avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,193 views

8,664 detections

Detects unauthorized processes (those not identified as standard web browsers) accessing browser profile directories (Local Storage or IndexedDB) associated with major AI platforms such as OpenAI, ChatGPT, Anthropic, and Copilot. This behavior is indicative of credential theft or session token exfiltration from local browser storage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of rundll32.exe with arguments pointing to remote UNC paths, HTTP/FTP URLs, or local DLL files residing outside of standard, trusted Windows system directories (System32/SysWOW64). This behavior is indicative of an attempt to proxy malicious code execution, commonly associated with fileless or remote payload retrieval techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects potential Remcos RAT loader activity involving process hollowing or injection into browser processes. This rule specifically looks for common browser executables (iexplore.exe, chrome.exe, firefox.exe) where the initiating parent process is 'Optimax.dll' or contains 'SystemOptimizer', which are indicators associated with the Remcos RAT loader.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
006
This rule detects the creation of common media file types (audio and video) within user-specific application data, temporary, or user profile directories. This activity could be indicative of various malicious behaviors, including data exfiltration, staging of malicious payloads, or the dropping of decoy files by malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
106
This rule detects the use of password derivation functions (like argon2id, scrypt, pbkdf2) in command lines, which can be indicative of ransomware activity, specifically associated with Prinz Eugen. It focuses on processes like 'servertool.exe', 'encrypt.exe', and 'powershell.exe' initiating these commands.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
006
This rule detects the creation or modification of executable files (.com, .exe, .scr, .pif, .bat, .cmd) in common user directories (Documents, Downloads, Desktop) where the initiating process is a legitimate application like explorer.exe, winrar.exe, or 7z.exe. This pattern is often used in phishing attacks where malicious executables are disguised as benign documents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
106
Detects suspicious installations of ManageEngine Endpoint Central components (ManageEngineADSelfService.exe or me_servicelaunchpad.exe) when executed with silent installation parameters or initiated by scripting engines (wscript.exe, cscript.exe, powershell.exe), followed by the execution of 'reg.exe' or 'regsvcs.exe' within a two-hour window. This pattern can indicate an attempt to install or configure the software surreptitiously, potentially for persistence or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
106
This rule detects inbound Remote Desktop Protocol (RDP) connections (ports 3389, 3390, 3391) that are initiated by common scripting engines such as wscript.exe, cscript.exe, or powershell.exe. This behavior can be indicative of post-exploitation activity where an attacker uses scripts to establish remote access.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
006
This rule detects potential memory-resident malware or staging activity by identifying instances where a high volume of DLL, OCX, or SYS files are loaded from user-writable directories (Temp, AppData, Users) on a specific device within a one-hour window. A threshold of 5 or more unique image loads from these locations is flagged as potentially suspicious, as it may indicate an attacker loading multiple malicious components or modules.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of script-based interpreters (wscript.exe, cscript.exe, powershell.exe) where the command line contains keywords typically associated with downloading or executing remote content (http, ftp, download, invoke, execute). This activity is often used in the initial stages of a malware attack to retrieve and run malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Page 563 of 867