avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,168 views

8,664 detections

This rule monitors for the creation of .exe or .msi files within common user-writable directories (Downloads, Temp, AppData) initiated by web browser processes (Chrome, Edge, Firefox, Brave). This behavior is often indicative of drive-by downloads or users interacting with malicious web content that delivers installers to the host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects execution of the Velociraptor binary (velociraptor.exe) running with SYSTEM privileges while not being launched by the expected services.exe process. This often indicates potential unauthorized use or manual deployment of the tool, bypassing standard management procedures.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects when the Microsoft Teams process (Teams.exe) creates an executable or installer file (.exe or .msi) in common user-writable directories such as AppData, Temp, or Users/Public. This behavior is indicative of potential malicious activity, as legitimate Teams application updates and add-ins typically reside in specific, protected subdirectories within the Teams folder structure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects network communication (connections, DNS queries, or proxy logs) between endpoints and a list of known malicious domains and IP addresses associated with Mistic and Woodgnat/KongTuke threat families. It identifies these activities across network event logs, DNS queries, and security logs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors DNS queries and network connections for access to a set of known domain names associated with Adversary-in-the-Middle (AiTM) phishing infrastructure. It correlates data from DNS events, device network logs, and virtual machine network connections to identify potential interactions with malicious phishing sites typically used to capture user credentials or session tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects instances where Microsoft Teams (Teams.exe or ms-teams.exe) initiates a PowerShell process (powershell.exe or pwsh.exe) with command-line arguments typically associated with malicious activity, such as downloading content from the internet, executing encoded commands, or utilizing scripting shortcuts (e.g., IEX, curl). This behavior may indicate an attempt to achieve code execution through compromised collaboration tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of the Mimikatz tool or the usage of specific command-line arguments associated with common credential dumping and persistence techniques, such as Skeleton Key or LSASS patching.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects successful NTLMv1 logon events (Event ID 4624) where the logon type is 3 (Network). NTLMv1 is a legacy and insecure authentication protocol. Its use in a modern environment, particularly for network logons, is often associated with pass-the-hash attacks or legacy compatibility issues that attackers may exploit.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the creation of a local user account in the Windows Security event logs. The rule filters out service accounts (those ending in '$') and events triggered by well-known system accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise. This helps identify unauthorized account creation, which can be an early indicator of persistence establishment or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects potential cleartext leakage of usernames and passwords over FTP (port 21) by identifying HTTP requests containing common credential-related keywords in the URL, while explicitly excluding HTTPS traffic. This could indicate sensitive information being transmitted insecurely.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105