avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,149 views

8,664 detections

This rule detects when critical Windows services or processes associated with Active Directory (NTDS, Netlogon, LSASS, LDAP) or the Print Spooler (Spooler, spoolsv.exe) crash multiple times (3 or more) on a machine within a 7-day period. This could indicate instability, a denial-of-service attempt, or a system compromise affecting core services.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects an unusually high number of outbound network connections originating from the Local Security Authority Subsystem Service (LSASS) process on a Windows machine. LSASS is a critical system process responsible for enforcing security policy on the system, including user authentication, and typically does not initiate a large number of outbound connections. A high count of outbound connections from LSASS could indicate credential dumping activity, where an attacker is exfiltrating harvested credentials, or other malicious activity compromising the LSASS process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential unauthorized browser extension installations or debugging activities by monitoring process and network events related to popular web browsers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule monitors system logs for attempts to disable or stop the Linux Audit daemon (auditd) or modify its configuration via auditctl or system management commands (systemctl, service). Disabling the audit system is a common technique used by adversaries to hide malicious activity from security monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the creation or modification of a Registry Run key value named 'csshost'. This technique is commonly used by malware or persistent threats to achieve automatic execution upon system logon or boot by masquerading as or hijacking a host-related entry.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network connections to known command and control (C2) infrastructure associated with malicious NPM packages acting as Remote Access Trojans (RATs). The rule identifies specific outbound connections to a hardcoded malicious IP and port, as well as traffic involving a suspicious domain string.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects a sequence of events where PowerShell is used to download files from 'nvidiadriver.net' or with filenames containing 'winPatch', followed by a suspicious file drop (specifically 'winPatch.zip' or 'update.vbs') in a temporary directory within a 30-minute window. This behavior is indicative of potential initial staging for a RAT or malicious script deployment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential discovery activities indicative of a virtual machine or virtualization environment enumeration. It monitors for the execution of wmic.exe or powershell.exe triggered by suspicious parent processes (python.exe, chost.exe) that query hardware-specific identifiers like Manufacturer, Model, or MAC Address using Win32_ComputerSystem or Win32_NetworkAdapterConfiguration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the creation or modification of a Registry Run key value named 'csshost'. This technique is commonly used by malware or persistent threats to achieve automatic execution upon system logon or boot by masquerading as or hijacking a host-related entry.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects indicators of execution related to a known NPM Remote Access Trojan (RAT), including masquerading via chost.exe, execution from specific temporary directories used by the malware, and Python scripts executing a loader.py file from temporary locations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001