avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,182 views

8,664 detections

Detects the creation of scheduled tasks using schtasks.exe where the task action executes a scripting engine or living-off-the-land binary (LOLBin). This behavior is often indicative of adversaries attempting to establish persistence or execute code using native system tools to evade detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the use of certutil.exe to download files from a remote URL using the -urlcache or -split flags. This behavior is a common Living-off-the-Land (LotL) technique used by adversaries to bypass security controls and download secondary payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the use of native Windows utilities (vssadmin, wmic, powershell, wbadmin) to delete volume shadow copies or backup catalogs. This activity is commonly associated with ransomware or destructive attacks attempting to prevent system recovery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of known adversary-in-the-middle (AiTM) phishing frameworks, such as Evilginx or Modlishka, by identifying process names, paths, or specific command-line arguments (e.g., --phishlets, --proxy, --lure) used to initiate these proxy-based phishing sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of Remote Monitoring and Management (RMM) software initiated by common Windows script interpreters. This pattern is indicative of unauthorized deployment of remote access tools, often used by adversaries to establish persistence and command-and-control channels following initial compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects file creation or modification events targeting sensitive cloud credential storage locations, such as AWS credentials files, Azure configurations, and Google Cloud credentials databases. The rule filters out known legitimate CLI tools, flagging potential unauthorized access or exfiltration of cloud credentials by other processes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects execution of regsvr32.exe with flags indicative of the Squiblydoo application control bypass technique. The rule monitors for the use of the /i flag to load COM scriptlets from remote URLs (http/https) or UNC paths, or the inline loading of scrobj.dll, specifically in conjunction with the silent (/s) flag. Legitimate processes signed by Microsoft are excluded from detection unless remote URL execution is involved.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of scheduled tasks using schtasks.exe where the task action executes a scripting engine or living-off-the-land binary (LOLBin). This behavior is often indicative of adversaries attempting to establish persistence or execute code using native system tools to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Page 562 of 867