avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views

8,664 detections

Detects the execution of known archive utilities (e.g., 7-Zip, WinRAR) when interacting with sensitive user or system directories. This behavior is often indicative of data staging prior to potential exfiltration, especially when the originating process is not a recognized installer or backup application.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
The rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or the use of its specific command-line arguments (e.g., sekurlsa::logonpasswords, /ntlm:). It also monitors for suspicious, unauthorized processes attempting to open a handle to the LSASS process to access its memory, a common technique for dumping credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects instances where Windows event logs are cleared using built-in utilities (wevtutil.exe) or PowerShell (Get-EventLog/Get-WinEvent, Clear-EventLog) shortly after those same logs were queried or enumerated by the same user on the same device. This pattern is highly indicative of an adversary attempting to conceal malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects potential financial data exfiltration by monitoring for bulk downloads of files with financial keywords from SaaS/Office365 platforms, and identifies unauthorized processes attempting to access sensitive financial application data files (.qbw, .qbb, etc.) on local systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule monitors for three categories of potentially suspicious network behavior: connections to common CDN providers over non-standard ports, high-volume HTTPS connections directly to IP addresses (IP-direct) bypassing standard domain resolution, and high-volume traffic to CDN infrastructure that may indicate domain fronting or C2 communication. Such patterns are often used by adversaries to mask egress traffic or exfiltrate data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects the creation of named pipes or mutexes with GUID-like naming patterns by non-system processes. Threat actors frequently use uniquely generated GUIDs for IPC mechanisms like named pipes and mutexes to coordinate between processes or to check for existing infection, often to avoid detection by using non-obvious names.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects suspicious OAuth application or service principal registration, or permission consent, performed by users who are not part of designated IT administrator groups. This rule flags high-privilege permission grants (e.g., Mail.Read, Directory.ReadWrite.All) or application consent events, which are common methods for establishing long-term persistence in cloud environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
703
This rule monitors for suspicious activity related to Microsoft Exchange server exploitation and persistence techniques. It detects three distinct behaviors: the creation of web shell files (.aspx, .ashx, .asmx) within Exchange directories (OWA/ECP), the spawning of shell processes (cmd, powershell) by the w3wp.exe web server process, and DLL sideloading occurring through identified signed binaries (dfsvc.exe, rasautou.exe) outside of standard system directories.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
303
Detects modifications to Registry Run or RunOnce keys that include references to 'ManageEngine' or 'SystemOptimizer' and attempt to execute scripting hosts like wscript, cscript, powershell, or cmd. This behavior is indicative of persistence mechanisms often used by adversaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
307
Detects the execution of rundll32.exe initiated by explorer.exe where the command line references common user folders (AppData, Temp, Downloads) and includes suspicious file extensions (e.g., images, PDFs, Office docs). This pattern is often indicative of malicious code execution where an adversary uses rundll32.exe to proxy execution of payloads masked as benign files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101