avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,226 views

8,664 detections

This rule detects malicious activity associated with Kimsuky JSE loaders, which leverage XML DOM manipulation (e.g., bin.base64) and ADODB.Stream components to decode and drop base64-encoded payloads into the ProgramData directory. It further monitors for subsequent decoding attempts using certutil and the presence of specific, suspicious file extensions (e.g., .a9oc, .lpXD, .lpxQ) often used by this threat actor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of JSE files by wscript.exe or cscript.exe followed by the immediate self-deletion of the file from the Downloads folder, a behavior commonly observed in Kimsuky dropper activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects when non-FileZilla processes attempt to read or access sensitive FileZilla configuration files, specifically 'recentservers.xml' or 'sitemanager.xml', which are known to store plain-text credentials for site connections. This behavior is indicative of credential harvesting.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
Detects modifications to Azure AD domain federation settings or authentication methods that could indicate attempts to establish persistent access or bypass authentication controls (e.g., golden SAML attacks, domain-level backdoors). The rule monitors for successful operations related to domain federation, authentication changes, and domain management, excluding known administrative actions from internal Microsoft domains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects potentially unauthorized or suspicious usage of the Jam build tool (jam.exe or jamplus.exe). The rule flags when Jam is executed by non-standard parent processes, when suspicious command-line arguments are used, when Jam spawns unexpected child processes, or when Jam initiates network connections.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation or modification of Azure Storage Account management policies that include rules configured to delete blobs, snapshots, or versions in less than 30 days. This behavior may indicate an attempt at data destruction or unauthorized cleanup of cloud storage objects.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
This rule detects a potential data collection or exfiltration attempt in Microsoft Teams by identifying accounts that have accessed an abnormally high number of messages (more than 100 within a 5-minute window). This behavior may indicate an automated process or a compromised user account attempting to scrape internal communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects instances where a specific identity or caller triggers Azure Function or Logic App workflows at a high volume (more than 50 successful invocations within a 5-minute window). This threshold may indicate automated exploitation, potential brute-force attempts on API endpoints, or a misconfigured/malfunctioning service causing excessive resource usage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the creation of multiple executable files (.exe or .dll) within a 6-hour window in non-standard directories (outside of Windows or Program Files). The rule identifies scenarios where a single filename has three or more distinct SHA256 hashes associated with it on a specific device, which may indicate iterative malware delivery, obfuscation techniques, or persistence mechanism testing.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Page 571 of 867