avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

Detects attempts to delete Volume Shadow Copies (VSS) using standard Windows utilities like vssadmin.exe, wmic.exe, or PowerShell commands. This behavior is a common tactic employed by ransomware to inhibit system recovery and prevent the restoration of encrypted files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of scheduled tasks (schtasks.exe) spawned by common scripting or social engineering-related parent processes (PowerShell, Cmd, WScript, MSHTA). The rule specifically looks for payloads associated with common attack patterns, such as downloading remote content or executing encoded commands, which indicates potential persistence or payload delivery activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects a multi-stage loader chain behavior. Stage 1 identifies PowerShell spawning mshta.exe or wscript.exe, which is commonly used to execute malicious scripts or loaders. Stage 2 detects mshta.exe or wscript.exe subsequently executing schtasks.exe or wmic.exe with command-line arguments indicative of establishing persistence via scheduled tasks or WMI event subscriptions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where known endpoint security product binaries (EDR/AV) load DLL files from directories outside of their trusted, standard installation paths. This behavior is a common indicator of DLL sideloading, where an attacker attempts to masquerade malicious code as a component of a trusted security process to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects attempts by unsigned or non-Microsoft processes to perform cross-process memory injection (such as CreateRemoteThread or NtCreateThreadEx) into critical processes including browser processes (chrome.exe, msedge.exe) or the local security authority subsystem service (lsass.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects FTP protocol traffic (on port 21) initiated by a process named 'squid.exe' or containing 'squid' in its filename. This rule is designed to identify potential exploitation attempts related to the Squidbleed vulnerability, where a compromised Squid proxy might be used for unauthorized FTP communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
005
Detects instances where the WMI Provider Host process (WmiPrvSE.exe) spawns common interactive shells, scripting interpreters, or other binaries typically associated with remote command execution. This pattern is a strong indicator of WMI being abused for lateral movement or remote code execution within a Windows environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects unauthorized attempts to enumerate stored Windows credentials using native command-line utilities such as vaultcmd.exe and cmdkey.exe, or by invoking CredEnumerate/Get-StoredCredential functions via PowerShell scripts. These methods are commonly used by attackers to gain access to cached passwords, tokens, or network credentials stored in the Windows Credential Manager.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of bitsadmin.exe to initiate file transfers from remote HTTP/HTTPS locations. This behavior is frequently used by adversaries to download malicious payloads onto a host using legitimate system utilities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects execution of regsvr32.exe with flags indicative of the Squiblydoo application control bypass technique. The rule monitors for the use of the /i flag to load COM scriptlets from remote URLs (http/https) or UNC paths, or the inline loading of scrobj.dll, specifically in conjunction with the silent (/s) flag. Legitimate processes signed by Microsoft are excluded from detection unless remote URL execution is involved.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Page 561 of 867