avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,987 views

8,664 detections

Detects anomalous activities targeting SaaS CRM applications (Salesforce, Microsoft Dynamics 365, HubSpot), including high-volume bulk exports, off-hours access, mass API queries for sensitive objects, and suspicious OAuth token grants.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
307
Flags HarborWatch RAT C2 traffic from mysql.exe to known malicious IPs.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects inbound RPC calls to the Server Service interface using operation number 12 (NetrSessionEnum), which may indicate remote session enumeration for account discovery and reconnaissance.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Identifies ScreenConnect client service execution initiated by trusted system processes (dfsvc.exe, services.exe) while referencing suspicious top-level domains (.top, .info, .site, .tk, .xyz, .pw, .ml, .club, .cf, ws) in the command line. This activity may indicate unauthorized remote access deployment or abuse of legitimate remote access tools.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Identifies 'forfiles.exe' being executed with a combination of multiple command-line switches ('/c', '/p', '/m' or their hyphenated equivalents). This pattern can indicate automated scripting or malicious Living-off-the-Land activity, where 'forfiles.exe' is used to execute commands on multiple files or in specific directories.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects named pipe activity with remote access enabled, initiated by JsonVMAccessExtension.exe running as SYSTEM. This may indicate abuse of the Azure VM Access Extension for unauthorized remote access.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects trusted .NET tooling launching shells, scripting engines, or administrative utilities that are not typically associated with legitimate compilation workflows, potentially indicating malicious execution or post-exploitation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects multiple attempts by a user account to perform a Directory Synchronization (DirSync) operation, which is a common indicator of a DCSync attack. The rule specifically looks for Event ID 4662 with properties containing 'DS-DirSync' or '131072', filters for user accounts, excludes known service accounts, and triggers if there are 5 or more attempts from the same account and computer.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Adversaries may create an encrypted RAR archive with specific compression level.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects processes loading the Sunburst backdoor DLL.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002