avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,484 copies160 likes51,969 views

8,664 detections

This rule detects potential automated credential stuffing attempts followed by successful authentication and subsequent access to sensitive/privileged APIs within Azure/Entra ID environments. It correlates multiple failed login attempts for service-oriented account names (e.g., svc, api, bot) with a successful login from the same user shortly thereafter, followed by privileged API operations (e.g., KeyVault secret access, user management) within a short time window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
008
This rule detects two scenarios on Linux systems: 1. A non-root process interacting with a root process (e.g., cross-process communication where the source is non-root and the target is root). 2. Any process (excluding root) exhibiting indicators related to 'AF_ALG' or 'splice', or mentioning 'CVE-2026-31431' in its name or description. These indicators are often associated with privilege escalation attempts or kernel exploits.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
1013
This rule detects the execution of VBScript files (.vbs or .vbe) by wscript.exe or cscript.exe where the filename contains keywords commonly associated with phishing lures (e.g., 'Invoice', 'Bill', 'Statement', 'Report', 'Debit', 'Credit', 'Notice', 'Alert', 'Urgent', 'Payment'). The rule triggers if three or more such executions are observed within a one-hour window on a single device, indicating potential malicious activity often associated with phishing campaigns.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
17018
This rule identifies potential account compromise by detecting successful logins to at least two different SaaS applications monitored by Microsoft Cloud App Security (MCAS) within a 2-hour window, originating from geolocations separated by more than 500 kilometers. This behavior is indicative of credential sharing or account hijacking where an adversary accesses multiple cloud services rapidly from geographically distant locations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
307
Detects when a new federated identity credential is successfully added to an Azure Active Directory (Entra ID) application. This activity is a common method for attackers to establish persistent access to cloud resources by bypassing password-based authentication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
507
Detects the configuration and usage of personal Microsoft OneDrive accounts on corporate endpoints. This is achieved by monitoring for OneDrive process execution with personal account command-line arguments, OneDrive setup utilities configured with personal tenant identifiers, and file system activity within directory paths associated with personal OneDrive synchronization.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
407
This rule detects the presence of Phoenix malware by identifying known SHA256 hashes of its components or network connections to its command and control (C2) infrastructure. It correlates file events with known malware hashes and network events with known C2 IP addresses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
Detects LampoRAT malware based on known file hash execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
003
This rule detects outbound network connections to URLs associated with common file sharing services (e.g., Dropbox, Mega, Gofile) or temporary email providers (e.g., Temp-Mail). Such connections can indicate data exfiltration attempts, use of unsanctioned services, or communication with command and control infrastructure.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
203
KQL Query from file: INC Ransomware Command Execution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
103