avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,137 views

8,664 detections

Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule monitors for inbound email messages containing SVG file attachments. SVG files can contain embedded scripts that may be leveraged for malicious purposes, such as SVG smuggling to deliver secondary payloads or perform credential harvesting.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects the installation of Visual Studio Code extensions from sources other than the official Marketplace. This activity is monitored by checking process command line arguments for the --install-extension flag combined with external URLs or local file paths, which may indicate an attempt to install malicious extensions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects the presence of Blackbeard malware by identifying known SHA256 hashes of its components or network connections to its known C2 infrastructure. It correlates file events with specific hashes and network events with specific remote IP addresses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects known malicious invoice PDFs and email samples used in Crimson Kingsnake campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential SSH brute force attacks by identifying multiple failed password attempts from a single source IP address to a specific computer within a 5-minute window. It specifically looks for 'Failed password' messages in syslog entries from the 'sshd' process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential SSH brute force attacks by monitoring syslog for multiple failed SSH login attempts, connection closures, or invalid user attempts from a single source IP address within a short time frame. It specifically looks for keywords like 'error', 'Connection closed', 'authentication failure', and 'invalid user' in SSHD logs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the loading of 'hostfxr.dll' from suspicious user-specific AppData folders by 'CrossDeviceService.exe' or 'Teams.exe'. This behavior can indicate an attempt to load a malicious .NET runtime, potentially for DLL hijacking or code injection, often associated with persistence or execution techniques.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001