avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,236 views

8,664 detections

Detects access, copying, or creation of files within common cryptocurrency wallet directories, as well as registry lookups related to Bitcoin data directories. This behavior is often indicative of info-stealing malware or an adversary attempting to exfiltrate digital currency assets from a compromised host.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects file creation, copy, or rename operations within known VPN application directories (CyberGhost, ExpressVPN, NordVPN) when initiated by Chromium Embedded Framework (CEF) related processes (CefSharp.BrowsersSubprocess). This behavior is highly irregular as standard web browser components should not be modifying the local configuration or installation directories of VPN software.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects potential exposure of API keys, tokens, or secrets within FTP directory listings. It specifically looks for network events on remote port 21 (FTP) where the 'RemoteUrl' contains keywords like 'api_key', 'apikey', 'token', 'secret', or 'key=' during a network signature inspection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects network events where FTP (port 21) traffic contains specific timestamp-like patterns in the RemoteUrl, which could indicate an attempt to exploit the Squidbleed vulnerability related to timestamp-to-filename parsing anomalies. The rule looks for 'LIST' command combined with '12:34:56', '2026-', or 'timestamp' in the URL.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
Detects file creations (images), image loads, and process execution activity originating from or related to the 'SCef.WindowsAdapter' directory. This directory is often associated with specific third-party application behaviors and should be monitored for potential anomalous execution or staging of suspicious files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects reads of HKLM\SYSTEM\CurrentControlSet\Control\SystemStartOptions, the value that stores boot parameters (e.g. NOEXECUTE=OPTIN vs SAFEBOOT:MINIMAL). Ransomware including Snatch and Qilin query this key to determine whether the host is already in Safe Mode before forcing a reboot and encrypting with AV/EDR unloaded.
Treat as a high-interest hunting lead when paired within minutes with Safe Mode staging:
bcdedit /set safeboot, reg add under SafeBoot\Minimal or SafeBoot\Network, or
shutdown /r.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects Hannibal Stealer reconnaissance activity involving the creation of a 'config.json' file within the 'SCef.WindowsAdapter' directory, correlated with suspicious process executions attempting to enumerate system information via 'GetComputerNameEx' or 'GetAdaptersInfo' API calls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potential exploitation of the Squidbleed vulnerability by identifying network connections to FTP port 21 where the remote URL contains 'PASV' or 'EPSV' commands, and the initiating process is 'squid.exe'. This indicates an attempt to abuse FTP passive mode through the Squid proxy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects potential credential harvesting activity associated with the Hannibal Stealer. It looks for non-standard processes (processes other than the browsers themselves) that access sensitive browser credential stores (like 'Login Data', 'cookies.sqlite', or 'key4.db') and correlate these file access events with the loading of 'bcrypt.dll' or 'CefSharp.BrowsersSubprocess.dll', which are often used for decryption or browser automation/sub-processes during credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Page 570 of 867