avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,530 copies160 likes52,244 views

8,664 detections

This rule detects VBScript execution (via wscript.exe or cscript.exe) that attempts to load WinHTTP objects (WinHttpRequest.5.1, MSXML2.XMLHTTP) or uses generic object creation functions (CreateObject, GetObject). This behavior is often associated with VBScripts establishing command and control (C2) communication or performing data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
This rule detects a suspicious sequence of events indicative of ransomware activity, specifically the Prinz Eugen ransomware. It looks for the execution of common file compression utilities (7z.exe, rar.exe, WinRAR.exe, winzip.exe) followed by the execution of known ransomware encryption executables (servertool.exe, encrypt.exe) on the same device within a 30-minute window. This pattern suggests that an attacker is compressing files before encrypting them, a common tactic to reduce the size of data for faster encryption or exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
105
This rule detects the execution of VBScript files (.vbs or .vbe) by wscript.exe or cscript.exe where the filename contains keywords commonly associated with phishing lures (e.g., 'Invoice', 'Bill', 'Statement', 'Report', 'Debit', 'Credit', 'Notice', 'Alert', 'Urgent', 'Payment'). The rule triggers if three or more such executions are observed within a one-hour window on a single device, indicating potential malicious activity often associated with phishing campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
205
Detects an unusually high frequency of storage blob and container listing operations within a short time window. This behavior often indicates an attempt to enumerate the contents of Azure Blob Storage, which may be a precursor to data discovery or exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
302
This rule detects the use of system utilities (wevtutil.exe, auditpol.exe, PowerShell) to interact with, query, or check status of security event logs and auditing configurations. While these tools are standard for administration, their usage by non-system accounts can indicate an adversary attempting to understand, monitor, or manipulate system audit policies and event log configurations as part of a reconnaissance or defense evasion strategy.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the use of the 'powercfg.exe' utility by non-system accounts to modify power settings, such as disabling hibernation, modifying standby/sleep timeouts, or changing monitor/disk timeout configurations. Such actions can be indicative of attempts to maintain system availability, prevent the system from entering a low-power state that might terminate malicious processes, or ensure persistent execution of unauthorized activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the successful execution of the 'Run Command' action on Azure virtual machines outside of defined business hours (8 AM to 6 PM). Run Command allows the execution of arbitrary scripts on a VM, which can be leveraged for administrative tasks but also by attackers for post-exploitation activities, persistence, or lateral movement. Monitoring these operations during off-hours may indicate unauthorized use or anomalous administrative activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
102
Detects the use of VMware ESXi command-line management tools (esxcli, esxcfg) or VMware PowerCLI cmdlets (e.g., Connect-VIServer, Invoke-VMScript) from endpoints that are not identified as servers. This behavior often indicates an attacker attempting to manage or interact with a virtualized environment from a compromised workstation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
202
This rule detects common security product executables (MsMpEng.exe, SenseNdr.exe, csfalconservice.exe, CylanceSvc.exe) that are running from file paths inconsistent with their legitimate installation directories. This behavior is indicative of an adversary attempting to masquerade as trusted security software to evade detection or achieve persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the modification of Azure Storage account management policies where the 'daysAfterModificationGreaterThan' condition is set to 7 days or less, specifically including a 'delete' action. This could indicate an attempt by an adversary to shorten the lifecycle of data for rapid, automated, and potentially malicious data destruction within Azure Blob Storage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Page 573 of 867