avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views

8,664 detections

Detects Microsoft Office applications (Word, Excel, PowerPoint, Outlook, OneNote, Access, Publisher) spawning common command interpreters or scripting engines. This behavior is a common indicator of macro-based malware or malicious document exploitation where Office applications are used as an initial access vector to execute arbitrary code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects unauthorized attempts to create, modify, rename, or delete sensitive browser data files (such as Login Data, Cookies, key4.db, and logins.json) used for storing credentials. It monitors for access by processes that are not known browser executables or authorized system services, which is a common indicator of credential dumping by malicious software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects behaviors associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, including the dropping of .sys driver files into non-canonical directories, the registration and execution of kernel services via sc.exe, the use of fltMC to load filter drivers, and the loading of driver modules from non-standard locations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential SSH brute force attacks by identifying high-frequency authentication failures from sshd logs (more than 10 failures in 5 minutes) and rapid, potentially automated connection attempts on port 22 (more than 20 connections in 1 minute) originating from the same source IP on Linux systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell processes. The rule looks for known bypass strings, memory patching via Marshal, reflection-based disabling of AmsiUtils, or base64-encoded AMSI patch targets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where a digitally signed process loads a DLL file from a user-writable directory (e.g., AppData, Downloads, or Temp). This behavior is characteristic of DLL side-loading or search-order hijacking, where an adversary attempts to execute malicious code within the context of a trusted, signed application.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects execution of PowerShell processes (powershell.exe, pwsh.exe) containing command-line arguments indicative of Antimalware Scan Interface (AMSI) bypass attempts. This includes known bypass strings, reflection-based patching of memory internals (AmsiUtils, GetDelegateForFunctionPointer), and base64-encoded fragments of common bypass techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential command and control (C2) beaconing activity by identifying devices communicating with known suspicious remote IP addresses at regular, repeating intervals. It calculates the time difference between consecutive connections to specific suspicious IPs and identifies devices that establish at least three connections within one-hour bins, adhering to a 1 to 15-minute heartbeat interval.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
105
This rule detects potential AS-REP Roasting attacks by monitoring for Kerberos TGT requests (Event ID 4768) where Kerberos pre-authentication is disabled (PreAuthType == 0) and the ticket encryption type uses weak algorithms (RC4-HMAC or AES128). This behavior allows an attacker to request a ticket for an account and perform offline password cracking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects anomalous network connections or DNS queries to known Ethereum RPC infrastructure providers (Infura, Alchemy, Cloudflare-eth) or ports/domains associated with Ethereum mainnet activity. It specifically targets processes other than common browsers or known blockchain clients, as well as Java-based processes performing DNS lookups for these domains. This behavior is indicative of potential 'EtherHiding' techniques where malicious code or data is hidden within blockchain transactions or distributed via blockchain infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001