avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,133 views

8,664 detections

Detects unauthorized processes reading, copying, or renaming Kerberos ticket cache files (ccache) located in common temporary directories. This behavior is often associated with credential theft and potential Pass the Ticket attacks where adversaries attempt to extract session credentials to perform lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects malicious activity associated with Kimsuky JSE loaders, which leverage XML DOM manipulation (e.g., bin.base64) and ADODB.Stream components to decode and drop base64-encoded payloads into the ProgramData directory. It further monitors for subsequent decoding attempts using certutil and the presence of specific, suspicious file extensions (e.g., .a9oc, .lpXD, .lpxQ) often used by this threat actor.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of cmd.exe triggered by specific potentially malicious filenames or involving known ransomware-related artifacts, such as 'boottel.dat', ransomware note files, or specific suspicious file extensions like '.SZO'. This is indicative of ransomware deployment or post-compromise cleanup and extortion activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects anomalous activity where multiple distinct Living-off-the-Land (LotL) binaries (e.g., powershell.exe, cmd.exe, wmic.exe, tasklist.exe, systeminfo.exe) are executed on the same device within a single hour. This threshold of 4 unique administrative or discovery tools being used in a short timeframe is often indicative of reconnaissance, lateral movement, or post-exploitation environment assessment by an adversary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects potential DLL hijacking persistence by identifying modifications to registry values containing executable or library files that point to locations outside standard Windows system directories (System32 or SysWow64), subsequently joined with the execution of legitimate binary proxies known to be abused for side-loading like rundll32.exe or regsvcs.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
704
This rule detects multiple outbound network connections to a specific set of known malicious C2 IP addresses on specific ports within a one-hour window. This behavior is indicative of a multi-payload delivery pattern associated with malware families such as Remcos, Agent Tesla, and RedLine.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects potential data exfiltration attempts by monitoring for network connections to URLs containing suspicious substrings (bit, onion, .cc, .su) over common web and DNS ports (53, 80, 443, 8080). It flags high-frequency unique connection attempts from a single device, which may indicate command-and-control (C2) traffic or data exfiltration over covert channels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects the creation of image-related files with generic names in common temporary or user download directories that fall within a specific file size range (100KB-1000KB). These characteristics are often indicative of steganography where malicious payloads or data are embedded within seemingly benign image files to bypass security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects the use of wmic.exe to execute commands or manage remote systems, specifically flagging indicators of lateral movement, credential usage, or command execution like 'node', 'user', 'password', and 'call create'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects network activity associated with Cobalt Strike Beacon behavior by identifying specific file extensions (.bin, .stager, .update, .task, .post) commonly used in Beacon staging and communication profiles within network inspection events.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004