avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,525 copies160 likes52,202 views

8,664 detections

Detects unusually fast response times for FTP LIST commands, which could indicate an automated or programmatic interaction with an FTP server, potentially related to a vulnerability exploitation or data exfiltration attempt. The rule specifically looks for network events on port 21 (FTP) where the URL contains 'LIST' and the response time is less than 100 milliseconds.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects network communication patterns indicative of RedLine Stealer activity by looking for specific keywords in the RemoteUrl field during inbound or outbound connections.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
This rule detects the execution of processes with command lines containing indicators associated with 'Phantom Stealer' malware, such as 'phantom stealer', 'stealer.dll', 'phantom.exe', or 'phtantom'. This could indicate an attempt to load or execute the stealer.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
Detects outbound network connections from workstations or servers to common message broker ports (MQTT 1883/8883, AMQP 5672). These protocols are sometimes abused for command-and-control (C2) communication, as they allow for pub/sub messaging patterns that can blend into legitimate network traffic.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
This rule detects the creation of an SVG file in common user-writable/temporary directories, followed closely (within 60 seconds) by the execution of common scripting interpreters (cmd.exe, powershell.exe, wscript.exe) by a web browser. This behavior is often associated with browser-based exploitation or malicious file downloads where an attacker uses an SVG or accompanying file to trigger secondary malicious processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects outbound network connections from 'squid.exe' to internal IP addresses on port 21 (FTP). This could indicate an attacker controlling an FTP server within the internal network, potentially exploiting a vulnerability like Squidbleed.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects instances where common web browsers (chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exe) initiate command-line utilities (cmd.exe, powershell.exe, wscript.exe) that include arguments indicative of downloading remote resources (curl, iwr, Invoke-WebRequest, bitsadmin, certutil). This pattern is frequently used to download and execute second-stage malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation or modification of Azure Storage Account management policies that include rules configured to delete blobs, snapshots, or versions in less than 30 days. This behavior may indicate an attempt at data destruction or unauthorized cleanup of cloud storage objects.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Page 569 of 867