avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views

8,664 detections

This rule detects potentially malicious activity related to the 'node-gyp' build tool used by npm. It monitors for two patterns: 1) npm spawning node-gyp, which can be an automated trigger for malicious binding.gyp files, and 2) node-gyp spawning node.exe with command-line arguments indicative of obfuscated JavaScript (e.g., base64 encoding, eval, AES-GCM patterns), a technique often seen in malicious Node.js packages.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects a sequence of events where PowerShell is used to download files from 'nvidiadriver.net' or with filenames containing 'winPatch', followed by a suspicious file drop (specifically 'winPatch.zip' or 'update.vbs') in a temporary directory within a 30-minute window. This behavior is indicative of potential initial staging for a RAT or malicious script deployment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects network connections from internal hosts to identified C2 or phishing infrastructure associated with the threat actor group UNC1151 (also known as Ghostwriter). It monitors both host-based network events (via DeviceNetworkEvents) and centralized network security logs (via CommonSecurityLog) for traffic targeting a curated list of known malicious IP addresses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
601
This rule detects potential Remote Access Trojan (RAT) activity by identifying specific indicators associated with Nuitka-compiled binaries, specifically the 'chost.exe' filename or paths containing 'win-driver-xd7d'. Additionally, it monitors for suspicious Python-based loader executions ('loader.py') initiated from temporary directories, which is a common persistence or execution technique for such malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Microsoft Office applications (Word, Excel, PowerPoint, Outlook, OneNote, Access, Publisher) spawning common command interpreters or scripting engines. This behavior is a common indicator of macro-based malware or malicious document exploitation where Office applications are used as an initial access vector to execute arbitrary code.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential SSH brute force attacks by identifying high-frequency authentication failures from sshd logs (more than 10 failures in 5 minutes) and rapid, potentially automated connection attempts on port 22 (more than 20 connections in 1 minute) originating from the same source IP on Linux systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential defense evasion using common Windows LOLBins (Living off the Land Binaries) to execute code from untrusted locations or remote sources. Specifically targets mshta.exe loading remote HTA files, regsvr32.exe performing Squiblydoo-style COM scriptlet execution via URL, and rundll32.exe executing DLLs from user-writable directories like Temp or AppData.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell processes. The rule looks for known bypass strings, memory patching via Marshal, reflection-based disabling of AmsiUtils, or base64-encoded AMSI patch targets.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects execution of PowerShell processes (powershell.exe, pwsh.exe) containing command-line arguments indicative of Antimalware Scan Interface (AMSI) bypass attempts. This includes known bypass strings, reflection-based patching of memory internals (AmsiUtils, GetDelegateForFunctionPointer), and base64-encoded fragments of common bypass techniques.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects modification or creation of Windows Registry Run keys by non-Microsoft signed instances of reg.exe, powershell.exe, or pwsh.exe. This activity is a common method for achieving persistence by ensuring malicious code executes automatically upon user login.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001