avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

Detects unauthorized access or modification to common CI/CD credential files (.npmrc, .pypirc, .git-credentials, jenkins credentials.xml) and CI/CD configuration files (.github/workflows, .gitlab-ci.yml). The rule monitors both file system activities by non-standard processes and the execution of command-line tools that reference these sensitive files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the abuse of Windows Background Intelligent Transfer Service (BITS) via 'bitsadmin.exe' or PowerShell's 'Start-BitsTransfer' cmdlet to download files from remote URLs. This rule identifies potentially malicious activity by monitoring for specific transfer-related command-line arguments coupled with external network connections, excluding Microsoft-signed processes. It further refines detection by flagging output to suspicious directories (like Temp, AppData, or Public) or files with common executable extensions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of tar.exe to extract archives into common staging directories (Temp, AppData, Public, ProgramData), particularly when the process is initiated by suspicious parent processes such as Office applications, command shells, or download utilities, which is often indicative of malicious payload staging.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects DNS lookups and network connections to known AI API endpoints (OpenAI, Anthropic, Google Generative Language) initiated by non-standard processes. This rule excludes common web browsers, productivity applications, and development tools to identify potentially unauthorized or suspicious interaction with AI services from internal processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects unauthorized attempts to terminate, stop, or access Endpoint Detection and Response (EDR) or Antivirus agent processes. This is identified by monitoring command-line utilities like taskkill, net, and sc targeting known security service names, as well as detecting suspicious cross-process access (e.g., OpenProcess) by unauthorized processes targeting security agent PIDs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized access to Windows Credential Manager files, TokenBroker OAuth cache files, or the loading of crypt32.dll from suspicious, user-writable directories (e.g., Temp, Downloads, Desktop) by non-Microsoft or non-system processes. This activity is indicative of credential theft, session hijacking, or attempts to abuse the Windows Data Protection API (DPAPI) to decrypt sensitive local secrets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects potential execution chains related to QR code phishing (Quishing) by monitoring for suspicious process creation or outbound network connections originating from document readers, office applications, and QR scanner utilities. It covers three primary vectors: suspicious process spawning (e.g., Office apps launching cmd or powershell), non-standard network connections from document readers, and malicious URL-based LNK files spawned via explorer.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects cross-process access to the Local Security Authority Subsystem Service (LSASS) memory by processes that are not standard Microsoft-signed system components. This behavior is often indicative of credential dumping activity using tools like Mimikatz or other custom malicious utilities attempting to read sensitive memory contents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where the WMI Provider Host (wmiprvse.exe) spawns common shell or script interpreter processes (cmd.exe, powershell.exe, cscript.exe, wscript.exe). This behavior is often indicative of fileless remote code execution used for lateral movement across Windows environments, as WMI is frequently abused by attackers to remotely trigger malicious commands.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of known AI/LLM command-line interface tools (such as Ollama, OpenAI, or Claude) when spawned by command shells (cmd.exe, powershell.exe) or executed from suspicious locations like user profiles or temporary directories. This pattern is indicative of potential use of LLMs for generating malicious code, analyzing data, or assisting in post-exploitation activities within a compromised environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Page 558 of 867