avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,131 views

8,664 detections

This rule detects suspicious staging activity by monitoring for the creation of 'editor.dat' files in sensitive directories like C:\Users\Public or C:\Windows\Tasks, or the rapid accumulation of multiple executable files (.exe, .dll, .cpl) within the C:\Users\Public directory, which is a common technique used by attackers to stage tools before execution or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects file creation or modification events associated with the Miasma campaign. It identifies specific payload files (e.g., .claude/setup.mjs, .vscode/tasks.json), the use of specific marker strings in file metadata or origin URLs, and obfuscated task configurations in VS Code directories that leverage bun or node to execute base64-encoded or character-encoded commands.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where the legitimate Windows utility 'Fondue.exe' (Features on Demand) loads the control panel library 'APPWIZ.cpl' from non-standard locations such as C:\Users\Public or AppData directories. It also identifies the staging phase where 'APPWIZ.cpl' is written to 'C:\Users\Public', which is indicative of a DLL side-loading attack sequence, often associated with the Elephant malware dropper.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential Command and Control (C2) communication associated with Emotet malware by monitoring for successful network connections to suspicious remote ports frequently used by the malware. The rule flags endpoints that establish connections to at least three of these high-risk ports within a one-hour window, which is indicative of automated C2 beaconing behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105
This rule detects potentially unauthorized installation of extensions in Visual Studio Code (VSIX) or plugins in JetBrains IDEs (IntelliJ, PyCharm, WebStorm). It flags installations that do not originate from verified official marketplaces, which may indicate the manual installation of malicious or supply-chain compromised development environment extensions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects outbound network connections from workstations or servers to common message broker ports (MQTT 1883/8883, AMQP 5672). These protocols are sometimes abused for command-and-control (C2) communication, as they allow for pub/sub messaging patterns that can blend into legitimate network traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects outbound network connections to common webhook and temporary storage services (e.g., discord.com webhooks, webhook.site, pipedream.net) initiated by processes other than standard web browsers. Such behavior is often indicative of automated data exfiltration, command-and-control (C2) communication, or malicious script activity using these services to bypass traditional network defenses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects potentially unauthorized installation of extensions in Visual Studio Code (VSIX) or plugins in JetBrains IDEs (IntelliJ, PyCharm, WebStorm). It flags installations that do not originate from verified official marketplaces, which may indicate the manual installation of malicious or supply-chain compromised development environment extensions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
Detects the use of PowerShell to perform DNS lookups for TXT records followed by immediate command execution, such as using 'Invoke-Expression' or 'Start-Process'. This pattern is frequently indicative of fileless command-and-control (C2) communication where stage-payload commands or scripts are retrieved via DNS TXT records to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the execution of Python interpreters spawned by code editors or runtime environments (e.g., VS Code, Cursor, Node.js) with specific command-line arguments involving 'init'. This behavior may indicate an adversary attempting to leverage development tools to execute custom scripts, potentially for automated deployment, persistence, or malicious payload initialization.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001