avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,548 copies160 likes52,256 views

8,664 detections

Identifies mshta.exe accessing externally hosted HTA content from a user-initiated Explorer session, potentially indicating malicious remote code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Identifies the creation of PowerShell or batch files in unusual ProgramData subdirectories by command-line interpreters, which may indicate malware staging or persistence preparation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects excessive caret (^) escaping in command lines, a common obfuscation technique used by attackers to evade detection and conceal malicious commands. The rule specifically looks for command-line executions by cmd.exe, powershell.exe, or pwsh.exe that contain more than 5 caret characters and a pattern of at least three alphanumeric characters immediately followed by a caret.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects mshta.exe launched from Windows Explorer to retrieve remote HTA content over HTTP, a technique frequently observed in phishing campaigns and initial access attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the use of 'forfiles.exe' with the '/c' execution parameter, a technique that can be abused to launch arbitrary commands while potentially bypassing application controls. This activity is often associated with defense evasion tactics.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects scheduled tasks created with embedded PowerShell XOR decoding logic, ReadAllBytes, and Invoke-Expression techniques that may be used to establish persistence and execute obfuscated payloads. The rule specifically looks for 'schtasks.exe' creating a task with '/create', containing 'OneDrive', 'Startup', 'Task' in the command line, and also includes '-bxor', 'ReadAllBytes', 'iex', and '[Text.Encoding]::UTF8.GetBytes' which are indicative of obfuscated PowerShell execution via XOR decoding.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects execution of DWAgent from download or temporary directories rather than standard installation locations, potentially indicating unauthorized remote management activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Detects the creation of PowerShell or batch scripts within the C:\ProgramData directory, which is a common location abused by malware for payload staging and persistence. The rule specifically looks for file creation events where the initiating process is cmd.exe or powershell.exe and the file extension is either .ps1 or .bat.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Look for traffic to the known Sunburst C&C.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Exploited SolarWinds process starting CMD with suspicious parameters.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
000
Page 607 of 867