avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,582 copies160 likes52,381 views

8,664 detections

This rule detects the creation of shortcut (.lnk) files within the Windows Startup folder initiated by potentially suspicious processes such as WinRAR, unrar, or PowerShell. This behavior is indicative of an attempt to achieve persistence by ensuring the execution of a malicious file upon user login.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects suspicious PowerShell execution patterns involving scripts or payloads stored within specific directory paths (ProgramData\WC3\ or ProgramData\wt1). It flags instances where PowerShell commands include reflective loading techniques ('IEX' or 'Invoke-Expression') while referencing files in these paths, which is often associated with fileless malware execution or malicious loaders.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of 'hdiutil' to mount disk images with the '-nobrowse' flag, initiated by common command-line or scripting interpreters. The '-nobrowse' flag prevents the mounted volume from appearing on the desktop or in Finder, which is a common technique used by attackers to mount malicious disk images stealthily to facilitate execution of payloads while avoiding user detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule monitors process command lines and file activity for keywords associated with potential reconnaissance, error logs, or debugging artifacts often used during post-exploitation or system profiling. It flags commands or files containing terms like 'memory dump', 'stack trace', 'SQL injection', or 'Redis failure', which may indicate an attacker analyzing system information or attempting to interact with backend services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects unusually large FTP responses containing 'LIST' or 'NLST' commands, potentially indicating an attempt to exploit the Squidbleed vulnerability or similar data exfiltration over FTP. The rule specifically looks for network events on port 21 (FTP) where the action type is 'NetworkSignatureInspected' and the RemoteUrl contains either 'LIST' or 'NLST' with a string length greater than 4000 characters.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
This rule detects the execution of known remote access tools (such as AnyDesk, TeamViewer, or RustDesk) that are spawned as child processes from common web browsers. It correlates process creation events with subsequent network connections by these tools to public IP addresses over specific ports commonly used by remote access software, within a 30-minute timeframe of the process start.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects the execution of known remote access and remote management tools (e.g., TeamViewer, AnyDesk) where the process was initiated by a web browser, suggesting potential drive-by downloads or social engineering attacks involving remote access software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects when a user or machine account is added to a highly privileged Active Directory group. This event is often a sign of privilege escalation or persistence establishment by an adversary.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects unauthorized modifications to sensitive Group Policy Object (GPO) attributes, such as file system paths, version numbers, or extension settings. It monitors Security Event 5136 for changes targeting GPO containers by non-standard administrative accounts, flagging potential attempts to persist access or escalate privileges via GPO tampering.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
This rule detects network connections to remote URLs containing indicators associated with the XWorm Remote Access Trojan (RAT). It specifically looks for 'xworm', 'x-worm', 'wormx', or '/xworm' within the RemoteUrl field of DeviceNetworkEvents.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
106
Page 552 of 867