avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

Detects the deployment, registration, and loading of known vulnerable drivers (e.g., mhyprot2.sys, gdrv.sys, rtcore64.sys) used in Bring Your Own Vulnerable Driver (BYOVD) attacks. This rule monitors file creation, module loading, service registration via sc.exe, and registry modifications associated with service installation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where non-browser processes access sensitive browser-related files (Login Data, Cookies, or Local State) located within AppData directories. This behavior is highly indicative of credential and session token theft, often associated with AiTM or post-compromise information harvesting activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized or non-standard processes attempting to create, modify, or access sensitive cloud configuration and credential files, such as AWS credentials, Azure CLI token caches, or GCP application default credentials. This behavior is indicative of potential credential theft or unauthorized access to cloud environment tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized access or modification to common CI/CD credential files (.npmrc, .pypirc, .git-credentials, jenkins credentials.xml) and CI/CD configuration files (.github/workflows, .gitlab-ci.yml). The rule monitors both file system activities by non-standard processes and the execution of command-line tools that reference these sensitive files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential wiper activity by monitoring for high-frequency deletion or modification of specific file types (e.g., .docx, .xlsx, .pdf, .db, .bak) within a short window. It triggers when a process like PowerShell or Cmd is observed executing destructive commands (e.g., 'del', 'erase', 'Remove-Item') on a large number of files across multiple directories, which is a common behavior of malware attempting to destroy data.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects potential persistence or configuration activity associated with the Remcos Remote Access Trojan (RAT). The rule monitors for the creation or modification of registry keys explicitly named 'Remcos', as well as the addition of executables from suspicious paths (e.g., AppData, Temp) to the Windows 'Run' registry keys, a common technique for achieving persistence.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects activities aimed at inhibiting system recovery by identifying attempts to delete volume shadow copies via vssadmin, wmic, or powershell, in combination with disabling windows recovery mode using bcdedit. This behavior is indicative of ransomware preparation, where an adversary attempts to prevent the restoration of data before encryption.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Detects usage of the Windows certutil.exe binary to perform potentially malicious operations such as downloading files via URL cache or decoding base64/hex payloads. The rule specifically alerts when these actions occur within common user-writable or temporary directories often used by threat actors for file staging.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
This rule detects potential persistence via Registry Run keys (T1547.001) where a value is added pointing to a file in an AppData or Temp directory, followed by a successful outbound network connection from a process located in those same directories. This behavior is indicative of malware or an adversary establishing persistence and immediately reaching out to a command-and-control (C2) server.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects attempts to terminate security-related processes or stop security-related services using common administrative tools like taskkill.exe, sc.exe, net.exe, or net1.exe. This activity is often indicative of an adversary attempting to disable security monitoring and protection software to facilitate further malicious actions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Page 559 of 867