avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,526 copies160 likes52,233 views

8,664 detections

Detects emails successfully delivered to the inbox that exhibit authentication failures for SPF, DKIM, or DMARC, or where a mismatch between the 'SenderFromDomain' and 'SenderMailFromDomain' is observed, indicating potential email spoofing or unauthorized sender impersonation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects the creation of scheduled tasks or 'at' jobs initiated by VBScript engines (wscript.exe or cscript.exe). This behavior can be indicative of malicious activity, such as persistence mechanisms established by malware or phishing attacks that leverage VBScript to schedule future execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
4 months ago
105
Detects the execution of AutoHotkey or AutoIt automation scripts, particularly when these tools spawn suspicious child processes (e.g., cmd.exe, powershell.exe, wmic.exe), initiate commands from non-standard directories (Temp, AppData, Downloads), or run from locations outside of the standard Program Files installation directory.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects usage of common built-in tools (driverquery.exe, sc.exe) and PowerShell commands (Get-WindowsDriver, WMI queries for Win32_PnPSignedDriver or Win32_SystemDriver) used to enumerate installed system drivers. This is often part of reconnaissance to identify third-party drivers for BYOVD (Bring Your Own Vulnerable Driver) attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects potentially malicious Wi-Fi network enumeration or profile creation using 'netsh' or 'nmcli', as well as the loading of 'wlanapi.dll' by non-standard, unauthorized processes. Such activities can indicate an attempt by an adversary to discover, connect to, or exfiltrate data via nearby wireless networks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects the execution of AutoHotkey or AutoIt automation scripts, particularly when these tools spawn suspicious child processes (e.g., cmd.exe, powershell.exe, wmic.exe), initiate commands from non-standard directories (Temp, AppData, Downloads), or run from locations outside of the standard Program Files installation directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
This rule detects various commands and processes used by adversaries to enumerate virtual machine software, hypervisor configurations, and virtualization-based security features on a host. This is often part of reconnaissance to understand the environment, detect sandboxing, or identify virtualization platforms for further post-exploitation activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
002
Detects high-volume SSH or network logon failures from a single source IP address within a short time window, indicative of a brute force attack. The rule specifically mentions consistency with 'mpbrute2.bin' tooling used in the 'FortiBleed' campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
4 months ago
005
This rule correlates multiple low-to-medium confidence signals across file, process, network, and registry events to detect potential ransomware activity. The rule identifies suspicious behaviors including mass file renames, creation of known ransom note file types in multiple directories, shadow copy deletion via system utilities, disabling of antivirus and security monitoring, large archive staging, unauthorized outbound network connections, and suspicious process injection. Alerts are generated based on the aggregation and frequency of these signals, indicating a high probability of ransomware-related malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detection rule monitoring for indicators of compromise related to SolarWinds Serv-U, including anomalous Content-Encoding headers, unexpected child process execution, large file staging indicative of data exfiltration (Cl0p-style), outbound exfiltration, SQL injection artifacts, and unauthorized LDAP/Active Directory object enumeration by the Serv-U process.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Page 574 of 867