avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views

8,664 detections

This rule detects processes attempting to access or manipulate Windows clipboard data, often used by adversaries to steal sensitive information copied by users. It monitors common living-off-the-land tools like PowerShell, WScript, CScript, and MSHTA executing clipboard-related functions or interacting with clip.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects when a signed process loads a DLL from a non-standard, user-writable directory (e.g., Temp, Downloads, Public folders). This is a common indicator of DLL hijacking or side-loading, where a legitimate signed application is leveraged to load a malicious library from a compromised location.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects activities associated with credential dumping, specifically targeting techniques that abuse the Directory Replication Service (DRS) protocol, such as DCSync or the use of tools like secretsdump. It monitors both process execution command lines and network traffic for keywords indicative of these credential extraction behaviors, which are commonly used by attackers to obtain domain credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects instances where common Windows system processes (dllhost.exe, mmc.exe, svchost.exe) spawn known living-off-the-land binaries (LotLBin) or command-line interpreters. This behavior is often indicative of process injection or malicious activity where an adversary leverages trusted system processes to execute commands or malicious scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects processes attempting to access or manipulate Windows clipboard data, often used by adversaries to steal sensitive information copied by users. It monitors common living-off-the-land tools like PowerShell, WScript, CScript, and MSHTA executing clipboard-related functions or interacting with clip.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of known command-line sync tools (Rclone, MEGAsync) or commands attempting to sync or move data to various cloud storage services (s3, gdrive, onedrive, mega, dropbox). The rule focuses on executions from suspicious or temporary directory paths and excludes processes signed by trusted publishers to minimize noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors for successful external logins occurring on an endpoint that previously demonstrated patterns of suspected MFA fatigue (multiple failed push notifications) and subsequent internal reconnaissance activity (execution of commands used for domain or system discovery). The rule correlates these events to identify potential compromised credentials being actively used for lateral movement or persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of common Windows utilities (diskpart, format, cipher, sdelete, eraser) when used with flags indicative of data destruction or disk wiping behavior. This rule monitors for process creations involving commands designed to irrecoverably erase data or wipe drive contents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of command-line archiving utilities (7z, rar, tar) invoked by common scripting engines (PowerShell, CMD, Python, etc.) targeting typical staging directories (Temp, Public, AppData, ProgramData). This pattern is frequently observed during the data staging phase of an attack, where adversaries encrypt or compress gathered files for eventual exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects unauthorized access, modification, or deletion attempts against common web browser credential storage files (key4.db, logins.json, and Microsoft Edge 'Login Data'). These files store sensitive authentication information, and non-browser processes interacting with them are indicative of credential harvesting attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001