avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,134 views

8,664 detections

This rule detects two suspicious activities within a user's mailbox: (1) An email flood, where a recipient receives more than 500 emails within a 5-minute window, potentially indicating an attempt to overwhelm or hide secondary emails; and (2) The creation or modification of inbox rules that include actions like deleting or moving messages, which is a common persistence and evasion technique used by attackers to hide C2 or phishing communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects instances where the WMI Provider Host process (WmiPrvSE.exe) spawns common interactive shells, scripting interpreters, or other binaries typically associated with remote command execution. This pattern is a strong indicator of WMI being abused for lateral movement or remote code execution within a Windows environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects potential email spoofing attempts by identifying mismatches between P1 (envelope) and P2 (header) sender addresses, identifying discrepancies between sender and reply-to domains, and flagging emails where the display name impersonates common executive or IT support roles.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects unauthorized attempts to enumerate stored Windows credentials using native command-line utilities such as vaultcmd.exe and cmdkey.exe, or by invoking CredEnumerate/Get-StoredCredential functions via PowerShell scripts. These methods are commonly used by attackers to gain access to cached passwords, tokens, or network credentials stored in the Windows Credential Manager.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Monitors GitHub audit logs for suspicious or high-risk activities within CI/CD pipelines, including actions triggered by forks, workflow approvals, branch policy overrides, self-hosted runner registration, and sensitive secret access.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
Detection rule monitoring for indicators of compromise related to SolarWinds Serv-U, including anomalous Content-Encoding headers, unexpected child process execution, large file staging indicative of data exfiltration (Cl0p-style), outbound exfiltration, SQL injection artifacts, and unauthorized LDAP/Active Directory object enumeration by the Serv-U process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects anomalous activity associated with information stealing malware, including unauthorized access to browser credential files (Login Data, Cookies), remote thread injection into browser processes, outbound connections to the Telegram API by non-browser processes, and rapid bulk access to multiple sensitive credential or crypto wallet files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects a multi-stage attack chain on macOS involving a browser or mail client spawning a shell to download a file (DMG) via curl/wget, followed by the mounting of that disk image, execution of an application bundle from the mounted volume, and a subsequent outbound network connection from that application. This behavior is indicative of a user-initiated malware execution chain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
Detects the use of legitimate administrative tools (regsvcs.exe, infinstall.exe, devcon.exe) being executed with command-line arguments indicative of driver or kernel-level installations (e.g., 'kernel', 'ring0', 'driver install'). This behavior is commonly associated with the installation of rootkits or the execution of Bring Your Own Vulnerable Driver (BYOVD) attacks to gain kernel-mode privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects FTP protocol traffic (on port 21) initiated by a process named 'squid.exe' or containing 'squid' in its filename. This rule is designed to identify potential exploitation attempts related to the Squidbleed vulnerability, where a compromised Squid proxy might be used for unauthorized FTP communications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
207