avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,141 views

8,664 detections

This rule detects attempts to bypass User Account Control (UAC) using specific Windows executables (eventviewer.exe, fodhelper.exe, computerdefaults.exe, slui.exe) initiated by cmd.exe or powershell.exe. The rule specifically looks for these executables being run from non-standard system directories, indicating a potential UAC bypass technique often observed after an initial compromise, such as via RDP.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
107
Detects the execution of known ransomware-related executables ('servertool.exe', 'encrypt.exe') when their command line arguments indicate interaction with cloud storage services such as OneDrive, SharePoint, GoogleDrive, Dropbox, or iCloud. This behavior is indicative of ransomware attempting to encrypt or exfiltrate data from cloud environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
207
This rule detects network connections on port 21 (FTP) where the remote URL contains keywords indicative of NetWare directory listings or related services (netware, NDS, bindery, ncf). This could indicate an attempt to discover or interact with NetWare services, potentially exploiting vulnerabilities like Squidbleed.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the creation or manipulation of mutexes by processes that contain keywords associated with the Remcos RAT (Remote Access Trojan). Specifically, it looks for command-line arguments containing "Remcos_Mutex_Inj", "Remcos_Mutex", "mutex", or "CreateMutex". This activity can indicate the presence or execution of Remcos RAT on a system, as mutexes are often used by malware for single-instance enforcement or inter-process communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential Command and Control (C2) communication associated with Emotet malware by monitoring for successful network connections to suspicious remote ports frequently used by the malware. The rule flags endpoints that establish connections to at least three of these high-risk ports within a one-hour window, which is indicative of automated C2 beaconing behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects network connections on port 21 (FTP) where the remote URL contains keywords indicative of NetWare directory listings or related services (netware, NDS, bindery, ncf). This could indicate an attempt to discover or interact with NetWare services, potentially exploiting vulnerabilities like Squidbleed.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential command and control (C2) beaconing activity by identifying devices communicating with known suspicious remote IP addresses at regular, repeating intervals. It calculates the time difference between consecutive connections to specific suspicious IPs and identifies devices that establish at least three connections within one-hour bins, adhering to a 1 to 15-minute heartbeat interval.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors Cisco Unified Communications Manager (UCM) environments for multiple stages of an attack chain, including potential Server-Side Request Forgery (SSRF) attempts against administrative interfaces, suspicious file modifications by service accounts, indicators of privilege escalation, and anomalous outbound network connections from core Cisco processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects anomalous device network activity involving 5G-specific protocol ports (e.g., GTP-U, SIP). The rule aggregates unique port usage per device over 1-hour intervals to identify potential network reconnaissance, scanning, or unauthorized control plane communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001