avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,186 views

8,664 detections

This rule detects the installation of known vulnerable kernel drivers (Bring Your Own Vulnerable Driver - BYOVD). These drivers are often exploited by adversaries to gain kernel-level code execution, elevate privileges, or disable security tools (EDR).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects potential persistence or configuration activity associated with the Remcos Remote Access Trojan (RAT). The rule monitors for the creation or modification of registry keys explicitly named 'Remcos', as well as the addition of executables from suspicious paths (e.g., AppData, Temp) to the Windows 'Run' registry keys, a common technique for achieving persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects high-frequency HTTPS network connections to Google Drive or Google APIs originating from processes that are not common web browsers or productivity software. This behavior is indicative of the GearDoor backdoor, commonly used by APT41, which leverages Google services as a command-and-control (C2) channel.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects critical Windows system processes (svchost.exe, lsass.exe, csrss.exe, wininit.exe, winlogon.exe, spoolsv.exe) that are either spawned by unexpected parent processes or reside in non-standard directories. This behavior is indicative of potential masquerading, process injection, or malicious persistence attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
This rule detects anomalous DNS query activity that may indicate command and control (C2) or data exfiltration over the DNS protocol. It monitors for three specific indicators: excessive query volume to a single domain family within a short timeframe, the use of abnormally long DNS subdomain labels, and the transmission of TXT record queries from endpoints not acting as designated DNS servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Detects attempts by the Remcos RAT loader to perform WebRTC IP leakage by monitoring process command lines for keywords like 'webrtc', 'stun', 'turn', or 'ice' when initiated by common browsers (chrome.exe, firefox.exe, opera.exe) and having a parent process related to 'Remcos'. This indicates an attempt to gather victim IP addresses.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
306
Detects the execution of known Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Action1) from user-writable directories such as Temp, Downloads, or INetCache. Adversaries frequently utilize these legitimate remote access tools to establish persistence or command-and-control channels, often dropping them into temporary directories to avoid detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects unauthorized processes attempting to create, modify, rename, or delete the 'Login Data' SQLite database files used by Google Chrome and Microsoft Edge to store saved credentials. By excluding legitimate browser processes and updates, the rule identifies potential credential theft attempts by infostealer malware or unauthorized actor tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential exploitation attempts related to the Squidbleed vulnerability, specifically looking for command-line arguments indicative of heap buffer overread conditions within the 'squid.exe' process. It monitors for keywords such as 'strchr', 'buffer', 'overread', 'parse', 'directory', and 'listing' in the command line.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
305
This rule detects the creation of large files (1MB or greater) with names suggestive of exfiltration or staging (e.g., containing 'exfil', 'stage', 'batch', 'zip', 'archive') in common temporary or public user directories. This behavior can indicate an adversary preparing data for exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
005
Page 560 of 867