avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views

8,664 detections

Detects processes attempting to query the Cloud Instance Metadata Service (IMDS) endpoint (169.254.169.254) that are not recognized as legitimate cloud agent software (such as AWS, Azure, or Google cloud agents). This behavior is often indicative of SSRF or unauthorized discovery attempts by an adversary on a compromised cloud instance.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of specific Python scripts associated with the FortiBleed campaign. These scripts include 'spray_da.py' for domain admin password spraying, 'smb_test.py' for SMB validation and lateral movement, 'spider.py' for Active Directory crawling, and 'ad_full_audit.py' for Active Directory auditing. Detection is based on the Python interpreter executing these specific script filenames.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
207
Detects the creation of scheduled tasks using 'schtasks.exe' with command line arguments that indicate suspicious activity. This includes tasks created in common temporary or user-writable directories, or tasks that involve PowerShell with encoded commands or obfuscated strings, which are often used by adversaries for persistence or execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
105
This rule detects a specific typosquatting pattern used by the EvilTokens phishing kit. It looks for HTTP traffic where the host contains 'workers.dev' and matches a regular expression for 'viewdoc[a-z0-9\-]+\.workers\.dev'. This indicates an attempt to mimic legitimate Cloudflare Workers domains for phishing purposes, specifically targeting the 'viewdoc' pattern often seen in document-sharing lures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
005
This rule detects network traffic indicative of the 'EvilTokens' phishing kit, specifically targeting Microsoft OAuth Device Code flow. It looks for HTTP POST requests to the '/api/device/start' URI on domains hosted on Cloudflare Workers ('.workers.dev'). This pattern suggests an attempt to initiate a device code phishing attack, where adversaries trick users into entering credentials or codes to grant access to malicious applications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
005
This rule detects cross-process memory access attempts against the Local Security Authority Subsystem Service (LSASS). Accessing LSASS memory is a common technique used by attackers to dump credentials (e.g., cleartext passwords, NTLM hashes, Kerberos tickets) for lateral movement and privilege escalation. The rule filters out known legitimate processes and system-signed components to reduce false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
301
Detects the creation or modification of Windows Registry Run or RunOnce keys, which are commonly used for persistence to execute malicious code automatically upon user logon. The rule excludes common, legitimate software installers and trusted publishers located in Program Files to minimize false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects the use of net.exe or net1.exe to perform enumeration of local administrators or domain-level users and groups. This behavior is commonly associated with attackers attempting to map out the environment for privilege escalation or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of mavinject.exe with the /INJECTRUNNING command-line argument. This utility is a signed Microsoft binary that can be abused by adversaries to inject arbitrary DLLs into the address space of running processes, a technique often used to evade detection or achieve code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of an executable file (.exe, .scr, .com, .pif) in user-writable directories (Temp, AppData, ProgramData) followed by the immediate execution of that same file. This is a common pattern for malware droppers where a file is dropped to disk and subsequently executed to initiate the next stage of an attack.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001