avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views

8,664 detections

Detects the use of vssadmin.exe or wmic.exe to delete Volume Shadow Copies. This is a common technique used by ransomware and other malware to prevent system recovery and impede incident response efforts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of mshta.exe with arguments containing URLs, script languages (vbscript, javascript), or .hta file extensions, which is a common technique used by attackers to execute malicious code via a legitimate Windows utility.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects unauthorized or suspicious processes attempting to access the memory of the Local Security Authority Subsystem Service (lsass.exe). This activity often indicates attempts to dump process memory to harvest sensitive credentials, a common technique used by attackers to facilitate lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of Mimikatz to perform a DCSync attack, which allows an adversary to simulate the replication process from a domain controller to extract sensitive password hashes from Active Directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of rundll32.exe from common user-writable or temporary directories (Temp, AppData, ProgramData), which is a common technique used by malware to execute payloads while avoiding security monitoring of standard system directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). The rule filters out known Microsoft-signed system processes and common Windows binaries to identify potential unauthorized credential dumping activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of PowerShell with an encoded command flag (e.g., -EncodedCommand, -e, -ec) where the command string exceeds 200 characters. This pattern is commonly used to obfuscate malicious PowerShell scripts, payloads, or downloader cradles.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the usage of net.exe or net1.exe to enumerate domain users, groups, local administrators, and domain controllers, which is frequently indicative of post-compromise reconnaissance.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of Windows Script Host (wscript.exe or cscript.exe) to run script files (.vbs, .js, .wsf, .hta) located in commonly abused writable directories such as Temp, AppData, Downloads, or ProgramData. This behavior is indicative of a malicious actor executing scripts that have been dropped onto the system as part of a phishing campaign or other attack vector.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential persistence attempts via WMI event subscriptions. The rule monitors for the creation of WMI event consumers using 'wmic.exe' with suspicious command line arguments, or the use of 'mofcomp.exe' to compile MOF files by non-standard, non-Microsoft signed processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001