
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,484 copies160 likes51,969 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects potential automated credential stuffing attempts followed by successful authentication and subsequent access to sensitive/privileged APIs within Azure/Entra ID environments. It correlates multiple failed login attempts for service-oriented account names (e.g., svc, api, bot) with a successful login from the same user shortly thereafter, followed by privileged API operations (e.g., KeyVault secret access, user management) within a short time window.
This rule detects two scenarios on Linux systems: 1. A non-root process interacting with a root process (e.g., cross-process communication where the source is non-root and the target is root). 2. Any process (excluding root) exhibiting indicators related to 'AF_ALG' or 'splice', or mentioning 'CVE-2026-31431' in its name or description. These indicators are often associated with privilege escalation attempts or kernel exploits.
This rule detects the execution of VBScript files (.vbs or .vbe) by wscript.exe or cscript.exe where the filename contains keywords commonly associated with phishing lures (e.g., 'Invoice', 'Bill', 'Statement', 'Report', 'Debit', 'Credit', 'Notice', 'Alert', 'Urgent', 'Payment'). The rule triggers if three or more such executions are observed within a one-hour window on a single device, indicating potential malicious activity often associated with phishing campaigns.
This rule identifies potential account compromise by detecting successful logins to at least two different SaaS applications monitored by Microsoft Cloud App Security (MCAS) within a 2-hour window, originating from geolocations separated by more than 500 kilometers. This behavior is indicative of credential sharing or account hijacking where an adversary accesses multiple cloud services rapidly from geographically distant locations.
Detects when a new federated identity credential is successfully added to an Azure Active Directory (Entra ID) application. This activity is a common method for attackers to establish persistent access to cloud resources by bypassing password-based authentication.
Detects the configuration and usage of personal Microsoft OneDrive accounts on corporate endpoints. This is achieved by monitoring for OneDrive process execution with personal account command-line arguments, OneDrive setup utilities configured with personal tenant identifiers, and file system activity within directory paths associated with personal OneDrive synchronization.
This rule detects the presence of Phoenix malware by identifying known SHA256 hashes of its components or network connections to its command and control (C2) infrastructure. It correlates file events with known malware hashes and network events with known C2 IP addresses.
Detects LampoRAT malware based on known file hash execution.
This rule detects outbound network connections to URLs associated with common file sharing services (e.g., Dropbox, Mega, Gofile) or temporary email providers (e.g., Temp-Mail). Such connections can indicate data exfiltration attempts, use of unsanctioned services, or communication with command and control infrastructure.
KQL Query from file: INC Ransomware Command Execution
