that match known patterns of malicious file downloads, specifically identifying poc.py scripts or skill.md files which are indicative of the ClawHavoc campaign activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects HTTP response bodies containing common PE/Shellcode magic headers (MZ, PE, or NOP sleds) which are associated with the delivery of payloads designed to exploit or utilize the Windows KernelCallbackTable for process injection. The detection focuses on suspicious content delivered over HTTP connections.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects usage of the Windows certutil.exe utility with flags commonly associated with malicious activity, including downloading files from remote URLs or decoding/encoding files within temporary or application data directories.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects the execution of vssadmin.exe or wmic.exe with command-line arguments intended to delete Volume Shadow Copies. This activity is a common indicator of ransomware or other destructive attacks aiming to inhibit system recovery.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects a high frequency of file rename or modification events targeting files with extensions commonly associated with ransomware. It filters out activity from processes signed by trusted vendors like Microsoft, Symantec, Sophos, and Trend Micro to reduce noise, flagging mass rename operations that could indicate an active ransomware encryption process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects usage of the Windows certutil.exe utility with flags commonly associated with malicious activity, including downloading files from remote URLs or decoding/encoding files within temporary or application data directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects attempts to access or copy the Active Directory domain database (NTDS.dit) by monitoring for direct file access to the file or the execution of ntdsutil.exe with arguments intended to create an Install From Media (IFM) set, which is a known technique for exfiltrating the NTDS.dit file for offline password cracking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of sc.exe with subcommands 'create' or 'start' where the command line includes a UNC path. This pattern is indicative of an adversary attempting to install or execute a service on a remote host to facilitate lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects attempts to extract the Security Account Manager (SAM) database, either by using the 'reg save' utility to export registry hives containing the SAM or by directly creating/modifying the SAM file on disk outside of known legitimate system processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of the PsExec service (PSEXESVC) or command-line usage indicating remote service execution, including the standard PsExec '-accepteula' flag combined with network path indicators. Additionally detects the creation of the PSEXESVC service registry key, which is indicative of PsExec-based lateral movement or remote administration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003