avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,152 views

8,664 detections

This rule monitors for the creation of specific file artifacts associated with the APT28 SimpleLoader malware, including malicious DLLs, steganographic image payloads, and configuration files dropped into non-standard or diagnostic directories.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects network and DNS activity involving domains known to be used by the threat actor APT28 for command and control, specifically for hosting WebDAV payloads, malicious LNK files, and weaponized documents.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the suspicious initialization of the Common Language Runtime (CLR) components (mscoree.dll, clr.dll, or oleaut32.dll) within the explorer.exe process, followed closely by an outbound HTTPS connection to filen.io domains. This pattern is indicative of fileless .NET-based C2 implants, such as those generated by the Covenant framework, executing within the context of a legitimate Windows shell process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where PowerShell.exe is launched by the OneDrive synchronization process, potentially indicating an attempt to mask malicious command execution as a legitimate cloud storage process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects the creation of a scheduled task named 'OneDriveHealth', which is associated with APT28 activity. This task is used for persistence via COM hijacking; it executes 60 seconds after registration, kills and restarts explorer.exe to facilitate the loading of a hijacked COM object, and subsequently removes itself.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects network and DNS activity involving domains known to be used by the threat actor APT28 for command and control, specifically for hosting WebDAV payloads, malicious LNK files, and weaponized documents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects file creation and process execution events associated with specific SHA256 hashes linked to the APT28 threat actor exploiting CVE-2026-21509.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects the suspicious initialization of the Common Language Runtime (CLR) components (mscoree.dll, clr.dll, or oleaut32.dll) within the explorer.exe process, followed closely by an outbound HTTPS connection to filen.io domains. This pattern is indicative of fileless .NET-based C2 implants, such as those generated by the Covenant framework, executing within the context of a legitimate Windows shell process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the opening of suspected APT28 (Fancy Bear) spearphishing lure documents by Microsoft Office or Outlook. The rule monitors for file access, creation, or renaming events where the filename matches known lure patterns associated with APT28 activities, such as naming conventions containing 'BULLETEN', 'OperInformativ', 'Courses', 'Consultation', 'Weapons', or 'Smuggling' in Word or Outlook processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001