avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,485 copies160 likes51,974 views

8,664 detections

This rule detects when a user grants an OAuth application consent to access high-privilege scopes in an Azure environment. It specifically flags instances where the consent is not for all principals and the user performing the action is not a Global Administrator, which may indicate an attacker-controlled application being granted access to sensitive data or resources.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
404
This rule detects potentially unauthorized installation of extensions in Visual Studio Code (VSIX) or plugins in JetBrains IDEs (IntelliJ, PyCharm, WebStorm). It flags installations that do not originate from verified official marketplaces, which may indicate the manual installation of malicious or supply-chain compromised development environment extensions.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1008
This rule monitors the creation of new Azure Function Apps and identifies those that receive external, non-private network requests within 48 hours of their creation. This pattern may indicate the deployment of malicious or unauthorized serverless infrastructure for command-and-control, proxying, or automated tasks.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
408
This rule detects two common persistence techniques: the modification of Windows Registry Run keys with paths referencing temporary or application data directories, and the creation of autorun.inf files on removable or non-system drives to facilitate potential code execution upon media insertion.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
004
This rule detects potentially malicious activity where a web browser (e.g., Chrome, Edge, Firefox) spawns suspicious child processes (e.g., mshta.exe, wscript.exe) with command-line arguments that include indicators of script execution, remote code download, or command invocation, which is a common pattern in drive-by download attacks and malicious link execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
704
This rule detects network connections from devices to a specific IP address (62.102.148.212) and a set of associated ports (37393, 45839, 38471, 12345, 4444, 5555). This IP address and these ports are known indicators of compromise for the Remcos Remote Access Trojan (RAT) Command and Control (C2) infrastructure. Detection of such connections indicates potential Remcos RAT activity within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
7018
Detects the execution of remote commands on cloud virtual machines (Azure RunCommand or AWS SSM SendCommand) during defined off-hours (18:00 to 06:00). This rule identifies potentially unauthorized administrative or management activity occurring outside of standard business hours across cloud environments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
108
Detects potential execution chains related to QR code phishing (Quishing) by monitoring for suspicious process creation or outbound network connections originating from document readers, office applications, and QR scanner utilities. It covers three primary vectors: suspicious process spawning (e.g., Office apps launching cmd or powershell), non-standard network connections from document readers, and malicious URL-based LNK files spawned via explorer.exe.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
706
This rule detects potentially malicious behavior associated with web browser processes, including the execution of Python scripts, the loading of browser extensions from non-standard directories like AppData or Temp, the creation of Python scripts by browsers in temp folders, and outbound network connections by Python processes following browser activity. These patterns are often associated with browser-based exploitation, extension-based malware, or initial access stages where a browser is used as a conduit for malicious code execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
308
Detects instances where common web browsers (Chrome, Edge, Firefox, Brave) spawn command-line tools or script interpreters (cmd, PowerShell, wscript, mshta) as child processes. This behavior is highly indicative of drive-by download attacks, including the 'ClickFix' technique, where users are socially engineered into executing malicious commands under the guise of fake browser updates or error resolution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
206