avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,226 views

8,664 detections

This rule detects WebSocket communication attempts from a device to known command and control (C2) IP addresses associated with the Remcos Remote Access Trojan (RAT). It specifically looks for network events where the remote URL contains 'ws://', 'wss://', or 'websocket' and the remote IP address matches one of the listed indicators of compromise (IOCs).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
205
Detects potential exploitation attempts related to the Squidbleed vulnerability by monitoring 'squid.exe' or processes with 'squid' in their command line for AddressSanitizer related keywords indicating memory safety issues like overflow, underflow, or use-after-free.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
205
This rule detects potential DarkCloud RAT activity by looking for specific strings in process command lines. The strings 'darkcloud', 'dark.cloud', 'cloud.dll', or 'shadow.exe' are indicative of the RAT's components or communication patterns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
205
Detects attempts to bypass User Account Control (UAC) by abusing 'eventviewer.exe'. This rule specifically looks for 'eventviewer.exe' being initiated by suspicious processes like 'powershell.exe', 'cmd.exe', 'rundll32.exe', or 'Optimax.dll', while excluding legitimate command-line usage of 'eventvwr.exe'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
This rule detects potential memory-resident malware or staging activity by identifying instances where a high volume of DLL, OCX, or SYS files are loaded from user-writable directories (Temp, AppData, Users) on a specific device within a one-hour window. A threshold of 5 or more unique image loads from these locations is flagged as potentially suspicious, as it may indicate an attacker loading multiple malicious components or modules.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects the execution of PowerShell or pwsh.exe with an encoded command. Adversaries often use encoded commands to obfuscate their malicious scripts and evade detection. The rule specifically looks for the '-EncodedCommand' or '-enc' parameter followed by a base64-encoded string of at least 20 characters.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
This rule detects various methods of establishing a reverse shell on Linux systems. It looks for process creation events involving common shell interpreters (bash, sh) attempting to connect to network devices via /dev/tcp or /dev/udp. It also identifies the use of network utilities like netcat (nc, ncat, netcat, nc.traditional) and socat when used with command execution flags (-e, -c, EXEC) and shell interpreters. Additionally, it flags direct outbound network connections initiated by these shell interpreters or network utilities, which could indicate a reverse shell communication channel.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
304
Detects EvilTokens phishing HTML page with AES-GCM encrypted payload by file hash and characteristic code patterns
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects attempts to invoke 'sudo' for privilege escalation or enumeration from non-interactive contexts such as scripts, scripting language interpreters, or web/application service processes. It also identifies 'sudo -l' or '--list' commands used for privilege enumeration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects potential persistence mechanism installation by monitoring the creation of registry values in 'Run' or 'RunOnce' keys, followed by the execution of 'powershell.exe' or 'wscript.exe' on the same host within a 5-minute window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Page 565 of 867