avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,513 copies160 likes52,123 views

8,664 detections

This rule detects attempts to delete Volume Shadow Copies (VSS) using native Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell. Attackers often perform this action during the impact phase to prevent file recovery after ransomware deployment or other data destruction activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects modifications to the WDigest UseLogonCredential registry value, which is a known technique to force Windows to store plaintext credentials in memory. This is often performed by adversaries using tools like Mimikatz to facilitate credential dumping from the LSASS process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the abuse of the Windows utility mshta.exe to execute potentially malicious scripts or remote HTML applications (HTA). The rule looks for command-line arguments involving remote URL fetches (HTTP/HTTPS/UNC) or inline script execution (vbscript/javascript), which are common techniques for bypassing security controls and executing payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or configuration of Windows services using sc.exe or PowerShell where the binary path points to suspicious, writable directories (Temp, AppData, or ProgramData). This behavior is often associated with persistence mechanisms where adversaries place malicious binaries in user-writable locations to execute with higher privileges.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects attempts to clear Windows event logs using the native command-line utility 'wevtutil' or PowerShell cmdlets 'Clear-EventLog' and 'Remove-EventLog'. Adversaries often perform this action to remove evidence of their activities from security, system, and application logs. The rule includes exclusions for common administrative, backup, and security-related processes to minimize false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects attempts to disable or modify Windows Firewall settings using netsh, PowerShell, or direct registry modifications. Adversaries often perform these actions to evade detection and maintain uninhibited network communication for C2 or data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects modifications or creation of 'StubPath' registry values within the 'Active Setup\Installed Components' registry key, where the value points to suspicious, user-writable directories. This technique is commonly used to establish persistence by executing a malicious file upon user logon.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects unauthorized or suspicious queries against Windows Registry paths known to contain sensitive information, including security hives (SAM, SECURITY), application-specific secrets (PuTTY, OpenSSH, RealVNC), and system autologon credentials. It monitors both command-line executions of 'reg.exe' and PowerShell commands targeting these registry keys.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of legitimate command-line utilities such as rclone, AWS CLI, AzCopy, curl, and wget to upload data to cloud storage endpoints, which is a common technique used for data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects attempts to disable the Windows Firewall using the netsh command-line utility or PowerShell cmdlets, as well as registry modifications related to firewall profiles. Adversaries often perform this action to impair host-based security controls and facilitate unauthorized inbound or outbound network traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001