avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,517 copies160 likes52,158 views

8,664 detections

Detects the execution of the Windows binary 'certutil.exe' using flags commonly abused by adversaries to download files from remote URLs or decode base64-encoded files. It excludes instances where certutil is executed by Microsoft-signed processes from the System32 directory to reduce false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the creation or modification of Windows Registry Run or RunOnce keys, which are commonly used for persistence to execute malicious code automatically upon user logon. The rule excludes common, legitimate software installers and trusted publishers located in Program Files to minimize false positives.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of processes with command-line arguments characteristic of the Mimikatz tool, specifically the 'sekurlsa', 'lsadump', and 'privilege::debug' modules used for credential dumping and process debugging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the deletion of volume shadow copies using standard Windows utilities such as vssadmin.exe, wmic.exe, or PowerShell. This behavior is a common indicator of ransomware activity aimed at preventing system recovery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential automated credential stuffing attempts followed by successful authentication and subsequent access to sensitive/privileged APIs within Azure/Entra ID environments. It correlates multiple failed login attempts for service-oriented account names (e.g., svc, api, bot) with a successful login from the same user shortly thereafter, followed by privileged API operations (e.g., KeyVault secret access, user management) within a short time window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects the execution of mshta.exe with suspicious command-line arguments, including the use of 'javascript:', 'vbscript:', or HTTP/HTTPS URLs. These patterns are commonly used to proxy the execution of malicious HTML Applications (HTA) or scripts to bypass security controls. The rule includes an exclusion for legitimate Microsoft-signed mshta.exe processes that do not contain these suspicious indicators.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of the 'diagnose sniffer packet' command on FortiOS devices. This command can be abused by malware, such as FortigateSniffer, to intercept authentication traffic, as observed in campaigns like FortiBleed.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
007
This rule detects suspicious activity related to high-volume Server Message Block (SMB) share enumeration and the execution of a specific Python script named 'backup_dfs.py'. It combines three detection logics: identifying processes executing 'backup_dfs.py', detecting an unusual number of SMB network connections to common administrative shares (SYSVOL, NETLOGON, DFS), and flagging high-volume SMB-related identity directory events targeting SYSVOL or NETLOGON. This behavior could indicate an adversary performing discovery of network shares, collecting data, or preparing for data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
207
Detects the use of the sc.exe utility to create a new service on a remote system by specifying a path using a UNC share. This behavior is indicative of lateral movement, where an attacker attempts to execute code on a remote host by installing a service via SMB/Admin Shares.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the creation of an executable file (.exe, .scr, .com, .pif) in user-writable directories (Temp, AppData, ProgramData) followed by the immediate execution of that same file. This is a common pattern for malware droppers where a file is dropped to disk and subsequently executed to initiate the next stage of an attack.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001