avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views

8,664 detections

Detects the use of reg.exe to query the Windows registry for information related to software versions or service configurations. This activity is often associated with discovery efforts to identify installed software, system configuration, or potential security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of a scheduled task using the schtasks.exe utility with persistence-related triggers such as system startup or user logon. The rule excludes common trusted processes that frequently interact with the Task Scheduler to minimize false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of the Windows command-line utility 'wevtutil.exe' to clear Windows event logs. Attackers often clear logs to hide evidence of post-compromise activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the use of 7-Zip (7z.exe or 7zip.exe) to archive files within common user directories (Desktop, Documents, Users, AppData). This activity is often associated with staging sensitive data prior to exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects unauthorized cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). Such attempts are commonly associated with credential dumping techniques to extract credentials from memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects execution of common network reconnaissance tools such as nmap, masscan, and zmap, or PowerShell commands that utilize Test-NetConnection for automated port sweeping across a defined range.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of PowerShell commands intended to disable or bypass the Antimalware Scan Interface (AMSI). This is achieved by referencing internal AMSI methods such as 'AmsiUtils', 'amsiInitFailed', or 'amsi.dll' within command line arguments, typically used to neutralize endpoint security scanning during malicious script execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of processes associated with remote command execution, specifically identifying the PsExec service (psexesvc.exe) or the invocation of command shell (cmd.exe) by the Service Control Manager (services.exe) with remote path arguments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects execution of the Microsoft InstallUtil.exe utility with suspicious command-line arguments (logging suppressed to file and console) where the binary is unsigned. This is a common technique used by adversaries to proxy execution of arbitrary .NET code while attempting to avoid detection and maintain stealth.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects SYSTEM privilege escalation attempts via ctfmon.exe or cloudfiles.exe processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
15155