avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views

8,664 detections

Detects high volumes of network connections initiated by common file sharing processes such as AirDrop, sharingd, NearShare, or QuickShare. This behavioral pattern, characterized by a large number of successful connections or numerous unique remote IP addresses, may indicate unauthorized mass data collection, reconnaissance, or potential lateral movement attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects successful outbound network connections from an endpoint to a known Tor directory authority IP address. Establishing a connection to these authorities is a strong indicator that the system is attempting to join the Tor network or is interacting with Tor infrastructure, which may be unauthorized in enterprise environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances of rundll32.exe being executed with command-line arguments that suggest malicious activity, specifically loading modules from remote UNC paths, using the javascript: protocol, or explicitly invoking ShellExec_RunDLL via shell32.dll. This rule filters out legitimate signed Microsoft binaries to focus on potentially unauthorized or malicious proxies.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of MAVInject.exe (Microsoft Application Virtualization Injector) with the /INJECTRUNNING parameter, a technique used to inject malicious code into a running process to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the use of native Windows binaries 'netsh.exe' to establish port proxies or 'pktmon.exe' for network packet monitoring/filtering by processes that are not signed by Microsoft. This behavior is indicative of network tunneling or C2 communication techniques used by actors such as Volt Typhoon to maintain persistence and establish network pivots.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects the creation, reading, or execution of payloads stored within NTFS Alternate Data Streams (ADS). This technique is commonly used by adversaries to hide malicious content within file metadata to evade security tools. The rule monitors process command-line arguments for ADS syntax, identifies usage of utilities like type, Get-Content, wmic, or various LOLBins (e.g., regsvr32, rundll32) interacting with ADS paths, and flags anomalous file creation/modification events that involve ADS, excluding known system-generated streams.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects unauthorized processes attempting to access or perform operations on sensitive files such as browser credentials, SSH keys, crypto wallets, and password manager databases. The rule specifically looks for non-standard or unsigned processes interacting with a high volume of these files in a short time frame, which is indicative of credential harvesting by infostealer malware like Lumma, Redline, or Vidar.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the creation of scheduled tasks using schtasks.exe that exhibit suspicious characteristics. This includes tasks referencing external URLs, those containing base64-encoded or obfuscated command strings, and tasks pointing to binaries or scripts in user-writable paths (e.g., AppData, Temp). The rule specifically targets tasks intended to run with SYSTEM privileges or those using common persistence triggers, while excluding known legitimate administrative software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects outbound network connections to common webhook and temporary storage services (e.g., discord.com webhooks, webhook.site, pipedream.net) initiated by processes other than standard web browsers. Such behavior is often indicative of automated data exfiltration, command-and-control (C2) communication, or malicious script activity using these services to bypass traditional network defenses.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects attempts to terminate security-related processes or stop security services using common Windows command-line utilities such as taskkill, tskill, or the net stop command. This behavior is indicative of an adversary attempting to impair defensive measures on a compromised system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003