avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,149 views

8,664 detections

This rule detects potential Business Email Compromise (BEC) attempts by identifying emails containing financial keywords sent to sensitive finance/accounting roles from domains that have not been observed in the last 180 days. It then correlates this email event with subsequent device-level network activity involving banking or financial URLs initiated by the recipient user, which may indicate follow-up reconnaissance or unauthorized access.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects the use of common cloud command-line interfaces (Azure CLI, Azure PowerShell, and AWS CLI) to perform resource discovery, specifically identifying commands used to list virtual machines or describe EC2 instances. Such activity, if performed by an unexpected user or on an endpoint where cloud management tools are not typically installed, may indicate reconnaissance by an adversary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects instances where common browser processes or Windows Explorer initiate suspicious child processes like cmd.exe, powershell.exe, or mshta.exe. The rule uses a scoring mechanism based on the presence of encoded command indicators, web-related payloads, or specific HTA script arguments to identify potentially malicious activity such as drive-by downloads or living-off-the-land execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule monitors the creation of new Azure Function Apps and identifies those that receive external, non-private network requests within 48 hours of their creation. This pattern may indicate the deployment of malicious or unauthorized serverless infrastructure for command-and-control, proxying, or automated tasks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects outbound network connections from workstations or servers to common message broker ports (MQTT 1883/8883, AMQP 5672). These protocols are sometimes abused for command-and-control (C2) communication, as they allow for pub/sub messaging patterns that can blend into legitimate network traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of regsvr32.exe with command-line arguments that attempt to load and execute a remote scriptlet (SCT file) via a URL. This technique is often used to bypass application control and proxy the execution of arbitrary code using the trusted regsvr32.exe binary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of files within the Windows Startup directory. Adversaries use this folder to achieve persistence by ensuring that malicious files or shortcuts are executed automatically when a user logs in.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects unauthorized cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). Such attempts are commonly associated with credential dumping techniques to extract credentials from memory.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of processes associated with remote command execution, specifically identifying the PsExec service (psexesvc.exe) or the invocation of command shell (cmd.exe) by the Service Control Manager (services.exe) with remote path arguments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
401
Detects the execution of net.exe or net1.exe with command line arguments used to enumerate domain users, domain groups, or local administrators. This pattern is commonly used by adversaries for discovery of accounts and permission groups within a Windows environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101