avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,230 views

8,664 detections

Detects process executions containing sensitive keywords related to trust, certificates, and multi-factor authentication (e.g., 'mfa', '2fa', 'otp') that are not initiated by standard trusted system processes (services.exe, wininit.exe, smss.exe). This pattern is often indicative of credential manipulation, certificate harvesting, or tampering with authentication mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects anomalous device network activity involving 5G-specific protocol ports (e.g., GTP-U, SIP). The rule aggregates unique port usage per device over 1-hour intervals to identify potential network reconnaissance, scanning, or unauthorized control plane communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects Microsoft Office applications (Word, Excel, PowerPoint) spawning command-line interpreters (PowerShell, CMD, WScript). This behavior is characteristic of malicious macros or exploitation attempts where Office applications execute shell commands to facilitate second-stage payload delivery or system compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
This rule detects network traffic containing keywords commonly associated with Indian payment gateways and financial transactions (NEFT, RTGS, IMPS, GST, PAN, IFSC). This could indicate data exfiltration or suspicious activity involving financial information, potentially related to malware like Remcos RAT.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
205
This rule detects when the Remcos RAT loader attempts to access browser cache folders (Chrome, Firefox, Opera). This activity is indicative of credential dumping, where the malware tries to extract sensitive information like stored passwords or session tokens from web browsers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
105
This rule detects potentially malicious PowerShell execution by identifying the use of obfuscated encoded commands or common execution policy bypass flags. It monitors for patterns such as '-EncodedCommand' with long strings, '-ExecutionPolicy Bypass', and other flags typically used to hide PowerShell execution or bypass security restrictions, while excluding trusted Microsoft-signed processes and commands executed from standard system paths.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects unauthorized or suspicious use of virtualization management tools (e.g., esxcli, vim-cmd, PowerShell cmdlets for vSphere/Hyper-V) to perform disruptive actions such as powering off VMs, removing snapshots, or modifying firewall configurations. The rule excludes activity originating from standard management processes and trusted VMware/Microsoft signed processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
502
Detects DNS resolutions for major AI/LLM provider domains (e.g., OpenAI, Anthropic, Google AI) originating from processes that are not common, known browsers or development tools. This behavior is indicative of potentially malicious applications or malware using AI APIs for automated tasks, such as content exfiltration or sophisticated C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potentially malicious PowerShell execution by identifying the use of obfuscated encoded commands or common execution policy bypass flags. It monitors for patterns such as '-EncodedCommand' with long strings, '-ExecutionPolicy Bypass', and other flags typically used to hide PowerShell execution or bypass security restrictions, while excluding trusted Microsoft-signed processes and commands executed from standard system paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects when common document-handling applications (such as Microsoft Office suite or PDF readers) spawn known remote access and support tools. This behavior is highly indicative of vishing-based social engineering attacks, where a user is tricked into downloading and executing a remote management tool via a malicious document.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Page 567 of 867