avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,139 views

8,664 detections

This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential ransomware lateral movement patterns by correlating specific network connection attempts (SMB/RDP/RPC) with the observed creation of files having the '.prinzeugen' extension on the same host within a 2-hour window. This behavior is indicative of a ransomware strain propagating across the network and performing encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the creation or manipulation of mutexes by processes that contain keywords associated with the Remcos RAT (Remote Access Trojan). Specifically, it looks for command-line arguments containing "Remcos_Mutex_Inj", "Remcos_Mutex", "mutex", or "CreateMutex". This activity can indicate the presence or execution of Remcos RAT on a system, as mutexes are often used by malware for single-instance enforcement or inter-process communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially malicious activity related to the 'node-gyp' build tool used by npm. It monitors for two patterns: 1) npm spawning node-gyp, which can be an automated trigger for malicious binding.gyp files, and 2) node-gyp spawning node.exe with command-line arguments indicative of obfuscated JavaScript (e.g., base64 encoding, eval, AES-GCM patterns), a technique often seen in malicious Node.js packages.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects rapid access (three or more distinct files within a 60-second window) to sensitive files typically containing credentials or configuration data (e.g., SSH keys, AWS credentials, environment files, container configurations). This pattern is often associated with credential dumping or reconnaissance activity by an adversary attempting to harvest secrets.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the creation or configuration of a scheduled task named 'GoogleErrorReport' which references 'Fondue.exe' located in the 'C:\Users\Public' directory. This specific pattern is associated with 'Dropping Elephant' malware persistence, where the task ensures the binary executes persistently on the host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where the legitimate Windows utility 'Fondue.exe' (Features on Demand) loads the control panel library 'APPWIZ.cpl' from non-standard locations such as C:\Users\Public or AppData directories. It also identifies the staging phase where 'APPWIZ.cpl' is written to 'C:\Users\Public', which is indicative of a DLL side-loading attack sequence, often associated with the Elephant malware dropper.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of PowerShell with suspicious download-related commands (Invoke-WebRequest, DownloadFile, WebClient, IEX, DownloadString) when initiated through conhost.exe, specifically when the originating parent process is a common shell or utility associated with shortcut (.lnk) file execution or specific command patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects suspicious activity related to GitHub Actions workflows, including the creation or modification of workflow configuration files, the placement of suspicious JavaScript files in the repository's .github directory, the execution of the 'Bun' runtime within an Actions runner environment, and cloud-based events indicating workflow modification containing 'Run Copilot' strings. These patterns are often associated with CI/CD pipeline compromise, malicious automation, or unauthorized code execution within build environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects command-line activity containing keywords associated with process injection or hollowing techniques (e.g., shellcode, inject, hollow, replace) when executed by common script interpreters targeting critical system processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004