avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views

8,664 detections

Detects the use of the Windows net.exe or net1.exe utilities to add users to privileged groups such as 'Administrators' or 'Domain Admins'. This is a common technique used by attackers to achieve privilege escalation or establish persistence by modifying sensitive account group memberships.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects command line patterns associated with Cobalt Strike Beacon injection, specifically looking for indicators of 'beacon.dll', 'beacon.exe', or 'injection' strings being executed by suspicious parent processes such as explorer.exe, svchost.exe, or winlogon.exe. This activity is indicative of post-exploitation behavior and potential lateral movement or persistence attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
204
Detects the execution of 'wevtutil.exe' with the 'cl' or 'clear-log' arguments targeted at primary Windows Event Logs (Security, System, or Application). This activity is commonly associated with an adversary attempting to clear audit logs to conceal malicious actions during an intrusion.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of common archive utilities (7-Zip, WinRAR) to perform file archiving operations within sensitive user-profile directories (Desktop, Documents, Downloads, etc.). This pattern is often used by adversaries to stage or bundle sensitive data prior to exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of 'cmd.exe' with a command line that includes 'ping 127.0.0.1' combined with a file deletion command ('del', 'delete', 'erase'). This pattern is often used by malware, such as ransomware, to introduce a delay before self-deletion or to ensure network connectivity before performing destructive actions, followed by an attempt to remove its traces.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
307
Detects instances where the Windows binary fodhelper.exe spawns various shell or utility processes. This behavior is a common indicator of a User Account Control (UAC) bypass attack, where the attacker leverages the auto-elevation property of fodhelper.exe to execute arbitrary commands with higher privileges.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of the netsh.exe utility to modify Windows Advanced Firewall settings, specifically disabling profiles or adding/deleting firewall rules. This activity is often used by adversaries to impair security controls on a compromised host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potentially malicious invocations of rundll32.exe that utilize scripting protocols (javascript:, vbscript:) or suspicious execution parameters (ShellExec_RunDLL, LaunchApplication), as well as rundll32.exe executing from non-standard or user-writable directories (e.g., AppData, Temp). The rule further filters out trusted Microsoft-signed binaries to reduce noise while highlighting potential proxy execution attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or starting of a Windows service on a remote host using the Service Control Manager (sc.exe) utility. This is a common method for lateral movement and remote execution of malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects reconnaissance activities targeting host-based security configurations, including AppLocker policies, Windows security features via registry keys, and endpoint security product status via WMI. These actions are common in the early stages of an attack to understand the environment's defensive posture.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001