avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views

8,664 detections

This rule detects potential command and control (C2) beaconing activity by identifying non-browser processes that initiate regular, sustained outbound network connections over port 443. It aggregates connection data by hour and calculates metrics such as average frequency and standard deviation to identify consistent, periodic communication patterns characteristic of C2 agents while excluding common legitimate web browsers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
100
Detects the execution of known debugger/disassembler tools (Ghidra, dnSpy, x64dbg) that exhibit suspicious network behavior. The rule specifically looks for these tools initiating network connections to destinations outside of their official update or project domains shortly after execution, and filters out known good hash signatures.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects a process identified as a Go-compiled binary (via command-line arguments like 'goroutine' or 'runtime.main') that exhibits rapid, high-volume file interactions (more than 100 files accessed or created in a 60-second window) alongside outbound network connectivity. This behavior is indicative of malicious automated activity such as file encryption for ransomware or rapid data staging and exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects potential execution of a Tox ransomware negotiation channel by monitoring for processes that exhibit a high rate of file writes (potential encryption activity) in conjunction with command-line arguments containing specific patterns such as a 76-character string or the 'tox://' URI scheme, which are associated with Tox ransomware client activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects potential supply chain attacks where a suspicious Python package is installed via 'pip' followed by execution of suspicious commands or network activity from 'python.exe' within a short timeframe. This rule correlates process creation events involving pip installations with subsequent suspicious command-line activity or external network connections from Python processes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects network connections to Filen.io cloud storage initiated by processes other than common web browsers. This behavior is often associated with the use of command-line tools or scripts for unauthorized file exfiltration or data staging.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects instances where Node.js (node.exe) or the Node Package Manager (npm.exe) process initiates common command-line shells (cmd.exe, powershell.exe) or network utility tools (curl.exe). This behavior is often associated with software supply chain attacks, exploitation of web applications, or malicious post-exploitation activity where Node-based environments are leveraged to execute system commands or download external payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects network connections to the Telegram API (api.telegram.org) from processes identified as LOLBins or residing in suspicious, potentially writable locations such as Temp, AppData, or user-defined directories. This activity is often indicative of C2 communication or data exfiltration by malware bypassing standard messaging client restrictions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule monitors for outbound network connections to 'graph.microsoft.com' initiated by processes that are either unsigned or not digitally signed by Microsoft. It further correlates these connections with proxy logs to identify processes utilizing non-standard or unexpected User-Agents. This behavior is indicative of potentially malicious activity attempting to masquerade as legitimate Microsoft services or using the Microsoft Graph API for command and control or data exfiltration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the execution of known remote access and monitoring software (RMM/RAT) when launched as a child process of common web browsers or email clients. This behavioral pattern is frequently observed in phishing attacks where users are tricked into downloading and executing remote support tools, a technique often associated with the Luna Moth (Silent Ransom Group) campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Page 598 of 867