avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views

8,664 detections

Detects the execution of known Command and Control (C2) frameworks such as Sliver, Havoc, SparkRAT, or VShell from common suspicious temporary or staging directories (temp, tmp, appdata, programdata). This rule monitors process creation events to identify the presence of these unauthorized remote access tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects Microsoft Outlook spawning a command-line interpreter (cmd.exe or powershell.exe) followed by a network connection originating from that interpreter within a 5-minute window. This behavior is highly suspicious and often indicative of malicious macro execution or exploit delivery via email attachments leading to command-and-control activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects instances where Node.js (node.exe) or the Node Package Manager (npm.exe) process initiates common command-line shells (cmd.exe, powershell.exe) or network utility tools (curl.exe). This behavior is often associated with software supply chain attacks, exploitation of web applications, or malicious post-exploitation activity where Node-based environments are leveraged to execute system commands or download external payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
This rule identifies instances where python.exe or python3.exe executes from non-standard system paths and establishes an outbound network connection to external (non-private/non-loopback) IP addresses. This behavior is indicative of potential malicious activity, as legitimate applications typically execute from protected program file directories, while adversaries often execute unauthorized binaries from temporary or user-writable locations to initiate command and control (C2) communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
This rule detects potential DNS hijacking or redirection by comparing the returned IP address from a DNS query against a known list of authoritative IP addresses for specific domains. If an internal DNS resolver returns an IP address that does not match the authoritative record, it flags the event as a potential DNS response mismatch. It includes risk scoring based on the number of distinct affected hosts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
This rule detects the creation and subsequent deletion of a local user account within a 240-minute window. This behavior is often indicative of an adversary creating a temporary, ephemeral account for malicious activity (e.g., persistence or lateral movement) and then removing it to evade detection or cover their tracks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects failed Windows logon attempts (Event ID 4625) where the supplied username conforms to typical password complexity requirements (minimum 10 characters, including uppercase, lowercase, digit, and special character). This behavior often indicates that a user has mistakenly entered their password into the username field, which may expose credentials in cleartext logs and suggests a potential security awareness issue or an attempt to bypass authentication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects repeated authentication failures (Event ID 4625) with a specific sub-status code 0xC0000072, which indicates that the user account is disabled. This behavior is indicative of a brute-force or credential-stuffing attack against disabled accounts, or potentially misconfigured automated services attempting to authenticate with stale credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects potential Pass-the-Hash (PtH) activity by identifying NTLM Type 3 logons where the account domain originates from outside the local or known corporate domain. The rule specifically excludes system-related accounts such as ANONYMOUS LOGON, WORKGROUP, and NT AUTHORITY, focusing on attempts to authenticate against internal resources using potentially forged or captured credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects instances where an interactive user initiates a password change attempt as captured by Windows Security Event ID 4723. The rule filters out non-interactive accounts (ending with '$') and common service account naming patterns to focus on human-driven account modifications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Page 600 of 867