avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,515 copies160 likes52,144 views

8,664 detections

Detects processes containing sensitive credential-related keywords (cookies, creds, password, token) in their command lines followed by a network connection to known suspicious remote IP addresses within a 60-minute window, suggesting potential credential exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
Detects potential DLL hijacking persistence by identifying modifications to registry values containing executable or library files that point to locations outside standard Windows system directories (System32 or SysWow64), subsequently joined with the execution of legitimate binary proxies known to be abused for side-loading like rundll32.exe or regsvcs.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
This rule detects potential command and control (C2) beaconing activity associated with Mythic implants. It monitors for high-frequency outbound connections (20 or more) from a single device to the same external IP address within a 30-minute window across common C2 listener ports (80, 443, 8080, 8443, 7443).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects outbound network connections to a known KuinaExtractor (k0to) infostealer C2 server. The rule monitors DeviceNetworkEvents for connections to the malicious IP address 103.229.53.18 on port 3000 and correlates them with process information to identify the originating application.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the KuinaExtractor UAC bypass technique, which exploits the auto-elevated 'SilentCleanup' scheduled task. The rule identifies suspicious activity via two patterns: the execution of 'cleanmgr.exe' from an unexpected parent process (bypassing normal task scheduler invocation) or the explicit execution of 'schtasks.exe' to trigger the 'SilentCleanup' task.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects attempts to disable or impair Microsoft Defender Antivirus using legitimate system administration tools such as PowerShell (Set-MpPreference, Add-MpPreference), WMIC, sc.exe, or net.exe. Adversaries may use these tools to bypass security controls by disabling real-time monitoring or adding unauthorized exclusion paths.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the activation of Android Accessibility Services by non-legitimate, potentially malicious applications. This behavior is commonly associated with banking trojans like Rokarolla that abuse accessibility permissions to perform UI automation, keystroke logging, and screen scraping.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects when the default SMS application on an Android device is changed to an application that is not recognized as a trusted SMS provider. This behavior is often indicative of malicious applications attempting to intercept incoming SMS messages, such as those containing multi-factor authentication (MFA) codes, by positioning themselves as the system's primary handler for SMS communications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects adversary activity consistent with credential dumping tools like KuinaExtractor. The rule monitors for the enumeration of Windows Credential Manager stores using vaultcmd /list or cmdkey /list, and the direct instantiation of the Windows PasswordVault via PowerShell, excluding system accounts and known legitimate applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects reconnaissance behavior associated with the KuinaExtractor tool, identified by three or more distinct WMI hardware-related queries (CPU, disk, memory, etc.) executed within a 5-minute window by a non-administrative parent process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001