avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,483 copies160 likes51,962 views

8,664 detections

Detects modifications to Azure AD/Entra ID application configurations, specifically updating the 'RedirectUri' or 'ReplyUrls' to point to potentially external or unauthorized domains. This technique is often used in OAuth-based application-consent phishing campaigns to redirect authorization codes to adversary-controlled servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
003
Detects network connections from common web browser processes (Chrome, Edge, Brave, Electron) to loopback addresses (127.0.0.1 or Localhost) where the URL path contains sensitive keywords like /code, /textbox, /credentials, or /secrets. This behavior is often associated with browser-based exploitation attempts, such as targeting local development servers or internal browser automation interfaces to extract sensitive information.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of known PetitPotam exploitation tools or the use of command line arguments related to EFS RPC functions (e.g., EfsRpcOpenFileRaw) used to coerce authentication via NTLM reflection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects web browsers and browser-related applications (e.g., Chrome, Edge, ChatGPT, Electron apps) spawning suspicious child processes that are commonly used for command-line execution or script interpretation. This behavior is often indicative of malicious extensions, browser exploits, or attempts to leverage browser processes for initial execution or lateral movement.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects high frequency inbound network connection attempts or accepted connections initiated by common file sharing processes (e.g., NearShare.exe, NearbySharing.exe, quickshare.exe, sharingd, airplayd). A high volume of inbound connection attempts may indicate brute force, discovery, or malicious scanning behavior using legitimate file sharing tools as a conduit.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the use of the 'net.exe' or 'net1.exe' command-line utilities to mount a local SMB share using loopback addresses (127.0.0.1 or localhost) with the '/tcpport' argument. This pattern is indicative of attempts to exploit CVE-2026-24294 to bypass NTLM authentication protections through local reflection or relay attacks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103
Detects the execution of known Impacket relay tools such as ntlmrelayx and smbrelayx, which are commonly used by adversaries to perform NTLM relay attacks to gain unauthorized access or execute code on remote systems.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects web browsers and browser-related applications (e.g., Chrome, Edge, ChatGPT, Electron apps) spawning suspicious child processes that are commonly used for command-line execution or script interpretation. This behavior is often indicative of malicious extensions, browser exploits, or attempts to leverage browser processes for initial execution or lateral movement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects the execution of known Impacket relay tools such as ntlmrelayx and smbrelayx, which are commonly used by adversaries to perform NTLM relay attacks to gain unauthorized access or execute code on remote systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
103
Detects GhostBackdoor malware execution via known file hash.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004