avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,255 views

8,664 detections

This rule identifies instances of PowerShell executing with an encoded command followed immediately (within 300 seconds) by an outbound network connection to a non-standard port or non-internal IP address. This behavior is indicative of a remote access tool or reverse shell establishing command and control (C2) communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
000
This rule detects when Microsoft Office applications (Word, Excel, PowerPoint) create INI files within the `C:\ProgramData\` directory. This behavior can be indicative of malicious activity, such as macro-enabled documents dropping configuration files or payloads, or other forms of malware attempting to establish persistence or store data in a less scrutinized location.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects when fodhelper.exe, a legitimate Windows utility, is used to spawn processes other than cmd.exe or conhost.exe. This behavior is commonly associated with UAC bypass techniques where fodhelper.exe is abused to execute arbitrary commands with elevated privileges without a UAC prompt.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects multiple failed logon attempts (more than 5 within a 5-minute window) for user accounts from a single IP address. This behavior is indicative of a brute-force attack or password guessing attempt against user accounts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects the presence of the string "xhxhxhxhxhxpp" within the AdditionalFields of DeviceEvents. This string =represents a Mutex Indicator of Compromise (IOC).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects modifications to the 'User Shell Folders' registry key, which can be abused by adversaries to alter the location of special folders (e.g., Desktop, Documents) to point to attacker-controlled locations, potentially for persistence or data staging.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detect connections to the known C2 domain.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects the creation or interaction with mutexes that contain both 'asus_' and '_v' in their names. This pattern has been observed in malware associated with ASUS systems, potentially indicating the presence of malicious software attempting to establish a unique identifier on the compromised system.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects the presence of known ShadowAgent malware files on devices by matching their SHA256 hashes. It queries 'DeviceFileEvents' to identify any files with SHA256 hashes that are part of a predefined list associated with ShadowAgent.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects the execution of 'REAGENTC.EXE' with the '/disable' argument and 'WBADMIN.EXE' with 'delete catalog -quiet' within a 10-minute window on the same device. This combination of commands is indicative of an adversary attempting to inhibit system recovery by disabling Windows Recovery Environment and deleting the Windows Backup Catalog, often seen in ransomware attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 602 of 867