avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,169 views

8,664 detections

This rule detects the creation of named pipes associated with known command-and-control (C2) frameworks, post-exploitation toolkits, and suspicious system activity. By filtering out common legitimate system processes and monitoring for specific pipe patterns (e.g., Cobalt Strike, Metasploit, PsExec, and sensitive RPC endpoints), the rule identifies potential lateral movement, remote execution, and post-exploitation communication channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects anomalous behavior associated with msiexec.exe that aligns with activity patterns of infostealer malwares like Lumma Stealer and Amadey Bot. This includes cross-process injection from unsigned processes, spawning of msiexec.exe by LOLBins or script interpreters, suspicious outbound network connectivity, and unauthorized access to browser credential storage files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized processes attempting to read, modify, or create files within common browser credential locations (Chrome, Firefox, Edge, and Windows Credential Manager). Legitimate browser processes and their known signers are excluded, focusing on suspicious secondary processes or tools frequently utilized by infostealers like Lumma and RedLine to dump credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potentially malicious activity within Azure Automation by monitoring for the creation or modification of runbooks and jobs, combined with the presence of suspicious command-line or script patterns in job stream output, such as credential harvesting (e.g., Get-AutomationPSCredential) or execution of web-based payloads (e.g., IEX, Invoke-WebRequest).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying successful user sign-ins from a new, historically unseen IP address occurring within 30 minutes of a legitimate sign-in from a known IP, indicating the potential replay of a stolen session or refresh token.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects modifications or publication of Azure Automation runbooks by users or service principals other than known, pre-approved automation service principals. This activity may indicate an unauthorized user or compromised service principal attempting to inject malicious code into automation workflows.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects modifications to Windows Registry keys associated with Event Tracing for Windows (ETW) Autologger configurations or Event Log service configurations. These modifications can be used by adversaries to disable or tamper with event logging mechanisms, effectively blinding security telemetry and evading detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects the use of regsvr32.exe to execute remote scripts or components via a URL (a technique often referred to as Squiblydoo). This rule flags process command lines containing /i flags combined with remote HTTP/HTTPS addresses, while excluding known management tools to reduce false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential ransomware activity by monitoring for two key signals: interaction with known canary/trap files designed to detect unauthorized access, and rapid, mass file modification of common user data extensions within a short timeframe. Either behavior is indicative of encryption or automated file destruction processes typical of ransomware attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects anomalous, high-frequency account enumeration activity in cloud audit logs, specifically targeting user, group, device, and service principal listing operations. This behavior is indicative of potential reconnaissance or discovery efforts by an attacker who has compromised a user account.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
101