avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,972 views

8,664 detections

Detects Distributed Component Object Model (DCOM) lateral movement activity by monitoring for mmc.exe and dllhost.exe network connections to non-local endpoints or when these processes are spawned by suspicious parent processes typically associated with command execution or malicious behavior.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
004
This rule detects successful self-service password reset (SSPR) operations performed by users from IP addresses geolocated to a country that does not match their typical sign-in activity over the past 30 days. This behavior may indicate account takeover where an adversary has compromised credentials and is resetting the password to maintain access or gain further persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects potential password spraying attacks against Azure Active Directory by identifying sign-in failures from a single source IP address targeting a large number of distinct user accounts within a short time window. It specifically filters for common authentication failure codes and checks for low volume of failures per account, which is characteristic of password spraying behavior.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects MFA push bombing attacks by identifying a high volume of MFA challenge failures (errorCode 500121) associated with a single user account within a short time window. This activity often indicates an attempt to overwhelm or fatigue a user into inadvertently approving an MFA request.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects anomalous authentication failure patterns against Azure AD Service Principals from a single IP address. The rule identifies potential brute force attacks (high volume of failures) or service principal enumeration (multiple distinct service principals targeted).
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
This rule detects potential Kerberoasting activity by monitoring for high volumes of Kerberos TGS (Ticket Granting Service) requests (Event ID 4769) using the RC4 encryption type (0x17) within a short timeframe. Kerberoasting involves requesting tickets for service accounts to offline crack their passwords. The rule filters out known service accounts and system-level accounts ending in '$'.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
104
Detects high-volume LDAP queries or specific expensive LDAP search events (Event ID 1644) on Domain Controllers, which are often indicative of reconnaissance activities such as domain environment mapping or user/group enumeration.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
204
Detects the invitation of an external user to the Azure AD tenant. This activity often results in the creation of a guest account with the '#EXT#' suffix in the User Principal Name (UPN). Monitoring this event is critical for identifying potential unauthorized external access or social engineering attempts aimed at gaining persistence within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
104
This rule detects network communication (connections, DNS queries, or proxy logs) between endpoints and a list of known malicious domains and IP addresses associated with Mistic and Woodgnat/KongTuke threat families. It identifies these activities across network event logs, DNS queries, and security logs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
Detects modifications to the AdminSDHolder object in Active Directory via Windows Security Event ID 5136. The AdminSDHolder object maintains the security permissions for all objects protected by the AdminSDHolder process. Adversaries often modify this object to establish persistence and gain unauthorized access to highly privileged accounts within the domain.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004