avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,148 views

8,664 detections

This rule detects the use of 'wmic.exe' with the '/format' switch to execute XSL files, or the direct execution of 'msxsl.exe'. These methods are common techniques used by adversaries to bypass security controls by executing arbitrary scripts embedded within XSL files, often fetched from remote locations or local paths.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
201
Detects the use of Windows utilities 'nltest.exe' and 'dsquery.exe' with specific command-line arguments to enumerate Active Directory domain trust relationships. This behavior is indicative of an attacker attempting to map the network environment to identify targets for lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network communication to well-known public DNS resolvers (1.1.1.1, 8.8.8.8, 9.9.9.9) or DNS queries for their domains, initiated by processes other than standard web browsers. This behavior is often associated with non-browser applications, potential C2 channels, or hidden network activity bypassing system DNS configurations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potentially malicious invocations of rundll32.exe that utilize scripting protocols (javascript:, vbscript:) or suspicious execution parameters (ShellExec_RunDLL, LaunchApplication), as well as rundll32.exe executing from non-standard or user-writable directories (e.g., AppData, Temp). The rule further filters out trusted Microsoft-signed binaries to reduce noise while highlighting potential proxy execution attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of cmstp.exe with suspicious command-line arguments (e.g., .inf file references or silent/unattended flags) often associated with bypass of application control or User Account Control (UAC).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the use of system utilities (wevtutil.exe, auditpol.exe, PowerShell) to interact with, query, or check status of security event logs and auditing configurations. While these tools are standard for administration, their usage by non-system accounts can indicate an adversary attempting to understand, monitor, or manipulate system audit policies and event log configurations as part of a reconnaissance or defense evasion strategy.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the use of the 'powercfg.exe' utility by non-system accounts to modify power settings, such as disabling hibernation, modifying standby/sleep timeouts, or changing monitor/disk timeout configurations. Such actions can be indicative of attempts to maintain system availability, prevent the system from entering a low-power state that might terminate malicious processes, or ensure persistent execution of unauthorized activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the use of VMware ESXi command-line management tools (esxcli, esxcfg) or VMware PowerCLI cmdlets (e.g., Connect-VIServer, Invoke-VMScript) from endpoints that are not identified as servers. This behavior often indicates an attacker attempting to manage or interact with a virtualized environment from a compromised workstation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects instances where common browser processes or Windows Explorer initiate suspicious child processes like cmd.exe, powershell.exe, or mshta.exe. The rule uses a scoring mechanism based on the presence of encoded command indicators, web-related payloads, or specific HTA script arguments to identify potentially malicious activity such as drive-by downloads or living-off-the-land execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
Detects the modification of Azure Storage account management policies where the 'daysAfterModificationGreaterThan' condition is set to 7 days or less, specifically including a 'delete' action. This could indicate an attempt by an adversary to shorten the lifecycle of data for rapid, automated, and potentially malicious data destruction within Azure Blob Storage.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003