avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views

8,664 detections

This rule monitors process command line arguments for a combination of programming language interpreters (java, python, node, .NET, go) and keywords commonly associated with malware, payloads, shellcode, or injection techniques. This is intended to identify suspicious execution patterns that may indicate the staging or execution of malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects the loading of DLLs with suspicious names ('hook.dll', 'inject.dll', 'logger.dll', 'loader.dll') from common user-writable directories such as 'Temp', 'AppData', or 'Downloads'. These patterns are frequently associated with malware loaders, persistence mechanisms, or unauthorized code injection attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
Detects the use of PowerShell to modify Microsoft Defender preferences, specifically attempting to disable security features like Realtime Monitoring, IOAV protection, or Behavior Monitoring.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of processes containing command-line arguments associated with the Mimikatz post-exploitation tool, such as credential dumping, privilege escalation, and certificate manipulation keywords.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or modification of registry values within the AppCertDlls registry key. Adversaries use this technique to achieve persistence by forcing malicious DLLs to be loaded into every process that calls common Windows API functions such as CreateProcess.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential lateral movement activity where PowerShell or the Windows Remote Management (WinRM) host process (wsmprovhost.exe) initiates network connections to multiple distinct destination IP addresses over the WinRM default ports (5985/5986). This behavior is characteristic of an adversary using legitimate remote administration tools to pivot or spread across a network.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the use of the Windows net.exe or net1.exe utilities to add users to privileged groups such as 'Administrators' or 'Domain Admins'. This is a common technique used by attackers to achieve privilege escalation or establish persistence by modifying sensitive account group memberships.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of processes containing command-line arguments associated with the Mimikatz post-exploitation tool, such as credential dumping, privilege escalation, and certificate manipulation keywords.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the creation or modification of registry values within the AppCertDlls registry key. Adversaries use this technique to achieve persistence by forcing malicious DLLs to be loaded into every process that calls common Windows API functions such as CreateProcess.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of command-line tools associated with Kerberoasting and Kerberos ticket manipulation techniques, such as requesting TGS tickets or targeting specific user accounts for ticket extraction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001