avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,518 copies160 likes52,162 views

8,664 detections

This rule monitors for suspicious activity related to Microsoft Exchange server exploitation and persistence techniques. It detects three distinct behaviors: the creation of web shell files (.aspx, .ashx, .asmx) within Exchange directories (OWA/ECP), the spawning of shell processes (cmd, powershell) by the w3wp.exe web server process, and DLL sideloading occurring through identified signed binaries (dfsvc.exe, rasautou.exe) outside of standard system directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects the use of net.exe and dsquery.exe to enumerate domain user accounts and domain groups. Adversaries often perform this reconnaissance to identify target accounts or privileged groups within an Active Directory environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or modification of Windows services using sc.exe where the binary path (binpath) points to suspicious or user-writable directories such as User profiles, AppData, Temp, or Public folders, which are often used by adversaries for persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation or modification of Windows Registry Run keys by processes that are not part of the standard Microsoft Windows installation, suggesting potential unauthorized persistence mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects cross-process operations (such as memory access or thread injection) initiated by processes that are not signed by known, trusted vendors, or that do not reside in protected system directories. This behavior is a common indicator of process injection techniques used to evade security controls.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the execution of known critical system processes (e.g., svchost.exe, lsass.exe) from directories other than the standard Windows System32 or SysWOW64 paths. This behavior is indicative of masquerading, where an adversary attempts to evade detection by naming malicious files after legitimate system binaries.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of common Windows system information discovery utilities (systeminfo, hostname, ver) when spawned by command interpreters or scripting engines, which is a common behavior in post-exploitation reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects network connections over port 3389 (RDP) initiated by processes other than standard Remote Desktop clients (mstsc.exe). This rule specifically looks for suspicious indicators such as execution from non-standard or temporary file paths, or the use of common living-off-the-land binaries (like powershell.exe, cmd.exe, rundll32.exe) that might be acting as a proxy for remote access or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potentially malicious process execution behaviors, including the use of 'runas.exe' with saved credentials, the execution of 'runas.exe' by unauthorized users, and unauthorized cross-process access to sensitive Windows system processes such as lsass.exe, winlogon.exe, or services.exe, which are common indicators of credential access or privilege escalation attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101
Detects attempts to bypass the Antimalware Scan Interface (AMSI) by monitoring for specific keywords associated with memory patching or tampering within the command lines of PowerShell, .NET-based binaries (dotnet.exe, csc.exe, msbuild.exe), and related processes. The rule specifically looks for strings like 'AmsiUtils', 'amsiInitFailed', and base64-encoded equivalents often used by offensive security tools to neutralize AMSI scanning capabilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001