avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,167 views

8,664 detections

Detects the creation of files with suspicious names (e.g., .xlamb, lambsys) in the /var/tmp directory, initiated by common command-line interpreters or network transfer utilities. This behavior is often indicative of malware deployment or staging in a Linux environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the modification or creation of registry values under the Windows Local Security Authority (LSA) configuration key, specifically targeting the 'Authentication Packages' or 'Security Packages' values. Adversaries often use these registry locations to inject custom DLLs that are loaded by the LSA process (lsass.exe) at system boot for persistence or credential dumping.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects when the Internet Information Services (IIS) worker process (w3wp.exe) accesses sensitive files such as 'web.config', 'applicationHost.config', or 'win.ini'. Unauthorized access to these files by the IIS process can be an indicator of a web shell or other malicious post-exploitation activity attempting to steal credentials, application secrets, or system configuration information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects the creation and loading of the 'NSecKrnl.sys' driver file on a system. The filename is associated with potentially malicious or unauthorized kernel-level activity, often indicative of rootkit behavior or unauthorized persistence mechanisms.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects execution of the Velociraptor binary (velociraptor.exe) running with SYSTEM privileges while not being launched by the expected services.exe process. This often indicates potential unauthorized use or manual deployment of the tool, bypassing standard management procedures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects outgoing network connections from the IIS worker process (w3wp.exe) to public-facing URLs that match common Microsoft Office WOPI (Web Application Open Platform Interface) request patterns, but are directed to domains other than trusted Microsoft-affiliated infrastructure. This behavior can be indicative of a Server-Side Request Forgery (SSRF) attempt, where an attacker tries to coerce the server into making unauthorized requests to external resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects when the Microsoft Teams process (Teams.exe) creates an executable or installer file (.exe or .msi) in common user-writable directories such as AppData, Temp, or Users/Public. This behavior is indicative of potential malicious activity, as legitimate Teams application updates and add-ins typically reside in specific, protected subdirectories within the Teams folder structure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects network connections over WinRM ports (5985, 5986) originating from potentially suspicious processes that are not standard Windows remote management binaries. It explicitly identifies activity where SharePoint-related processes initiate WinRM, which may indicate lateral movement patterns such as those seen in activity attributed to Storm-2603.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects modifications to the Windows Registry keys under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network. These keys control which services or drivers are permitted to load during Safe Mode with Networking. Unauthorized changes to these keys can be used to ensure malicious drivers or services load during Safe Mode, providing a persistence mechanism that bypasses many security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the modification or creation of registry values under the Windows Local Security Authority (LSA) configuration key, specifically targeting the 'Authentication Packages' or 'Security Packages' values. Adversaries often use these registry locations to inject custom DLLs that are loaded by the LSA process (lsass.exe) at system boot for persistence or credential dumping.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001