avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,132 views

8,664 detections

This rule detects instances where common productivity applications (like Office suite) or web browsers spawn child processes that create system mutexes. This is a common indicator of malicious activity where a benign-looking document or web-based threat launches secondary payloads or persistence mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects potential cloud resource hijacking (e.g., cryptojacking) by monitoring for a sudden spike in the deployment of Azure virtual machines by a single user. It triggers if a user creates five or more virtual machines in a 10-minute window, specifically looking for deployments in regions where the user has not recently created VMs, or deployments utilizing high-compute SKUs commonly targeted for cryptocurrency mining.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects potential Business Email Compromise (BEC) attempts by identifying emails containing financial keywords sent to sensitive finance/accounting roles from domains that have not been observed in the last 180 days. It then correlates this email event with subsequent device-level network activity involving banking or financial URLs initiated by the recipient user, which may indicate follow-up reconnaissance or unauthorized access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects the use of PowerShell to perform DNS lookups for TXT records followed by immediate command execution, such as using 'Invoke-Expression' or 'Start-Process'. This pattern is frequently indicative of fileless command-and-control (C2) communication where stage-payload commands or scripts are retrieved via DNS TXT records to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
This rule detects network connections on TCP ports 7000, 7001, 8770, and 5353 (commonly associated with Apple services like AirPlay, AirPrint, and Bonjour) initiated by processes other than standard Apple binaries such as iTunes, AppleMobileDeviceService, Bonjour, or mDNSResponder. This behavior may indicate an attempt to blend into expected network traffic by masquerading as legitimate Apple service communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects high volumes of network connections initiated by common file sharing processes such as AirDrop, sharingd, NearShare, or QuickShare. This behavioral pattern, characterized by a large number of successful connections or numerous unique remote IP addresses, may indicate unauthorized mass data collection, reconnaissance, or potential lateral movement attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
201
Detects the creation of user accounts or modifications to sensitive groups (Event IDs 4720, 4728, 4732, 4756) where the account name matches naming conventions typically associated with backup service accounts or elevated administrative roles (e.g., prefix 'backup_', 'bkp_' or suffix '_da', '_ea'). This activity can indicate an attacker attempting to establish persistence or escalate privileges via compromised or newly created accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the creation or modification of Windows Registry keys or values within the 'CurrentControlSet\Services' path that refer to 'rustdesk'. This typically indicates the installation or configuration of the RustDesk remote access tool as a system service, which may be unauthorized or used for persistence by an adversary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the creation of scheduled tasks using schtasks.exe that point to the ProgramData directory, which is a common persistence location for malware like SystemBC. The rule excludes common, benign software installers and updaters that frequently use this directory to avoid false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors web request URLs and associated messages for common SQL injection characters and sequences, such as quotes and semicolons. It specifically targets requests involving the 'apiuser' account to identify potential attempts to manipulate or exploit backend database queries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001