avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,953 views

8,664 detections

This rule detects a high volume of successful sign-in attempts to Exchange Online from a single IP address where the UserPrincipalName ends with '@' (indicating an anonymous or malformed UPN) and Conditional Access was not applied. This pattern can be indicative of anonymous SMTP relay abuse, often used for spamming or phishing campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects potential brute force attacks against Active Directory accounts by identifying multiple failed login attempts (EventID 4625) from the same IP address to the same account within a short time frame (10 failed attempts within 10 minutes).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the creation or modification of files that contain common certificate-related keywords such as 'crl', 'certificate', or 'pem'. This activity could indicate the deployment of new certificates, which might be legitimate or malicious, such as for establishing command and control, code signing, or evading detection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects suspicious command-line activity by looking for the presence of keywords such as 'risk', 'threat', or 'exposure' in process creation command lines (Event ID 4688). It then aggregates these events by computer and account over one-hour intervals and flags if 3 or more such activities occur within that hour, indicating potential reconnaissance or malicious activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects a high volume (10 or more within an hour) of file creations or modifications within the 'Program Files' directory where the filename contains the string 'update'. This could indicate legitimate software updates, but also potentially malicious activity attempting to masquerade as an update process, or an application writing to protected directories.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects a high volume of successful network connections to common web ports (80, 443, 8080, 8443) where the remote URL contains keywords like 'version' or 'software'. This pattern could indicate an adversary performing reconnaissance to identify installed software and their versions, potentially looking for vulnerabilities or specific applications to target. The threshold of 10 such activities within an hour for a single device is set to flag anomalous behavior.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects devices making a high volume (5 or more per hour) of successful network connections to remote URLs containing 'update' or 'patch' on port 443 (HTTPS). This could indicate legitimate system updates, but also potentially malicious update checks or beaconing activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects the creation of a Windows service where the service type is set to 'kernel' via the sc.exe command-line utility. This behavior is indicative of an attempt to load a kernel driver or perform low-level system modifications, which is often used by rootkits or malicious drivers. The rule filters out known trusted publishers to reduce noise.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects the execution of PowerShell with the EncodedCommand (-enc/-e/-ec) argument, which is frequently used by adversaries to hide malicious scripts and bypass simple command-line inspection. The rule excludes processes signed by Microsoft to reduce noise from legitimate system administration scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
This rule detects potential AS-REP Roasting activities by monitoring process creations for the Rubeus toolset (using the asreproast command) and PowerShell scripts executing commands related to AS-REP Roasting (Get-ASREPHash or asreproast). This technique is used by adversaries to extract Kerberos TGTs for accounts with Kerberos pre-authentication disabled, allowing for offline password cracking.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103