avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views

8,664 detections

Detects successful authentication events from accounts identified as service, managed, or robot accounts (e.g., svc_, sa_, msol, robot) originating from external IP addresses or exhibiting an unusually high number of distinct source IP addresses. This behavior is indicative of potential credential theft, token replay attacks, or unauthorized usage of service account identities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the creation of suspicious named pipes by low-privilege processes, which is a technique used by local privilege escalation tools (like PrintSpoofer, RoguePotato, and GodPotato) to intercept and impersonate high-privilege (SYSTEM) tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects indicators of Adversary-in-the-Middle (AiTM) phishing infrastructure, specifically targeting Evilginx2 and similar proxy frameworks. It identifies unauthorized execution of Evilginx2 binaries, the presence of specific session and configuration files (.evilginx/, phishlets, session databases), unauthorized modifications to Nginx configurations, and the dropping of suspicious HTML lure files into web document roots by scripting interpreters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects the creation of scheduled tasks using the 'schtasks.exe' utility with command-line arguments indicating persistence triggers ('onlogon', 'onstart') or elevation to the 'SYSTEM' account. Adversaries commonly use these methods to ensure malicious code executes automatically upon system startup or with high privileges to facilitate further exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects unauthorized attempts to access or list stored credentials via Windows Credential Manager using standard administrative tools (cmdkey.exe, vaultcmd.exe) or PowerShell, as well as direct unauthorized access to credential storage files within the AppData directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the abuse of the CertUtil.exe Windows utility to download, decode, encode, or split files. This behavior is considered suspicious when initiated by common command-line shells or Office applications, which are frequently used as entry points for malicious scripts or macro-based attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects instances where common web server processes initiate command interpreters or system utilities. This behavior is a common indicator of web shell execution, where an adversary uses a web application vulnerability to gain remote code execution on the underlying server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects various techniques used by an attacker to escape a container environment or gain unauthorized access to host-level resources. This includes the execution of namespace manipulation tools (nsenter, unshare, chroot), unauthorized access to the docker.sock Unix socket, mounting of host filesystems from within a container, and direct attempts to access the host's /proc/1 namespace files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
201
This rule detects suspicious activity involving the BITSAdmin (bitsadmin.exe) utility, which is a known LOLBin (Living Off the Land Binary). It monitors for the creation of BITS jobs using suspicious flags (e.g., /transfer, /setnotifycmdline) potentially indicating external file downloads, as well as the execution of known command interpreters or utilities spawned as child processes by BITSAdmin, which is a common post-exploitation technique for persistence or secondary payload execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential PrintNightmare or Print Spooler exploitation by monitoring for the spoolsv.exe service spawning suspicious child processes (e.g., cmd, powershell, rundll32) and unauthorized files being dropped into the printer driver directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001