avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views

8,664 detections

Detects DNS queries and network connection attempts to a set of known malicious domains associated with the threat actor UNC1151 (Ghostwriter). This rule monitors both DNS resolutions and direct network connection attempts to these indicators of compromise (IOCs), which are commonly used in spearphishing campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the activation of Android Accessibility Services by non-legitimate, potentially malicious applications. This behavior is commonly associated with banking trojans like Rokarolla that abuse accessibility permissions to perform UI automation, keystroke logging, and screen scraping.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential Command and Control (C2) communication activity by identifying instances of Domain Generation Algorithms (DGA). It monitors DNS query responses for patterns consisting of 8 to 16 lowercase alphabetic characters followed by common TLDs (com, net, org, ru, cc, su). An alert is triggered if 5 or more unique suspicious domains are queried by the same device within a one-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
Detects adversary activity consistent with credential dumping tools like KuinaExtractor. The rule monitors for the enumeration of Windows Credential Manager stores using vaultcmd /list or cmdkey /list, and the direct instantiation of the Windows PasswordVault via PowerShell, excluding system accounts and known legitimate applications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects Microsoft Excel (excel.exe) spawning child processes commonly used in post-exploitation scenarios, such as command shells, scripting interpreters, and living-off-the-land binaries. This behavior is indicative of potential exploitation of vulnerabilities like CVE-2025-60727 to achieve remote code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or loading of specific DLL files identified as part of the Turla STOCKSTAY malware framework. The rule monitors both file system operations (creation, modification, renaming) and process image loads to identify indicators of this specific campaign.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Python processes that combine potentially dangerous pickle deserialization (pickle.loads) with network-fetching libraries (urllib, requests, socket) and decoding methods (b64decode, fromhex). This pattern is consistent with backdoors or remote access tools (RATs) that fetch encoded payloads over the network and execute them directly in memory via deserialization.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects Python processes executing complex, multi-layered decoding chains (Base64, ROT13, and Hex) in their command line arguments. This pattern is often used by malicious AI skill backdoors, such as ClawHub, to obfuscate payload execution and evade signature-based detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious inter-process communication (IPC) attempts using WM_COPYDATA messaging, where processes (often script interpreters or unsigned binaries) interact with high-value GUI-based applications (like browsers or shell environments). This pattern is a common indicator of process injection techniques, such as hijacking existing Windows callbacks to execute code within the context of a target process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects host-based reconnaissance activity patterns indicative of Trickbot malware. The rule monitors for a high frequency (>= 4 unique commands within a 30-minute window) of diagnostic commands ('tasklist', 'systeminfo', 'ipconfig', 'net') executed by cmd.exe or powershell.exe, which is a common behavior pattern for adversary discovery processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104