avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,254 views

8,664 detections

This rule detects cross-process memory access events (Sysmon Event ID 10) where a process attempts to hook into keyboard-related Windows API functions such as SetWindowsHookEx, GetKeyState, or GetAsyncKeyState. It further filters for processes executing from suspicious locations (Temp, AppData, ProgramData) or those that are unsigned/unverified, which are common indicators of malicious keylogging or spyware activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects high-frequency requests (over 30 unique paths within a 5-minute window) to sensitive VPN-related URL paths that result in 403 (Forbidden) or 404 (Not Found) status codes from non-internal IP addresses. This behavior is indicative of an adversary performing directory enumeration or vulnerability scanning on public-facing infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects high-frequency requests (over 30 unique paths within a 5-minute window) to sensitive VPN-related URL paths that result in 403 (Forbidden) or 404 (Not Found) status codes from non-internal IP addresses. This behavior is indicative of an adversary performing directory enumeration or vulnerability scanning on public-facing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects high volume HTTPS outbound traffic (greater than 50MB within a 5-minute window) from a host that does not show evidence of preceding file encryption or volume shadow copy deletion activity. This rule is designed to identify potential unauthorized data exfiltration that deviates from typical ransomware-associated behavior patterns.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects the creation of scheduled tasks using schtasks.exe that point to high-risk directories (Temp, AppData, ProgramData) or utilize obfuscated PowerShell commands (encoded parameters). This behavior is often associated with adversary persistence or initial execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the execution of PowerShell or Command Prompt as child processes spawned by wscript.exe or cscript.exe, where the parent process command line indicates a JavaScript file being executed from the AppData or Temp directories. This behavior is highly characteristic of the Gootloader malware dropper, which leverages script engines to initiate subsequent malicious stages.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the use of built-in Windows utilities (vssadmin, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or modify boot configuration settings to disable recovery features, which is a common precursor to ransomware encryption.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the creation of scheduled tasks using schtasks.exe that point to high-risk directories (Temp, AppData, ProgramData) or utilize obfuscated PowerShell commands (encoded parameters). This behavior is often associated with adversary persistence or initial execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects the execution of PowerShell or Command Prompt as child processes spawned by wscript.exe or cscript.exe, where the parent process command line indicates a JavaScript file being executed from the AppData or Temp directories. This behavior is highly characteristic of the Gootloader malware dropper, which leverages script engines to initiate subsequent malicious stages.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Detects potential password spraying or brute force activity by monitoring Windows Event Code 4625. The rule identifies source IP addresses that have attempted to authenticate against more than 10 unique accounts within a 5-minute window, calculating a spray ratio to differentiate high-intensity credential spraying attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
Page 601 of 867