avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,163 views

8,664 detections

Detects the execution of the Mimikatz tool or the usage of specific command-line arguments associated with common credential dumping and persistence techniques, such as Skeleton Key or LSASS patching.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects successful NTLMv1 logon events (Event ID 4624) where the logon type is 3 (Network). NTLMv1 is a legacy and insecure authentication protocol. Its use in a modern environment, particularly for network logons, is often associated with pass-the-hash attacks or legacy compatibility issues that attackers may exploit.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
201
Detects instances of FTP transfer mode switching (ASCII/Binary) by monitoring network events for FTP traffic on port 21 and specific commands like 'TYPE A' or 'TYPE I' in the RemoteUrl. This behavior can be indicative of data transfer activities, potentially related to vulnerabilities or malicious data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
105
Detects potential exploitation attempts related to the Squidbleed vulnerability by monitoring 'squid.exe' process command lines for indicators of ASAN (AddressSanitizer) heap overflow reports. This includes keywords like '==', 'ERROR', 'ERROR SUMMARY', and 'SUMMARY', which are often present in ASAN crash reports.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects potential browser fingerprinting and network reconnaissance behavior associated with Bluekit BitM PhaaS campaigns. The rule correlates large suspicious JavaScript file downloads (excluding common CDNs) with STUN server connectivity within a 10-minute window, a pattern often used by adversary-in-the-middle (AiTM) frameworks to fingerprint victims and establish WebRTC channels.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects successful configuration modifications to diagnostic settings or storage services where the destination resource is identified as being outside of the organization's trusted subscriptions or expected storage naming conventions. This activity may indicate an adversary attempting to exfiltrate logs or data to an attacker-controlled storage account.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the execution of the 'unshare' utility with arguments that create new user, network, and mount namespaces (-U, -n, -r) by a non-root user. This technique is often used to bypass namespace restrictions or perform privilege escalation by gaining elevated capabilities within a new, user-controlled namespace.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of the built-in Windows tool 'ntdsutil.exe' to perform an Install from Media (IFM) operation, which creates a copy of the Active Directory database (NTDS.dit). The rule specifically flags when this output is directed to suspicious paths like 'C:\Windows\Temp' or 'C:\Users\Public', which are common locations used by adversaries to stage files for exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects the creation of shortcut (.lnk) files within the Windows Startup folder initiated by potentially suspicious processes such as WinRAR, unrar, or PowerShell. This behavior is indicative of an attempt to achieve persistence by ensuring the execution of a malicious file upon user login.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious PowerShell execution patterns involving scripts or payloads stored within specific directory paths (ProgramData\WC3\ or ProgramData\wt1). It flags instances where PowerShell commands include reflective loading techniques ('IEX' or 'Invoke-Expression') while referencing files in these paths, which is often associated with fileless malware execution or malicious loaders.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001