avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,550 copies160 likes52,264 views

8,664 detections

This rule detects attempts to authenticate to SSH using GSSAPI (Generic Security Service Application Programming Interface). While GSSAPI can be used for legitimate authentication, its presence in logs might indicate an attacker attempting to use alternative authentication methods, potentially for lateral movement or privilege escalation, especially if unexpected in the environment.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects successful SSH authentications using the GSSAPI-with-MIC mechanism. This can indicate legitimate user logins or, in some cases, an adversary using valid credentials to access a system via SSH.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects attempts to manipulate user or service principal names (SPN/UPN) in Active Directory by adding non-ASCII or zero-width characters. Such modifications can be used by adversaries for obfuscation, to bypass detection mechanisms, or to create stealthy persistence. The rule specifically looks for Event IDs 4738 (User Account Changed) and 5136 (Directory Service Object Modified) where the 'servicePrincipalName' or 'userPrincipalName' attributes contain characters outside the standard ASCII range or zero-width characters like U+200B, U+200C, U+200D.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects network connections to a specific suspicious IP address (94.156.181.89) or to domains associated with Cloudflare Tunnel (.trycloudflare.com). This could indicate command and control activity, data exfiltration, or other malicious network communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the loading of 'hostfxr.dll' from suspicious user-specific AppData folders by 'CrossDeviceService.exe' or 'Teams.exe'. This behavior can indicate an attempt to load a malicious .NET runtime, potentially for DLL hijacking or code injection, often associated with persistence or execution techniques.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the creation of a named object with the specific name 'MakeAmericaGreatAgain'. This string has been associated with various malware and potentially unwanted programs, often used as a mutex or other synchronization object to ensure only one instance of the malicious process is running.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects when a file is renamed to have the suffix ':payload' and the initiating process's file name is the same as the previous file name. This behavior can be indicative of Payload Ransomware to hide or modify files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
This rule detects the presence of Blackbeard malware by identifying known SHA256 hashes of its components or network connections to its known C2 infrastructure. It correlates file events with specific hashes and network events with specific remote IP addresses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects LampoRAT malware based on known file hash execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects when 'Cursor.exe' (a legitimate application) spawns common command-line utilities (cmd.exe, powershell.exe, pwsh.exe, curl.exe, wget.exe, certutil.exe, bitsadmin.exe) with command-line arguments indicative of downloading files from the internet (e.g., containing 'http://', 'https://', 'ftp://', '-o', '-OutFile', 'iwr', 'DownloadString', 'DownloadFile'). This could indicate malicious activity where 'Cursor.exe' is being abused to facilitate ingress tool transfer or execute malicious payloads.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 603 of 867