avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,193 views

8,664 detections

Detects modifications to Windows Registry keys related to Component Object Model (COM) objects (CLSID or InprocServer32) where the registry value points to suspicious file paths, specifically those within temporary directories like Temp or AppData. This behavior is indicative of an attacker attempting to establish persistence or perform privilege escalation by hijacking COM object execution flow.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
503
Detects host-based reconnaissance activity patterns indicative of Trickbot malware. The rule monitors for a high frequency (>= 4 unique commands within a 30-minute window) of diagnostic commands ('tasklist', 'systeminfo', 'ipconfig', 'net') executed by cmd.exe or powershell.exe, which is a common behavior pattern for adversary discovery processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of processes with command-line arguments containing keywords related to known supply chain attacks (e.g., solarwinds, 3cx, kaseya, npm, pypi). This rule is intended for threat hunting to identify potential exploitation attempts or malicious activity involving software supply chain components.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of processes with command-line arguments indicative of destructive activity, such as wiping disks, partitions, or boot records, often associated with wiper malware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
This rule detects potential lateral movement activity by identifying devices that establish connections to three or more distinct remote IP addresses via SMB/CIFS ports (445 or 139) within a one-hour window. The query excludes internal network ranges (10.x.x.x and 192.168.x.x) to focus on connections that may be traversing network boundaries or reaching out to segments that might indicate unauthorized discovery or movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects connection attempts to common administrative and remote access ports (RDP, SSH, SMB, RPC) from non-internal IP address ranges. Such activity may indicate an attempt to bypass Zero-Trust network policies or unauthorized remote access attempts from external or untrusted segments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
303
Detects a sequence of events where ManageEngine or IDrive remote monitoring software is followed within 120 minutes by the execution of potential staging or encryption-related tools (servertool.exe or encrypt.exe) on the same device. This pattern may indicate the abuse of legitimate administrative tools for unauthorized activities or ransomware-like behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects the usage of standard Windows system administration utilities (infinstall.exe, devcon.exe, pnputil.exe, sc.exe) when the command line arguments include keywords commonly associated with driver loading or kernel-level operations, which may indicate the installation of a rootkit or malicious driver.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects attempts to exploit the Squidbleed vulnerability (C11 strchr() Null Terminator Behavior Exploitation) by monitoring 'squid.exe' process command lines for the presence of null terminator characters or their string representations. This indicates an attempt to manipulate string handling functions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
105
This rule detects WebSocket communication attempts from a device to known command and control (C2) IP addresses associated with the Remcos Remote Access Trojan (RAT). It specifically looks for network events where the remote URL contains 'ws://', 'wss://', or 'websocket' and the remote IP address matches one of the listed indicators of compromise (IOCs).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
205
Page 564 of 867