avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views

8,664 detections

Detects the execution of common system discovery utilities (whoami, ipconfig, net, etc.) by a process named 'setup.exe' originating from suspicious directories such as 'AppData\Local\Temp\' or 'Downloads'. This behavior is often indicative of automated reconnaissance following the initial execution of a potentially malicious installer or dropper.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or modification of '.config' or '.exe.config' files within commonly user-writable directories such as AppData, Temp, Downloads, or Desktop. These files are often used by .NET applications to define behavior, and attackers may manipulate them to perform activities such as assembly redirection, loading malicious DLLs, or altering security settings for elevated processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule monitors for processes named 'setup.exe' executing from user-writable directories (e.g., AppData, Downloads, Temp) that load unsigned or non-Microsoft DLLs from the same suspicious directories. This pattern is commonly associated with DLL side-loading or malicious installation attempts where a process attempts to load illegitimate code from local user space.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule correlates multiple suspicious activities indicative of ransomware or destructive attacks. It detects a combination of volume shadow copy deletion, bulk file modifications, creation of suspicious scheduled tasks, and network connections occurring during periods of high file write activity. The rule triggers when multiple signals are observed or when specific high-fidelity destructive indicators are present.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of PowerShell with encoded commands initiated by common Windows script hosting utilities (mshta.exe, wscript.exe, or cscript.exe). This pattern is frequently used by adversaries to bypass execution policy restrictions or evade detection by proxying the execution of malicious payloads through legitimate, signed system binaries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potentially malicious behavior associated with web browser processes, including the execution of Python scripts, the loading of browser extensions from non-standard directories like AppData or Temp, the creation of Python scripts by browsers in temp folders, and outbound network connections by Python processes following browser activity. These patterns are often associated with browser-based exploitation, extension-based malware, or initial access stages where a browser is used as a conduit for malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the creation or modification of '.config' or '.exe.config' files within commonly user-writable directories such as AppData, Temp, Downloads, or Desktop. These files are often used by .NET applications to define behavior, and attackers may manipulate them to perform activities such as assembly redirection, loading malicious DLLs, or altering security settings for elevated processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects a suspicious execution chain potentially associated with Deed RAT (used by Mustang Panda/Twill Typhoon), consisting of DLL sideloading by a legitimate signed executable followed by persistence mechanism creation (Registry Run keys or Scheduled Tasks) on the same host. Additionally, it identifies devices exhibiting repeated outbound connections to the same remote public IP over multiple days, serving as an indicator of potential re-compromise or persistent C2.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
This rule monitors for indicators associated with MiniUpdate/MiniJunk V2 RAT and general .NET AppDomainManager hijacking. It detects suspicious registry keys (AppDomainManagerAssembly/Type) or environment variable manipulation used to hijack .NET application execution flow. Additionally, it identifies .NET host processes loading DLLs from user-writable directories (e.g., AppData, Temp) and tracks suspicious beaconing patterns to known Azure CDN domains often used by these threats for Command and Control.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the use of the command-line utility 'taskkill' to terminate 'explorer.exe' followed by a command to restart it, often used by malware or unauthorized scripts to force a refresh of the desktop environment or hide malicious activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001