
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,980 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
Phishing-as-a-Service kit abusing OAuth device code flow against Microsoft 365
Campaign converting compromised FortiGate firewalls into credential stealers
Campaign converting compromised FortiGate firewalls into credential stealers
Cloud extortion group exploiting exposed credentials and storage
Campaign converting compromised FortiGate firewalls into credential stealers
Cloud extortion group exploiting exposed credentials and storage
Detects the execution of command-line tools associated with Kerberoasting and Kerberos ticket manipulation techniques, such as requesting TGS tickets or targeting specific user accounts for ticket extraction.
Detects the use of icacls.exe or cacls.exe to modify access control lists (ACLs) on sensitive Windows system directories and files. The rule specifically alerts when these commands are executed by non-Microsoft signed processes, which is a common indicator of unauthorized privilege escalation or persistence mechanisms.
AI-powered phishing-as-a-service abusing device-code authentication
Banking trojan and loader using malicious Office macro delivery
