avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views

8,664 detections

Detects core Windows system processes (svchost.exe, lsass.exe, csrss.exe, winlogon.exe) executing from non-standard locations other than System32 or SysWOW64. This is a common indicator of process masquerading, where malicious actors rename or move their executable to blend in with legitimate system activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects DNS queries with exceptionally long request strings (30 characters or more), which is a common indicator of DNS tunneling or command and control (C2) communication. Adversaries often encode data within the subdomain portion of a DNS query to bypass network security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of sensitive ESXi administrative commands (e.g., esxcli, vim-cmd) that suggest potential hypervisor management or tampering, especially when initiated by non-administrative processes or specific shells.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects various commands and processes used by adversaries to enumerate virtual machine software, hypervisor configurations, and virtualization-based security features on a host. This is often part of reconnaissance to understand the environment, detect sandboxing, or identify virtualization platforms for further post-exploitation activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the creation of named pipes or mutexes with GUID-like naming patterns by non-system processes. Threat actors frequently use uniquely generated GUIDs for IPC mechanisms like named pipes and mutexes to coordinate between processes or to check for existing infection, often to avoid detection by using non-obvious names.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of remote commands on cloud virtual machines (Azure RunCommand or AWS SSM SendCommand) during defined off-hours (18:00 to 06:00). This rule identifies potentially unauthorized administrative or management activity occurring outside of standard business hours across cloud environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects attempts to clear Windows event logs using the native 'wevtutil.exe' utility or the PowerShell 'Clear-EventLog' command. This behavior is often associated with adversaries attempting to remove evidence of their actions from a compromised system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects native Windows command and scripting interpreters (e.g., cmd.exe, powershell.exe, mshta.exe) initiating external network connections to multiple distinct IP addresses, which is often an indicator of automated C2 beaconing or lateral movement activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of the 'net.exe' or 'net1.exe' utilities with the 'group' and '/domain' arguments, indicating an attempt to query domain-level groups. This technique is commonly used by attackers during the discovery phase to map out domain security groups.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects attempts to clear Windows event logs using the native 'wevtutil.exe' utility or the PowerShell 'Clear-EventLog' command. This behavior is often associated with adversaries attempting to remove evidence of their actions from a compromised system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001