avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,137 views

8,664 detections

This rule detects potentially malicious lateral movement or persistence activities by monitoring the creation or modification of executable files in remote network shares and startup folders, as well as the use of administrative tools like sc.exe or schtasks.exe to create services or tasks. The rule specifically filters out processes signed by Microsoft, focusing on non-standard or unsigned binaries that perform these administrative actions across multiple instances, indicating potential automated lateral propagation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects a network-connected Linux process exhibiting beaconing behavior (high-frequency external connections) that is subsequently correlated with unauthorized file access to sensitive Linux configuration files (/etc/passwd, /etc/shadow, or authorized_keys). This rule filters out common system processes and standard management binaries, targeting suspicious command-and-control activity combined with credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects Python or Node.js processes executing command-line interpreters (e.g., cmd.exe, bash) while simultaneously performing network connections. This behavior is indicative of a post-exploitation activity where an attacker leverages language-specific package paths to execute shell commands and establish command-and-control communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects a high frequency of successful network connections from a single device to multiple unique destination IP addresses within a one-hour window. The targeted ports (445, 139, 3389, 22, 21) are commonly used for remote administrative access, file transfers, and remote shell services, which are frequently leveraged by adversaries for lateral movement. The threshold of 3 unique targets in an hour may indicate automated scanning or credential brute-forcing activity across the network.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
405
This rule detects the creation or modification of scheduled tasks using utilities like schtasks.exe or at.exe that are followed by the execution of script-based interpreters (PowerShell, CMD, or WScript). This pattern is commonly indicative of an attacker establishing persistence by scheduling malicious scripts to run automatically.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects command-line activity containing keywords related to API hooking (e.g., SetWindowsHookEx, hook, inline, trampoline) initiated by common scripting interpreters like powershell.exe, cmd.exe, or rundll32.exe. This pattern is often associated with malware attempting to inject code or capture data by intercepting process function calls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects command lines that reference known supply chain attack targets or commonly used package management tools like npm and pypi, which can be indicators of supply chain compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
205
This rule detects the execution or file interaction of known local AI/Large Language Model tools (e.g., Ollama, LM Studio, GPT4All) when initiated by non-interactive system processes (such as services.exe, svchost.exe, or lsass.exe) or under system/network service account contexts. This behavior is indicative of unauthorized local model staging or enumeration within a compromised environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule correlates rapid file modifications (potential encryption or mass deletion) with the execution of commands known to inhibit system recovery (e.g., deleting shadow copies or modifying boot recovery settings) and significant outbound network data transfers from the same host. This pattern is characteristic of ransomware deployment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects outbound network connections to major Large Language Model (LLM) API endpoints (OpenAI, Google, Anthropic) initiated by processes not explicitly identified as standard web browsers or command-line utilities. This pattern may indicate automated data exfiltration ('prompt stealing' or unauthorized access to corporate data) using custom or malicious tools executing from suspicious directories like temp, appdata, or public folders.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004