avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,236 views

8,664 detections

Detects unauthorized processes reading, copying, or renaming Kerberos ticket cache files (ccache) located in common temporary directories. This behavior is often associated with credential theft and potential Pass the Ticket attacks where adversaries attempt to extract session credentials to perform lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule monitors network logs (from proxies and firewalls) for web traffic (HTTP GET requests) containing suspicious JavaScript code injection patterns in the request context or message fields. It specifically looks for common XSS indicators such as <script tags, eval(), document.write(), fromCharCode(), and atob().
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects a pattern of network shared folder access followed by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') within a 45-minute window. This behavior is indicative of ransomware preparing to encrypt data on network shares.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
This rule detects a sequence of events indicative of ransomware deployment following a successful Remote Desktop Protocol (RDP) connection. Specifically, it looks for an inbound RDP connection (RemotePort 3389) to a device, followed within 60 minutes by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') on the same device. This pattern suggests an attacker gaining initial access or moving laterally via RDP and then deploying ransomware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
105
Detects network connections originating from a Squid proxy process (squid.exe or processes containing 'squid' in their name) attempting to connect to an FTP server (port 21). This could indicate a reachability test or other activity related to the Squidbleed vulnerability, or general proxy misuse.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
204
This rule detects network events where an FTP LIST response contains malformed directory entries, potentially indicating an attempt to exploit the Squidbleed vulnerability. It specifically looks for network signature inspections on port 21 (FTP) with common FTP commands (LIST, NLST, MLSD, MLST, RETR) in the RemoteUrl, while excluding common log and text file extensions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
004
This rule detects attempts to inject malicious DLLs into common Windows processes such as svchost.exe, explorer.exe, lsass.exe, and winlogon.exe. The detection is based on the loading of DLLs with suspicious names like 'hook.dll', 'inject.dll', 'payload.dll', or 'stage.dll' by these processes, which is indicative of process injection techniques often used by malware like Remcos RAT.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
104
Detects attempts by processes identified as Remcos RAT or its loader (GST*.com) to access Local Security Authority (LSA) secrets. This activity is indicative of credential dumping, where an attacker tries to extract sensitive authentication material from the system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
204
Detects unusual FTP command sequences where common file listing commands (LIST, NLST, MLSD) are used without specifying a filename parameter, and the RemoteUrl length is unusually short, potentially indicating reconnaissance or an attempt to exploit a vulnerability like Squidbleed. The rule specifically excludes common file extensions to reduce false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
104
Detects attempts by processes identified as Remcos RAT or its loader (GST*.com) to access Local Security Authority (LSA) secrets. This activity is indicative of credential dumping, where an attacker tries to extract sensitive authentication material from the system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
004
Page 572 of 867