avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views

8,664 detections

Detects suspicious modifications to Registry Run and RunOnce keys that include common scripting or command execution keywords (powershell, cmd, .bat). This activity is often associated with persistence mechanisms where adversaries attempt to execute malicious code upon user login.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects attempts to delete volume shadow copies using 'vssadmin' or 'wmic shadowcopy' commands. Adversaries often delete shadow copies to prevent system recovery and hinder forensic analysis, especially during ransomware attacks or data destruction efforts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects suspicious execution of wmic.exe where the command line contains keywords often associated with enumeration or manipulation of processes and services. This can indicate an adversary using WMI for discovery or execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects the installation of new Windows services (EventID 7045) where the service's executable path (ServiceFileName) contains common scripting interpreters like 'cmd', 'powershell', or 'wscript'. This pattern can indicate an adversary attempting to establish persistence or execute malicious code via a newly created service that leverages scripting capabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects the creation or modification of scheduled tasks (EventID 4698 or 4699) where the command line for the task contains references to scripting languages like PowerShell, cmd, or VBScript. It then groups these events by computer and user, flagging if two or more such tasks are created by the same user on the same computer, which could indicate malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
801
This rule detects potential brute force attacks against Azure AD accounts by identifying users with 10 or more failed sign-in attempts due to invalid credentials within a 5-minute window. It summarizes the failure count and associated IP addresses for each user.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects multiple failed Kerberos pre-authentication attempts (EventID 4771 with status codes 0x18 or 0x1f) from a single IP address against a target user within a short timeframe (20 attempts in 5 minutes). This pattern is indicative of a brute-force attack against Kerberos accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects when five or more driver-related files (.inf, .sys, or .drv) are created or modified within a one-hour window by the same initiating process account. This behavior can be indicative of malicious driver installation, rootkit activity, or other forms of persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential vulnerability scanning activity by identifying multiple network connection attempts to common vulnerable ports (135, 139, 445) where the remote URL contains keywords like 'vuln' or 'scan'. It aggregates these activities by device and time, flagging devices with 5 or more such connections within an hour.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the creation of files containing keywords such as 'vulnerability', 'assessment', or 'scan'. This rule aims to identify activities related to vulnerability scanning or security assessments being performed on a system, potentially indicating reconnaissance or unauthorized activity. The events are summarized by the initiating process account name and time to help identify the source of these activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001