avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,193 views

8,664 detections

Detects command-line execution patterns associated with the BumbleBee malware loader, specifically looking for process names like 'secur.exe', 'secure.exe', 'update.exe', or the string 'bumblebee' within the command line arguments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects modifications to Windows Registry keys related to Component Object Model (COM) objects (CLSID or InprocServer32) where the registry value points to suspicious file paths, specifically those within temporary directories like Temp or AppData. This behavior is indicative of an attacker attempting to establish persistence or perform privilege escalation by hijacking COM object execution flow.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects outbound network connections to URLs containing strings associated with Qakbot (Qbot) malware infrastructure and common ports used by the malware for command-and-control communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
203
Detects the creation of executable files (.exe, .com, .scr, .vbs, .js) that contain financial-themed keywords (e.g., GST, NEFT, RTGS, IMPS, Banking) in their filename. This pattern is commonly used in social engineering and phishing attacks to trick users into executing malicious payloads disguised as legitimate banking or financial documents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects command line activity indicative of an attempt to access or extract browser-related files such as 'Cookies' or 'Local State', which are commonly associated with session theft or credential harvesting from major web browsers like Chrome, Firefox, Edge, and Safari.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects potential ransomware lateral movement patterns by correlating specific network connection attempts (SMB/RDP/RPC) with the observed creation of files having the '.prinzeugen' extension on the same host within a 2-hour window. This behavior is indicative of a ransomware strain propagating across the network and performing encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects network activity associated with the ROOTBOY actor, specifically identifying internal devices communicating with known malicious command and control (C2) IP addresses and subsequently attempting to access specific suspicious domains or URLs linked to the actor's infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
This rule detects network connections made to specific non-standard ports (7777, 8080, 8443) where the remote URL contains substrings associated with proxy or tunneling activities ('proxy', 'tunnel', 'hide'). This behavior is commonly associated with malware attempting to evade security controls by routing traffic through unauthorized intermediaries or obfuscated tunnels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects the creation of image-related files with generic names in common temporary or user download directories that fall within a specific file size range (100KB-1000KB). These characteristics are often indicative of steganography where malicious payloads or data are embedded within seemingly benign image files to bypass security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects process executions containing sensitive keywords related to trust, certificates, and multi-factor authentication (e.g., 'mfa', '2fa', 'otp') that are not initiated by standard trusted system processes (services.exe, wininit.exe, smss.exe). This pattern is often indicative of credential manipulation, certificate harvesting, or tampering with authentication mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Page 566 of 867