avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,139 views

8,664 detections

Detects when a non-root user modifies, creates, or renames files within common cron directories or the main crontab file on Linux systems. This activity can indicate an attempt to establish persistence or schedule malicious tasks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
006
This rule detects network connections to phishing pages hosted on the workers.dev domain that are attempting to interact with EvilTokens device code API endpoints. These pages are known to implement developer hotkey prevention (F12 blocked, context menu disabled) to hinder in-browser analysis, indicating malicious intent.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
206
This rule detects the creation of user namespaces on Linux systems by unprivileged users. The 'unshare' command with '--user' or '-U' flags allows a process to move into a new user namespace, which can be abused for privilege escalation or container escape. The rule specifically excludes common container runtimes and processes running as 'root' to reduce false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
006
This rule detects attempts to tamper with critical Linux log files such as /var/log/auth.log, /var/log/syslog, and /var/log/audit/audit.log. It specifically looks for file deletion or modification events, or process creation events that involve commands like 'rm', 'shred', 'truncate', 'unlink', or 'dd' targeting these log files. Legitimate processes like 'logrotate', 'rsyslog', 'syslog-ng', 'auditd', 'systemd', and 'journald' are excluded to reduce false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
206
This rule detects a sequence of events indicative of ransomware deployment following a successful Remote Desktop Protocol (RDP) connection. Specifically, it looks for an inbound RDP connection (RemotePort 3389) to a device, followed within 60 minutes by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') on the same device. This pattern suggests an attacker gaining initial access or moving laterally via RDP and then deploying ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
508
Detects instances of FTP transfer mode switching (ASCII/Binary) by monitoring network events for FTP traffic on port 21 and specific commands like 'TYPE A' or 'TYPE I' in the RemoteUrl. This behavior can be indicative of data transfer activities, potentially related to vulnerabilities or malicious data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
006
Detects the execution of Mimikatz or its common command-line arguments used for credential dumping. This rule identifies attempts to extract sensitive authentication material such as passwords, hashes, and tickets from memory (LSASS), SAM database, LSA secrets, and cached domain credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
506
This rule detects instances where the WhatsApp Desktop application (WhatsApp.exe) spawns suspicious child processes commonly used for scripting or command execution, such as wscript.exe, cscript.exe, powershell.exe, cmd.exe, or rundll32.exe. It specifically excludes known legitimate update and service-related command lines to reduce false positives. This behavior could indicate a phishing attempt or malware execution originating from a compromised WhatsApp session.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
008
Detects attempts to exploit the Squidbleed vulnerability by monitoring 'squid.exe' process command lines for keywords related to FTP default configuration exploitation, specifically 'Safe_ports', 'CONNECT', 'PORT', 'PASV', '21', and 'tcp_outgoing_address'. This indicates an adversary trying to bypass security controls or exfiltrate data via FTP.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
207
Detects process command lines containing keywords associated with resource extraction, decryption, or decompression, specifically when initiated by 'GST*.com' or involving 'Optimax.dll'. This behavior is indicative of a Remcos RAT loader attempting to unpack or prepare its payload.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
107